Civil aircraft air-ground interconnection identity authentication and network management system and method

By adopting a distributed architecture and high availability mechanism in the air-ground interconnection system of civil aircraft, combined with the identity authentication management method based on secondary IP address allocation, the problem of excessive hardware resources consumption of a single air-mounted entertainment server is solved, and the efficient operation and scalability of the system is achieved.

CN120200757APending Publication Date: 2025-06-2410TH RES INST OF CETC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510349702.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the civil aircraft air-to-ground interconnection scenario, a single on-board entertainment server consumes too much hardware resources when handling passenger identity authentication, data forwarding and other services, resulting in high server operation load, lag in access resources, extended response time or even timeout, and the sanitary traffic flow is repeatedly billed.

Method used

The distributed architecture of the air-ground interconnected identity authentication and network management system is adopted, and the server hardware resource consumption is reduced through core modules such as authentication server, dynamic IP address allocation server, domain name resolution server and portal server, combined with high availability mechanism and identity authentication management method based on secondary IP address allocation.

Benefits of technology

It effectively reduces the hardware resource consumption of a single on-board entertainment server, improves the scalability and easy maintenance of the system, reduces the consumption of device processor resources, and avoids resource lag and duplicate billing problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200757A_ABST
    Figure CN120200757A_ABST
Patent Text Reader

Abstract

The invention provides a civil aircraft air-ground interconnection identity authentication and network management system and method, relates to the technical field of civil aircraft air-ground interconnection, and aims to solve the problems of network delay and resource waste caused by overhigh load of an airborne server. According to the invention, by separating control plane and user plane processing and optimizing a strategy matching mechanism, the resource consumption of the server is obviously reduced, the authentication efficiency and the system reliability are improved, and repeated charging of the satellite communication link is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of civil aircraft air - ground interconnection, and particularly to a civil aircraft air - ground interconnection identity authentication and network management system and method. Background Art

[0002] The statements in this section only provide background information related to the present disclosure and may not constitute prior art.

[0003] With the development of civil aircraft air - ground interconnection technology, passengers can use their own portable devices to access the cabin wireless network and access ground resources via air - ground links such as satellite communication (SatCom) and Aeronautical Tele - ground (ATG), so as to realize Internet access, online office, etc. during the flight. To implement the above services, the airborne entertainment server in the cabin system needs to add functions such as passenger Internet access identity authentication and air - ground interaction data traffic forwarding. However, as the number of devices accessing the Internet increases, the server needs to process a large number of passenger identity authentications, update release / block policies, and the forwarded data volume surges. However, its processor capacity is limited. In the actual use process, the server runs with an extremely high load, resulting in problems such as slow access to Internet resources, long response time or even timeout, and duplicate billing of purchased SatCom traffic.

[0004] The reason is that in the current implementation method, both the control plane and user plane service processing in the air - ground interaction process are concentrated in the airborne entertainment server. For the control plane service, the application - layer software needs to process passenger identity authentication / log - off requests in real time and update the release / block policy of the operating system kernel. For the user plane service, during the process of the server forwarding packets, in extreme cases, it is necessary to traverse all release / block policies in the operating system kernel to determine whether the packet should be forwarded or discarded. The method of simply increasing the number of airborne entertainment servers to share the load requires re - planning of the cabin wireless network and hardware upgrade, which greatly increases the online cost. Therefore, in the scenario of a single airborne entertainment server, how to reduce the hardware resource consumption of the server in the process of control plane and user plane service processing is an urgent problem to be solved. Summary of the Invention

[0005] The purpose of the present invention is to provide a civil aircraft air - ground interconnection identity authentication and network management system and method for the problems existing in the prior art. The following several measures are taken to solve the problem of reducing the server resource consumption in the process of control plane and user plane service processing in the scenario of a single airborne entertainment server:

[0006] (1) Distributed architecture of the air - ground interconnection identity authentication and network management platform;

[0007] (2) High - availability mechanism of the air - ground interconnection identity authentication and network management platform;

[0008] (3) Identity authentication management mechanism based on secondary IP address allocation.

