Method for accessing terminal to network, network controller and terminal

Dynamically allocate authorized vlan logos by network controllers, the problems of high management and maintenance costs of dumb terminals and difficulty in automatically accessing the network are solved, and plug-and-play and multi-use of dumb terminals are realized, reducing operation and maintenance workload and improving network security.

CN120017291APending Publication Date: 2025-05-16RUIJIE NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311525959.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-16
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the park office network, dumb terminals have high management and maintenance costs, and cannot be automatically accessed, which poses security risks. The existing solutions have problems such as MAC address collection dependency, single-service network isolation, and high operation and maintenance costs.

Method used

The network controller receives terminal feature information sent by the switch, determines the terminal type, and dynamically allocates the authorized virtual LAN vlan identification to realize the automatic network access and vlan follow-up of dumb terminals, without the need for an administrator to collect MAC addresses in advance.

Benefits of technology

It realizes plug-and-play for dumb terminals, reduces operation and maintenance workload, supports one-network multi-use and business network isolation, and improves network management efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017291A_ABST
    Figure CN120017291A_ABST
Patent Text Reader

Abstract

The invention discloses a method for accessing a terminal to a network, the terminal and a network controller, and the method comprises the steps: receiving a first message which is transmitted by a switch and comprises the feature information of the terminal under the condition that the terminal accesses the switch; determining the type of the terminal according to the feature information; when the terminal type is a first terminal type, allocating an identifier of an authorized virtual local area network vlan corresponding to the first terminal type to the terminal, and sending a white list to the switch, and the terminal sends a second message to equipment in the authorized virtual local area network vlan after passing the white list authentication of the switch, so that vlan following and plug-and-play can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data communication, in particular to a method for a terminal to access a network, a network controller and a terminal. Background Art

[0002] In the park office network, dumb terminals are diverse, including telephones, access control, printers, money counters, electronic display screens, interactive tablets, etc. These dumb terminals bring great management and maintenance costs to network administrators: first, it is impossible to determine the number of dumb terminals connected to the network and the regional locations of the dumb terminals; second, there are devices that counterfeit dumb terminals without authorization to access the network, resulting in security risks; third, in a multi-service network environment, dumb terminals cannot be automatically connected to the network and need to be manually configured by the administrator.

[0003] At present, there are several solutions to the problem of dumb terminals having difficulty accessing the network:

[0004] Solution 1: Using MAC (Media Access Control Address) authentication, the administrator collects the MAC address of the dumb terminal and configures the dumb terminal's authorized virtual LAN VLAN (Virtual Local Area Network) and network access policy on the authentication server in advance. When the dumb terminal accesses the network, it is automatically authorized to the corresponding service network through MAC-aware authentication, realizing dumb terminal non-aware access.

[0005] Solution 2: Use the terminal access control solution. The interface opens the access control function. After the dumb terminal enters the network, it triggers the SDN (Software Defined Network) controller to pop up the approval page. After the administrator approves it on the web page, the dumb terminal automatically enters the network.

[0006] Solution 3: Use static configuration to directly configure the MAC address binding of the dumb terminal on the interface of each dumb terminal access device to implement dumb terminal control and network access.

[0007] The above solutions all have certain defects:

[0008] Solution 1 requires collecting the MAC information of dumb terminals in advance and entering it into the authentication server. This cannot be implemented if the authentication server does not support authorized VLAN or does not support MAC import.

[0009] Solution 2 can implement dumb terminal access control, but it cannot support isolation of multiple business networks and can only be implemented on one business network.

[0010] Solution 3 has high manual operation and maintenance costs, and when the terminal is migrated, there will be a large amount of operation and maintenance workload. Summary of the invention

[0011] In order to solve the above technical problems, the embodiments of the present application adopt the following technical solutions:

[0012] A first aspect of an embodiment of the present application is to provide a method for a terminal to access a network, which is applied in a network controller and includes:

[0013] When the terminal is connected to the switch, a first message including characteristic information of the terminal is received from the switch;

[0014] Determine the type of the terminal according to the characteristic information;

[0015] When the terminal type is the first terminal type, the identifier of the authorized virtual local area network VLAN corresponding to the first terminal type is assigned to the terminal, and a whitelist is sent to the switch, so that the terminal sends a second message to the device in the authorized virtual local area network VLAN after passing the switch whitelist authentication.

