Blacklist management method and device for broadband network access authentication and medium
By implementing a blacklist management method in the broadband access network, the resource consumption and performance stability problems caused by frequent terminal authentication are solved, and the filtering of invalid authentication requests and the optimal use of system resources are realized.
Patent Information
- Application Number
- CN202311850691.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-01
AI Technical Summary
In broadband access networks, terminals frequently try to de-number access to the network, resulting in frequent transmission of authentication requests to provincial authentication systems, resulting in resource consumption and performance stability problems.
The blacklist management method is adopted to obtain the authentication blacklist and graylist in the broadband authentication platform, receive the authentication request of the target terminal, and calculate the summary information based on the account number, password, network line and MAC address, and perform blacklist filtering policy processing to allow or deny authentication requests.
Effectively filter out invalid terminal repeated authentication requests, reduce resource consumption for provincial authentication systems, and improve the performance and stability of provincial platforms.
Smart Images

Figure CN120238323A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technologies, and in particular, to a blacklist management method, device, and medium for broadband network access authentication. Background Art
[0002] In the broadband access network of an operator, a Broadband Remote Access Server (BRAS) is a device used to authenticate terminals.
[0003] Most broadband dial-up terminals are of the type such as home router dialers. These devices are connected to the network for a long time at home. When a user cannot obtain the permission to access the network due to arrears or other reasons, they will still frequently attempt to dial and access the network. Moreover, in the actual network operation of the operator, most broadband access authentications adopt a provincial centralized method.
[0004] In this method, for each access attempt of the terminal, the BRAS needs to send the authentication to the provincial remote server for authentication. Since the user has no access permission, it will cause repeated and frequent authentications of many terminals, consuming a large amount of resources for the provincial authentication system. Especially during line cutover and centralized payment, a large number of authentication requests will suddenly occur in a short time, which will affect the performance and stability of the provincial platform. Summary of the Invention
[0005] Embodiments of the present application provide a blacklist management method, device, and medium for broadband network access authentication to solve the problems existing in the related technologies. The technical solutions are as follows:
[0006] In a first aspect, embodiments of the present application provide a blacklist management method for broadband network access authentication, including:
[0007] Obtain an authentication blacklist and an authentication gray list pre-stored in a broadband authentication platform, where the authentication gray list includes a number of broadband accounts, and the authentication blacklist includes a number of summary information;
[0008] Receive a target authentication request of a target terminal, where the target authentication request is used to request broadband access authentication for the target terminal, and the target authentication request carries key information of the target terminal, namely a target broadband account, a target account password, a target network line, and a target MAC address;
[0009] When it is determined that the target broadband account is in the authentication gray list, allow the BRAS (which is a broadband access server) to perform normal authentication on the target terminal;
[0010] When it is determined that the target broadband account is not in the authentication gray list, the following blacklist filtering policy is executed:
[0011] Extract the key information of the target terminal from the target authentication request, and calculate the target digest information of the target terminal according to the key information;
[0012] When it is determined that the target digest information is in the authentication blacklist, return an authentication failure result to the target terminal.
[0013] In one implementation, any of the digest information in the authentication blacklist is collected from the broadband account, account password, network line, and MAC address in the authentication request with authentication failure according to the historical authentication results of the BRAS, and the target digest information is calculated according to the collected broadband account, account password, network line, and MAC address;
[0014] The authentication gray list is manually configured by the installation and maintenance personnel before on-site debugging.
[0015] In one implementation, calculating the target digest information of the target terminal according to the key information includes:
[0016] After splicing the target broadband account, target account password, target network line, and target MAC address in the key information, perform a hash calculation using the MD5 information digest algorithm to obtain the target digest information.
[0017] In one implementation, the blacklist filtering policy further includes:
[0018] When it is determined that the target digest information is not in the authentication blacklist, allow the BRAS to perform normal authentication on the target terminal.