[0009] The technical solution of the present invention is as follows:

[0010] An airborne-ground interconnection identity authentication and network management system for civil aircraft, comprising:

[0011] Four core modules: authentication server software, dynamic IP address allocation server software, domain name resolution server software, and portal server software, where:

[0012] The authentication server software is used to implement identity authentication, authorization, and billing functions, and cooperate with the dynamic IP address allocation server software to complete authentication status query;

[0013] The dynamic IP address allocation server software is used to allocate addresses in the unauthenticated network segment or the authenticated network segment according to the user authentication status. Among them, the addresses in the unauthenticated network segment are only allowed to access in-cabin resources, and the addresses in the authenticated network segment are allowed for airborne-ground interaction;

[0014] The domain name resolution server software is used to redirect the domain name resolution request of the unauthenticated user terminal to the portal server software;

[0015] The portal server software is used to receive user authentication requests and forward them to the authentication server software, and provide the function of redirecting the identity authentication page.

[0016] Furthermore, it further includes:

[0017] Three optional modules: resource management service software, configuration management service software, and password authentication service software;

[0018] The resource management service software is used to monitor hardware resources and manage primary / backup switching;

[0019] The configuration management service software provides a man-machine interaction configuration interface;

[0020] The password authentication service software is used to cooperate with the authentication server software to complete password verification.

[0021] Furthermore, the dynamic IP address allocation server software executes:

[0022] Allocate unauthenticated network segment addresses with a lease time ≤ 30 seconds to unauthenticated users, including unauthenticated gateway and domain name resolution server addresses;

[0023] Allocate authenticated network segment addresses with a lease time ≥ 30 minutes to authenticated users, including authenticated gateway and domain name resolution server addresses.

[0024] Furthermore, the authentication server software includes:

[0025] An authentication module based on the Radius / Diameter / 802.1X protocol;

[0026] A release / blocking policy update module linked to the operating system kernel, and the policy update trigger conditions include system initialization and user configuration modification.

[0027] The present invention also proposes a method for realizing high availability of civil aircraft air-ground interconnection, adopting an N+1 primary and standby redundant architecture, including:

[0028] The core modules of the above system are deployed on both the primary node and at least one secondary node;

[0029] The dynamic IP address allocation server software of the primary node and the dynamic IP address allocation server software of the secondary node synchronize lease information in real time through a Transmission Control Protocol long connection;

[0030] When the resource management service software detects a secondary node failure, the primary node immediately takes over its services and delays the service fallback after the secondary node recovers.

[0031] Furthermore, the primary node and the secondary node coexist on the same hardware device, and:

[0032] The failover only targets the dynamic IP address allocation server software and the authentication server software modules;

[0033] The business continuity of the portal server software and the domain name resolution server software modules is guaranteed by the status synchronization of the dynamic IP address allocation server software.

[0034] Furthermore, the lease information synchronization adopts:

[0035] The dynamic IP address allocation server software of the secondary node actively pushes lease data to the primary node;

[0036] The primary node attempts to reconnect after the Transmission Control Protocol connection is interrupted, and determines the secondary node failure after a timeout.

[0037] The present invention also proposes an identity authentication management method based on secondary address allocation, including:

[0038] The first allocation stage: Allocate unauthenticated network segment addresses to unauthenticated terminals, restricting their access to only in-cabin resources;

[0039] The authentication trigger stage: Redirect the terminal to access the portal server software through the domain name resolution server software to complete authentication;

[0040] The second allocation stage: After the terminal authentication is successful, force the terminal to re-obtain the authenticated network segment address by refusing to renew the lease.

[0041] Furthermore, the second allocation stage specifically includes:

[0042] When the dynamic IP address allocation server software receives a renewal request from an authenticated terminal, it actively returns a rejection response;

[0043] After the terminal reinitiates a dynamic address request, the dynamic IP address allocation server software allocates an address within the authenticated network segment.

[0044] Furthermore, network segment-level policy matching is adopted:

[0045] The operating system kernel maintains forwarding policies based on unauthenticated / authenticated network segments;

[0046] When forwarding packets, the policy is directly matched according to the network segment to which the source address belongs, eliminating the need to traverse individual user policies.

[0047] Compared with existing technologies, the beneficial effects of the present invention are:

[0048] 1. An identity authentication and network management system for civil aircraft air-ground interconnection:

[0049] 1) Each software module can be independently compiled / deployed and communicate via the network, reducing the dependence of this platform on hardware devices;

[0050] 2) Except for the core module, the remaining software modules can be added or deleted according to the actual usage scenario, and users can perform secondary development based on the unified interfaces provided by this platform, enhancing the scalability of this platform;

[0051] 3) The operating mode of this platform can be configured and resource consumption can be monitored, enhancing the maintainability of this platform.

