Access method and device of access authentication technology, communication equipment and storage medium

By encapsulating the DHCP discovery packet into a unicast form and sending it to the control plane, the broadcast storm and L2 security problems caused by IPoE access are solved, and the state of no broadcast traffic in the signaling process is realized, which improves the stability and security of the network.

CN120223333APending Publication Date: 2025-06-27CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311809563.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Under the BRAS CU separation technology system, IPoE access causes broadcast storms and L2 security issues, such as MAC address spoofing and ARP flooding.

Method used

By encapsulating the original broadcast DHCP discovery message, it is directly sent to the control plane, and only layer 2 unicast traffic messages are used in the subsequent signaling process to avoid the occurrence of broadcast traffic.

Benefits of technology

It effectively avoids the broadcast storm problem that may be brought to the bearer network during the access process of the access authentication technology IPoE, and solves the security problems of the bearer network L2 such as MAC address spoofing and ARP flooding.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223333A_ABST
    Figure CN120223333A_ABST
Patent Text Reader

Abstract

The invention relates to an access method and device of an access authentication technology, communication equipment, a storage medium and a computer program product. The method comprises the following steps: acquiring network configuration information, accessing a control plane based on the network configuration information, and sending a dynamic host configuration protocol DHCP discovery message to the control plane in a unicast form; receiving media access control address MAC information of the user plane fed back by the control plane; the MAC information is determined by the control plane based on service attribute information of the terminal after user authentication information contained in the DHCP discovery message passes authentication; a DHCP providing message sent by the user plane is received, and a unicast DHCP request message is sent to the user plane; and a DHCP confirmation message fed back by the user plane is received, and DHCP related configuration is completed. By adopting the method, the broadcast storm problem brought to the bearer network is avoided, and the security problems of the bearer network L2, such as MAC address cheating and ARP flooding, are avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the fields of network technology and security technology, and in particular, to an access method, apparatus, communication device, storage medium, and computer program product for an access authentication technology. Background Art

[0002] With the development of network technology, under the BRAS CU (Broadband Remote Access Server, CU Resource Control Unit) separation technology system defined in IETF RFC8772 (a document on Internet Engineering Task Force standards), IPoE (Internet Protocol over Ethernet) access is terminated by the user plane UP (User Plane).

[0003] Due to the high-hanging deployment of the UP pool, that is, the user plane function is separated from the core device and centrally deployed as a pooled (Pool) resource. The function of the control plane (CP, Control Plane) is deployed in an independent controller device, and the control plane is used as an independent entity to manage various control tasks in the network. A bearer network (TN, Transport Network) is deployed between the access network (including the terminal side) and the UP, and the initial discovery information (DHCP Discovery message information) of the IPoE access is carried in a layer 2 broadcast message. When attacks such as MAC (Media Access Control Address) address flooding and ARP (Address Resolution Protocol) flooding occur on the terminal side, there will be a large number of broadcast messages in the bearer network, causing a broadcast storm, and there may be a MAC address spoofing problem on the terminal side, which brings L2 (Layer 2) security problems to the bearer network. Summary of the Invention

[0004] Embodiments of the present application provide an access method, apparatus, communication device, storage medium, and computer program product for an access authentication technology. By accessing the control plane, the original broadcast-form DHCP discovery message is encapsulated and directly sent to the control plane, and all subsequent sent messages are layer 2 unicast traffic messages. Therefore, no broadcast traffic is involved in the entire signaling process.

[0005] An access method for an access authentication technology, the method is applied to a terminal, and the method includes:

[0006] Obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form;

[0007] Receive the Media Access Control (MAC) address information of the user plane feedback by the control plane; the MAC address information of the user plane is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message is authenticated;

[0008] Receive the DHCP offer message sent by the user plane, and send a unicast DHCP request message to the user plane;

[0009] Receive the DHCP acknowledgment message feedback by the user plane to complete the DHCP related configuration.

[0010] In one embodiment, the obtaining network configuration information includes:

[0011] Obtain the management address corresponding to the terminal, Domain Name System (DNS) information, and the Uniform Resource Locator (URL) information of the control plane through DHCP.

[0012] In one embodiment, the accessing the control plane based on the network configuration information and sending a DHCP discovery message to the control plane in unicast form includes:

[0013] Access the control plane based on the URL in the network configuration information, and initiate a Hypertext Transfer Protocol (HTTP) connection establishment request to the control plane; the DHCP discovery message is carried in the HTTP connection establishment request.

[0014] In one embodiment, the accessing the control plane based on the network configuration information and sending a DHCP discovery message to the control plane includes:

[0015] Access the control plane based on the network configuration information, encapsulate the DHCP discovery message in the form of a three-layer message, and send the encapsulated DHCP discovery message to the control plane.

[0016] In one embodiment, the receiving the MAC address information of the user plane feedback by the control plane includes:

[0017] Receive the MAC address information of the user plane feedback by the control plane, and the MAC address information of the user plane is used to verify the source MAC address information in the DHCP offer message received from the user plane.