[0019] In one implementation, the method further includes:
[0020] Receive the authentication failure result of the target terminal, where the authentication failure result is sent after the BRAS fails to authenticate the target terminal;
[0021] Determine the current time when the authentication failure result is received as the authentication failure time of the target terminal, and save the target digest information and the authentication failure time correspondingly to the authentication blacklist.
[0022] In one implementation, the authentication blacklist further includes the validity period of any of the digest information, and the method further includes:
[0023] When it is determined that the target digest information is in the authentication blacklist, if the current time is within the validity period of the target digest information, return an authentication failure result to the target terminal; or,
[0024] If the current time has passed the expiration date of the target summary information, normal authentication of the target terminal is allowed through the BRAS.
[0025] In one embodiment, the authentication gray list further includes the expiration date of any of the broadband accounts, and the method further includes:
[0026] When it is determined that the target broadband account is in the authentication gray list, if the current time is within the expiration date of the target broadband account, normal authentication of the target terminal is allowed through the BRAS; or,
[0027] If the current time has passed the expiration date of the target broadband account, the blacklist filtering policy is executed.
[0028] In a second aspect, an embodiment of the present application further provides a blacklist management device for broadband network access authentication, including:
[0029] A transceiver unit, configured to obtain an authentication blacklist and an authentication gray list pre-stored in a broadband authentication platform, where the authentication gray list includes a plurality of broadband accounts, and the authentication blacklist includes a plurality of summary information; receive a target authentication request of a target terminal, where the target authentication request is used to request broadband access authentication for the target terminal, and the target authentication request carries key information of the target terminal, namely, a target broadband account, a target account password, a target network line, and a target MAC address;
[0030] A processing unit, configured to allow normal authentication of the target terminal through the BRAS when it is determined that the target broadband account is in the authentication gray list, where the BRAS is a broadband access server; when it is determined that the target broadband account is not in the authentication gray list, execute the following blacklist filtering policy:
[0031] Extract the key information of the target terminal from the target authentication request, and calculate the target summary information of the target terminal according to the key information; when it is determined that the target summary information is in the authentication blacklist, return an authentication failure result to the target terminal.
[0032] In one embodiment, any of the summary information in the authentication blacklist is calculated according to the historical authentication results of the BRAS, collecting the broadband account, account password, network line, and MAC address in the authentication request with authentication failure, and calculating according to the collected broadband account, account password, network line, and MAC address;
[0033] The authentication gray list is manually configured by the installation and maintenance personnel before on-site debugging.
[0034] In one embodiment, the processing unit is specifically configured to:
[0035] After splicing the target broadband account, target account password, target network line, and target MAC address in the key information, perform a hash calculation using the MD5 message-digest algorithm to obtain the target digest information.
[0036] In one embodiment, the blacklist filtering policy further includes:
[0037] When it is determined that the target digest information is not in the authentication blacklist, allow the BRAS to perform normal authentication on the target terminal.
[0038] In one embodiment, the transceiver unit is further configured to: receive the authentication failure result of the target terminal, where the authentication failure result is sent by the BRAS after the authentication of the target terminal fails;
[0039] The processing unit is further configured to: determine the current time when the authentication failure result is received as the authentication failure time of the target terminal, and save the target digest information and the authentication failure time correspondingly to the authentication blacklist.
[0040] In one embodiment, the authentication blacklist further includes the validity period of any of the digest information, and the processing unit is further configured to:
[0041] When it is determined that the target digest information is in the authentication blacklist, if the current time is within the validity period of the target digest information, return an authentication failure result to the target terminal; or,
[0042] If the current time has passed the validity period of the target digest information, allow the BRAS to perform normal authentication on the target terminal.
[0043] In one embodiment, the authentication gray list further includes the validity period of any of the broadband accounts, and the processing unit is further configured to:
[0044] When it is determined that the target broadband account is in the authentication gray list, if the current time is within the validity period of the target broadband account, allow the BRAS to perform normal authentication on the target terminal; or,
[0045] If the current time has passed the validity period of the target broadband account, then execute the blacklist filtering policy.
