Authentication process between network device and client
Provide server certificates to network devices through the certificate registration server, and use orchestration servers to manage the certificate registration server, solving the problem of electronic devices being unable to connect when the authentication server is unavailable, and achieving simplification and security of authentication viability and certificate management.
Patent Information
- Application Number
- CN202410936237.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-07-12
- Publication Date
- 2025-05-23
AI Technical Summary
In the prior art, when the authentication server is unavailable, electronic devices cannot maintain connection with the network, resulting in users being unable to use network resources, and manually uploading the server certificate is time-consuming and prone to errors, posing security risks.
Automatically provide server certificates to network devices through the certificate registration server, allowing network devices to support authentication survivability when the authentication server is unavailable, and simplify the certificate acquisition process by orchestrating the server.
This enables network devices to continue to provide authentication services when the authentication server is unavailable, ensuring the stable network connection of electronic devices, and reducing the risk and complexity of manually uploading certificates.
Smart Images

Figure CN120034348A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present disclosure generally relate to the field of communications, and in particular to a method for an authentication process between a network device and a client, a network device, and a non-transitory machine-readable storage medium. Background Art
[0002] Electronic devices can communicate via a network, which can include a wireless network or a wired network. A network can include network devices with which electronic devices can associate to gain access to the network. Summary of the invention
[0003] In general, embodiments of the present disclosure provide a method for an authentication process between a network device and a client, a network device, and a non-transitory machine-readable storage medium.
[0004] In a first aspect, a non-transitory machine-readable storage medium is provided, the non-transitory machine-readable storage medium comprising instructions that, when executed, cause a network device to: receive, at the network device, from an orchestration server a name for obtaining a certificate; send, from the network device, a certificate request including the name to a certificate enrollment server; receive, at the network device, a response to the certificate request from the certificate enrollment server, the response including information about a certificate, the certificate being based on the name in the certificate request; detect that an authentication server is unavailable for an authentication process of a client coupled to the network device; and based on detecting that the authentication server is unavailable, use a certificate based on the name in the certificate request as part of an authentication process between the network device and the client.
[0005] In a second aspect, a network device is provided, comprising: a hardware processor; and a non-transitory storage medium storing instructions, the instructions being executable on the hardware processor to: receive, at the network device, from an orchestration server a name for obtaining a first certificate of the network device, the name received from the orchestration server being the same as a name used by an authentication server to obtain a second certificate of the authentication server; send, from the network device, a certificate request including the name to a certificate registration server; receive, at the network device, a response to the certificate request from the certificate registration server, the response including information of a first certificate, the first certificate being based on the name in the certificate request; derive the first certificate from the information of the first certificate; and store the first certificate in a memory of the network device for use in an authentication process performed by the network device in response to the authentication server being unavailable.
[0006] In a third aspect, a method is provided, comprising: receiving, at a network device, identification information and parameters for inclusion in a certificate request from an orchestration server, the identification information identifying a certificate registration server, the parameters including a name for obtaining a certificate; sending, from the network device, a certificate request including the parameters to a certificate registration server identified by the identification information; receiving, at the network device, a response to the certificate request from the certificate registration server, the response including information of a certificate based on a name that is one of the parameters included in the certificate request; detecting, by the network device, that an authentication server is unavailable for an authentication process of a client coupled to the network device; and based on detecting that the authentication server is unavailable, using, by the authentication server, a certificate based on the name in the certificate request as part of the authentication process between the network device and the client. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] Some implementations of the present disclosure will be described in conjunction with the following figures.
[0008] Figure 1 is a block diagram of a network arrangement including an access point (AP) capable of supporting authentication survivability according to some examples.
[0009] Figure 2 is a block diagram of an arrangement including orchestrating servers to support use of a certificate enrollment server according to some examples.
[0010] Figure 3 is a flow diagram of a process performed by an AP according to some examples.
[0011] Figure 4 is a block diagram of a storage medium storing machine-readable instructions according to some examples.
[0012] Figure 5 is a block diagram of a network device according to some examples.
[0013] Figure 6 is a flow diagram of a process according to some examples.
[0014] Throughout the drawings, the same reference numerals denote similar, but not necessarily identical, elements. The drawings are not necessarily to scale, and the dimensions of some parts may be exaggerated in order to more clearly illustrate the examples shown. In addition, the drawings provide examples and / or embodiments consistent with the description; however, the description is not limited to the examples and / or embodiments provided in the drawings. DETAILED DESCRIPTION
[0015] An electronic device can obtain access to a network by associating with a network device. In some examples, the network device can be a wireless access point (AP) to which the electronic device can establish a wireless connection. In other examples, the network device can include a switch (a layer 2 switch or a layer 3 router) to which the electronic device can connect using a wired connection. Before the electronic device is granted access to network resources, an authentication process is performed between the electronic device and an authentication server. After the electronic device is successfully authenticated by the authentication server, the electronic device is granted access to the network resources.
[0016] Authentication survivability refers to the ability to provide a network connection for an electronic device even if an authentication server is unavailable. For example, an authentication server may become unavailable due to a failure at the authentication server (e.g., a hardware failure, a failure of machine-readable instructions such as software or firmware, or other failure). As another example, an authentication server may become unavailable due to a loss of network connection to the authentication server. If the electronic device cannot connect to the network or cannot maintain a connection to the network when the authentication server becomes unavailable, the user is prevented from using the electronic device to access network resources. In addition, the loss of network connection will cause the operation of the electronic device on the network to be interrupted.