[0016] In one possible implementation, the method further includes:

[0017] When the terminal type is the second terminal type, an authentication request initiated by the terminal is received, and when the authentication is passed, an identifier of an authorized virtual local area network VLAN corresponding to the second terminal type is assigned to the terminal, and the switch is instructed to allow the message sent by the terminal to pass, so that the terminal can send a second message to a device in a service network corresponding to the authorized virtual local area network VLAN through the switch.

[0018] In a possible implementation, before receiving the first message sent by the switch and containing the characteristic information of the terminal, the method further includes:

[0019] A temporary IP address is sent to the terminal, wherein the temporary IP address is used by the terminal to send the first message through the switch in a default VLAN according to the temporary IP address.

[0020] In a possible implementation, the first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

[0021] Another aspect of an embodiment of the present application is to provide a method for a terminal to access a network, which is applied to a terminal and includes:

[0022] Sending a first message including characteristic information of the terminal to a network controller through a switch, so that the network controller determines the type of the terminal according to the characteristic information;

[0023] When the terminal type is a first terminal type, receiving an identifier of an authorized virtual local area network (vlan) corresponding to the first terminal type allocated by the network controller,

[0024] After the network controller sends the whitelist to the switch and the terminal passes the whitelist authentication, a second message is sent to the device in the authorized virtual local area network (vlan) through the switch.

[0025] In a possible implementation, sending the first message including the characteristic information of the terminal to the network controller through the switch includes:

[0026] Receiving a temporary IP address sent by the network controller;

[0027] According to the temporary IP address being in the default VLAN, the first message is sent to the network controller through the switch.

[0028] In a possible implementation, after receiving the temporary IP address sent by the network controller, the method further includes:

[0029] After the temporary IP address expires, receiving a non-temporary IP address corresponding to the authorized VLAN sent by a DHCP server;

[0030] A second message is sent through the switch to a device in the service network corresponding to the authorized VLAN according to the non-temporary IP address.

[0031] Another aspect of the embodiment of the present application is to provide a network controller, including:

[0032] A receiving module, configured to receive a first message including characteristic information of the terminal sent by the switch when the terminal is connected to the switch;

[0033] An identification module, used to determine the type of the terminal according to the characteristic information;

[0034] The sending module is used to assign an identifier of an authorized virtual local area network (VLAN) corresponding to the first terminal type to the terminal when the terminal type is the first terminal type, and send a whitelist to the switch so that the terminal can send a second message to a device in the authorized virtual local area network (VLAN) after passing the whitelist authentication of the switch.

[0035] Another aspect of an embodiment of the present application is to provide a terminal for accessing a network, including:

[0036] A first sending module, configured to send a first message including characteristic information of the terminal to a network controller through a switch, so that the network controller determines the type of the terminal according to the characteristic information;

[0037] a first receiving module, configured to receive, when the terminal type is a first terminal type, an identifier of an authorized virtual local area network (vlan) corresponding to the first terminal type and allocated by the network controller;

[0038] The second sending module is used to send a second message to the device in the authorized virtual local area network (vlan) through the switch after the network controller sends the white list to the switch and the terminal passes the white list authentication.

[0039] Another aspect of the embodiment of the present application is to provide a system for a terminal to access a network, comprising:

[0040] The switch is used to send a first message containing characteristic information of the terminal to the network controller when the terminal is connected to the switch;

[0041] A network controller is used to receive the first message; determine the type of the terminal according to the characteristic information; when the terminal type is the first terminal type, assign an identifier of an authorized virtual local area network (VLAN) corresponding to the first terminal type to the terminal, and send a whitelist to the switch, so that the terminal can send a second message to a device in the authorized virtual local area network (VLAN) after passing the whitelist authentication of the switch.

[0042] Another aspect of the embodiments of the present application is to provide an electronic device, including:

[0043] Memory, used to store computer programs;

[0044] The processor is used to implement the method steps described in the first aspect when executing the computer program stored in the memory.

[0045] Another aspect of the embodiments of the present application is to provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the method for terminal accessing a network described in the first aspect above.

[0046] The beneficial effect of the embodiment of the present application is that for terminals accessing the network, such as dumb terminals, VLAN following and plug-and-play can be realized without the need for administrators to collect terminal MAC address information in advance. At the same time, one network is used for multiple purposes, and different service networks are isolated from each other. When the terminal is migrated, the operation and maintenance workload is reduced.