[0046] In a third aspect, an embodiment of the present application further provides a communication device, which includes: a memory and a processor. Instructions are stored in the memory and are loaded and executed by the processor to implement the method in any of the above aspects and any of its implementation manners. Wherein, the memory and the processor communicate with each other through an internal connection path.
[0047] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program runs on a computer, the method in any of the above aspects and any of its implementation manners is implemented.
[0048] The advantages or beneficial effects in the above technical solutions at least include:
[0049] In the present application, by enabling the authentication gray list, in cases where the user changes the account password, changes the network line, changes the terminal, etc., since the account password, network line, MAC address, etc. will change, the corresponding digest information of the terminal will also change, and these changes can be detected in a timely manner, and normal authentication can be completed immediately, without being affected by the authentication blacklist. At the same time, by enabling the authentication blacklist, invalid terminal repeated authentication requests can be filtered out, which can reduce the resource consumption of the provincial authentication system and improve the performance and stability of the provincial platform.
[0050] The above summary is only for the purpose of the specification and is not intended to be limiting in any way. In addition to the above-described illustrative aspects, implementation manners, and features, further aspects, implementation manners, and features of the present application will be readily apparent by reference to the drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In the drawings, unless otherwise specified, the same reference numerals throughout the several views denote the same or similar components or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings only depict some implementation manners disclosed according to the present application and should not be regarded as limiting the scope of the present application.
[0052] Figure 1 It is a schematic flowchart of a blacklist management method for broadband network access authentication provided by an embodiment of the present application;
[0053] Figure 2 It is a schematic flowchart of another blacklist management method for broadband network access authentication provided by an embodiment of the present application;
[0054] Figure 3 It is a structural block diagram of a blacklist management device for broadband network access authentication provided by an embodiment of the present application;
[0055] Figure 4Block diagram of a communication device provided by an embodiment of the present application. Detailed implementation manners
[0056] In the following, only some exemplary embodiments are simply described. As those skilled in the art can recognize, the described embodiments can be modified in various different ways without departing from the spirit or scope of the present application. Therefore, the drawings and the description are considered to be exemplary in nature rather than restrictive.
[0057] Figure 1 Flowchart showing a blacklist management method for broadband network access authentication according to an embodiment of the present application. As Figure 1 shown, the method may include the following steps:
[0058] S101. Obtain an authentication blacklist and an authentication gray list pre-stored in a broadband authentication platform.
[0059] In one implementation manner, the authentication gray list may include, but is not limited to: several broadband accounts. The authentication blacklist may include, but is not limited to: several digest information.
[0060] In one implementation manner, the authentication gray list may be manually configured by a line installer and maintainer before on-site debugging.
[0061] In one implementation manner, any digest information in the authentication blacklist is obtained by collecting the broadband account, account password, network line, and MAC address in an authentication request with an authentication failure according to the historical authentication results of the BRAS, and calculating based on the collected broadband account, account password, network line, and MAC address. Wherein, the MAC address refers to the Media Access Control Address.
[0062] For example, after concatenating the 4 parameter strings of the broadband account, account password, network line, and MAC address, the MD5 Message-Digest Algorithm may be used for hash calculation to obtain digest information, and then the digest information is saved to the authentication blacklist.
[0063] As an example, an authentication blacklist filtering module may be added to the broadband authentication platform, and the authentication blacklist and the authentication gray list are set by an authentication server (such as a provincial remote server) to facilitate optimizing the authentication process through the authentication blacklist filtering module according to the authentication blacklist and the authentication gray list.
[0064] In this application, for a large number of terminals that do not have access permissions but frequently dial to access the network, a method of calculating the digest of the key information of the terminal can be used to set up an authentication blacklist, and the invalid terminal repeated authentication requests can be filtered through the blacklist filtering mechanism.
