Authentication method, device and system, network equipment and server
By pre-cacheting the authentication page on the network device and returning to the cache page according to the page policy configured by the server, the problem of unsmooth opening of the authentication page in the WAN environment is solved, and efficient authentication page loading is achieved without increasing the server operation and maintenance costs.
Patent Information
- Application Number
- CN202510401049.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-20
AI Technical Summary
In a wide area network environment, when the terminal authenticates after accessing the network, it may be affected by network delay and jitter, resulting in poor opening of the authentication page, affecting the user experience, and increasing the server deployment and operation and maintenance costs.
By pre-cacheting the authentication page on the network device and returning the cached authentication page to the terminal according to the page policy configured by the server, the dependence on the server is reduced and the fluency of the authentication page is improved.
Without increasing server deployment and operation and maintenance costs, ensure that the terminal can keep the authentication page open smoothly when network delay and jitter exist, improving user experience.
Smart Images

Figure CN120185901A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of network technologies, and particularly relates to an authentication method, an authentication device, an authentication system, a network device, a server, and a computer program product. Background Art
[0002] Currently, after a terminal accesses a network, if authentication is required, the server usually directly returns an authentication page. In a wide area network environment, this process may be affected by network latency and / or jitter, resulting in an unsmooth opening of the authentication page and affecting the user experience. At the same time, as the number of terminals accessing the server increases, the deployment and operation and maintenance costs of the server will also increase accordingly. Summary of the Invention
[0003] This application provides an authentication method, an authentication device, an authentication system, a network device, a server, and a computer program product, which can ensure the smoothness of the terminal when opening the authentication page even in the presence of network latency and / or jitter without increasing the deployment and operation and maintenance costs of the server.
[0004] In a first aspect, this application provides an authentication method, which is applied to a network device. The authentication method includes:
[0005] Receiving a detection request sent by a terminal;
[0006] Filling the detection request based on preset authentication parameters to obtain a first request;
[0007] Redirecting the first request to a preset server, so that when the server is configured with a first page policy, filling the first request based on preset first configuration parameters to obtain a second request, and redirecting the second request to the network device, where the first configuration parameters include a target authentication page template ID;
[0008] Returning, among all the cached authentication pages, the target authentication page corresponding to the target authentication page template ID carried in the second request to the terminal, so that the terminal performs authentication through the target authentication page.
[0009] In a second aspect, this application provides an authentication method, which is applied to a server. The authentication method includes:
[0010] Determining the current page policy after receiving the redirected first request;
[0011] When the page policy is configured as the first page policy, filling the first request based on preset first configuration parameters to obtain a second request, where the first configuration parameters include a target authentication page template ID;
[0012] Redirect the second request to the network device so that the network device returns the target authentication page corresponding to the target authentication page template ID to the terminal among all the cached authentication pages;
[0013] When the page policy is configured as the second page policy, return the target authentication page to the terminal.
[0014] Thirdly, the present application provides an authentication device, which is applied to a network device; the authentication device includes:
[0015] A first receiving module, configured to receive a detection request sent by the terminal;
[0016] A first filling module, configured to fill the detection request based on preset authentication parameters to obtain a first request;
[0017] A first redirection module, configured to redirect the first request to a preset server so that, when the server is configured with a first page policy, the first request is filled based on preset first configuration parameters to obtain a second request, and the second request is redirected to the network device, where the first configuration parameters include the target authentication page template ID;
[0018] A first return module, configured to return, among all the cached authentication pages, the target authentication page corresponding to the target authentication page template ID carried in the second request to the terminal so that the terminal performs authentication through the target authentication page.
[0019] Fourthly, the present application provides an authentication device, which is applied to a server; the authentication device includes:
[0020] A determination module, configured to determine the current page policy after receiving the redirected first request;
[0021] A second filling module, configured to fill the first request based on preset first configuration parameters to obtain a second request when the page policy is configured as the first page policy, where the first configuration parameters include the target authentication page template ID;
[0022] A second redirection module, configured to redirect the second request to the network device so that the network device returns the target authentication page corresponding to the target authentication page template ID to the terminal among all the cached authentication pages;
[0023] A second return module, configured to return the target authentication page to the terminal when the page policy is configured as the second page policy.
[0024] In a fifth aspect, the present application provides a network device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method according to the first aspect are implemented.
[0025] In a sixth aspect, the present application provides a server, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method according to the second aspect are implemented.
[0026] In a seventh aspect, the present application provides an authentication system, including the network device according to the fifth aspect and the server according to the sixth aspect.
[0027] In an eighth aspect, the present application provides a computer program product. The computer program product includes a computer program. When the computer program is executed by one or more processors, the steps of the method according to the first aspect and / or the second aspect are implemented.
[0028] The beneficial effects of the present application compared with the prior art are as follows: The server proposes two possible page strategies, namely the first page strategy and the second page strategy. When the server is configured with the first page strategy, instead of the server directly returning an authentication page to the terminal, the network device pre-caches a number of authentication pages, and the network device returns an authentication page to the terminal based on the content it has cached; when the server is configured with the second page strategy, the server continues to directly return an authentication page to the terminal. For the server, it can control whether the network device pre-caches the authentication page based on the user's configuration, realizing flexible control of the two schemes of the server returning the authentication page in real time and the network device caching and returning the authentication page. For the network device, when the server is configured to adopt the scheme of the network device caching and returning the authentication page, it can pre-cache a number of authentication pages and return the cached authentication pages to the accessed terminal, so as to ensure the smoothness when the terminal opens the authentication page even in the case of network latency and / or jitter without increasing the deployment and operation and maintenance costs of the server.