[0047] Other features and advantages of the present application will be described in the following description. The purpose and other advantages of the present application can be realized and obtained through the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0049] Figure 1 A method flow chart provided for an embodiment of the present application;

[0050] Figure 2 A method flow chart provided for an embodiment of the present application;

[0051] Figure 3 A method flow chart provided for an embodiment of the present application;

[0052] Figure 4 A method flow chart provided for an embodiment of the present application;

[0053] Figure 5 A device flow chart provided for an embodiment of the present application;

[0054] Figure 6 A device structure diagram provided for an embodiment of the present application;

[0055] Figure 7 A device structure diagram provided for an embodiment of the present application;

[0056] Figure 8 A device structure diagram provided for an embodiment of the present application. DETAILED DESCRIPTION

[0057] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the technical solution of the present application, rather than all of the embodiments. Based on the embodiments recorded in the present application documents, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the technical solution of the present application.

[0058] The terms "first" and "second" in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any of their variations are intended to cover non-exclusive protection. For example, a process, method, system, product or device comprising a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices. "Multiple" in the present application can mean at least two, for example, two, three or more, and the embodiments of the present application are not limited.

[0059] In addition, the term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article, unless otherwise specified, generally indicates that the associated objects before and after are in an "or" relationship.

[0060] A first aspect of an embodiment of the present application is to provide a method for a terminal to access a network, which is applied in a network controller, such as Figure 1 As shown, including

[0061] S101, when a terminal is connected to a switch, receiving a first message including characteristic information of the terminal sent by the switch;

[0062] In a possible implementation, this step may specifically include: when the terminal accesses the switch and initiates MAC authentication but fails, receiving a first message including characteristic information of the terminal sent by the switch.

[0063] S103, determining the type of the terminal according to the characteristic information;

[0064] S105, when the terminal type is the first terminal type, assign an identifier of an authorized virtual local area network (vlan) corresponding to the first terminal type to the terminal, and send a whitelist to the switch, so that the terminal sends a second message to a device in the authorized virtual local area network (vlan) after passing the whitelist authentication of the switch.

[0065] Among them, in a possible implementation, such as Figure 2 As shown, including

[0066] S107, when the terminal type is the second terminal type, receiving an authentication request initiated by the terminal, and when the authentication is successful, allocating an identifier of the authorized virtual local area network VLAN corresponding to the second terminal type to the terminal, and instructing the switch to allow the message sent by the terminal to pass, so that the terminal can send a second message to a device in a service network corresponding to the authorized virtual local area network VLAN through the switch.

[0067] In a possible implementation, before receiving the first message sent by the switch and containing the characteristic information of the terminal, Figure 3 As shown, it also includes:

[0068] S1011, sending a temporary IP address to the terminal, wherein the temporary IP address is used by the terminal to send the first message through the switch in a default VLAN according to the temporary IP address.

[0069] In a possible implementation, the first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

[0070] The beneficial effect of the embodiment of the present application is that for terminals accessing the network, such as dumb terminals, VLAN following and plug-and-play can be realized without the need for administrators to collect terminal MAC address information in advance. At the same time, one network is used for multiple purposes, and different service networks are isolated from each other. When the terminal is migrated, the operation and maintenance workload is reduced.

[0071] In one possible implementation, the method further includes:

[0072] Establish a correspondence between terminal types and service networks, where each service network corresponds to an authorized virtual local area network (VLAN);

[0073] In a possible implementation, in one embodiment of the present application, the first terminal type is a dumb terminal, and the second terminal type is an intelligent terminal. A dumb terminal is a terminal that relies on a host to process. Generally speaking, a dumb terminal does not have a processor, a hard disk or a floppy disk, but only a keyboard, a display and a communication path to the host (usually through some types of controllers). The dumb terminal cannot actively initiate an authentication request and does not have the function of initiating authentication. In this way, the dumb terminal cannot obtain an authorized VLAN through the authentication path, and access the switch. It can only rely on the network controller to identify that its terminal type is a dumb terminal, actively assign the authorized VLAN identifier to the dumb terminal, and send a white list to the switch so that the dumb terminal's message can pass through the switch. The intelligent terminal has its own processor, storage device and software program, can actively initiate an authentication request, and has the function of initiating authentication. In this way, the intelligent terminal can obtain the authorized VLAN identifier through the authentication path, and access the switch. The intelligent terminal's message can pass through the switch without the need for the network controller to assign the authorized VLAN identifier and send a white list to the switch. This embodiment can realize automatic identification and security management and control in the scenario where dumb terminals and intelligent terminals are shared.