[0065] S102. Receive a target authentication request from a target terminal.
[0066] In one implementation, the target authentication request is used to request broadband access authentication for the target terminal, and the target authentication request carries the key information of the target terminal, namely, the target broadband account, the target account password, the target network line, and the target MAC address.
[0067] It should be understood that in this application, the target terminal refers to any terminal that requests broadband access authentication.
[0068] In specific implementation, the target terminal can initiate a target authentication request to request network access authentication.
[0069] S103. Determine whether the target broadband account is in the authentication gray list. When it is determined that the target broadband account is in the authentication gray list, execute step S104; otherwise, execute step S105.
[0070] In specific implementation, when it is determined that the target broadband account is in the authentication gray list, that is, when the target broadband account matches a certain broadband account in the authentication gray list, it means that the authentication of the target terminal is not affected by the authentication blacklist, and the blacklist filtering policy can be not executed, and normal authentication can be performed. In this case, step S104 can be executed.
[0071] In specific implementation, when it is determined that the target broadband account is not in the authentication gray list, that is, when the target broadband account does not match any broadband account in the authentication gray list, it means that the authentication of the target terminal may be affected by the authentication blacklist. In this case, step S105 can be executed to execute the blacklist filtering policy.
[0072] S104. Allow BRAS to perform normal authentication on the target terminal.
[0073] In specific implementation, in step S104, BRAS can use existing conventional methods to authenticate the target terminal, and this will not be elaborated in this embodiment of the application.
[0074] In this application, by enabling the authentication gray list, the installation and maintenance can be carried out normally without being affected by the authentication blacklist, and the problem that the key users cannot dial normally due to the authentication blacklist can also be solved. For example, the broadband account with anomalies can be added to the authentication gray list by the installation and maintenance personnel to restore normal authentication.
[0075] S105. Extract the key information of the target terminal from the target authentication request, and calculate the target digest information of the target terminal according to the key information.
[0076] In one implementation, when the target broadband account is not in the authentication gray list, the key information of the target terminal, that is, the target broadband account, the target account password, the target network line, and the target MAC address, can be extracted from the target authentication request. After that, the target broadband account, the target account password, the target network line, and the target MAC address can be concatenated and then hashed using the MD5 message-digest algorithm to obtain the target digest information.
[0077] It can be understood that in this application, the involved digest information can be a hash value.
[0078] In this application, the digest information in the authentication blacklist is calculated based on the broadband account, the account password, the network line, and the MAC address, so it can well avoid the phenomenon that users dial normally but the dialing fails due to the restriction of the authentication blacklist in scenarios such as line cutover, password adjustment, and terminal replacement.
[0079] S106. Determine whether the target digest information is in the authentication blacklist. When it is determined that the target digest information is in the authentication blacklist, execute step S107; otherwise, execute step S108.
[0080] In specific implementation, when it is determined that the target digest information is in the authentication blacklist, that is, when the target digest information matches a certain digest information in the authentication blacklist, it means that the authentication of the target terminal is affected by the authentication blacklist. In this case, step S107 can be executed to filter the authentication of the target terminal.
[0081] In specific implementation, when it is determined that the target digest information is not in the authentication blacklist, that is, when the target digest information does not match any digest information in the authentication blacklist, it means that the authentication of the target terminal is not affected by the authentication blacklist. In this case, step S108 can be executed to perform normal authentication on the target terminal.
[0082] S107. Return an authentication failure result to the target terminal.
[0083] In this application, through authentication blacklist filtering, a large number of authentication requests of terminals that do not have access permissions but frequently dial to access the network can be filtered, thereby reducing the resource consumption of the provincial authentication system and improving the performance and stability of the provincial-end platform.
[0084] S108. Allow BRAS to perform normal authentication on the target terminal.
[0085] In specific implementation, in step S108, the BRAS can authenticate the target terminal in an existing conventional manner, which will not be elaborated in this embodiment of the present application.