[0029] It can be understood that the beneficial effects of the above third aspect to the eighth aspect can be referred to the above relevant descriptions and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0031] Figure 1 It is a schematic diagram of the implementation process of the authentication method provided by an embodiment of the present application;
[0032] Figure 2 It is a schematic diagram of the implementation process of another authentication method provided by an embodiment of the present application;
[0033] Figure 3 It is a schematic diagram of the interaction within the authentication system provided by an embodiment of the present application during the configuration stage;
[0034] Figure 4 It is a schematic diagram of the interaction between the terminal and the authentication system provided by an embodiment of the present application during the sub - stage of authentication page display;
[0035] Figure 5 It is a schematic diagram of the interaction between the terminal and the authentication system provided by an embodiment of the present application during the sub - stage of authentication processing;
[0036] Figure 6 It is a block diagram of the structure of the authentication device provided by an embodiment of the present application;
[0037] Figure 7 It is a block diagram of the structure of another authentication device provided by an embodiment of the present application;
[0038] Figure 8 It is a schematic diagram of the structure of the network device provided by an embodiment of the present application;
[0039] Figure 9 It is a schematic diagram of the structure of the server provided by an embodiment of the present application. Detailed implementation manners
[0040] In the following description, specific details such as specific system structures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well - known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.
[0041] Currently, after the terminal accesses the network, if authentication is required, the server usually directly returns the authentication page. This method has the following problems:
[0042] 1. In a wide - area network environment, this process may be affected by network latency and / or jitter, resulting in an unsmooth opening of the authentication page and affecting the user experience.
[0043] 2. Each time the terminal requests the authentication page, it needs to download from the server, increasing the network bandwidth and traffic consumption, resulting in an increase in the deployment and operation and maintenance costs of the server.
[0044] Based on the above considerations, the embodiments of the present application propose an authentication method, which can configure the network device to cache the authentication page in advance, so that after the terminal accesses, the network device can return the authentication page, without the need for the server to return the authentication page. Thus, without increasing the deployment and operation and maintenance costs of the server, even in the case of network latency and / or jitter, the smoothness of the terminal opening the authentication page can still be guaranteed. To illustrate the technical solutions proposed by the embodiments of the present application, specific embodiments are used for illustration below.
[0045] The following describes an authentication method proposed by the embodiments of the present application. This authentication method is applied to a network device. Only as an example, the network device includes an access point (AP), a gateway, etc., which are not limited here. It can be understood that the network device and the server together constitute an authentication system.
[0046] Please refer to Figure 1 , the authentication method provided by the embodiments of the present application includes:
[0047] Step 101, receive a detection request sent by the terminal.
[0048] After the terminal accesses the network provided by the network device through wireless connection or wired connection, it can first send a detection request to detect the availability of the network to determine whether authentication is required currently. Thus, the authentication system enters the first sub-phase of the authentication phase, specifically the authentication page display sub-phase. Generally speaking, this detection request is specifically a Hypertext Transfer Protocol (HTTP) request. The network device can intercept and receive this detection request to ensure that the authentication traffic is correctly guided.
[0049] Step 102, fill the detection request based on preset authentication parameters to obtain a first request.
[0050] After the network device intercepts the detection request of the terminal, it will not directly forward this detection request to the Internet, but will perform a filling operation on this detection request based on the parameters related to the authentication process. For ease of description, the embodiments of the present application denote the parameters related to the authentication process as authentication parameters.
[0051] In some examples, the authentication parameters may include, but are not limited to: the address information of the terminal, the address information of the network device, the identification information of the network device, and the identification information of the session; where the address information includes Media Access Control (MAC) address, Internet Protocol (IP) address, etc., which will not be elaborated here. Among them, the identification information of the network device can be obtained by a preset server allocating it to the network device during the configuration phase; or, it can also be obtained through negotiation between the network device and the server. The acquisition method of this identification information is not limited here.
[0052] Based on the above-mentioned proposed authentication parameters, step 102 can be specifically refined as follows: First, fill the probe request based on the address information of the terminal and the address information of the network device to obtain an intermediate request, and redirect the intermediate request to the network device; then, fill the intermediate request based on the identification information of the network device and the identification information of the session to obtain a first request. This redirection operation is to centralize some control rights to the network device uniformly, ensure that the terminal traffic is taken over by the network device, and attach basic parameters (such as IP address and MAC address), which is beneficial to the combination of different specifications of products and the expansion of subsequent services.
[0053] Step 103: Redirect the first request to a preset server so that when the server is configured with the first page policy, fill the first request based on the preset first configuration parameters to obtain a second request, and redirect the second request to the network device.
[0054] The network device can perform a second redirection operation, specifically redirecting the filled first request to a preset server. For the server, after receiving the redirected first request, it can match the corresponding page policy according to the request parameters of the first request. In the embodiments of the present application, the page policy can be configured as the first page policy or the second page policy according to the specific needs of the staff; among them, the first page policy is that the network device pre-downloads the authentication page template, generates and caches the authentication page, and the network device displays the authentication page for the terminal; the second page policy is that the server displays the authentication page for the terminal. Based on this, the server can perform corresponding operations according to the current specific configuration of the matched page policy.