[0017] Authentication survivability can be achieved by configuring an authentication server function for a network device (such as a wireless AP, a switch, or other network device), so that when the authentication server becomes unavailable, the network device can perform the authentication process together with the electronic device coupled to the network device. The electronic device can determine whether to trust the network device based on a server certificate at the network device (such as a Remote Authentication Dial-In User Service (RADIUS) server certificate). In some cases, a user (such as a network administrator) can manually upload a server certificate and a private key used by the authentication server to the network device, so that the network device can provide the server certificate to the electronic device, enabling the electronic device to verify the credibility of the network device. However, if any network device is damaged (such as infected by malware, hacked by an authorized user, etc.), the security of all network devices and the authentication server may be compromised due to the exposure of the security certificate and private key on the damaged network device.
[0018] In other examples, a user can manually upload a dedicated server certificate to different network devices (i.e., provide each network device with a corresponding different server certificate). In this way, even if one network device becomes compromised, other network devices and the authentication server will not be compromised because they use different dedicated server certificates. However, manually uploading a dedicated server certificate to a network device is time-consuming and error-prone. In addition, manual communication of the server certificate may occur over an insecure communication channel, which may allow an attacker (e.g., a malware program, a compromised machine, a user, or other entity) to gain unauthorized access to the server certificate.
[0019] According to some implementations of the present disclosure, a certificate enrollment server is used to automatically provide a server certificate to a network device to which an electronic device is coupled (via wireless or wired connection), so that the network device can support authentication survivability in the event that an authentication server is unavailable. The server certificates provided to network devices of different network providers are different. Therefore, even if one network device is damaged, the server certificates of other network devices are still not exposed, and other network devices can continue to operate securely. For a given network provider (e.g., X company) operating a network device, the name of the given network provider can be provided to both the authentication server and the network device. The authentication server may send a first certificate request containing a name to a certificate enrollment server (e.g., a secure transmission protocol enrollment (EST) server). In response, the certificate enrollment server provides a server certificate to the authentication server based on the name in the first certificate request. The network device may send a second certificate request containing the same name to the certificate enrollment server, and in response, the certificate enrollment server provides a server certificate to the network device based on the name in the second certificate request. If the authentication server becomes unavailable, the network device can take over to provide authentication services to the electronic device coupled to the network device. During the authentication process, the network device provides the electronic device with a server certificate received from the certificate enrollment server. Since the server certificate received from the certificate enrollment server is based on the name of the network provider of the network device, the electronic device can establish a trust relationship with the network device.
[0020] A "certificate" may refer to digital information, which may be in the form of a file or other type of object, that contains information such as the identity of the entity to be authenticated based on the certificate. A "server certificate" may refer to a server's certificate, which a client may use to authenticate the server. In a network context, a client may use a server certificate to authenticate a network device (i.e., determine that the network device can be trusted by the client). As described above, examples of network devices may include a wireless AP, a switch, or any other type of network device.
[0021] Figure 1 1 is a block diagram of an example network arrangement including a wireless AP 102 to which an electronic device 104 may be associated to allow the electronic device 104 to access a network 103 including the AP 102. Examples of the electronic device 104 may include any one or some combination of the following: a computer (desktop computer, notebook computer, tablet computer, server computer, etc.), a smartphone, a gaming device, an Internet of Things (IoT) device, a vehicle, a home appliance, or any other type of electronic device. Before the electronic device 104 is associated with the AP 102, the electronic device 104 first performs an authentication process to authenticate the electronic device 104.
[0022] The network 103 may include a wireless network, such as a wireless local area network (WLAN). The WLAN may include one or more APs having respective coverage areas with which electronic devices can establish wireless connections. In other examples, the network 103 may include a cellular network, and the AP 102 may be a base station of the cellular network.
[0023] In other examples, network 103 may be a wired network having one or more network devices (eg, switches) with which electronic devices may associate to gain access to the wired network.
[0024] The network arrangement also includes an authentication server 106, through which the client can perform an authentication process to allow the client to gain access to a target resource, such as network 103. In some examples, the authentication server 106 is a Remote Authentication Dial-In User Service (RADIUS) server. RADIUS refers to a network protocol that provides authentication, authorization, and accounting (AAA) management for clients.
[0025] In some examples, the authentication process performed between the client and the authentication server 106 is performed according to the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) protocol, which is described in Request for Comments (RFC) 5216 entitled "EAP-TLS Authentication Protocol" published in March 2008. The authentication process according to EAP-TLS can be an Institute of Electrical and Electronics Engineers (IEEE) 802.1X authentication process. The EAP-TLS protocol used in the IEEE 802.1X authentication process allows the client and the authentication server 106 to use their respective certificates to verify their identities to each other and perform mutual authentication. The certificates used can be X.509 certificates, including server certificates and client certificates. X.509 is an International Telecommunication Union (ITU) standard that defines the format of public key certificates, such as server certificate 110.
[0026] Although specific protocols or standards are referenced in this discussion, it is noted that other protocols or standards may be used in other examples, such as those related to authentication, obtaining or generating credentials, or other activities. "Protocol" may refer to a standardized protocol, an open source protocol, or a proprietary protocol.