[0074] Among them, the terminal can be assigned an identifier of an authorized virtual local area network VLAN corresponding to the first terminal type or the second terminal type through various management protocols such as NETCONF (Network Configuration Protocol), CLI (command-line interface), TR069 (CPE Wide Area Network Management Protocol), etc.

[0075] In one possible implementation, the method further includes:

[0076] When the terminal type is the first terminal type and the first message contains a non-temporary IP address of the terminal, an identifier of an authorized virtual local area network (vlan) corresponding to the first terminal type is assigned to the terminal, and a whitelist is sent to the switch so that the terminal can send a second message to a device in the authorized virtual local area network (vlan) through the switch according to the non-temporary IP address.

[0077] In this embodiment, the first message includes the non-temporary IP address of the terminal, so that the terminal can send the second message to the device in the authorized virtual local area network vlan through the switch according to the non-temporary IP address. It is not necessary to re-initiate a DHCP (Dynamic Host Configuration Protocol) request to obtain an IP address after the temporary IP address ages, and then send the second message.

[0078] In one possible implementation, the method further includes:

[0079] When the terminal type is the second terminal type and the first message includes a non-temporary IP address of the terminal, an authentication request initiated by the terminal is received.

[0080] When the authentication is passed, the terminal is assigned an identifier of the authorized virtual local area network (vlan) corresponding to the second terminal type, and the switch is instructed to allow the message sent by the terminal to pass, so that the terminal can send the second message to the device in the authorized virtual local area network (vlan) through the switch according to the non-temporary IP address.

[0081] In one possible implementation,

[0082] The determining the type of the terminal according to the characteristic information includes:

[0083] The first message is collected and the type of the terminal is determined according to the terminal feature information in the collected first message.

[0084] A temporary IP address is an IP address with a shorter lease, such as 1 or 2 minutes. A non-temporary IP address is an IP address with a longer lease, a static IP address, or a fixed IP address.

[0085] Among them, terminal identification technology can be used in conjunction with terminal anti-counterfeiting technology to achieve strategic blocking of counterfeit terminals.

[0086] Among them, a DHCP (Dynamic Host Configuration Protocol) function can be deployed on the network controller, a DHCP temporary address pool can be set, and a temporary IP address can be sent to the terminal. With the temporary IP address, the terminal can send the first message through the switch in the default VLAN.

[0087] In a possible implementation, after the terminal obtains the non-temporary IP address, the step of sending the second message to the device in the authorized virtual local area network vlan through the switch specifically includes:

[0088] After the temporary IP address expires, the terminal obtains a non-temporary IP address corresponding to the authorized VLAN sent by the DHCP server, and sends a second message to a device in a service network corresponding to the authorized VLAN through the switch.

[0089] The non-temporary IP address corresponding to the authorized first VLAN may also be obtained from other devices with DHCP function, such as a network controller. In this embodiment, the network controller is deployed with DHCP function.

[0090] Among them, non-temporary IP addresses refer to IP addresses with longer leases, static IP addresses, or fixed IP addresses. For example, the lease is 1 day or 2 days.

[0091] Among them, after the switch receives the port close / open command sent by the network controller, the terminal can initiate a request for an IP address to the DHCP server to obtain the non-temporary IP address corresponding to the authorized VLAN sent by the DHCP server, and send a second message to the device in the service network corresponding to the authorized VLAN through the switch.

[0092] Another aspect of the present application is to provide a method for a terminal to access a network, which is applied to a terminal, such as Figure 4 As shown, including:

[0093] S401, sending a first message including characteristic information of the terminal to a network controller through a switch, so that the network controller determines the type of the terminal according to the characteristic information;

[0094] S403, when the terminal type is a first terminal type, receiving an identifier of an authorized virtual local area network (vlan) corresponding to the first terminal type allocated by the network controller,

[0095] S405, after the network controller sends the whitelist to the switch and the terminal passes the whitelist authentication, a second message is sent to a device in the authorized virtual local area network (vlan) through the switch.

[0096] In a possible implementation, sending the first message including the characteristic information of the terminal to the network controller through the switch includes:

[0097] Receiving a temporary IP address sent by the network controller;

[0098] According to the temporary IP address being in the default VLAN, the first message is sent to the network controller through the switch.

[0099] In a possible implementation, after receiving the temporary IP address sent by the network controller, the method further includes:

[0100] After the temporary IP address expires, receiving a non-temporary IP address corresponding to the authorized VLAN sent by a DHCP server;

[0101] A second message is sent through the switch to a device in the service network corresponding to the authorized VLAN according to the non-temporary IP address.