[0086] That is, in this application, the blacklist filtering policy includes the above steps S105 - S108.
[0087] In one implementation manner, after executing step S108, if the target terminal fails to pass the authentication, the blacklist management method for broadband network access authentication provided by this embodiment of the present application may further include the following steps:
[0088] S109. Receive the authentication failure result of the target terminal.
[0089] In specific implementation, this authentication failure result may be sent after the BRAS fails to authenticate the target terminal.
[0090] S110. Determine the current time when the authentication failure result is received as the authentication failure time of the target terminal, and save the target digest information and this authentication failure time correspondingly into the authentication blacklist.
[0091] In this application, by executing steps S109 - S110, the subsequent authentication requests initiated by the target terminal can be directly filtered out, which can further reduce the resource consumption of the provincial authentication system and contribute to improving the performance and stability of the provincial platform.
[0092] In another implementation manner, after executing step S104, if the target terminal fails to pass the authentication, the target digest information and this authentication failure time can be saved correspondingly into the authentication blacklist in the same or similar manner as the above steps S109 - S110, which will not be elaborated in this embodiment of the present application. Among them, in this case, the target digest information of the target terminal can be calculated in the manner of the above step S105.
[0093] Figure 2 Show a flowchart of a blacklist management method for broadband network access authentication according to another embodiment of the present application. As Figure 2 shown, this method may include the following steps:
[0094] S201. Obtain the authentication blacklist and authentication gray list pre - stored in the broadband authentication platform.
[0095] S202. Receive the target authentication request of the target terminal.
[0096] S203. Determine whether the target broadband account is in the authentication gray list. When it is determined that the target broadband account is in the authentication gray list, execute step S204, otherwise, execute step S207.
[0097] In specific implementation, the implementation processes of the above steps S201 - S203 are the same as or similar to those of the above steps S101 - S103, and will not be elaborated here.
[0098] S204. Determine whether the current time is within the valid period of the target broadband account. If the current time is within the valid period of the target broadband account, execute step S205; or, if the current time has passed the valid period of the target broadband account, execute step S206.
[0099] In specific implementation, the authentication gray list can also include the valid period of any broadband account. That is, the installation and maintenance personnel can also manually configure the valid period of the broadband account before on-site debugging. For example, the valid period can be set to 10 minutes according to requirements.
[0100] In this application, by setting the valid period of the broadband account in the authentication gray list, it is possible to support skipping the authentication blacklist filtering mechanism through the authentication gray list in special scenarios.
[0101] S205. Allow the BRAS to perform normal authentication on the target terminal.
[0102] In specific implementation, in step S205, the BRAS can use existing conventional methods to authenticate the target terminal, which will not be elaborated in this embodiment of the application.
[0103] S206. Execute the blacklist filtering policy.
[0104] In specific implementation, the blacklist filtering policy in step S206 can refer to the above steps S105 - step S108, or refer to the following steps S207 - step S211, which will not be elaborated in this embodiment of the application.
[0105] In specific implementation, it is also possible to regularly clean up the expired gray list data (such as broadband accounts and their valid periods) in the authentication gray list before, during, or after step S206 is executed.
[0106] S207. Extract the key information of the target terminal from the target authentication request, and calculate the target digest information of the target terminal according to the key information.
[0107] S208. Determine whether the target digest information is in the authentication blacklist. When it is determined that the target digest information is in the authentication blacklist, execute step S209; otherwise, execute step S211.
[0108] In specific implementation, the implementation processes of the above steps S207 - S208 are the same as or similar to those of the above steps S105 - S106, and will not be elaborated here.
[0109] S209. Determine whether the current time is within the validity period of the target summary information. If the current time is within the validity period of the target broadband account, execute step S210. Or, if the current time has passed the validity period of the target summary information, execute step S211.
[0110] In specific implementation, the authentication blacklist can also include the validity period of any summary information. This validity period can be set manually or default set automatically by the system, such as default set to 10 minutes.