[0027] A "client" may refer to an electronic device, such as electronic device 104, or a program in an electronic device. A "server" may refer to a computing platform including one or more computers. A server may be accessed by a client to provide requested operations, such as performing authentication to obtain access to a target resource.
[0028] The authentication server 106 may be a remote authentication server located in the cloud or any other location remote from the location of the AP 102. In other examples, the authentication server 106 and the AP 102 may be co-located in a physical facility, such as a building, an office, a retail location, or any other location. In examples where the authentication server 106 is a remote authentication server, the authentication server 106 may provide for performing authentication processes for clients of different customers (e.g., different companies, different organizations, different users, etc.).
[0029] As described above, in some cases, authentication server 106 may become unavailable due to any of a variety of reasons. If authentication server 106 becomes unavailable, electronic devices including electronic device 104 will be unable to access the network of AP 102 due to failure to successfully perform the authentication process with authentication server 106.
[0030] Furthermore, in some cases, even if the electronic device has successfully performed an authentication process with authentication server 106 to gain access to network 103, there may be conditions under which the electronic device may have to subsequently re-authenticate with authentication server 106 in order to maintain connection with network 103. If authentication server 106 becomes unavailable while the electronic device is attempting to re-authenticate, the electronic device may lose connection with network 103 due to an inability to perform re-authentication.
[0031] Examples of triggers for re-authentication may include time-based triggers, roaming-based triggers, power conversion triggers, or any other triggers. The time-based trigger may be a trigger based on the expiration of a time interval. After the time interval expires since the last time the electronic device successfully performed an authentication process, the electronic device will be triggered to perform re-authentication with the authentication server 106.
[0032] A roaming-based trigger may be a trigger in response to an electronic device roaming between different APs. When an electronic device moves between coverage areas of different APs, the electronic device may lose connection with a first AP and establish a connection with a second AP. Under certain conditions, due to such roaming, the electronic device may have to perform re-authentication with the authentication server 106.
[0033] The power transition trigger may be a trigger caused by the electronic device transitioning from a lower power state (e.g., a sleep state, a hibernation state, a shutdown state, or any other lower power state) to an operational state, in which the electronic device executes machine-readable instructions (e.g., an operating system (OS), an application, or other machine-readable instructions). When the electronic device transitions from a low power state to an operational state, the electronic device may have to re-authenticate with the authentication server 106.
[0034] According to some implementations of the present disclosure, AP 102 includes an authentication service 108 to support authentication survivability in the event that authentication server 106 becomes unavailable. A "service" may refer to machine-readable instructions executed on a computing platform (e.g., AP 102 or any other computing platform). In some examples, authentication service 108 is a RADIUS service or any other type of authentication service that can perform authentication procedures with a client, such as an EAP-TLS authentication procedure.
[0035] The authentication process may involve the electronic device 104 and the authentication service 108 verifying the identities of each other using the respective certificates of the electronic device 104 and the AP 102. The certificate of the electronic device 104 is a client certificate, and the certificate of the AP 102 is a server certificate 110. The electronic device 104 provides the client certificate to the authentication service 108 to allow the authentication service 108 to verify the identity of the electronic device 104, and the authentication service 108 provides the server certificate 110 to the electronic device 104 to allow the electronic device 104 to verify the identity of the AP 102.
[0036] The server certificate 110 is stored in a memory 112 of the AP 102. The memory 112 may be implemented using one or more memory devices. Examples of memory devices may include any one or some combination of the following: a dynamic random access memory (DRAM) device, a static random access memory (SRAM) device, a flash memory device, or any other type of memory device.
[0037] In some examples, memory 112 is secure memory, such as secure memory of a Trusted Platform Module (TPM), which is a secure cryptographic processor that generates cryptographic keys. More generally, secure memory can be any memory in AP 102 that is protected from unauthorized access.
[0038] AP 102 may obtain server certificate 110 from certificate enrollment server 114. In some examples, certificate enrollment server 114 operates according to the Secure Transport Enrollment (EST) protocol, as described in RFC 7030, October 2013, entitled "Enrollment over Secure Transport." The EST protocol automatically issues certificates, such as X.509 certificates, for public key infrastructure (PKI) clients such as electronic device 104. In the EST framework, AP 102 is an example of an EST client, and certificate enrollment server 114 is an example of an EST server. The EST client (AP 102) obtains a signed server certificate from the EST server (certificate enrollment server 114).
[0039] The authentication server 106 also obtains a server certificate 116 from the certificate enrollment server 114. The server certificate 116 is stored in a memory 118 of the authentication server 106 (eg, a secure memory).
[0040] AP 102 requests a certificate from certificate enrollment server 114 by sending certificate request 120 to certificate enrollment server 114. In some examples, certificate request 120 may be a certificate signing request (CSR). CSR refers to an encoded file or message containing information associated with AP 102.
[0041] Examples of information contained in a CSR may include any one or some combination of the following parameters:
[0042] The public key of AP 102 and the signature of AP 102, which can be used by the certificate enrollment server 114 to verify the identity of AP 102. The signature of the CSR is generated based on the private key of AP 102. The public key and the private key form an encrypted public-private key pair and are referred to as a "bootstrap certificate."