[0102] The beneficial effect of the embodiment of the present application is that for terminals accessing the network, such as dumb terminals, VLAN following and plug-and-play can be realized without the need for administrators to collect terminal MAC address information in advance. At the same time, one network is used for multiple purposes, and different service networks are isolated from each other. When the terminal is migrated, the operation and maintenance workload is reduced.

[0103] Another aspect of the present application is to provide a network controller such as Figure 5 As shown, including,

[0104] The receiving module 501 is configured to receive a first message including characteristic information of the terminal sent by the switch when the terminal is connected to the switch;

[0105] An identification module 503, configured to determine the type of the terminal according to the characteristic information;

[0106] The sending module 505 is used to assign an identifier of an authorized virtual local area network (VLAN) corresponding to the first terminal type to the terminal when the terminal type is the first terminal type, and send a whitelist to the switch so that the terminal can send a second message to the device in the authorized virtual local area network (VLAN) after passing the whitelist authentication of the switch.

[0107] The beneficial effect of the embodiment of the present application is that for terminals accessing the network, such as dumb terminals, VLAN following and plug-and-play can be realized without the need for administrators to collect terminal MAC address information in advance. At the same time, one network is used for multiple purposes, and different service networks are isolated from each other. When the terminal is migrated, the operation and maintenance workload is reduced.

[0108] In one possible implementation, Figure 6 As shown, the network controller also includes,

[0109] Establishing module 507, used to establish a correspondence between terminal types and service networks, wherein each service network corresponds to an authorized virtual local area network vlan;

[0110] In one possible implementation,

[0111] The sending module 505 is also used to, when the terminal type is the first terminal type and the first message contains the non-temporary IP address of the terminal, assign an identifier of the authorized virtual local area network VLAN corresponding to the first terminal type to the terminal, and send a whitelist to the switch, so that the terminal can send a second message to the device in the service network corresponding to the authorized virtual local area network VLAN according to the non-temporary IP address and after passing the whitelist authentication of the switch.

[0112] In one possible implementation, Figure 7 As shown, the network controller also includes,

[0113] an authentication module 509, configured to receive an authentication request initiated by the terminal when the terminal type is the second terminal type and the first message contains a non-temporary IP address of the terminal,

[0114] The sending module 505 is also used to, when authentication is passed, assign an identifier of an authorized virtual local area network VLAN corresponding to the second terminal type to the terminal, and instruct the switch to allow the message sent by the terminal to pass, so that the terminal can send a second message to a device in a service network corresponding to the authorized virtual local area network VLAN through the switch according to the non-temporary IP address.

[0115] Another aspect of the embodiment of the present application is to provide a terminal for accessing a network, such as Figure 8 As shown, including,

[0116] A first sending module 801 is used to send a first message containing characteristic information of the terminal to a network controller through a switch, so that the network controller determines the type of the terminal according to the characteristic information;

[0117] The first receiving module 803 is configured to receive, when the terminal type is a first terminal type, an identifier of an authorized virtual local area network (VLAN) corresponding to the first terminal type and allocated by the network controller,

[0118] The second sending module 805 is used to send a second message to the device in the authorized virtual local area network (vlan) through the switch after the network controller sends the white list to the switch.

[0119] The beneficial effect of the embodiment of the present application is that for terminals accessing the network, such as dumb terminals, VLAN following and plug-and-play can be realized without the need for administrators to collect terminal MAC address information in advance. At the same time, one network is used for multiple purposes, and different service networks are isolated from each other. When the terminal is migrated, the operation and maintenance workload is reduced.

[0120] Another aspect of the embodiment of the present application is to provide a system for a terminal to access a network, comprising:

[0121] The switch is used to send a first message containing characteristic information of the terminal to the network controller when the terminal is connected to the switch;

[0122] A network controller is used to receive the first message; determine the type of the terminal according to the characteristic information; when the terminal type is the first terminal type, assign an identifier of an authorized virtual local area network (VLAN) corresponding to the first terminal type to the terminal, and send a whitelist to the switch, so that the terminal can send a second message to a device in the authorized virtual local area network (VLAN) after passing the whitelist authentication of the switch.

[0123] The beneficial effect of the embodiment of the present application is that for terminals accessing the network, such as dumb terminals, VLAN following and plug-and-play can be realized without the need for administrators to collect terminal MAC address information in advance. At the same time, one network is used for multiple purposes, and different service networks are isolated from each other. When the terminal is migrated, the operation and maintenance workload is reduced.