[0052] 2. A method for achieving high availability in civil aircraft air-ground interconnection:

[0053] 1) Implement primary / backup redundancy to enhance the operating reliability of this platform;

[0054] 2) The N+1 backup mechanism reduces the number of redundant nodes compared to other methods. On the other hand, the primary node and the secondary nodes can coexist on the same hardware device, reducing the number of devices;

[0055] 3) The real-time synchronization mechanism of stateful software modules ensures that after a secondary node fails, the primary node can immediately resume the operating state of the platform before the failure, avoiding network paralysis caused by duplicate IP address allocation.

[0056] 3. An identity authentication management method based on secondary address allocation:

[0057] 1) The operating system kernel's allow / block policies only need to be modified during initialization and when user configurations are updated, reducing the frequency of modifying the operating system kernel's allow / block policies and decreasing the consumption of device processor resources;

[0058] 2) The message forwarding process performs policy matching in units of network segments, reducing the number of allow / block policies that the operating system kernel needs to retrieve during the forwarding process and decreasing the consumption of the device's processor resources. Description of the Drawings

[0059] Figure 1 It is a schematic block diagram of an airborne-ground interconnection identity authentication and network management system for civil aircraft;

[0060] Figure 2 It is the architecture of the airborne-ground interconnection system for civil aircraft;

[0061] Figure 3 It is the high-availability architecture of the airborne-ground interconnection identity authentication and network management platform;

[0062] Figure 4 It is the first IP address allocation process;

[0063] Figure 5 It is the identity authentication process;

[0064] Figure 6 It is the second IP address allocation process. Detailed Implementation Modes

[0065] It should be noted that relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.

[0066] The features and performance of the present invention will be further described in detail below in conjunction with embodiments.

[0067] Embodiment 1

[0068] The application scenario of this embodiment is as follows:

[0069] The network architecture of the airborne-ground interconnection system for civil aircraft is as Figure 2 shown, and it is divided into four major parts: airborne applications, airborne systems, airborne-ground interconnection, and ground applications.

[0070] 1) Airborne applications: refer to applications where terminals such as passengers, flight attendants, and maintenance personnel access the airborne WiFi network wirelessly to conduct interactions inside the cabin and between air and ground;

[0071] 2) Airborne system: With the airborne entertainment server as the core, it provides service functions closely related to airborne applications, air-ground interconnection, and ground applications;

[0072] 3) Air-ground interconnection: Air-ground broadband communication (ATG), satellite communication and other air-ground interconnection links cross-linked with the airborne entertainment server;

[0073] 4) Ground application: Public Internet application.

[0074] This embodiment proposes a civil aircraft air-ground interconnection identity authentication and network management system. As Figure 1 shown, each software module is distributed and runs independently on different hardware devices, specifically including:

[0075] Four core modules: authentication server software, dynamic IP address allocation server software, domain name resolution server software, and portal server software (PortalSvr server software). Among them:

[0076] The authentication server software is used to implement the functions of authentication, authorization, and accounting (AAA), and cooperate with the dynamic IP address allocation server software to complete the authentication status query;

[0077] The dynamic IP address allocation server software is used to allocate addresses in the unauthenticated network segment or the authenticated network segment according to the user authentication status. Among them, the addresses in the unauthenticated network segment are only allowed to access in-cabin resources, and the addresses in the authenticated network segment are allowed for air-ground interaction;

[0078] The domain name resolution server software is used to redirect the domain name resolution request of the unauthenticated user terminal to the portal server software; that is, to implement the user terminal domain name resolution service function and the http / https request redirection function;

[0079] The portal server software is used to receive the user authentication request and forward it to the authentication server software, and provide the identity authentication page redirection function; that is, to receive the user terminal authentication request and forward it to the authentication server software for identity authentication;

[0080] In this embodiment, a civil aircraft air-ground interconnection identity authentication and network management system further includes:

[0081] Three optional modules: resource management service software, configuration management service software, and password authentication service software;

[0082] The resource management service software is used to monitor the hardware resources and manage the primary / backup switch; that is, to implement the functions of monitoring the hardware resources of this platform, counting the authentication information, and managing the high reliability of the platform;

[0083] The configuration management service software provides a human-machine interaction configuration interface; that is, it provides a human-machine interaction interface for users to perform configuration operations.