[0043] Common Name (CN), which is the primary domain of the certificate requested by the CSR. The Common Name can be a fully qualified domain name, such as CompanyA.com (an example of a web address). Figure 1 In the example of , CompanyA is the network provider of network 103 .
[0044] • Location information regarding the location (eg, locality, state, country, etc.) of the requesting entity that is requesting the certificate.
[0045] The organization identifier of the requesting entity's organization.
[0046] Other information
[0047] Although reference is made to examples of information that may be included in a certificate request (eg, a CSR), in other examples, alternative or additional information may be included in a certificate request.
[0048] In addition to the CN (Common Name) mentioned above, in examples where SAN is supported, the CSR may also include a Subject Alternative Name (SAN). The SAN may refer to an additional domain outside the domain referred to by the CN. For example, the additional domain may be the domain of the network provider of network 103. In examples where the SAN is included in the CSR, the certificate generated in response to the CSR is a multi-domain certificate that applies to multiple domains identified by the CN and SAN.
[0049] A "domain" identified by a domain name (eg, CN or SAN) refers to a collection of one or more resources (eg, websites, services, or other resources). The term "name" used herein may refer to the domain name of one or more domains.
[0050] The certificate request 120 (e.g., CSR) is issued to a certificate authority (CA), which issues the certificate to the certificate authority. Figure 1 1 is a CA 122 associated with the certificate enrollment server 114. The CA is the entity responsible for generating a certificate based on the information contained in the certificate request. Note that the CA 122 may be independent of the certificate enrollment server 114, or may be a part of the certificate enrollment server 114.
[0051] The information in the certificate request 120 is passed from the certificate enrollment server 114 to the CA 122. Based on the information in the certificate request 120, the CA 122 generates a signed server certificate (e.g., signed by the private key of the CA 122) for the domain(s) identified in the CN (and possibly the SAN) in the certificate request 120. The certificate enrollment server 114 sends the signed server certificate 124 to the AP 102. By decrypting the signed server certificate 124 using the encryption key (e.g., public key) of the AP 102, the AP can derive the server certificate 110 from the signed server certificate 124. In some examples, the process of requesting and obtaining certificates is performed according to the EST protocol.
[0052] The authentication server 106 may similarly issue a certificate request 126 to the certificate enrollment server 114 to obtain a server certificate 116. The certificate request 126 from the authentication server 106 includes the same name (e.g., CN and possibly SAN) included in the certificate request 120 from the AP 102. The certificate request 126 also includes parameters similar to those of the certificate request 120 from the AP 102 (e.g., the public key and signature of the authentication server 106, location information, organization information, etc.). The certificate enrollment server 114 passes the information of the certificate request 126 to the CA 122, which generates a signed server certificate. The certificate enrollment server 114 sends the signed server certificate 128 to the authentication server 106, which derives the server certificate 116 by decrypting the signed server certificate using the public key of the authentication server 106.
[0053] The connection between AP 102 and certificate enrollment server 114 and between authentication server 106 and certificate enrollment server 114 is a secure connection, such as a secure tunnel. For example, the secure tunnel may include a secure socket layer (SSL) tunnel. In other examples, other types of secure connections (where messages may be protected by signing or encrypting messages) may be employed between certificate enrollment server 114 and each of AP 102 and authentication server 106.
[0054] According to some embodiments of the present disclosure, the same name (related to the domain (or domains) of the network provider of network 103) is included in the certificate requests 120 and 126 respectively issued by AP 102 and authentication server 106. In this way, the server certificates 110 and 116 provided by certificate enrollment server 114 to AP 102 and authentication server 106, respectively, are part of the same authentication chain. More specifically, each of server certificates 110 and 116 includes the same name of the network provider of network 103. The client can trust authentication server 106 based on server certificate 116 including the same name, and can trust authentication service 108 in AP 102 based on server certificate 110 including the same name.
[0055] Figure 2 206 and 208 to enable authentication server 106 and APs 102, 206, and 208 to access a given one of certificate enrollment servers 204. Figure 1 The certificate enrollment server 114 in FIG. 2 is an example of one of the certificate enrollment servers 204 .
[0056] An “orchestration server” may refer to a server that manages the use of a certificate enrollment server and provides information that enables other devices to use the certificate enrollment server.
[0057] "Starting" a certificate enrollment server may refer to launching the certificate enrollment server, transitioning the certificate enrollment server from an inactive state to an active state, or otherwise causing the certificate enrollment server to operate.
[0058] In some examples, authentication server 106 may be configured with a boot certificate 210 that is stored in memory 118 of authentication server 106. Boot certificate 210 may be configured during the manufacturing process of authentication server 106, or may be configured at a different time. Boot certificate 210 includes a public key and a private key of authentication server 106. In some examples, the public key and the private key are elliptic curve cryptography (ECC) keys. In other examples, other types of public keys and private keys may be used.
[0059] Similarly, AP 102 may be configured with a bootstrap certificate 212, which is stored in the memory 112 of AP 102. Bootstrap certificate 212 may be configured during the manufacturing process of AP 102, or may be configured at a different time. Other APs 206 and 208 may similarly be configured with their respective bootstrap certificates, which are stored in the memory of APs 206 and 208.
[0060] As above combined Figure 1 As discussed, when sending a certificate request to the certificate enrollment server 114, the AP 102 and the authentication server 106 use the public and private keys of the bootstrap certificate.