[0018] An access method for an access authentication technology, the method is applied to a control plane, and the method includes:

[0019] Receiving a Dynamic Host Configuration Protocol (DHCP) discovery message sent by a terminal;

[0020] Sending the user authentication information included in the DHCP discovery message to an Authentication, Authorization, and Accounting (AAA) node, and determining an authentication result of the user authentication information through the AAA;

[0021] If the authentication result is authentication passed, selecting a user plane based on the service attribute information of the terminal, and allocating an Internet Protocol address to the terminal;

[0022] Sending the Media Access Control (MAC) address of the user plane to the terminal, and sending the MAC information of the terminal's Media Access Control address and the Internet Protocol (IP) address allocated to the terminal to the user plane.

[0023] In one embodiment, the sending the Media Access Control address of the user plane to the terminal includes:

[0024] Sending the selected Media Access Control (MAC) address of the user plane to the terminal.

[0025] An access device for an access authentication technology, the device is applied to a terminal, and the device includes:

[0026] A sending module, configured to obtain network configuration information, access a control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in a unicast form;

[0027] A first receiving module, configured to receive the Media Access Control (MAC) address information of the user plane fed back by the control plane; the Media Access Control (MAC) address information is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message passes authentication;

[0028] A second receiving module, configured to receive a DHCP offer message sent by the user plane, and send a unicast DHCP request message to the user plane;

[0029] A third receiving module, configured to receive a DHCP acknowledgment message fed back by the user plane to complete DHCP-related configuration.

[0030] A communication device, including: a transmitter and a receiver

[0031] The transmitter is used to obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form;

[0032] The receiver is used to receive the Media Access Control (MAC) address information of the user plane fed back by the control plane; the MAC address information is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message passes the authentication;

[0033] The receiver is used to receive the DHCP offer message sent by the user plane and send a unicast DHCP request message to the user plane;

[0034] The receiver is used to receive the DHCP acknowledgment message fed back by the user plane to complete the DHCP-related configuration.

[0035] A computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0036] Obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form;

[0037] Receive the Media Access Control (MAC) address information of the user plane fed back by the control plane; the MAC address information is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message passes the authentication;

[0038] Receive the DHCP offer message sent by the user plane and send a unicast DHCP request message to the user plane;

[0039] Receive the DHCP acknowledgment message fed back by the user plane to complete the DHCP-related configuration.

[0040] A computer program product includes a computer program. The feature is that when the computer program is executed by a processor, it implements the access method of the access authentication technology provided by the embodiments of the present application. The method may be:

[0041] Obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form;

[0042] Receive the Media Access Control (MAC) address information of the user plane fed back by the control plane; the MAC address information is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message passes the authentication.

[0043] Receive the DHCP offer message sent by the user plane and send a unicast DHCP request message to the user plane.

[0044] Receive the DHCP acknowledgment message fed back by the user plane to complete the DHCP-related configuration.

[0045] The access method, device, communication device, storage medium, and computer program product of the above access authentication technology obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form; receive the MAC address information of the user plane fed back by the control plane. The MAC address information is determined by the control plane based on the service attribute information of the terminal after the user information included in the DHCP discovery message passes the authentication; receive the DHCP offer message sent by the user plane and send a unicast DHCP request message to the user plane; receive the DHCP acknowledgment message fed back by the user plane to complete the DHCP-related configuration. By adopting this method, by directly accessing the control plane, the original DHCP discovery message in the form of a broadcast message is encapsulated and directly sent to the control plane in the form of a unicast message. And since the subsequent sent messages are all Layer 2 unicast traffic messages, therefore, the entire signaling process does not involve broadcast traffic. And since the control plane selects the user plane according to the service attribute information of the terminal, that is, the control plane can achieve unified control, it avoids the broadcast storm problem that may be brought to the bearer network during the access process of the IPoE access authentication technology, and also avoids the security problems of the bearer network L2 such as MAC address spoofing and ARP flooding. Description of the Drawings

[0046] Figure 1 It is an application environment diagram of the access method of the access authentication technology in an embodiment.

[0047] Figure 2 It is a schematic flowchart of the access method of the access authentication technology on the terminal side in an embodiment.

[0048] Figure 3 It is a schematic flowchart of the access method of the access authentication technology on the control plane side in another embodiment.

[0049] Figure 4 It is an example flowchart of the access method of the access authentication technology in an embodiment.

[0050] Figure 5 It is a schematic diagram of the traditional in-network deployment structure in an embodiment;

[0051] Figure 6 It is a schematic diagram of the in-network deployment structure of the present application in an embodiment;

[0052] Figure 7 It is a block diagram of the access device of the access authentication technology in an embodiment;

[0053] Figure 8 It is a block diagram of the access device of the access authentication technology in another embodiment;

[0054] Figure 9 It is an internal structure diagram of a communication device in an embodiment. Detailed implementation manners

[0055] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0056] Figure 1 It is a schematic diagram of the application scenario of an access method of an access authentication technology provided by an embodiment of the present application. As Figure 1 shown, this scenario includes: a terminal 100, a user plane 200, and a control plane 300. Specifically, in the present application, the terminal 100 has been managed by the operator's management and control system before initiating the IPoE access process, and its behavior can be managed and controlled; and the IPoE discovery phase can be achieved through unicast, avoiding data link layer security problems such as MAC address spoofing and ARP flooding, ensuring the security and reliability of the bearer network service, and reducing the deployment and operation and maintenance difficulties.