[0055] Specifically, when the currently matched page policy is configured as the first page policy, the server can fill the first request based on a preset first configuration parameter to obtain a second request, and redirect the second request to the network device. The first configuration parameter includes a target authentication page template ID. It can be understood that the network device may have pre-cached authentication pages corresponding to multiple authentication page templates respectively. Therefore, through the target authentication page template ID, the server can inform the network device which specific authentication page needs to be presented to the terminal currently.
[0056] Specifically, when the currently matched page policy is configured as the second page policy, the server can directly present the required authentication page to the terminal without the need for the network device to intervene, and the authentication page presentation sub-phase ends accordingly. That is to say, in this case, all operations of the network device in the authentication page presentation sub-phase have been completed, and there is no need to execute the subsequent step 104.
[0057] Step 104: Among all the cached authentication pages, return the target authentication page corresponding to the target authentication page template ID carried in the second request to the terminal, so that the terminal can perform authentication through the target authentication page.
[0058] After receiving the second request, the network device can first determine the corresponding target authentication page from all the cached authentication pages according to the target authentication page template ID carried in the second request. Then, the network device can return the target authentication page to the terminal, so as to present the target authentication page to the terminal. Thus, when the server is configured as the first page policy, all operations of the network device in the authentication page presentation sub-phase have been completed.
[0059] In some embodiments, after the network device is initialized and before the terminal accesses the network provided by the network device, the authentication system can first enter the configuration phase. That is to say, before the authentication phase, the authentication system can first enter the configuration phase. In this configuration phase, the operations performed by the network device include:
[0060] A1. Receive the second configuration parameter sent by the server.
[0061] After establishing communication with the server, the network device can bind relevant authentication configuration information. This process can be manually operated by the staff on the server page, and the specific operations may involve the following: configuring the Service Set Identifier (SSID), configuring the page policy of the server, configuring the binding relationship with the network device, configuring the authentication method (such as one-key authentication, account authentication, SMS authentication, guest authentication, or membership authentication, etc.), configuring the authentication page template, configuring the uplink and downlink bandwidth limits, and configuring the authentication duration, etc., which will not be elaborated here. Based on all the content configured during the binding process, the server can generate a second configuration parameter for the network device and send the second configuration parameter to the network device. It should be noted that the second configuration parameter may also include the device identifier generated by the server for the network device (i.e., the device identifier of the network device proposed above), the signature key, and the redirect address, etc. Thus, the network device can receive the second configuration parameter sent by the server.
[0062] A2. When the second configuration parameter includes the authentication page template ID, initiate a download request to the server based on the authentication page template ID.
[0063] When the second configuration parameter includes the authentication page template ID, it can be known that during the previous binding process, the staff configured the page policy as the first page policy and configured the authentication page template for the network device, which is why the second configuration parameter includes the authentication page template ID. It should be noted that the embodiments of the present application do not limit the number of the authentication page template IDs; that is, the authentication page template ID can be one or multiple. The network device can initiate a download request to the server based on the authentication page template ID, so as to download the authentication page template corresponding to the authentication page template ID from the server.
[0064] A3. Generate and cache the corresponding authentication page according to the downloaded authentication page template.
[0065] After the network device downloads the authentication page template, it can generate the corresponding authentication page. It can be understood that when there are multiple authentication page template IDs included in the second configuration parameter, there are also multiple downloaded authentication page templates, so that multiple authentication pages can be generated. These multiple authentication pages can be cached locally on the network device, so that when a terminal accesses later, the target authentication page indicated by the server can be returned to the terminal from the cached authentication pages through the steps 101 - 104 described above, which will not be elaborated here.
[0066] It should be noted that the configuration of the network device on the server can be modified according to the actual situation. For example, when the network device is bound to the relevant authentication configuration information, it may be initially configured as the first page strategy, and the network device downloads several authentication page templates from the server; the server may subsequently adjust its relevant configuration and adjust the page strategy to the second page strategy. Although the network device has downloaded several authentication page templates, the server will still directly return the target authentication page required by the newly connected terminal.
[0067] In some embodiments, after the authentication page display sub-stage ends, the second sub-stage of the authentication stage is entered, specifically the authentication processing sub-stage; that is, after the target authentication page is displayed on the terminal, regardless of whether the target authentication page is returned by the server or the network device, the authentication system can enter the authentication processing sub-stage; in the authentication processing sub-stage, the operations performed by the network device include:
[0068] B1. After receiving the redirected third request, verify the first signature carried by the third request.
[0069] After the authentication processing sub-phase begins, the terminal first initiates an authentication request to the server. The server can first authenticate the identity of the authentication request; after passing the authentication, the authentication request is signed, specifically generating a first signature based on a preset signature algorithm; finally, after filling the authentication request with the authentication result and the first signature, a third request is obtained, and the third request is redirected to the network device. As a result, the network device can receive the redirected third request and perform necessary verification on the network device, specifically: verifying the first signature carried by the third request to confirm whether the first signature is legal.
[0070] Specifically, the network device can use the same signature algorithm as the server to generate a second signature, and compare the second signature with the first signature. If the comparison is consistent, it is confirmed that the first signature has passed the verification. The signature algorithm is introduced below:
[0071] First, obtain the parameters to be signed, which include: a random string of specified character length, terminal parameters, and a preset signature key. The terminal parameters specifically refer to the address information of the terminal, that is, the IP address and MAC address of the terminal, which can be carried in the authentication request. In addition, for network devices, the preset signature key is specifically issued by the server during the configuration phase. For details, please refer to the previous description of the configuration phase, which will not be repeated here.