[0111] In this application, by setting the validity period of the summary information in the authentication blacklist, it can support users to access the Internet after the blacklist expires.
[0112] S210. Return an authentication failure result to the target terminal.
[0113] S211. Allow the BRAS to perform normal authentication on the target terminal.
[0114] In specific implementation, it can also regularly clean up the expired blacklist data (such as summary information and its validity period) in the authentication blacklist before, during or after executing step S211.
[0115] In one implementation, after executing step S211, if the target terminal fails to pass the authentication, the blacklist management method for broadband network access authentication provided by the embodiments of this application can further include the following steps:
[0116] S212. Receive the authentication failure result of the target terminal.
[0117] S213. Determine the authentication failure time of the target terminal as the current time when the authentication failure result is received, and save the target summary information and this authentication failure time correspondingly to the authentication blacklist.
[0118] In specific implementation, the implementation processes of the above steps S212 - step S213 are the same or similar to the implementation processes of the above steps S109 - S110, and will not be elaborated here.
[0119] In another implementation, after executing step S205, if the target terminal fails to pass the authentication, the target summary information and this authentication failure time can be saved correspondingly to the authentication blacklist in a manner the same or similar to the above steps S109 - step S110, and the embodiments of this application will not be elaborated here. Among them, in this case, the target summary information of the target terminal can be calculated in the manner of the above step S105.
[0120] To further understand the technical solution provided by the above another embodiment, three scenarios will be provided for illustrative description below.
[0121] I. Account Password Update Scenario
[0122] If a user updates the account password through the business hall, the authentication blacklist expires within 10 minutes, and the user can access the Internet after the authentication blacklist expires. In special scenarios, the authentication gray list can be set to bypass the authentication blacklist filtering mechanism; if the account password is updated on the router, the new account password causes the digest information to be updated, and it is not affected by the previous authentication blacklist.
[0123] II. Network Line Update Scenario
[0124] The user's network line is a new network line, and the digest information will be updated immediately, without being affected by the authentication blacklist. If there is a situation where a network line is not unbound, after the network line is supplemented and unbound, it will take effect after the authentication blacklist expires. Special users can take effect immediately by setting the authentication gray list.
[0125] III. Terminal Update Scenario
[0126] If the terminal is replaced, the MAC address of the terminal will change, and the digest information will also be updated immediately, without being affected by the blacklist.
[0127] In summary, in the above two embodiments of the present application, by enabling the authentication gray list, in the cases where the user changes the account password, changes the network line, replaces the terminal, etc., due to changes in the account password, network line, MAC address, etc., the corresponding digest information of the terminal will also change, and these changes can be detected in a timely manner, and normal authentication can be completed immediately, without being affected by the authentication blacklist. At the same time, by enabling the authentication blacklist, invalid terminal repeated authentication requests can be filtered out, which can reduce the resource consumption of the provincial authentication system and improve the performance and stability of the provincial platform.
[0128] Figure 3 The structural block diagram of a blacklist management device and medium for broadband network access authentication according to an embodiment of the present application is shown. As Figure 3 shown, the device may include:
[0129] A transceiver unit 301, configured to obtain an authentication blacklist and an authentication gray list pre-stored in a broadband authentication platform, where the authentication gray list includes a plurality of broadband accounts, and the authentication blacklist includes a plurality of digest information; receive a target authentication request of a target terminal, where the target authentication request is used to request broadband access authentication for the target terminal, and the target authentication request carries key information of the target terminal, that is, a target broadband account, a target account password, a target network line, and a target MAC address;
[0130] The processing unit 302 is used to allow the BRAS to perform normal authentication on the target terminal when it is determined that the target broadband account is in the authentication gray list; when it is determined that the target broadband account is not in the authentication gray list, the following blacklist filtering policy is executed, where the BRAS is a broadband access server:
[0131] Extract the key information of the target terminal from the target authentication request, and calculate the target digest information of the target terminal according to the key information; when it is determined that the target digest information is in the authentication blacklist, return an authentication failure result to the target terminal.