[0057] Among them, the terminal 100 is a wired terminal

[0058] The user plane UP (User Plane) is used to transmit user-generated data. It is responsible for transmitting these data packets between different nodes in the network to achieve communication between users or interaction between users and network resources.

[0059] The control plane CP (Control Plane) is responsible for configuring, managing, and controlling the network to ensure that the network can operate normally.

[0060] In the traditional technology, under the BRAS CU separation technology regime defined in IETF RFC8772 (Internet Engineering Task Force), the IPoE access is terminated by the user plane (UP). Since the UP pooling is deployed high-hung, a bearer network is deployed between the access network and the user plane, and the initial discovery information (i.e., Discovery information) of the IPoE access is carried in the layer 2 broadcast packet. When attacks such as MAC address flooding and ARP flooding occur on the terminal side, there will be a large number of broadcast packets in the bearer network, causing a broadcast storm, and there may be a MAC address spoofing problem on the terminal side, which brings L2 (data link layer) security problems to the bearer network.

[0061] Based on the problems existing in the above traditional technology, the embodiment of the present application provides an access method for an access authentication technology. In the access method of this access authentication technology, the original broadcast-form DHCP discovery packet is encapsulated and directly sent to the control plane, and the subsequent packets sent are all layer 2 unicast traffic packets. And the control plane selects the user plane according to the service attribute information of the terminal, that is, the control plane can perform unified control. Therefore, the entire signaling process does not involve broadcast traffic, avoiding the broadcast storm problem that may be brought to the bearer network during the access process of the access authentication technology IPoE, and avoiding the security problems of the bearer network L2 such as MAC address spoofing and ARP flooding.

[0062] It should be noted that the beneficial effects or the technical problems solved by the embodiment of the present application are not limited to this one, and there may also be other implicit or related problems. For specific details, please refer to the description of the following embodiments.

[0063] Before introducing the specific embodiments of the present invention, the professional terms involved in the present invention are first explained:

[0064] IPoE (IP over Ethernet, Internet Protocol over Ethernet): A connection method that uses the IP protocol in an Ethernet environment, especially in Ethernet and fiber optic networks. IPoE uses DHCP (Dynamic Host Configuration Protocol) to assign IP addresses to terminals and performs user identity authentication and authorization through an authentication server.

[0065] The host configuration protocol DHCP: A network protocol used for automatically configuring network devices. In a computer network, the DHCP protocol is used to automatically assign network configuration parameters such as IP addresses, subnet masks, default gateways, and important information such as DNS servers to devices in the network. It enables network devices to access the network quickly and easily without manually configuring network parameters.

[0066] MAC address (Media Access Control Address): Also known as the media access control address, it is the unique identifier of a network device's network card (such as an Ethernet network card or a wireless network card).

[0067] DNS (Domain Name System): It is a distributed naming system in the Internet used to convert domain names (such as example.com) into corresponding IP addresses.

[0068] URL (Uniform Resource Locator): It is the address used to identify and locate resources on the Internet.

[0069] AAA (Authentication, Authorization, and Accounting, the authorization authentication and accounting node): It is used to authenticate user identities, authorize user access rights, and record user activities.

[0070] The technical solution of this application and how this technical solution solves the above technical problems will be described in detail below with specific embodiments. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of this application will be described below in conjunction with the accompanying drawings.

[0071] In one embodiment, as Figure 2 shown, an access method for access authentication technology is provided. Taking the method applied to the Figure 1 terminal as an example for illustration, it includes the following steps:

[0072] Step 202, obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form.

[0073] In implementation, before initiating an IPOE access request, based on existing standard mechanisms, device onboarding usually needs to be completed. This process aims to ensure that the access device (i.e., the terminal) can effectively access the network and comply with corresponding network policies and security requirements. At the same time, it can also be used to configure and manage relevant settings of the device. Specifically, when the terminal powers on, it obtains network configuration information, which can include but is not limited to management addresses, DNS, URLs, etc. Then, the terminal directly accesses the control plane (CP) based on this network configuration information. Furthermore, after the terminal successfully accesses, the terminal sends a DHCP discovery message (i.e., DHCP Discovery message information) to the control plane.

[0074] Optionally, the DHCP Discovery message information can be carried in HTTP to send the DHCP Discovery broadcast message in unicast form.

[0075] Optionally, the DHCP Discovery message information can be encapsulated in a Layer 3 message to send the DHCP Discovery broadcast message in unicast form.

[0076] Step 204: Receive the media access control address (MAC) information of the user plane fed back by the control plane.

[0077] The media access control address (MAC) information is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP Discovery message information passes the authentication.

[0078] In implementation, after receiving the DHCP Discovery message information sent by the terminal, the control plane sends the user authentication information included in the DHCP Discovery message information to the AAA (Authorization, Authentication, and Accounting node) for authentication of the user authentication information. Then, the control plane can obtain the authentication result fed back by the AAA. When the authentication result indicates that the user authentication information passes the authentication, the control plane selects a corresponding user plane for the terminal in the user plane pool, that is, the user plane, and allocates IP address information for the terminal. Then, the control plane sends the media access control address (MAC) information of the selected UP for the terminal to the terminal. Thus, the terminal can receive the media access control address (MAC) information of the user plane (i.e., the target UP) fed back by the control plane to implement two-layer unicast message transmission with the user plane.