[0084] The password authentication service software is used to cooperate with the authentication server software to complete password verification; that is, it completes password verification during the identity authentication process and supports authentication methods including dynamic passwords, static passwords, or LDAP authentication.

[0085] In this embodiment, specifically, the dynamic IP address allocation server software performs:

[0086] Assign an unauthenticated network segment address with a lease time ≤ 30 seconds to unauthenticated users, including the unauthenticated gateway and domain name resolution server addresses.

[0087] Assign an authenticated network segment address with a lease time ≥ 30 minutes to authenticated users, including the authenticated gateway and domain name resolution server addresses.

[0088] In this embodiment, specifically, the authentication server software includes:

[0089] An authentication module based on the Radius / Diameter / 802.1X protocol;

[0090] A release / block policy update module linked to the operating system kernel, and the policy update trigger conditions include system initialization and user configuration modification.

[0091] It should be noted that the above system has the following functions:

[0092] On the premise of network reachability, each software module can be independently deployed on different devices;

[0093] According to the actual usage scenario, each software module in the platform can be trimmed, and only the minimum set of core software modules that support the platform operation can be retained. The core modules include: AuthSvr, DHCPSvr, DNSSvr, PortalSvr.

[0094] The functions of the above modules are described in detail as follows:

[0095] Authentication server software (AuthSvr, core function module):

[0096] a) Support user identity authentication, authorization, and accounting (AAA) functions, and the authentication protocols that can be used include but are not limited to Radius, Diameter, 802.1X, etc.;

[0097] b) Support cooperation with DHCPSvr, receive its authentication status query request and return the user terminal authentication status information;

[0098] c) Identity authentication process, which supports password verification locally and also supports collaborative password verification with PWDSvr;

[0099] d) According to user configuration, taking "authenticated network segment" and "unauthenticated network segment" as units, the operating system kernel release / block policy is updated in real time after initialization and user configuration modification.

[0100] Dynamic IP address allocation server software (DHCPSvr, core functional module):

[0101] a) For unauthenticated user terminals: Receive the dynamic IP address allocation request from the user terminal and return a response, which carries:

[0102] An IP address allocated from the "unauthenticated network segment", which only allows access to the in-cabin local area network resources and cannot perform air-ground interaction;

[0103] The gateway address, domain name resolution server address, and lease time of the "unauthenticated network segment". Usually, the lease time is short (≤30 seconds) and configurable;

[0104] b) For authenticated user terminals: Receive the dynamic IP address allocation request from the user terminal and return a response, which carries:

[0105] An IP address allocated from the "authenticated network segment", which allows access to both in-cabin local area network resources and air-ground interaction;

[0106] The gateway address, domain name resolution server address, and lease time of the "authenticated network segment". Usually, the lease time is long (≥30 minutes) and configurable.

[0107] Domain name resolution server software (DNSSvr, core functional module):

[0108] a) For unauthenticated user terminals: Resolve all their domain name resolution requests to the PortalSvr address;

[0109] b) For authenticated user terminals: Complete the normal domain name resolution process.

[0110] Portal server software (PortalSvr, core functional module):

[0111] a) Redirect the http / https service requests of unauthenticated user terminals to the identity authentication page and return it to the user terminal;

[0112] b) Receive the identity authentication information (including but not limited to username, password, etc.), convert it into the authentication protocol format used with AuthSvr, initiate an authentication request to AuthSvr, receive the authentication result and display it.

[0113] Resource Management Service Software (ResMgr, non-core module):

[0114] a) Monitor the device resources running on this platform, including but not limited to CPU, memory, disk, etc.;

[0115] b) High reliability management of this platform: Responsible for monitoring the running health status of all software modules. When the primary software module fails, switch the service to the standby (if any). When the primary recovers, switch the service back;

[0116] c) Statistic authentication information and real-time synchronization of key running status information.