[0132] In an implementation, any digest information in the authentication blacklist is calculated based on the historical authentication results of the BRAS, collecting the broadband account, account password, network line, and MAC address in the authentication request with authentication failure, and calculating based on the collected broadband account, account password, network line, and MAC address.
[0133] The authentication gray list is manually configured by the installation and maintenance personnel before on-site debugging.
[0134] In an implementation, the processing unit 302 is specifically used for:
[0135] After splicing the target broadband account, target account password, target network line, and target MAC address in the key information, perform hash calculation using the MD5 information digest algorithm to obtain the target digest information.
[0136] In an implementation, the blacklist filtering policy further includes:
[0137] When it is determined that the target digest information is not in the authentication blacklist, allow the BRAS to perform normal authentication on the target terminal.
[0138] In an implementation, the transceiver unit 301 is further used for: receiving the authentication failure result of the target terminal, where the authentication failure result is sent after the BRAS fails to authenticate the target terminal;
[0139] The processing unit 302 is further used for: determining the current time when the authentication failure result is received as the authentication failure time of the target terminal, and correspondingly saving the target digest information and the authentication failure time to the authentication blacklist.
[0140] In an implementation, the authentication blacklist further includes the expiration period of any digest information, and the processing unit 302 is further used for:
[0141] When it is determined that the target digest information is in the authentication blacklist, if the current time is within the expiration period of the target digest information, return an authentication failure result to the target terminal; or,
[0142] If the current time has passed the expiration date of the target summary information, normal authentication of the target terminal is allowed through the BRAS.
[0143] In one embodiment, the authentication gray list further includes the expiration date of any broadband account, and the processing unit 302 is further configured to:
[0144] When it is determined that the target broadband account is in the authentication gray list, if the current time is within the expiration date of the target broadband account, normal authentication of the target terminal is allowed through the BRAS; or,
[0145] If the current time has passed the expiration date of the target broadband account, the blacklist filtering policy is executed.
[0146] For the functions of the units in the blacklist management device for broadband network access authentication in the embodiments of the present application, reference can be made to the corresponding descriptions in the above methods, which will not be elaborated here.
[0147] Figure 4 The structural block diagram of a communication device according to an embodiment of the present application is shown. As Figure 4 shown, the communication device includes: a memory 401 and a processor 402. Instructions are stored in the memory 401, and the instructions are loaded and executed by the processor 402 to implement the blacklist management method for broadband network access authentication in the above embodiments. The number of the memory 401 and the processor 402 can be one or more.
[0148] The communication device further includes:
[0149] A communication interface 403, configured to communicate with external devices and perform data interaction and transmission.
[0150] If the memory 401, the processor 402, and the communication interface 403 are implemented independently, the memory 401, the processor 402, and the communication interface 403 can be connected to each other through a bus and complete communication with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 4 only a thick line is shown in the figure, but it does not mean that there is only one bus or one type of bus.
[0151] Optionally, in a specific implementation, if the memory 401, the processor 402, and the communication interface 403 are integrated on a single chip, the memory 401, the processor 402, and the communication interface 403 can communicate with each other through an internal interface.
[0152] An embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program runs on a computer, the method provided in the embodiment of the present application is implemented.
[0153] An embodiment of the present application further provides a chip, which includes a processor for calling and running instructions stored in a memory, so that a communication device equipped with the chip executes the method provided in the embodiment of the present application.
[0154] An embodiment of the present application further provides a chip, including: an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is configured to execute code in the memory. When the code is executed, the processor is configured to execute the method provided in the embodiment of the application.
[0155] It should be understood that the above-mentioned processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor that supports the advanced reduced instruction set machine (ARM) architecture.
[0156] Further, optionally, the above-mentioned memory may include a read-only memory and a random access memory, and may also include a non-volatile random access memory. The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may include a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may include a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).