[0079] Optionally, the service attribute information of the terminal can include, but is not limited to, IPTV (Internet Protocol Television) service attribute information and VoIP (Voice over Internet Protocol) service attribute information. The embodiments of the present application do not limit the service attribute information of the terminal.

[0080] Step 206: Receive the DHCP offer message sent by the user plane and send a unicast DHCP request message to the user plane.

[0081] In implementation, when the control plane feeds back the media access control address (MAC) information of the selected user plane to the terminal, the control plane also sends the MAC address, IP address, and authentication information (i.e., authentication results including user authentication information, etc.) of the terminal to the user plane. Then, the user plane feeds back a DHCP offer message (i.e., DHCP Offer message) to the terminal. Thus, the terminal can receive the DHCP Offer message fed back by the user plane, and then the terminal responds to the DHCP Offer message and sends a DHCP request message (i.e., DHCP Request message) to the user plane to indicate acceptance of the corresponding configuration.

[0082] Specifically, the terminal first verifies the DHCP Offer based on the source MAC address of the user plane included in the DHCP Offer and the media access control address (MAC) information of the user plane received in advance. If the source MAC address is consistent with the media access control address of the user plane received in advance, the DHCP Offer verification passes. Then, the terminal responds to the DHCP Offer message, accepts its configuration, and responds with a DHCP Request message.

[0083] Step 208: Receive the DHCP acknowledgment message fed back by the user plane to complete the DHCP-related configuration.

[0084] In implementation, after receiving the DHCP Request message sent by the terminal, the user plane acknowledges the DHCP Request message and feeds back an acknowledgment message to the terminal. Therefore, the terminal can receive the DHCP acknowledgment message (i.e., DHCP ACK) fed back by the user plane and apply the allocated IP address, subnet mask, gateway, DNS server, etc. in the configuration information in the DHCP ACK to its own network settings. This application does not limit the process of the terminal completing its own network configuration.

[0085] In the access method of the above access authentication technology, the terminal directly accesses the control plane, encapsulates the original DHCP discovery message in the form of a broadcast message, and directly sends it to the control plane in the form of a unicast message. And since the subsequent messages sent are all layer 2 unicast traffic messages, there is no broadcast traffic involved in the entire signaling process. And since the control plane selects the user plane according to the service attribute information of the terminal, that is, the control plane can achieve unified control, thus avoiding the broadcast storm problem that the access process of the IPoE access authentication technology may bring to the bearer network, and also avoiding security problems of the bearer network layer 2 such as MAC address spoofing and ARP flooding.

[0086] In one embodiment, obtaining the network configuration information in step 202 may include:

[0087] In step 2021, obtain the management address corresponding to the terminal, Domain Name System information DNS, and Uniform Resource Locator URL information of the control plane through DHCP.

[0088] In implementation, the network configuration information may include, but is not limited to, the management address, Domain Name System information DNS, Uniform Resource Locator URL information of the control plane, etc. Therefore, after the terminal is powered on and starts up, it can directly obtain the management address, DNS, URL information of the control plane, etc. corresponding to the terminal through DHCP.

[0089] In this embodiment, the terminal can directly obtain the management address, DNS, and URL information of the control plane through DHCP. Thus, it improves the convenience for realizing direct access and information interaction with the control plane.

[0090] The terminal directly accesses the control plane and sends a DHCP Discovery message in unicast form. There are various methods to implement the method of sending a DHCP Discovery message in unicast. This application takes the following two access methods as examples for illustration. In the specific application process, it can be determined based on service and protocol requirements. This application does not limit the specific method for the terminal to access the control plane.

[0091] Method 1: In one embodiment, step 202 of accessing the control plane based on the network configuration information and sending a Dynamic Host Configuration Protocol DHCP discovery message to the control plane may specifically include:

[0092] In step 2022, access the control plane based on the URL in the network configuration information and initiate a Hypertext Transfer Protocol connection establishment request to the control plane.

[0093] Among them, the DHCP discovery message is carried in the Hypertext Transfer Protocol connection establishment request.

[0094] In implementation, the terminal resolves the URL (Uniform Resource Locator URL) information of the control plane (CP) based on the DNS in the network configuration information to obtain the IP address corresponding to the control plane. Then, the terminal uses the obtained IP address of the control plane and the URL address to access the control plane. Therefore, the terminal can directly access the control plane based on the obtained IP address and URL of the control plane. After accessing the control plane, send an HTTP connection establishment request to the control plane, and carry the DHCP Discovery message information through this HTTP connection.

[0095] In this embodiment, by encapsulating the DHCP Discovery message information in the form of a broadcast through HTTP, broadcast traffic during the access process can be avoided, thereby avoiding the broadcast storm problem that may be brought to the bearer network, and improving the stability and security of the bearer network.

[0096] Method 2. In one embodiment, in step 202, accessing the control plane based on network configuration information and sending a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane may specifically include:

[0097] Step 2023, accessing the control plane based on network configuration information, encapsulating the DHCP discovery message in the form of a three-layer message, and sending the encapsulated DHCP discovery message to the control plane.