[0061] In an example where multiple certificate enrollment servers 204 are deployed, orchestration server 202 may provide certificate enrollment servers 204 for obtaining server certificates to authentication server 106 and APs 102, 206, and 208. For example, certificate enrollment servers 204 may be located in different locations (e.g., different geographic regions, such as cities, states, provinces, countries, etc.). The certificate enrollment server selected for an AP may be based on the location of the AP.
[0062] For example, the information of the selected certificate enrollment server of the certificate enrollment server 204 to be used may include a uniform resource identifier (URI). Orchestration server 202 may send the URI of a given certificate enrollment server (certificate enrollment server URI) for obtaining a server certificate to each of authentication server 106 and APs 102, 206, and 208. In this way, authentication server 106 and APs 102, 206, and 208 do not need to evaluate which certificate enrollment server to use.
[0063] In a specific example, for example, the certificate enrollment server URI may have the form https: / / www.example.com / enrollment-service / company-x / enroll , where "company-x" may identify a network provider of network 103. In other examples, other types of information may be used to identify a certificate enrollment server.
[0064] like Figure 2 As shown, orchestration server 202 sends information (at 220) to authentication server 106 to enable authentication server 106 to obtain a server certificate, wherein the information includes: (1) a certificate enrollment server URI for identifying a certificate enrollment server to be used (from certificate enrollment server 204); and (2) certificate request parameters, including parameters to be included in a certificate request sent from authentication server 106 to the certificate enrollment server identified by the certificate enrollment server URI (e.g., Figure 1 The certificate request parameters may be obtained from a database by orchestration server 202, the database including information of devices added to the network arrangement (including authentication servers and APs or other network devices).
[0065] Similarly, orchestration server 202 sends (at 222) information to AP 102 to cause AP 102 to obtain a server certificate, wherein the information includes: (1) a certificate enrollment server URI identifying a certificate enrollment server to be used (from among certificate enrollment servers 204); and (2) certificate request parameters included in a certificate request (e.g., Figure 1 Orchestration server 202 also sends (at 224, 226) similar information to other APs 206 and 208, respectively.
[0066] In some examples, if multiple APs are used by the same client (e.g. Figure 1 If the APs are operated by different clients (e.g., client 1 and client 2), then orchestration server 202 may provide the same certificate registration server URI to each of the multiple APs. On the other hand, if the multiple APs are operated by different clients (e.g., client 1 and client 2), then orchestration server 202 may provide different certificate registration server URIs to different APs. For example, orchestration server 202 provides a first certificate registration server URI to a first AP operated by client 1, and provides a different second certificate registration server URI to a second AP operated by client 2.
[0067] The certificate request parameters included in the information sent by orchestration server 202 to authentication server 106 and APs 102, 206, and 208 include the name (CN and possibly SAN) of the domain(s) included in the respective certificate requests sent to the certificate enrollment server.
[0068] In some examples, orchestration server 202 is part of management system 230. Clients (such as Figure 1 The network provider of the network 103 in the network 103 can access the management system 230, for example, by logging into the management system 230, and provide the configuration of the certificate registration server. The configuration of the certificate registration server may include any one or some combination of the following: the domain name of the certificate registration server URI, the retention time of the signed certificate, etc. For example, the customer can also upload a CA, which can be used as Figure 1 CA 122 in. The CA uploaded by the customer is the CA used to generate a server certificate in response to a certificate request. The orchestration server 202 can start one or more certificate enrollment servers 204 based on the configuration, and the uploaded CA is deployed to generate a certificate in response to a certificate request.
[0069] Figure 3is a flow diagram of a process 300 performed by AP 102 according to some examples. AP 102 receives (at 302) from orchestration server 202 a certificate enrollment server URI identifying a certificate enrollment server and certificate request parameters including the name of the domain(s) of a network provider associated with AP 102.
[0070] To obtain a server certificate from the certificate enrollment server identified by the received certificate enrollment server URI, the AP sends a certificate to the certificate enrollment server (eg, Figure 1 114 in ), sends (at 304) a certificate request including certificate request parameters. A CA (e.g. Figure 1 AP 102 receives (at 306) a signed server certificate (e.g., Figure 1 124 in ). AP 102 derives (at 308) a server certificate (e.g. Figure 1 110 in the above table).
[0071] When authentication server 106 is available, any client (e.g. Figure 1 The electronic device 104 in the AP 102 will first perform an authentication process with the authentication server 106. The authentication process involves the exchange of messages (eg, RADIUS messages) between the electronic device 104 and the authentication server 106 via the AP 102.
[0072] However, in some cases, authentication server 106 may become unavailable. AP 102 detects (at 310) that authentication server 106 has become unavailable. In some cases, this may be based on AP 102 failing to receive a response to a message sent by AP 102 to authentication server 106. For example, during an authentication process (e.g., an IEEE 802.1X authentication process) between electronic device 104 and authentication server 106, AP 102 may forward a message of the authentication process received from electronic device 104 to authentication server 106. If AP 102 does not receive a response to the message, AP 102 may determine that authentication server 106 is unavailable.
[0073] In other examples, AP 102 may periodically send a status request to authentication server 106 to check the availability of the authentication server. If authentication server 106 does not respond to the status request, AP 102 may mark authentication server 106 as unavailable.