[0117] Configuration Management Service Software (CfgMgr, non-core module):

[0118] a) Provide a human-computer interaction interface for users to perform system configuration operations;

[0119] b) Unified database interface;

[0120] c) Unified log and file storage / reading interface.

[0121] Password Authentication Service Software (PWDSvr, non-core module):

[0122] a) Receive password verification requests from AuthSvr and complete password verification;

[0123] b) Support password verification with AuthSvr in dynamic, static, and dynamic+static modes based on a private protocol;

[0124] c) Support password verification with AuthSvr based on the standard LDAP protocol.

[0125] Embodiment 2

[0126] This embodiment proposes a method for realizing high availability of civil aircraft air-ground interconnection, adopting an N+1 primary and standby redundant architecture, including:

[0127] Deploy the core modules of the above system on both the primary node and at least one secondary node;

[0128] The dynamic IP address allocation server software of the primary node and the dynamic IP address allocation server software of the secondary node synchronize lease information in real time through a Transmission Control Protocol long connection;

[0129] When the Resource Management Service Software detects a failure of a secondary node, the primary node immediately takes over its service and delays the service backswitching after the secondary node recovers.

[0130] In this embodiment, specifically, the primary node and the secondary node coexist on the same hardware device, and:

[0131] The failover is only applicable to the dynamic IP address allocation server software and the authentication server software module;

[0132] The business continuity of the portal server software and the domain name resolution server software module is guaranteed by the status synchronization of the dynamic IP address allocation server software.

[0133] In this embodiment, specifically, the lease information synchronization adopts:

[0134] The child node dynamic IP address allocation server software actively pushes lease data to the master node;

[0135] After the transmission control protocol connection is interrupted, the master node attempts to reconnect, and determines that the child node has failed after a timeout.

[0136] It should be noted that when the air-ground interconnection identity authentication and network management system runs on multiple devices with network reachability, its high availability mechanism can be enabled to achieve primary / backup redundancy. The high availability mechanism of this system adopts the N+1 backup method, that is, multiple child nodes and one master node. When each child node is working properly, the master node does not process services, but only processes synchronization messages from each child node. When a child node fails, the ResMgr controls the switchover, and the master node automatically takes over the services of the failed child node.

[0137] AuthSvr, PortalSvr, and DNSSvr in the air-ground interconnection identity authentication and network management platform are all stateless modules. Even if a failure occurs, the services can be quickly taken over by the standby module without knowing the running state before the failure. However, DHCPSvr is a stateful module, and the primary node needs to know the IP address allocation situation before the failure when taking over the services of the failed node.

[0138] The high availability architecture of the air-ground interconnection identity authentication and network management system is as Figure 3 shown, where:

[0139] (a) The airborne master node and the airborne child node at least include the core modules of the platform, namely: AuthSvr, DHCPSvr, DNSSvr, PortalSvr, ResMgr;

[0140] (b) Figure 3 The red line in is the key status data synchronization channel between DHCPSvrs, and the green line is the DHCPSvr service channel. Each airborne switch forwards the same service request it receives to both the master node and the child node simultaneously;

[0141] (c) The DHCPSvr in the master node maintains long TCP connections with all slave nodes. When a TCP connection is interrupted, the master node attempts to reconnect to the slave node. If the retransmission limit is exceeded, the slave node is determined to be faulty and the master node takes over the services of the faulty slave node.

[0142] (d) Under normal circumstances of the long TCP connection, each slave node's DHCPSvr synchronizes its own lease information to the master node for backup in real time over the TCP connection.

[0143] (e) To prevent frequent switching between the master node and slave nodes, the high-availability mechanism adopts a method of fast switching and slow recovery, that is: when the master node confirms a slave node is faulty, it immediately switches to take over the services. After the slave node recovers, the master node continues to handle the services and switches the services back to the slave node after confirming that the slave node has been running stably.

[0144] (f) The switching criterion of this platform comes from the DHCPSvr in the master node. Once the DHCPSvr in the master node discovers a fault in the DHCPSvr of a slave node, the master node immediately notifies the ResMgr in this node to perform the switching operation.

[0145] (g) During the switching process, only the services of DHCPSvr and AuthSvr are switched, and PortalSvr and DNSSvr do not need to be switched because the working input parameters of PortalSvr and DNSSvr both come from DHCPSvr.