[0098] In implementation, the terminal resolves the IP address of the control plane based on the DNS in the obtained network configuration information. Based on the IP address of the control plane (CP), the terminal further encapsulates the DHCP discovery message in the form of a three-layer message and directly sends the encapsulated DHCP Discovery message information to the control plane.

[0099] In this embodiment, by directly sending the DHCP Discovery message information to the control plane in three layers based on the IP address within the control plane, the original broadcast message is sent in the form of a unicast, avoiding broadcast traffic during the access process, thereby avoiding the broadcast storm problem that may be brought to the bearer network, and improving the stability and security of the bearer network.

[0100] In one embodiment, in step 204, receiving the Media Access Control (MAC) address of the user plane feedback by the control plane may include:

[0101] Step 2041, receiving the MAC information of the Media Access Control address of the user plane feedback by the control plane.

[0102] Among them, the MAC information is used to verify the source MAC information in the DHCP offer message sent by the received user plane.

[0103] In implementation, after the control plane selects the user plane, it will send the MAC information of the Media Access Control address of the user plane to the terminal. The terminal receives the MAC information of the Media Access Control address of the user plane, and uses this MAC information as the reference MAC information to verify the source MAC information in the subsequent DHCP offer message.

[0104] In this embodiment, the Media Access Control (MAC) address information provides a unique identifier and is used for addressing and routing in the network. Moreover, based on the received MAC address information, the terminal can verify the DHCP offer message sent by the user plane, improving the access security of the access authentication technology.

[0105] In one embodiment, as Figure 3 shown, an access method for an access authentication technology is provided. This method is applied to the control plane and includes:

[0106] Step 302, receive a Dynamic Host Configuration Protocol (DHCP) discovery message sent by the terminal.

[0107] In implementation, the control plane receives the DHCP discovery message sent by the terminal (i.e., the DHCP Discovery message information). Specifically, since the terminal directly accesses the control plane, without going through the relay of the UP pool, the control plane can directly receive the unicast-form DHCP Discovery message information sent by the terminal. The DHCP Discovery message information contains the information required for user authentication.

[0108] Step 304, send the user authentication information to the Authentication, Authorization, and Accounting (AAA) node, and determine the authentication result of the user authentication information through the AAA.

[0109] In implementation, the control plane obtains the information required for user authentication contained in the DHCP discovery message, constructs the user authentication information based on the information required for user authentication, and sends the user authentication information to the authentication, authorization, and accounting node. The AAA node authenticates information such as the username, password, and Option 82 (line information used to identify the user location information) contained in the user authentication information to obtain the authentication result of the user authentication information. Then, the AAA node will feedback the authentication result of the user authentication information to the control plane.

[0110] Optionally, the user authentication information may include, but is not limited to, the username, password, and Option 82. The embodiments of the present application do not limit the types and numbers of information contained in the user authentication information.

[0111] Step 306, if the authentication result is authentication passed, select the user plane based on the service attribute information of the terminal and allocate an Internet Protocol (IP) address to the terminal.

[0112] In implementation, terminals with different service attributes need to match the user plane corresponding to the service attribute. Therefore, in the DHCP discovery message sent by the terminal, in addition to the information required for user authentication, it also includes the service attribute information corresponding to the terminal and the media access control address (MAC) information. After the authentication result corresponding to the user authentication information of the terminal is authentication passed, the control plane selects a user plane that matches the service attribute of the terminal from the user plane pool (i.e., the UP pool). If the control plane receives an authentication passed result feedback from AAA, the control plane can select a user plane for the terminal based on the service attribute information contained in the DHCP discovery message, and the control plane can allocate an IP address for the terminal.

[0113] Specifically, the unified control of the MAC forwarding table and the ARP table is implemented in the control plane, that is, the control plane can implement the unified control of the MAC forwarding table and ARP table entries based on the media access control address (MAC) information of the terminal contained in the DHCP Discovery message information and the IP address allocated for the terminal.

[0114] Step 308: Send the media access control address (MAC) information of the user plane to the terminal, and send the media access control address (MAC) information of the terminal and the Internet Protocol (IP) address allocated for the terminal to the user plane.

[0115] In implementation, after the control plane completes the management of the terminal and the user plane, the control plane sends the media access control address (i.e., the media access control address (MAC) information of the user plane) of the selected user plane to the terminal, and sends the media access control address (MAC) information of the terminal and the IP address allocated for the terminal to the user plane.

[0116] In this embodiment, by directly accessing the control plane through the terminal, the original broadcast-form DHCP discovery message is encapsulated and directly sent to the control plane in unicast form, so that there is no broadcast traffic in the entire signaling process. Moreover, the control plane selects a user plane for the terminal according to the service attribute information of the terminal and allocates an IP address for the terminal, realizing the unified control of the terminal and the user plane, avoiding the broadcast storm problem that may be brought to the bearer network during the access process of the access authentication technology, and also avoiding the security problems of the bearer network L2 such as MAC address spoofing and ARP flooding.

[0117] In one embodiment, specifically, sending the media access control address (MAC) information of the user plane to the terminal in step 308 may include:

[0118] Step 3081: Send the media access control address (MAC) information of the selected user plane to the terminal.