[0072] Then, based on the preset sorting order and preset splicing rule, the parameters to be signed are reorganized to obtain the string to be signed. In some examples, the sorting order can be: the ascending order of the ASCII codes of the field names of the fields to which each parameter to be signed belongs; the splicing rule can be: splicing in the form of a Uniform Resource Locator (URL) key-value pair, that is, splicing in the way of key1=value1&key2=value2... where key1 is the field name with the earliest sorting and value1 is the value of the specific parameter to be signed under this field name. On this basis, to further ensure the consistency when the server and network device calculate the signature, when reorganizing the parameters to be signed, all characters can also be converted to lowercase. The result of the reorganization is the string to be signed.
[0073] Finally, the string to be signed is encrypted based on the preset encryption algorithm to obtain the signature. In some examples, the signature can be a string in hex format and all characters are in lowercase, which is not limited in the embodiments of the present application. For the convenience of distinction, the signature generated by the server is denoted as the first signature, and the signature generated by the network device is denoted as the second signature; in this way, the network device can verify the first signature by comparing the first signature and the second signature. In some examples, the encryption algorithm can be the SHA1 algorithm, or the MD5 or other types of algorithms, which is not limited here.
[0074] B2. When the first signature passes the verification, confirm that the terminal authentication is successful, and perform network management on the terminal based on the authentication result.
[0075] The network device can return the authentication result to the terminal. Specifically, when the first signature passes the verification, it can be known that this authentication is legal, that is, the terminal authentication is successful; otherwise, it is a terminal authentication failure. The terminal can obtain the authentication result interface from the network device or the server based on this authentication result.
[0076] It can be understood that if the target authentication interface during this authentication is returned by the network device, the terminal can specifically obtain the authentication result interface from the network device; otherwise, if the target authentication interface during this authentication is returned by the server, the terminal can specifically obtain the authentication result interface from the server. That is, the authentication result interface and the target authentication interface are returned by the same entity, which is specifically determined based on the page policy currently configured by the server.
[0077] When the terminal authentication is successful, the network device can perform network management on the terminal according to the authentication result; among them, the authentication result includes, but is not limited to, bandwidth limit and Internet access duration, etc., which will not be elaborated here. On this basis, the network device can also perform network management on the terminal in combination with its own network policy; among them, the network policy includes, but is not limited to, terminal speed limit policy and traffic release policy, etc., which will not be elaborated here.
[0078] As can be seen from the above, in the embodiment of the present application, when the server is configured to adopt the solution of caching and returning the authentication page by the network device, the network device can cache the authentication page in advance and return the cached authentication page to the accessed terminal, so that without increasing the deployment and operation and maintenance costs of the server, even if there is network delay and / or jitter, the smoothness of the terminal opening the authentication page is still guaranteed. And during the authentication process, on the one hand, the work of the server and the network device is separated and does not depend on other protocols, which simplifies the authentication process; on the other hand, the authentication parameter transfer between the server and the network device is completed through multiple redirects, maintaining the flexibility of the authentication process; on the other hand, a preset encryption algorithm is used to calculate the verification signature, and the signature is compared to complete the authentication consistency check, effectively protecting the data integrity and security.
[0079] The following describes another authentication method proposed in the embodiment of the present application. This authentication method is applied to the server. Please refer to Figure 2 , the authentication method provided by the embodiment of the present application includes:
[0080] Step 201, after receiving the redirected first request, determine the current page policy.
[0081] After the terminal accesses the network provided by the network device through wireless connection or wired connection, it can first send a detection request to detect the availability of the network to determine whether authentication is required currently. Thus, the authentication system enters the first sub-phase of the authentication phase, specifically the authentication page display sub-phase. The network device can first intercept the detection request of the terminal, and then perform a filling operation on the detection request based on the parameters related to the authentication process (that is, the authentication parameters), so as to obtain the first request, and redirect the first request to the server.
[0082] After the server receives the redirected first request, it can match the corresponding page policy according to the request parameters of the first request. In the embodiment of the present application, this page policy can be configured as the first page policy or the second page policy according to the specific needs of the staff; among them, the first page policy is that the network device downloads the authentication page template in advance, generates and caches the authentication page, and the network device displays the authentication page for the terminal; the second page policy is that the server displays the authentication page for the terminal. Based on this, the server can perform corresponding operations according to the current specific configuration of the matched page policy.
[0083] Step 202: When the page policy is configured as the first page policy, fill the first request based on a preset first configuration parameter to obtain a second request.
[0084] When the currently matched page policy is configured as the first page policy, the server can fill the first request based on a preset first configuration parameter to obtain a second request. The first configuration parameter includes a target authentication page template ID. It can be understood that the network device may have previously cached authentication pages corresponding to multiple authentication page templates. Therefore, through the target authentication page template ID, the server can inform the network device which specific authentication page needs to be presented to the terminal currently.
[0085] Step 203: Redirect the second request to the network device.
[0086] The server can redirect the obtained second request after filling to the network device, so that the network device returns the target authentication page corresponding to the target authentication page template ID to the terminal among all the cached authentication pages.
[0087] Step 204: When the page policy is configured as the second page policy, return the target authentication page to the terminal.
[0088] When the currently matched page policy is configured as the second page policy, the server can directly present the authentication page required by the terminal, that is, the target authentication page.