[0146] Embodiment III

[0147] This embodiment also proposes an identity authentication management method based on secondary address allocation, including:

[0148] The first allocation stage: Allocate unauthenticated network segment addresses to unauthenticated terminals, restricting them to access only the resources inside the cabin.

[0149] The authentication trigger stage: Redirect the terminal to access the portal server software through the domain name resolution server software to complete authentication.

[0150] The second allocation stage: After the terminal is authenticated successfully, force the terminal to re-obtain the authenticated network segment address by refusing to renew the lease.

[0151] In this embodiment, specifically, the second allocation stage specifically includes:

[0152] When the dynamic IP address allocation server software receives a lease renewal request from an authenticated terminal, it actively returns a rejection response.

[0153] After the terminal re-initiates a dynamic address request, the dynamic IP address allocation server software allocates an authenticated network segment address.

[0154] In this embodiment, specifically, network segment-level policy matching is adopted:

[0155] The operating system kernel maintains forwarding policies based on unauthenticated network segments / authenticated network segments;

[0156] When forwarding packets, the policy is directly matched according to the network segment to which the source address belongs, without traversing individual user policies.

[0157] That is, this embodiment introduces an identity authentication management mechanism based on secondary IP address allocation. If the user terminal has not completed identity authentication, an "unauthenticated network segment" IP address is assigned to it. If the user terminal has completed identity authentication, an "authenticated network segment" IP address is assigned to it. This mechanism solves the problem of hardware resource consumption of the airborne entertainment server from the following two aspects: on the one hand, the operating system kernel's allow / block policies are only modified during initialization and user configuration updates, reducing the frequency of modifying the operating system kernel's allow / block policies; on the other hand, during the packet forwarding process, policy matching is performed in units of network segments, greatly reducing the number of allow / block policies that the operating system kernel needs to retrieve during the forwarding process.

[0158] The identity authentication management mechanism based on secondary IP address allocation is as follows:

[0159] First IP address allocation:

[0160] When the user terminal accesses the wireless network but has not completed identity authentication, the process of the user terminal dynamically applying for an IP address is as Figure 4 shown;

[0161] a) The user terminal accesses the in-cabin wireless network and broadcasts a dynamic IP address request, such as Figure 4 Step 1;

[0162] b) The dynamic IP address allocation server software (DHCPSvr) receives the request and initiates an authentication status query to the authentication server software (AuthSvr), such as Figure 4 Step 2;

[0163] c) AuthSvr queries its authentication status based on the user terminal information carried in the request and returns a query response to DHCPSvr, such as Figure 4 Step 3;

[0164] d) DHCPSvr determines that the terminal has not completed identity authentication according to the authentication status query response, assigns it an unauthenticated network segment IP address, and sends a dynamic IP address request response to the user terminal, such as Figure 4 Step 4. The gateway address and DNS Svr address parameters carried in this response are both server addresses of the unauthenticated network segment, and the lease time parameter carried is relatively short (≤30s), the purpose of which is to let the user terminal initiate a renewal request as soon as possible;

[0165] e) At this point, the user terminal completes a dynamic IP address request process and successfully obtains an unauthenticated network segment IP address, but this address can only access the cabin LAN resources. When initiating air-ground interaction, all messages requested to be forwarded by the in-flight entertainment server will be discarded;

[0166] f) When the user terminal lease expires, it sends a renewal request to DHCPSvr, requesting to continue using the previously allocated IP address. Figure 4 Step 5;

[0167] g) After receiving the renewal request, DHCPSvr sends an authentication status query to AuthSvr, such as Figure 4 Step 6;

[0168] h) AuthSvr queries the authentication status of the user terminal according to the user terminal information carried in the authentication status query request, and returns the authentication status query response to DHCPSvr, such as Figure 4 Step 7;

[0169] i) DHCPSvr determines that the terminal has not completed identity authentication based on the authentication status query response, and renews the lease of the unauthenticated network segment IP address for it. The response message carries the gateway address of the unauthenticated network segment, DNSSvr address, and lease time and is sent to the user terminal. Figure 4 Step 8;

[0170] j) After the next lease expires, if the user terminal has not completed identity authentication, it will repeat Figure 4 Step 5 to Step 8.