[0119] In implementation, the control plane sends the media access control (MAC) address information of the selected user plane to the terminal to perform subsequent processes of the access method of the access authentication technology based on the MAC address information of the user plane.

[0120] In this embodiment, the control plane sends the MAC of the selected user plane to the terminal. Thus, the terminal can establish communication with the user plane based on the MAC address of the user plane.

[0121] In one embodiment, as Figure 4 shown, a specific example of the access method of the access authentication technology is provided, and this example includes:

[0122] Step 401, the terminal is powered on and obtains network configuration information through DHCP. The network configuration information includes management address, DNS, URL information, etc.;

[0123] Step 402, the terminal accesses the CP through the URL and initiates an HTTP connection establishment request, and carries the DHCP Discovery message information through the HTTP connection establishment request;

[0124] Step 403, the CP constructs user authentication information based on the DHCP Discovery message information and sends it to the AAA;

[0125] Step 404, the AAA authenticates the user authentication information;

[0126] Step 405, the AAA returns the authentication result of the user authentication information;

[0127] Step 406, if the authentication result of the user authentication information is authentication passed, the CP selects the target UP according to the service attribute information of the terminal service included in the DHCP Discovery message information of the terminal and assigns an IP address to the terminal;

[0128] Step 407, the CP returns a connection establishment message to the terminal, and at the same time, sends the MAC address of the selected target UP to the terminal;

[0129] Step 408, the CP sends the MAC address and IP address of the terminal, as well as the authentication result of the user authentication information, to the target UP;

[0130] Step 409, the target UP sends a DHCP Offer message to the terminal;

[0131] Step 410, the terminal verifies the source Media Access Control (MAC) address information in the DHCP Offer packet sent by the target UP, responds to the DHCP Offer packet, accepts the relevant configuration, and simultaneously sends a unicast DHCP Request packet to the target UP;

[0132] Step 411, the UP returns an access success message through a DHCP ACK packet.

[0133] In one embodiment, for services with different service attributes of the terminal, for example, IPTV and VoIP services, in the traditional existing network deployment, pUP (Physical User Plane) bears the IPTV service, and vUP (Virtual User Plane) bears the VoIP service. As Figure 5 shown, when different services are dialed up to the UP through IPoE, it is necessary to deploy L2VPN for different services separately on the bearer network, and at the same time, corresponding VLANs (Virtual Local Area Networks) corresponding to different L2VPNs need to be opened on the home gateway. This requires a large amount of planning and deployment. This application provides an access method for access authentication technology. As Figure 6 shown, for a service request initiated by the terminal, the DHCP Discovery packet information will be carried through an HTTP connection and sent to the CP. The CP selects the relevant UP (i.e., the user plane) according to the service attribute of the service request. Therefore, a unified L2VPN channel can be opened in advance on the bearer network, and all services share this L2VPN. When a new service is enabled, there is no need to deploy a new VPN on the bearer network. Compared with the traditional method, the access method of the access authentication technology proposed in this application has good service scalability and reduces the deployment difficulty of the bearer network.

[0134] It should be understood that although Figures 2 to 4 the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, Figures 2 to 4 at least a part of the steps in

[0135] In one embodiment, as Figure 7As shown in the figure, an access device 700 for access authentication technology is provided, including: a sending module 701, a first receiving module 702, a second receiving module 703, and a third receiving module 704, where:

[0136] The sending module 701 is configured to obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form.

[0137] The first receiving module 702 is configured to receive Media Access Control (MAC) information of the user plane fed back by the control plane; the MAC information is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message is authenticated.

[0138] The second receiving module 703 is configured to receive a DHCP offer message sent by the user plane and send a unicast DHCP request message to the user plane.

[0139] The third receiving module 704 is configured to receive a DHCP acknowledgment message fed back by the user plane and complete DHCP-related configurations.

[0140] In one embodiment, the sending module 701 is specifically configured to obtain the management address corresponding to the terminal, Domain Name System (DNS) information, and Uniform Resource Locator (URL) information of the control plane through DHCP.

[0141] In one embodiment, the first receiving module 702 is specifically configured to access the control plane based on the URL in the network configuration information and initiate a Hypertext Transfer Protocol (HTTP) connection establishment request to the control plane; the DHCP discovery message is carried in the HTTP connection.

[0142] In one embodiment, the second receiving module 703 is specifically configured to access the control plane based on the network configuration information, encapsulate the DHCP discovery message in the form of a three-layer message, and send the encapsulated DHCP discovery message to the control plane.

[0143] In one embodiment, the first receiving module 702 is specifically configured to receive the MAC information of the user plane fed back by the control plane, and the MAC information is used to verify the source MAC information in the DHCP offer message sent by the received user plane.

[0144] In one embodiment, as Figure 8 shown, another access device 800 for access authentication technology is provided, including: a receiving module 801, a first sending module 802, a processing module 803, and a second sending module 804, where:

[0145] A receiving module 801, configured to receive a Dynamic Host Configuration Protocol (DHCP) discovery message sent by a terminal;

[0146] A first sending module 802, configured to send user authentication information to an Authentication, Authorization, and Accounting (AAA) node, and determine an authentication result of the user authentication information through the AAA;

[0147] A processing module 803, configured to, if the authentication result is authentication passed, select a user plane based on service attribute information of the terminal, and allocate an Internet Protocol (IP) address to the terminal;

[0148] A second sending module 804, configured to send Media Access Control (MAC) information of the user plane to the terminal, and send the MAC information of the terminal and the IP address allocated to the terminal to the user plane.