[0089] In some embodiments, after the network device is initialized and before the terminal accesses the network provided by the network device, the authentication system can first enter the configuration phase; that is, before the authentication phase, the authentication system can first enter the configuration phase. The operations performed by the server in this configuration phase include:
[0090] C1: Send a second configuration parameter to the network device.
[0091] After establishing communication with the server, the network device can bind relevant authentication configuration information. This process can be manually operated by the staff on the server page and involves the following operations: configuring the SSID, configuring the page policy of the server, configuring the binding relationship with the network device, configuring the authentication method (such as one-key authentication, account authentication, SMS authentication, guest authentication, or member authentication, etc.), configuring the authentication page template, configuring the uplink and downlink bandwidth limits, and configuring the authentication duration, etc., which will not be elaborated here. Based on all the content configured during the binding process, the server can generate a second configuration parameter for the network device and send the second configuration parameter to the network device. It should be noted that in this second configuration parameter, there are also included the device identifier generated by the server for the network device (i.e., the device identifier of the network device proposed above), the signature key, and the redirect address, etc.
[0092] C2. When the second configuration parameter includes the authentication page template ID, receive the download request initiated by the network device based on the authentication page template ID, and in response to the download request, transmit the authentication page template corresponding to the authentication page template ID to the network device, so that the network device can generate and cache the corresponding authentication page according to the downloaded authentication page template.
[0093] When the second configuration parameter includes the authentication page template ID, it can be known that during the previous binding process, the staff configured the page policy as the first page policy and configured the authentication page template for the network device, which is why the second configuration parameter includes this authentication page template ID. It should be noted that the embodiments of the present application do not limit the number of the authentication page template IDs; that is, the authentication page template ID can be one or multiple. For the network device, it can initiate a download request to the server based on the authentication page template ID; correspondingly, for the server, it can receive the download request initiated by the network device based on the authentication page template ID, and thus in response to the download request, transmit the authentication page template corresponding to the authentication page template ID to the network device.
[0094] In some embodiments, after the authentication page display sub-stage ends, the second sub-stage of the authentication stage is entered, specifically the authentication processing sub-stage; that is, after the target authentication page is displayed on the terminal, regardless of whether the target authentication page is returned by the server or the network device, the authentication system can enter the authentication processing sub-stage; in this authentication processing sub-stage, the operations performed by the server include:
[0095] D1. Receive the authentication request sent by the terminal through the target authentication page.
[0096] The user of the terminal can input the identity information to be authenticated in the target authentication page displayed by the terminal. In some examples, the identity information may specifically be a username and password, or it may be other types of identity information, which is not limited here. The terminal can encapsulate the identity information to be authenticated, generate an authentication request, and send the authentication request to the server. Thus, the server can receive the authentication request sent by the terminal through the target authentication page.
[0097] D2. Perform identity authentication based on the authentication request to obtain an authentication result.
[0098] After parsing the authentication request, the server can obtain the identity information to be authenticated carried by the authentication request, and perform identity authentication on the terminal based on this identity information, so as to obtain an authentication result. The authentication result includes: information indicating whether the terminal passes the authentication. On this basis, if the authentication is passed, the authentication result may further include: permission information, where the permission information includes but is not limited to bandwidth limit and Internet access duration, etc., which is not limited here.
[0099] D3. Generate a first signature when the authentication result indicates that the authentication is passed.
[0100] When the authentication result indicates that the authentication is passed, the server can continue to generate a first signature based on a preset signature algorithm. Among them, the signature algorithm has been described above, and its process is briefly described as follows: first obtain the parameters to be signed, and the parameters to be signed include: a random string with a specified character length, the terminal parameters carried by the authentication request, and a preset signature key; then recombine the parameters to be signed based on a preset sorting order and a preset splicing rule to obtain a string to be signed; finally, encrypt the string to be signed based on a preset encryption algorithm to obtain the first signature.
[0101] D4. Fill the authentication request based on the authentication result and the first signature to obtain a third request.
[0102] D5. Redirect the third request to the network device, so that the network device verifies the first signature carried by the third request. When the verification is passed, it is confirmed that the terminal authentication is successful, and the network device performs network management on the terminal based on the authentication result carried by the third request.
[0103] As can be seen from the above, in the embodiment of the present application, the server proposes two possible page strategies, namely the first page strategy and the second page strategy. When the server is configured as the first page strategy, the server no longer returns the authentication page directly to the terminal, but the network device pre-caches the authentication page, and the network device returns the authentication page to the terminal based on its cached content; when the server is configured as the second page strategy, the server continues to return the authentication page directly to the terminal. For the server, it can control whether the network device caches the authentication page in advance based on the user's configuration, and realize the flexible control of the two schemes of the server returning the authentication page in real time and the network device caching and returning the authentication page, so that the terminal can still ensure the fluency when opening the authentication page without increasing the deployment and operation and maintenance costs of the server, even if there is network delay and / or jitter. In addition, during the authentication process, on the one hand, the work of the server and the network device is separated, and it does not rely on other protocols, which simplifies the authentication process; on the other hand, the authentication parameter transfer between the server and the network device is completed through multiple redirections, maintaining the flexibility of the authentication process; on the other hand, a preset encryption algorithm is used to calculate the verification signature, and the authentication consistency check is completed by comparing the signature, which effectively protects the data integrity and security.