[0074] In response to detecting that the authentication server 106 is unavailable after the electronic device 104 has initiated the authentication process, the AP 102 invokes (at 312) the authentication service 108 of the AP 102 to perform (at 314) the authentication process requested by the electronic device 104. As part of the authentication process, the AP 102 provides the server certificate 110 to the electronic device 104 for the electronic device 104 to use to verify the identity of the AP 102. Assuming that the electronic device 104 has successfully authenticated the AP 102 based on the server certificate 110, the electronic device 104 and the authentication service 108 in the AP 102 can complete the authentication process. At this point, the electronic device 104 can access the network 103 even if the authentication server 106 is unavailable.
[0075] A similar process may be performed for reauthenticating the electronic device 104 .
[0076] By using a certificate enrollment server to provide service certificates to network devices (e.g., APs) and authentication servers, the risk of server certificate exposure is reduced due to the use of secure connections between the certificate enrollment server and the network devices and authentication servers. Different network devices operated by different clients can receive different server certificates from the certificate enrollment server, so that even if a server certificate at a compromised first network device is exposed, the server certificate at an uncompromised second network device can remain secure.
[0077] The use of a certificate enrollment server can simplify the process of providing server certificates to APs and authentication servers, which can be used by clients to verify the trustworthiness of APs and authentication servers.
[0078] like Figure 2 As discussed, the orchestration server 202 of the management system 230 can be used to start a certificate registration server to serve various customers. This allows customers to utilize the management system 230 to deploy a certificate registration server, so that customers do not need to deploy their own certificate registration servers. The management system 230 can be operated as a service by a service provider for use by different customers.
[0079] In addition, the authentication server can also be provided as a service provider, so that customers do not need to deploy their own authentication server. This can reduce the costs associated with the deployment of the authentication server.
[0080] In other examples, customers may deploy their own proprietary authentication servers. In such examples, orchestration server 202 may provide the customer's authentication server with a certificate enrollment server URI to identify the certificate enrollment server to be used by the customer's authentication server. Orchestration server 202 may also provide a template defining the format of the certificate request to be used by the customer's authentication server when sending the certificate request.
[0081] Figure 4 is a block diagram of a non-transitory machine-readable or computer-readable storage medium 400 storing machine-readable instructions that, when executed, cause a network device to perform various tasks. An example of a network device is an AP, such as Figure 1 In other examples, the network device may be a switch or other type of network device to which the electronic device may be connected to access the network.
[0082] The machine-readable instructions include name receiving instructions 402 to receive, at a network device, a name for obtaining a certificate from an orchestration server. An example of an orchestration server is Figure 2 The name may include a CN (or alternatively, a set of a CN and a SAN).
[0083] The machine-readable instructions include certificate request instructions 404 to send a certificate request including a name from a network device to a certificate enrollment server. An example of a certificate request is a CSR. An example of a certificate enrollment server is Figure 1 The certificate registration server 114 in.
[0084] The machine-readable instructions include certificate response receiving instructions 406 to receive, at the network device, a response to the certificate request from the certificate enrollment server, wherein the response includes certificate information based on the name in the certificate request. For example, the certificate information in the response may be a signed certificate, such as Figure 1 The signed server certificate 124 in.
[0085] The machine readable instructions include authentication server unavailable detection instructions 408 to detect that the authentication server is unavailable for an authentication process of a client coupled to the network device. Detection of authentication server unavailability may be performed during the authentication process, or may be performed before the authentication process is initiated.
[0086] The machine-readable instructions include network device authentication capability instructions 410 to use a certificate as part of an authentication process between a network device and a client based on a name in a certificate request based on detecting that an authentication server is unavailable. For example, the network device authentication capability instructions 410 may call an authentication service of the network device (e.g., Figure 1 108) to perform the authentication process between the network device and the client.
[0087] In some examples, the certificate request sent from the network device is a first certificate request, and the name included in the first certificate request is the same as the name included in the second certificate request from the authentication server to the certificate enrollment server.
[0088] In some examples, the client is a first client. The machine-readable instructions are executable to further detect that the second client is coupled to the network device (e.g., the second client performs wireless or wired communication with the network device), and based on detecting that the authentication server is available for the authentication process of the second client, the machine-readable instructions cause the network device to act as an intermediary for the second client authentication process performed between the second client and the authentication server. For example, when acting as an intermediary, the network device forwards the authentication process message from the client to the authentication server, and forwards the authentication process message from the authentication server to the client. In this case, the client is the requester of the authentication process, and the network device acts as an authenticator between the requester and the authentication server. In some examples, the intermediary is a RADIUS client (also known as a network access server or NAS), which can act as a gateway between the client and the RADIUS server.
[0089] In some examples, the certificate information included in the response from the certificate enrollment server is provided by a CA (e.g., Figure 1 The machine-readable instructions cause the network device to derive a certificate from the signed certificate, such as by decrypting the signed certificate using an encryption key.
[0090] In some examples, the certificate enrollment server includes an EST server, wherein the network device and the authentication server are EST clients that obtain certificates from the EST server.
[0091] In some examples, during the authentication process, the machine-readable instructions cause the network device to send a certificate to the client for the client to verify the identity of the network device based on the certificate.
[0092] In some examples, the machine-readable instructions cause the network device to receive information of a certificate enrollment server from the orchestration server and to access the certificate enrollment server using the received information.