[0149] In one embodiment, the second sending module 804 is configured to send the MAC information of the selected user plane to the terminal.

[0150] For specific limitations on the access device regarding the access authentication technology, reference may be made to the limitations on the access method of the access authentication technology in the foregoing text, which will not be elaborated herein. Each module in the access device of the foregoing access authentication technology may be implemented in whole or in part by software, hardware, and their combination. The foregoing modules may be embedded in or independent of a processor in a computer device in a hardware form, or stored in a memory in a computer device in a software form, so as to facilitate the processor to call and execute operations corresponding to the foregoing modules.

[0151] In one embodiment, a communication device is provided. Refer to Figure 9 . Figure 9 It is a schematic structural diagram of a terminal provided by an embodiment of the present invention. Figure 9 The terminal 900 shown includes at least one processor 901, a memory 902, at least one network interface 904, and a user interface 903. Each component in the terminal 900 is coupled together through a bus system 905. It can be understood that the bus system 905 is used to implement connection communication between these components. In addition to a data bus, the bus system 905 further includes a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, in Figure 9 all kinds of buses are labeled as the bus system 905. In addition, in an embodiment of the present invention, a transceiver 906 is further included, and the transceiver may be multiple elements, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on a transmission medium.

[0152] Among them, the user interface 903 may include a display, a keyboard, or a pointing device (such as a mouse, a trackball, a touchpad, or a touch screen, etc.).

[0153] It can be understood that the memory 902 in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM). The memory 702 of the systems and methods described in the embodiments of the present invention is intended to include but not be limited to these and any other suitable types of memory.

[0154] In some embodiments, the memory 902 stores the following elements, executable modules, or data structures, or subsets thereof, or extended sets thereof: an operating system 9021 and application programs 9022.

[0155] Among them, the operating system 9021 includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks. The application programs 9022 include various application programs, such as a media player, a browser, etc., for implementing various application services. The program for implementing the method of the embodiments of the present invention may be included in the application programs 9022.

[0156] In an embodiment of the present invention, by invoking a program or instruction stored in the memory 902, specifically, it may be a program or instruction stored in the application program 9022. Among them, a transmitter is configured to obtain network configuration information, access a control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane; a receiver is configured to receive the Media Access Control (MAC) address of the user plane fed back by the control plane; the address information is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message passes the authentication; the receiver is further configured to receive a DHCP offer message sent by the user plane and send a unicast DHCP request message to the user plane; and the receiver is further configured to receive a DHCP acknowledgment message fed back by the user plane.

[0157] Some or all of the methods disclosed in the above embodiments of the present invention may also be applied to the processor 901, or implemented by the processor 901, or implemented in cooperation with other components (such as a transceiver) by the processor 901. The processor 901 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method may be completed by the integrated logic circuit in the hardware of the processor 901 or by an instruction in the form of software. The above-mentioned processor 901 may be a general-purpose processor, a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present invention may be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 902, and the processor 901 reads the information in the memory 902 and combines its hardware to complete the steps of the above method.

[0158] It can be understood that the embodiments described in the embodiments of the present invention can be implemented by hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing unit can be implemented in one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), general purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions of the present application, or a combination thereof.

[0159] For software implementation, the technology of the embodiments of the present invention can be implemented by modules (such as procedures, functions, etc.) that execute the functions of the embodiments of the present invention. The software code can be stored in a memory and executed by the processor 901. The memory can be implemented inside or outside the processor 901.

[0160] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0161] Obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form;

[0162] Receive the Media Access Control (MAC) address information of the user plane feedback by the control plane; the MAC address information is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message is authenticated.

[0163] Receive the DHCP offer message sent by the user plane, and send a unicast DHCP request message to the user plane;

[0164] Receive the DHCP acknowledgment message feedback by the user plane to complete the DHCP-related configuration.

[0165] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:

[0166] Obtain the management address corresponding to the terminal, Domain Name System (DNS) information, and the Uniform Resource Locator (URL) information of the control plane through DHCP.

[0167] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented:

[0168] Access the control plane based on the URL in the network configuration information, and initiate a Hypertext Transfer Protocol (HTTP) connection establishment request to the control plane; the Hypertext Transfer Protocol (HTTP) connection establishment request carries a DHCP discovery message.

[0169] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0170] Access the control plane based on the network configuration information, encapsulate the DHCP discovery message in the form of a layer-3 message, and send the encapsulated DHCP discovery message to the control plane.

[0171] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0172] Receive the Media Access Control (MAC) address information of the user plane fed back by the control plane, and the Media Access Control (MAC) address information is used to verify the source Media Access Control (MAC) address information in the DHCP offer message sent by the received user plane.

[0173] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0174] Receive a Dynamic Host Configuration Protocol (DHCP) discovery message sent by a terminal;

[0175] Send the user authentication information to an Authentication, Authorization, and Accounting (AAA) node, and determine the authentication result of the user authentication information through the AAA;

[0176] If the authentication result is authentication passed, select a user plane based on the service attribute information of the terminal, and allocate an Internet Protocol (IP) address to the terminal;

[0177] Send the Media Access Control (MAC) address information of the user plane to the terminal, and send the Media Access Control (MAC) address information of the terminal and the allocated Internet Protocol (IP) address of the terminal to the user plane.