[0104] To understand the operation of the authentication system during the configuration phase, see Figure 3 , Figure 3 The following is a brief description of the interactions within the authentication system at this stage:
[0105] The server first binds the relevant authentication configuration information to the network device, and sends the second configuration parameter to the network device, wherein the second configuration parameter carries the authentication page template ID. The network device thus initiates a download request to the server, wherein the download request is generated based on the authentication page template ID. In response to the download request, the server transmits the authentication page template corresponding to the authentication page template ID to the network device. The network generates and caches the corresponding authentication page based on the downloaded authentication page template.
[0106] To understand the operation of the authentication system in the authentication page display sub-stage, please refer to Figure 4 , Figure 4 The following is a schematic diagram of the interaction between the terminal and the authentication system when the server is configured as the first page strategy at this stage:
[0107] The terminal initiates a probe request. The network device intercepts the probe request, fills it with the address information of the terminal and itself to obtain an intermediate request, and redirects it to the network device. The network device continues to fill the intermediate request with its own identification information and the identification information of the session to obtain a first request, and redirects it to the server. The server fills the first request based on the preset first configuration parameter to obtain a second request, and redirects the second request to the network device, where the first configuration parameter carries the target authentication page template ID. The network device thus returns the target authentication page to the terminal, where the target authentication page is an authentication page generated based on the authentication page template corresponding to the target authentication page template ID.
[0108] For ease of understanding the operations of the authentication system in the authentication processing sub-phase, please refer to Figure 5 , Figure 5 which gives the interaction schematic between the terminal and the authentication system when the server is configured with the first page policy in this phase, briefly described as follows:
[0109] The terminal sends an authentication request to the server. The server performs identity authentication on the authentication request, generates a first signature after passing the authentication, and fills the authentication request based on the authentication result and the first signature to obtain a third request. The server redirects the third request to the network device. The network device verifies the first signature in the third request and returns the verification result to the terminal. The terminal obtains the authentication result page from the network device based on the verification result.
[0110] Corresponding to the authentication method applied to the network device provided above, an embodiment of the present application also provides an authentication device applied to the network device. As Figure 6 shown, the authentication device 6 includes:
[0111] A first receiving module 601, configured to receive a probe request sent by the terminal;
[0112] A first filling module 602, configured to fill the probe request based on preset authentication parameters to obtain a first request;
[0113] A first redirecting module 603, configured to redirect the first request to a preset server, so that when the server is configured with the first page policy, the first request is filled based on the preset first configuration parameter to obtain a second request, and the second request is redirected to the network device, where the first configuration parameter includes the target authentication page template ID;
[0114] A first returning module 604, configured to return, among all the cached authentication pages, the target authentication page corresponding to the target authentication page template ID carried in the second request to the terminal, so that the terminal performs authentication through the target authentication page.
[0115] In some embodiments, the authentication device 6 further includes:
[0116] A second receiving module, configured to receive second configuration parameters sent by the server;
[0117] A download module, configured to, when the second configuration parameter includes an authentication page template ID, initiate a download request to the server based on the authentication page template ID, where the download request is used to download the authentication page template corresponding to the authentication page template ID;
[0118] A generation module, configured to generate and cache a corresponding authentication page according to the downloaded authentication page template.
[0119] In some embodiments, the authentication device 6 further includes:
[0120] A verification module, configured to, after receiving a redirected third request, verify the first signature carried by the third request, where the third request is obtained after the server fills the authentication request with the authentication result and the first signature when the authentication request initiated by the terminal to the server passes the authentication and signature of the server;
[0121] A management module, configured to, when the first signature passes the verification, confirm that the terminal authentication is successful, and perform network management on the terminal based on the authentication result.
[0122] In some embodiments, the authentication parameters include: the address information of the terminal, the address information of the network device, the identification information of the network device, and the identification information of the session; the first filling module includes:
[0123] An address filling unit, configured to fill the probe request based on the address information of the terminal and the address information of the network device to obtain an intermediate request;
[0124] An intermediate request redirecting unit, configured to redirect the intermediate request to the network device;
[0125] An identification filling unit, configured to fill the intermediate request based on the identification information of the network device and the identification information of the session to obtain a first request.
[0126] As can be seen from the above, in the embodiments of the present application, when the server is configured to adopt the solution of caching and returning the authentication page by the network device, the network device can cache the authentication page in advance and return the cached authentication page to the accessed terminal, so that without increasing the deployment and operation and maintenance costs of the server, even if network latency and / or jitter occur, the smoothness of the terminal when opening the authentication page is still guaranteed. Moreover, during the authentication process, on the one hand, the work of the server and the network device is separated, without relying on other protocols, which simplifies the authentication process; on the other hand, the authentication parameter transfer between the server and the network device is completed through multiple redirects, maintaining the flexibility of the authentication process; on the other hand, a preset encryption algorithm is used to calculate the verification signature, and the signature is compared to complete the authentication consistency check, effectively protecting the data integrity and security.
[0127] Corresponding to the authentication method applied to the server provided above, an embodiment of the present application further provides an authentication device applied to the server. As Figure 7 shown, the authentication device 7 includes:
[0128] A determination module 701, configured to determine the current page policy after receiving the redirected first request;
[0129] A second filling module 702, configured to fill the first request based on a preset first configuration parameter to obtain a second request when the page policy is configured as the first page policy, where the first configuration parameter includes a target authentication page template ID;
[0130] A second redirect module 703, configured to redirect the second request to the network device, so that the network device returns the target authentication page corresponding to the target authentication page template ID to the terminal among all the cached authentication pages;
[0131] A second return module 704, configured to return the target authentication page to the terminal when the page policy is configured as the second page policy.