[0124] Another aspect of the embodiments of the present application is to provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the method for terminal accessing a network described in the first aspect above.

[0125] Another aspect of the embodiments of the present application is to provide an electronic device, including:

[0126] Memory, used to store computer programs;

[0127] The processor is used to implement the method steps described in the first aspect when executing the computer program stored in the memory.

[0128] The beneficial effect of the embodiment of the present application is that for terminals accessing the network, such as dumb terminals, VLAN following and plug-and-play can be realized without the need for administrators to collect terminal MAC address information in advance. At the same time, one network is used for multiple purposes, and different service networks are isolated from each other. When the terminal is migrated, the operation and maintenance workload is reduced.

[0129] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0130] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a controller of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the controller of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0131] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0132] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0133] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.

[0134] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

[0135] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0136] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0137] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0138] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for a terminal to access a network, applied in a network controller, characterized in that: include: When the terminal accesses the switch, receiving a first message sent by the switch and containing characteristic information of the terminal; Determine the type of the terminal according to the characteristic information; When the terminal type is the first terminal type, an identifier of an authorized virtual local area network (VLAN) corresponding to the first terminal type is assigned to the terminal, and a whitelist is sent to the switch, so that the terminal sends a second message to a device in the authorized virtual local area network (VLAN) after passing the switch whitelist authentication.

2. The method according to claim 1, characterized in that Also includes: When the terminal type is the second terminal type, an authentication request initiated by the terminal is received, and when the authentication is passed, an identifier of an authorized virtual local area network VLAN corresponding to the second terminal type is assigned to the terminal, and the switch is instructed to allow the message sent by the terminal to pass, so that the terminal can send a second message to a device in a service network corresponding to the authorized virtual local area network VLAN through the switch.

3. The method according to claim 1 or 2, characterized in that Before receiving the first message sent by the switch and containing the characteristic information of the terminal, the method further includes: A temporary IP address is sent to the terminal, wherein the temporary IP address is used by the terminal to send the first message through the switch in a default VLAN according to the temporary IP address.

4. A method for a terminal to access a network, applied to a terminal, characterized in that: include: Sending a first message including characteristic information of the terminal to a network controller through a switch, so that the network controller determines the type of the terminal according to the characteristic information; When the terminal type is a first terminal type, receiving an identifier of an authorized virtual local area network (vlan) corresponding to the first terminal type allocated by the network controller; After the network controller sends the whitelist to the switch and the terminal passes the whitelist authentication, a second message is sent to the device in the authorized virtual local area network (vlan) through the switch.

5. The method according to claim 4, characterized in that The sending of the first message including the characteristic information of the terminal to the network controller through the switch includes: Receiving a temporary IP address sent by the network controller; According to the temporary IP address being in the default VLAN, the first message is sent to the network controller through the switch.

6. The method according to claim 5, characterized in that After receiving the temporary IP address sent by the network controller, the method further includes: After the temporary IP address expires, receiving a non-temporary IP address corresponding to the authorized VLAN sent by a DHCP server; A second message is sent through the switch to a device in the service network corresponding to the authorized VLAN according to the non-temporary IP address.

7. A network controller, characterized in that: include, A receiving module, configured to receive a first message including characteristic information of the terminal sent by the switch when the terminal is connected to the switch; An identification module, used to determine the type of the terminal according to the characteristic information; The sending module is used to assign an identifier of an authorized virtual local area network (VLAN) corresponding to the first terminal type to the terminal when the terminal type is the first terminal type, and send a whitelist to the switch so that the terminal can send a second message to a device in the authorized virtual local area network (VLAN) after passing the whitelist authentication of the switch.

8. A terminal for accessing a network, characterized in that: include: A first sending module, configured to send a first message including characteristic information of the terminal to a network controller through a switch, so that the network controller determines the type of the terminal according to the characteristic information; a first receiving module, configured to receive, when the terminal type is a first terminal type, an identifier of an authorized virtual local area network (vlan) corresponding to the first terminal type and allocated by the network controller; The second sending module is used to send a second message to the device in the authorized virtual local area network (vlan) through the switch after the network controller sends the white list to the switch and the terminal passes the white list authentication.

9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, for implementing the method steps of any one of claims 1 to 3 or 4 to 6 when executing the computer program stored in the memory.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method steps as described in any one of claims 1 to 3 or 4 to 6 are implemented.