[0178] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0179] Send the Media Access Control (MAC) address information of the selected user plane to the terminal.

[0180] An embodiment of the present application further provides a computer program product containing instructions. When it runs on a computer, it causes the computer to execute the following steps:

[0181] Obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form;

[0182] Receive the Media Access Control (MAC) address information of the user plane feedback by the control plane; the MAC address information is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message passes the authentication;

[0183] Receive the DHCP offer message sent by the user plane, and send a unicast DHCP request message to the user plane;

[0184] Receive the DHCP acknowledgment message feedback by the user plane to complete the DHCP-related configuration.

[0185] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include Read-Only Memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include Random Access Memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM), etc.

[0186] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0187] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it cannot be understood as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

Claims

1. An access method for an access authentication technology, characterized in that, The method includes: Obtain network configuration information, access the control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form; Receive the Media Access Control (MAC) address information of the user plane fed back by the control plane; the MAC address information of the user plane is determined by the control plane based on the service attribute information of the terminal after the user authentication information included in the DHCP discovery message passes the authentication; Receive the DHCP offer message sent by the user plane, and send a unicast DHCP request message to the user plane; Receive the DHCP acknowledgment message fed back by the user plane to complete the DHCP-related configuration.

2. The method according to claim 1, wherein The obtaining of the network configuration information includes: Obtain the management address corresponding to the terminal, Domain Name System (DNS) information, and the Uniform Resource Locator (URL) information of the control plane through DHCP.

3. The method according to claim 1, characterized in that The accessing of the control plane based on the network configuration information and sending a DHCP discovery message to the control plane in unicast form includes: Access the control plane based on the URL in the network configuration information, and initiate a Hypertext Transfer Protocol (HTTP) connection establishment request to the control plane; the DHCP discovery message is carried in the HTTP connection.

4. The method according to claim 1, wherein The accessing of the control plane based on the network configuration information and sending a DHCP discovery message to the control plane includes: Access the control plane based on the network configuration information, encapsulate the DHCP discovery message in a three-layer message form, and send the encapsulated DHCP discovery message to the control plane.

5. The method according to claim 1, wherein The receiving of the MAC address information of the user plane fed back by the control plane includes: Receive the MAC address information of the user plane fed back by the control plane, and the MAC address information of the user plane is used to verify the source MAC address information in the DHCP offer message sent by the received user plane.

6. An access method for an access authentication technology, characterized in that, The method is applied to the control plane, and the method includes: Receive the DHCP discovery message sent by the terminal; Send the user authentication information to the Authentication, Authorization, and Accounting (AAA) node for user authentication; If the authentication result is authentication passed, select the user plane based on the service attribute information of the terminal and assign an Internet Protocol (IP) address to the terminal; Send the MAC address information of the user plane to the terminal, and send the MAC address information of the terminal and the assigned IP address of the terminal to the user plane.

7. The method according to claim 6, wherein The sending of the MAC address information of the user plane to the terminal includes: Send the MAC address information of the selected user plane to the terminal.

8. An access device for an access authentication technology, characterized in that, The device is applied to the terminal, and the device includes: A sending module, configured to obtain network configuration information, access a control plane based on the network configuration information, and send a Dynamic Host Configuration Protocol (DHCP) discovery message to the control plane in unicast form; A first receiving module, configured to receive Media Access Control (MAC) information of a user plane fed back by the control plane; the MAC information is determined by the control plane based on service attribute information of a terminal after user authentication information included in the DHCP discovery message passes the authentication; A second receiving module, configured to receive a DHCP offer message sent by the user plane and send a unicast DHCP request message to the user plane; A third receiving module, configured to receive a DHCP acknowledgment message fed back by the user plane to complete DHCP-related configuration.

9. An access device for an access authentication technology, characterized in that, The apparatus is applied to a control plane and includes: A receiving module, configured to receive a DHCP discovery message sent by a terminal; A first sending module, configured to send user authentication information to an Authentication, Authorization and Accounting (AAA) node for user authentication; A processing module, configured to, if the authentication result is authentication passed, select a user plane based on the service attribute information of the terminal and allocate an Internet Protocol (IP) address to the terminal; A second sending module, configured to send the MAC information of the user plane to the terminal, and send the MAC information of the terminal and the IP address allocated to the terminal to the user plane.

10. A communication device, characterized in that, Including: A transmitter and a receiver The transmitter is configured to obtain network configuration information, access a control plane based on the network configuration information, and send a DHCP discovery message to the control plane in unicast form; The receiver is configured to receive the MAC information of the user plane fed back by the control plane; the MAC information is determined by the control plane based on service attribute information of a terminal after user authentication information included in the DHCP discovery message passes the authentication; The receiver is configured to receive a DHCP offer message sent by the user plane and send a unicast DHCP request message to the user plane; The receiver is configured to receive a DHCP acknowledgment message fed back by the user plane to complete DHCP-related configuration.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5, or 6 to 7.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5, or 6 to 7.