[0132] In some embodiments, the authentication device 7 further includes:
[0133] A distribution module, configured to distribute second configuration parameters to the network device;
[0134] A download response module, configured to receive a download request initiated by the network device based on the authentication page template ID when the second configuration parameter includes the authentication page template ID, and in response to the download request, transmit the authentication page template corresponding to the authentication page template ID to the network device, so that the network device generates and caches the corresponding authentication page according to the downloaded authentication page template.
[0135] In some embodiments, the authentication device 7 further includes:
[0136] A fourth receiving module, configured to receive an authentication request sent by a terminal through a target authentication page;
[0137] An authentication module, configured to perform identity authentication based on the authentication request to obtain an authentication result;
[0138] A signature module, configured to generate a first signature when the authentication result indicates that the authentication is passed;
[0139] A third filling module, configured to fill the authentication request based on the authentication result and the first signature to obtain a third request;
[0140] A third redirection module, configured to redirect the third request to a network device, so that the network device verifies the first signature carried in the third request, confirms that the terminal authentication is successful when the verification is passed, and performs network management on the terminal based on the authentication result carried in the third request.
[0141] In some embodiments, the signature module includes:
[0142] An obtaining unit, configured to obtain signature parameters to be signed, where the signature parameters to be signed include: a random string with a specified character length, terminal parameters carried in the authentication request, and a preset signature key;
[0143] A sufficient unit, configured to reorganize the signature parameters to be signed based on a preset sorting order and a preset splicing rule to obtain a signature string to be signed;
[0144] An encryption unit, configured to encrypt the signature string to be signed based on a preset encryption algorithm to obtain a first signature.
[0145] As can be seen from the above, in the embodiments of the present application, the server proposes two possible page strategies, namely the first page strategy and the second page strategy. When the server is configured with the first page strategy, instead of directly returning the authentication page to the terminal by the server, the network device pre-caches the authentication page, and the network device returns the authentication page to the terminal based on the content it has cached; when the server is configured with the second page strategy, the server continues to directly return the authentication page to the terminal. For the server, it can control whether the network device caches the authentication page in advance based on the user's configuration, realizing flexible control of the two solutions of the server returning the authentication page in real time and the network device caching and returning the authentication page. Thus, without increasing the deployment and operation and maintenance costs of the server, even in the case of network latency and / or jitter, the smoothness of the terminal opening the authentication page is still guaranteed. Moreover, during the authentication process, on the one hand, the work of the server and the network device is separated and does not rely on other protocols, simplifying the authentication process; on the other hand, the authentication parameter transfer between the server and the network device is completed through multiple redirects, maintaining the flexibility of the authentication process; on the other hand, a preset encryption algorithm is used to calculate the verification signature, and the signature is compared to complete the authentication consistency check, effectively protecting the data integrity and security.
[0146] Corresponding to the authentication method applied to the network device provided above, an embodiment of the present application further provides a network device. Please refer to Figure 8 , the network device 8 in the embodiments of the present application includes: a memory 801, one or more processors 802 ( Figure 8 only one is shown in the figure) and a computer program stored on the memory 801 and executable on the processor. Among them: the memory 801 is used to store software programs and modules, and the processor 802 executes various functional applications and data processing by running the software programs and units stored in the memory 801 to obtain the resources corresponding to the above preset events. Specifically, when the processor 802 runs the above computer program stored in the memory 801, it realizes each step of the authentication method applied to the network device, which will not be elaborated here.
[0147] It should be understood that in the embodiments of the present application, the so-called processor 802 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0148] The memory 801 may include a read-only memory and a random access memory, and provide instructions and data to the processor 802. A part or all of the memory 801 may also include a non-volatile random access memory. For example, the memory 801 may also store information about the device type.
[0149] Corresponding to the authentication method applied to the server provided above, the embodiments of the present application also provide a server. Please refer to Figure 9 , the server 9 in the embodiments of the present application includes: a memory 901, one or more processors 902 ( Figure 9 only one is shown in the figure) and a computer program stored in the memory 901 and executable on the processor. Among them: the memory 901 is used to store software programs and modules, and the processor 902 executes various functional applications and data processing by running the software programs and units stored in the memory 901 to obtain the resources corresponding to the above preset events. Specifically, when the processor 902 runs the above computer program stored in the memory 901, it implements each step of the authentication method applied to the server, which will not be elaborated here.
[0150] It should be understood that in the embodiments of the present application, the so-called processor 902 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0151] The memory 901 may include a read-only memory and a random access memory, and provide instructions and data to the processor 902. A part or all of the memory 901 may also include a non-volatile random access memory. For example, the memory 901 may also store information about the device type.
[0152] The embodiments of the present application also provide a computer program product. When the computer program product runs on a network device, the network device can implement the steps in the above-mentioned embodiments of the authentication method applied to the network device; and / or when the computer program product runs on a server, the server can implement the steps in the above-mentioned embodiments of the authentication method applied to the server.
[0153] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the above device can be divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiments can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of mutual distinction and do not limit the protection scope of the present application. The specific working processes of the units and modules in the above system can refer to the corresponding processes in the foregoing method embodiments and will not be described herein again.
[0154] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0155] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of external device software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0156] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the above-mentioned modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical or other forms.