[0093] In some examples, the received certificate enrollment server information includes a URI of the certificate enrollment server.
[0094] In some examples, the machine-readable instructions cause a network device to establish a secure connection between the network device and a certificate enrollment server accessible at a URI, and to send a certificate request including a name from the network device to the certificate enrollment server over the secure connection.
[0095] In some examples, the certificate enrollment server is selected by the orchestration server from a plurality of certificate enrollment servers based on a location of the network device.
[0096] In some examples, the network device is a first network device and the certificate is a first certificate, where the first certificate is different from a second certificate of a second network device that obtains the second certificate information from the certificate enrollment server or another certificate enrollment server.
[0097] Figure 5 is a block diagram of a network device 500 according to some examples of the present disclosure. The network device 500 may be an AP or other types of network devices.
[0098] Network device 500 includes one or more hardware processors 502. A hardware processor may include a microprocessor, a core of a multi-core microprocessor, a microcontroller, a programmable integrated circuit, a programmable gate array, or other hardware processing circuit.
[0099] Network device 500 includes non-transitory storage media 504 that stores machine-readable instructions executable on hardware processor 502 for performing various tasks. Machine-readable instructions executable on a hardware processor may refer to instructions executable on a single hardware processor or instructions executable on multiple hardware processors.
[0100] The machine-readable instructions in storage medium 504 include name receiving instructions 506 for receiving, at network device 500, from an orchestration server a name for obtaining a first certificate for the network device. The name received from the orchestration server is the same as the name used by the authentication server to obtain a second certificate for the authentication server.
[0101] The machine-readable instructions in storage medium 504 include certificate request instructions 508 for sending a certificate request including a name from the network device to a certificate enrollment server. The certificate request may further include other parameters provided by the orchestration server to the network device.
[0102] The machine-readable instructions in the storage medium 504 include certificate response receiving instructions 510 for receiving a response to the certificate request from the certificate enrollment server at the network device, wherein the response includes information of the first certificate based on the name in the certificate request. For example, the information of the first certificate may include a signing certificate.
[0103] The machine-readable instructions in the storage medium 504 include certificate export instructions 512 for exporting the first certificate from the information of the first certificate. For example, the certificate export instructions 512 can decrypt the signed certificate to obtain the first certificate (an unsigned version of the first certificate).
[0104] The machine-readable instructions in the storage medium 504 include credential storage instructions 514 for storing a first credential in a memory of the network device for use in an authentication process performed by the network device in response to the authentication server being unavailable.
[0105] Figure 6 is a flow diagram of a process 600 according to some examples. Process 600 may be performed by a network device, such as an AP or other type of network device.
[0106] Process 600 includes receiving (at 602) from an orchestration server at a network device identification information identifying a certificate enrollment server and parameters for inclusion in a certificate request. The parameters include a name for obtaining a certificate and other parameters discussed further above. The identification information may include a URI of the certificate enrollment server.
[0107] Process 600 includes sending (at 604) a certificate request including parameters from a network device to a certificate enrollment server identified by identification information. An example of a certificate request is Figure 1 The certificate request 120 in.
[0108] Process 600 includes receiving (at 606) at a network device from a certificate enrollment server a response to the certificate request, the response including information of a certificate based on a name that is one of the parameters included in the certificate request.
[0109] Process 600 includes an authentication process in which a network device detects (at 608) that an authentication server is unavailable for a client coupled to the network device. Process 600 includes using (at 610) by the authentication server a certificate based on a name in a certificate request as part of an authentication process between the network device and the client based on detecting that the authentication server is unavailable. The authentication process between the network device and the client is performed by an authentication service in the network device that is invoked for authentication survivability in response to the authentication server being unavailable.
[0110] Storage media (such as Figure 4 400 or Figure 5504) may include any one or some combination of the following: semiconductor memory devices, such as DRAM or SRAM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), and flash memory; disks, such as fixed disks, floppy disks, and removable disks; another magnetic medium, including tape; optical media, such as compact disks (CDs) or digital video disks (DVDs); or another type of storage device. It should be noted that the instructions discussed above may be provided on one computer-readable or machine-readable storage medium, or alternatively may be provided on multiple computer-readable or machine-readable storage media, which are distributed in a large system that may have multiple nodes. Such computer-readable or machine-readable storage media are considered part of an article (or article of manufacture). An article or article of manufacture may refer to any single component or multiple components that are manufactured. The storage medium or media may be placed in a machine to execute machine-readable instructions, or may be placed at a remote site from which machine-readable instructions may be downloaded over a network for execution.
[0111] In the present disclosure, unless the context clearly indicates otherwise, the use of the terms "a", "an" or "the" is intended to include plural forms. In addition, when used in the present disclosure, the terms "comprises", "including", "comprising", "containing", "having" or "having" refer to the presence of the elements described, but do not exclude the presence or addition of other elements.
[0112] In the foregoing description, many details are presented to provide an understanding of the subject matter disclosed herein. However, the implementations described may be practiced without some of these details. Other implementations may include modifications and variations to the details discussed above. The appended claims are intended to cover these modifications and variations.