[0171] User terminal identity authentication:

[0172] After the user terminal successfully obtains the unauthenticated network segment IP address, all its http / https requests are redirected to PortalSvr. During this process, the user terminal can initiate identity authentication. The process is as follows: Figure 5 As shown;

[0173] a) The user terminal has completed the first IP address allocation and successfully obtained an unauthenticated network segment IP address;

[0174] b) If the user terminal wants to initiate an air-ground interaction request, it must first initiate a domain name resolution to the DNSSvr address carried in the "dynamic IP address request response", such as Figure 5 Step 1;

[0175] c) DNSSvr receives the request, determines that the terminal has not completed identity authentication, resolves any domain name requested by the terminal to the PortalSvr address and returns a response, such as Figure 5 Step 2;

[0176] d) The user terminal initiates an http / https request to the PortalSvr address carried in the domain name resolution request response, such as Figure 5 Step 3;

[0177] e) After receiving the request, PortalSvr redirects it to the identity authentication page and returns the link address, such as Figure 5 Step 4;

[0178] f) The user terminal fills in the user name, password and other identity information on the identity authentication page and initiates identity authentication, such as Figure 5 Step 5;

[0179] g) PortalSvr receives the identity information and converts it into the actual authentication protocol format to initiate an authentication request to AuthSvr, such as Figure 5 Step 6;

[0180] h) AuthSvr receives the authentication request:

[0181] If the local password verification method is used, AuthSvr completes the password verification locally and returns the authentication response to PortalSvr, such as Figure 5 Step 9;

[0182] If a non-local password verification method is used, AuthSvr initiates a password verification request to PWDSvr, such as Figure 5 Step 7: After completing the password verification, PWDSvr returns the result to AuthSvr. Figure 5 Step 8: AuthSvr determines the password verification result and returns the authentication response to PortalSvr. Figure 5 Step 9.

[0183] i) PortalSvr receives the authentication response and returns the identity authentication result to the user terminal, such as Figure 5 Step 10;

[0184] j) At this point, the user terminal has completed identity authentication, but the user terminal IP address is still an unauthenticated network segment address, and air-ground interaction is impossible. All messages requested to be forwarded by the in-flight entertainment server will be discarded.

[0185] Second IP address allocation:

[0186] After the user terminal completes identity authentication, it waits for the lease time of the unauthenticated network segment to expire and initiates a renewal request. This renewal request will trigger the second IP address allocation. The process is as follows Figure 6 As shown:

[0187] a) The user terminal has completed the first IP address allocation and identity authentication process. At this time, the IP address of the user terminal is still an unauthenticated network segment address;

[0188] b) The lease time of the IP address in the unauthenticated network segment expires, and the user terminal sends a renewal request to the DHCPSvr, as follows Figure 6 Step 1;

[0189] c) After receiving the renewal request, the DHCPSvr sends an authentication status query request to the AuthSvr, as follows Figure 6 Step 2;

[0190] d) The AuthSvr queries the identity authentication status of the user terminal and returns a query response, as follows Figure 6 Step 3;

[0191] e) After receiving the authentication status query response, the DHCPSvr determines that the user terminal has completed the identity authentication and immediately sends a renewal rejection response to the user terminal, as follows Figure 6 Step 4;

[0192] f) After receiving the renewal rejection response, the user terminal re-broadcasts a dynamic IP address request according to the requirements of the standard DHCP protocol, as follows Figure 6 Step 5;

[0193] g) After receiving the request, the DHCPSvr sends an authentication status query request to the AuthSvr, as follows Figure 6 Step 6;

[0194] h) The AuthSvr queries the identity authentication status of the user terminal and returns a query response to the DHCPSvr, as follows Figure 6 Step 7;

[0195] i) The DHCPSvr determines that the user terminal has completed the identity authentication according to the received query response, allocates an IP address in the authenticated network segment for the user terminal and returns a dynamic IP address request response, as follows Figure 6 Step 8;

[0196] At this point, the user terminal successfully obtains an IP address in the authenticated network segment. When the operating system kernel performs packet forwarding, it will execute the forwarding policy, and the user terminal can perform normal air-ground interaction.

[0197] The above-described embodiments only represent the specific implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation to the protection scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the technical solution of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application.

[0198] This Background of the Invention section is provided to generally present the context of the present invention. Work of the presently named inventors, to the extent it is described in this Background of the Invention section, and aspects of the work that are not yet prior art as of the filing date of this application are neither expressly nor impliedly admitted to be prior art to the present invention.