[0157] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0158] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. An authentication method, characterized in that: The authentication method is applied to a network device; The authentication method comprises: Receiving a probe request sent by a terminal; Filling the detection request based on preset authentication parameters to obtain a first request; redirecting the first request to a preset server, so that the server, when configured as a first page strategy, fills the first request based on a preset first configuration parameter to obtain a second request, and redirects the second request to the network device, wherein the first configuration parameter includes a target authentication page template ID; Among all the cached authentication pages, a target authentication page corresponding to the target authentication page template ID carried in the second request is returned to the terminal, so that the terminal performs authentication through the target authentication page.
2. The authentication method according to claim 1, characterized in that: The authentication method further comprises: Receiving a second configuration parameter sent by the server; In the case where the second configuration parameter includes an authentication page template ID, initiating a download request to the server based on the authentication page template ID, the download request being used to download the authentication page template corresponding to the authentication page template ID; According to the downloaded authentication page template, a corresponding authentication page is generated and cached.
3. The authentication method according to claim 1, characterized in that: The authentication method further comprises: After receiving the redirected third request, verifying the first signature carried by the third request, wherein the third request is obtained by the server filling the authentication request with the authentication result and the first signature when the authentication request initiated by the terminal to the server passes the authentication and signature of the server; When the first signature passes the verification, it is confirmed that the terminal is successfully authenticated, and network management is performed on the terminal based on the authentication result.
4. The authentication method according to any one of claims 1 to 3, characterized in that: The authentication parameters include: address information of the terminal, address information of the network device, identification information of the network device, and identification information of the session, wherein the identification information of the network device is allocated to the network device by the server; the step of filling the detection request based on the preset authentication parameters to obtain the first request includes: Filling the detection request based on the address information of the terminal and the address information of the network device to obtain an intermediate request; redirecting the intermediate request to the network device; The intermediate request is filled based on the identification information of the network device and the identification information of the session to obtain the first request.
5. An authentication method, characterized in that: The authentication method is applied to the server; the authentication method includes: After receiving the redirected first request, determining the current page policy, wherein the first request is obtained by the network device filling the authentication parameter into the detection request when the terminal initiates the detection request; In the case where the page policy is configured as the first page policy, filling the first request based on a preset first configuration parameter to obtain a second request, wherein the first configuration parameter includes a target authentication page template ID; redirecting the second request to the network device, so that the network device returns a target authentication page corresponding to the target authentication page template ID to the terminal from among all cached authentication pages; In a case where the page policy is configured as the second page policy, the target authentication page is returned to the terminal.
6. The authentication method according to claim 5, characterized in that: The authentication method further comprises: Sending a second configuration parameter to the network device; In a case where the second configuration parameter includes an authentication page template ID, a download request initiated by the network device based on the authentication page template ID is received, and in response to the download request, an authentication page template corresponding to the authentication page template ID is transmitted to the network device, so that the network device generates and caches a corresponding authentication page based on the downloaded authentication page template.
7. The authentication method according to claim 5, characterized in that: The authentication method further comprises: Receiving an authentication request sent by the terminal through the target authentication page; Perform identity authentication based on the authentication request and obtain an authentication result; If the authentication result indicates that the authentication is passed, generating a first signature; Filling the authentication request based on the authentication result and the first signature to obtain a third request; The third request is redirected to the network device so that the network device verifies the first signature carried by the third request, confirms that the terminal authentication is successful if the verification passes, and performs network management on the terminal based on the authentication result carried by the third request.
8. The authentication method according to claim 7, characterized in that: The generating of the first signature comprises: Obtaining parameters to be signed, the parameters to be signed including: a random character string of a specified character length, terminal parameters carried by the authentication request, and a preset signing key; Based on a preset sorting order and a preset splicing rule, the parameters to be signed are reorganized to obtain a character string to be signed; The character string to be signed is encrypted based on a preset encryption algorithm to obtain the first signature.
9. An authentication device, characterized in that: The authentication device is applied to a network device; The authentication device comprises: A first receiving module, used to receive a detection request sent by a terminal; A first filling module, used to fill the detection request based on preset authentication parameters to obtain a first request; a first redirection module, configured to redirect the first request to a preset server, so that the server, when configured as a first page strategy, fills the first request based on a preset first configuration parameter to obtain a second request, and redirects the second request to the network device, wherein the first configuration parameter includes a target authentication page template ID; The first returning module is used to return a target authentication page corresponding to the target authentication page template ID carried in the second request to the terminal among all cached authentication pages, so that the terminal performs authentication through the target authentication page.
10. An authentication device, characterized in that: The authentication device is applied to the server; the authentication device comprises: A determination module, configured to determine a current page policy after receiving a redirected first request, wherein the first request is obtained by a network device filling authentication parameters into a detection request when a terminal initiates a detection request; A second filling module is used to fill the first request based on a preset first configuration parameter to obtain a second request when the page policy is configured as the first page policy, wherein the first configuration parameter includes a target authentication page template ID; a second redirection module, configured to redirect the second request to the network device, so that the network device returns a target authentication page corresponding to the target authentication page template ID to the terminal from among all cached authentication pages; The second returning module is used to return the target authentication page to the terminal when the page policy is configured as the second page policy.
11. A network device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 4 is implemented.
12. A server comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 5 to 8 is implemented.
13. An authentication system, characterized in that: The authentication system comprises the network device according to claim 11 and the server according to claim 12.
14. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by one or more processors, the method according to any one of claims 1 to 8 is implemented.