Claims
1. A non-transitory machine-readable storage medium comprising instructions that, when executed, cause a network device to: receiving, at the network device, from an orchestration server, a name for obtaining a certificate; sending a certificate request including the name from the network device to a certificate enrollment server; receiving, at the network device, a response to the certificate request from the certificate enrollment server, the response including information of a certificate, the certificate being based on the name in the certificate request; detecting that an authentication server is unavailable for an authentication process of a client coupled to the network device; as well as Based on detecting that the authentication server is unavailable, using the certificate based on the name in the certificate request as part of the authentication process between the network device and the client.
2. The non-transitory machine-readable storage medium of claim 1 , wherein the certificate request sent from the network device is a first certificate request, and wherein the name included in the first certificate request is the same as a name included in a second certificate request from the authentication server to the certificate enrollment server.
3. The non-transitory machine-readable storage medium of claim 1 , wherein the client is a first client, and wherein the instructions, when executed, cause the network device to: detecting that a second client is coupled to the network device; and Based on detecting that the authentication server is available for the authentication process of the second client, acting as an intermediary for the authentication process of the second client performed between the second client and the authentication server.
4. The non-transitory machine-readable storage medium according to claim 3, wherein the authentication process of the second client performed between the second client and the authentication server comprises: The authentication server sends a certificate to the second client, the certificate being acquired by the authentication server from the certificate enrollment server based on a certificate request including the name sent from the authentication server to the certificate enrollment server.
5. A non-transitory machine-readable storage medium according to claim 1, wherein the information of the certificate included in the response from the certificate registration server is a signed certificate signed by a certificate authority (CA) associated with the certificate registration server, and wherein the instructions, when executed, cause the network device to derive the certificate from the signed certificate.
6. The non-transitory machine-readable storage medium of claim 1, wherein the certificate registration server comprises a certificate registration over secure transmission (EST) protocol server. 7 . The non-transitory machine-readable storage medium of claim 6 , wherein the network device and the authentication server are EST clients that obtain certificates from the EST server.
8. The non-transitory machine-readable storage medium of claim 1 , wherein the instructions, when executed, cause the network device to: In the authentication process, the certificate is sent from the network device to the client for use by the client in verifying the identity of the network device based on the certificate.
9. The non-transitory machine-readable storage medium of claim 1 , wherein the instructions, when executed, cause the network device to: receiving information of the certificate registration server from the orchestration server; and The certificate enrollment server is accessed using the received information. 10 . The non-transitory machine-readable storage medium of claim 9 , wherein the received information of the certificate enrollment server comprises a uniform resource identifier (URI) of the certificate enrollment server.
11. The non-transitory machine-readable storage medium of claim 10, wherein the instructions, when executed, cause the network device to: establishing a secure connection between the network device and the certificate enrollment server accessible at the URI; and The certificate request including the name is sent from the network device to the certificate enrollment server over the secure connection.
12. The non-transitory machine-readable storage medium of claim 9, wherein the certificate enrollment server is selected by the orchestration server from a plurality of certificate enrollment servers based on a location of the network device. 13 . The non-transitory machine-readable storage medium of claim 1 , wherein the name comprises a common name (CN) of a domain of a network provider of the network device.
14. The non-transitory machine-readable storage medium of claim 1, wherein the name comprises a Common Name (CN) and a Subject Alternative Name (SAN) of a domain of a network provider of the network device.
15. The non-transitory machine-readable storage medium of claim 1, wherein the network device is a first network device, and the certificate is a first certificate, and wherein the first certificate is different from a second certificate for a second network device, and the second network device obtains information of the second certificate from the certificate registration server or another certificate registration server.
16. A network device comprising: Hardware processor; as well as A non-transitory storage medium storing instructions executable on a hardware processor to: receiving, at the network device, from an orchestration server, a name for obtaining a first certificate of the network device, the name received from the orchestration server being the same as a name used by an authentication server to obtain a second certificate of the authentication server; sending a certificate request including the name from the network device to a certificate enrollment server; receiving, at the network device, a response to the certificate request from the certificate enrollment server, the response including information of a first certificate, the first certificate being based on the name in the certificate request; deriving the first certificate from the information of the first certificate; as well as The first certificate is stored in a memory of the network device for use in an authentication process performed by the network device in response to the authentication server being unavailable.
17. The network device of claim 16, wherein the instructions are executable on the hardware processor to: detecting that the authentication server is unavailable for authentication processing of a client coupled to the network device; and Based on the detection that the authentication server is unavailable: calling the authentication service of the network device, and The first certificate based on the name in the certificate request is used as part of the authentication process between the authentication service of the network device and the client.
18. The network device of claim 16, wherein the name comprises a common name (CN) of a domain of a network provider of the network device.
19. A method comprising: receiving, at a network device, identification information from an orchestration server and parameters for inclusion in a certificate request, the identification information identifying a certificate enrollment server, the parameters including a name for obtaining a certificate; sending, from the network device, a certificate request including the parameters to the certificate enrollment server identified by the identification information; receiving, at the network device, a response to the certificate request from the certificate enrollment server, the response including information of a certificate based on the name as one of the parameters included in the certificate request; detecting, by the network device, that the authentication server is unavailable for authentication procedures of a client coupled to the network device; as well as Based on detecting that the authentication server is unavailable, using the certificate by the authentication server based on the name in the certificate request as part of the authentication process between the network device and the client.
20. The method of claim 19, wherein the authentication process between the network device and the client is performed by an authentication service in the network device, the authentication service being invoked for authentication survivability in response to the authentication server being unavailable.