Claims

1. A civil aircraft air-ground interconnection identity authentication and network management system, characterized in that: include: The four core modules are authentication server software, dynamic IP address allocation server software, domain name resolution server software, and portal server software, among which: The authentication server software is used to implement identity authentication, authorization and billing functions, and collaborates with the dynamic IP address allocation server software to complete authentication status query; The dynamic IP address allocation server software is used to allocate an address of an unauthenticated network segment or an authenticated network segment according to the user authentication status, wherein the unauthenticated network segment address is only allowed to access the resources in the cabin, and the authenticated network segment address is allowed to interact with the air and ground; The domain name resolution server software is used to redirect the domain name resolution request of the unauthenticated user terminal to the portal server software; The portal server software is used to receive user authentication requests and forward them to the authentication server software, and provide an identity authentication page redirection function.

2. A civil aircraft air-ground interconnection identity authentication and network management system according to claim 1, characterized in that: Also includes: Three optional modules: resource management service software, configuration management service software, and password authentication service software; The resource management service software is used to monitor hardware resources and manage active / standby switching; The configuration management service software provides a human-computer interaction configuration interface; The password authentication service software is used to cooperate with the authentication server software to complete the password verification.

3. A civil aircraft air-ground interconnection identity authentication and network management system according to claim 1, characterized in that: The dynamic IP address allocation server software performs: Allocate unauthenticated network segment addresses with a lease time of ≤30 seconds to unauthenticated users, including unauthenticated gateway and domain name resolution server addresses; Assign authenticated network segment addresses with a lease time of ≥ 30 minutes to authenticated users, including authenticated gateway and domain name resolution server addresses.

4. A civil aircraft air-ground interconnection identity authentication and network management system according to claim 1, characterized in that: The authentication server software comprises: Authentication module based on Radius / Diameter / 802.1X protocol; A release / blocking policy update module that is linked to the operating system kernel. Policy update trigger conditions include system initialization and user configuration modification.

5. A method for realizing high availability of civil aircraft air-ground interconnection, characterized in that: Adopt N+1 active-standby redundant architecture, including: The master node and at least one sub-node are deployed with the core module of the platform described in any one of claims 1 to 4; The main node dynamic IP address allocation server software and the sub-node dynamic IP address allocation server software synchronize the lease information in real time through the transmission control protocol long connection; When the resource management service software detects a subnode failure, the master node immediately takes over its business and delays business switchback after the subnode recovers.

6. A method for realizing high availability of civil aircraft air-ground interconnection according to claim 5, characterized in that: The master node and the sub-node coexist on the same hardware device, and: Failover is only available for the dynamic IP address allocation server software and authentication server software modules; The business continuity of the portal server software and domain name resolution server software modules is ensured by synchronizing the server software status through dynamic IP address allocation.

7. A method for realizing high availability of civil aircraft air-ground interconnection according to claim 5, characterized in that: Lease information is synchronized using: The sub-node dynamic IP address allocation server software actively pushes lease data to the master node; The master node attempts to reconnect after the TCP connection is interrupted, and determines that the child node is faulty after a timeout.

8. An identity authentication management method based on secondary address allocation, characterized in that: include: The first allocation stage: allocate unauthenticated network segment addresses to unauthenticated terminals, restricting them to access only the resources within the cabin; Authentication triggering stage: redirection through domain name resolution server software enables the terminal to access the portal server software to complete authentication; Second allocation stage: After the terminal is successfully authenticated, the terminal is forced to re-acquire the authenticated network segment address by refusing to renew the lease.

9. The identity authentication management method based on secondary address allocation according to claim 8, characterized in that: The second distribution stage specifically includes: When the dynamic IP address allocation server software receives a renewal request from an authenticated terminal, it actively returns a rejection response; After the terminal re-initiates a dynamic address request, the dynamic IP address allocation server software allocates an authenticated network segment address.

10. The identity authentication management method based on secondary address allocation according to claim 8, characterized in that: Use network segment-level policy matching: The operating system kernel maintains forwarding policies based on unauthenticated network segments / authenticated network segments; When forwarding packets, the policy is directly matched according to the network segment to which the source address belongs, without traversing individual user policies.