[0157] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium.
[0158] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this application. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0159] In addition, the terms "first" and "second" are used only for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of such features. In the description of this application, "a plurality of" means two or more unless otherwise specifically defined.
[0160] Any process or method description represented in a flowchart or described in other ways herein can be understood to represent a module, segment, or portion of code including one or more executable instructions for implementing a specific logical function or process. And the scope of the preferred embodiments of this application includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in a reverse order according to the involved functions, rather than in the order shown or discussed.
[0161] The logic and / or steps represented in a flowchart or described in other ways herein, for example, can be considered as an ordered list of executable instructions for implementing a logical function, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in combination with these instruction execution systems, apparatuses, or devices.
[0162] It should be understood that each part of this application can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. All or part of the steps of the method in the above embodiments can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.
[0163] In addition, each functional unit in various embodiments of the present application may be integrated into a processing module, or each unit may exist physically alone, or two or more units may be integrated into one module. The above integrated module may be implemented in the form of hardware or in the form of a software functional module. If the above integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium. The storage medium may be a read-only memory, a magnetic disk, an optical disc, or the like.
[0164] As described above, the foregoing are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various changes or substitutions, and these should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A blacklist management method for broadband network access authentication, characterized in that, Including: Obtain an authentication blacklist and an authentication gray list pre-stored in a broadband authentication platform. The authentication gray list includes a number of broadband accounts, and the authentication blacklist includes a number of digest information; Receive a target authentication request from a target terminal. The target authentication request is used to request broadband access authentication for the target terminal, and the target authentication request carries key information of the target terminal, namely a target broadband account, a target account password, a target network line, and a target MAC address; When it is determined that the target broadband account is in the authentication gray list, allow the BRAS (Broadband Remote Access Server) to perform normal authentication on the target terminal; When it is determined that the target broadband account is not in the authentication gray list, execute the following blacklist filtering strategy: Extract the key information of the target terminal from the target authentication request, and calculate the target digest information of the target terminal according to the key information; When it is determined that the target digest information is in the authentication blacklist, return an authentication failure result to the target terminal.
2. The method according to claim 1, wherein Any of the digest information in the authentication blacklist is calculated based on the historical authentication results of the BRAS, collecting the broadband account, account password, network line, and MAC address in the authentication request with authentication failure, and calculating according to the collected broadband account, account password, network line, and MAC address; The authentication gray list is manually configured by the installation and maintenance personnel before on-site debugging.
3. The method according to claim 1, wherein Calculating the target digest information of the target terminal according to the key information includes: After splicing the target broadband account, target account password, target network line, and target MAC address in the key information, then perform hash calculation using the MD5 information digest algorithm to obtain the target digest information.
4. The method according to claim 1, characterized in that The blacklist filtering strategy further includes: When it is determined that the target digest information is not in the authentication blacklist, allow the BRAS to perform normal authentication on the target terminal.
5. The method according to claim 4, wherein The method further includes: Receive the authentication failure result of the target terminal, where the authentication failure result is sent after the BRAS fails to authenticate the target terminal; Determine the current time when the authentication failure result is received as the authentication failure time of the target terminal, and store the target digest information and the authentication failure time correspondingly in the authentication blacklist.
6. The method according to any one of claims 1-5, characterized in that, The authentication blacklist further includes the expiration date of any of the digest information, and the method further includes: When it is determined that the target digest information is in the authentication blacklist, if the current time is within the expiration date of the target digest information, return an authentication failure result to the target terminal; or, If the current time has passed the expiration date of the target digest information, allow the BRAS to perform normal authentication on the target terminal.
7. The method according to any one of claims 1-5, characterized in that, The authentication gray list further includes the expiration date of any of the broadband accounts, and the method further includes: When it is determined that the target broadband account is in the authentication gray list, if the current time is within the expiration date of the target broadband account, allow the BRAS to perform normal authentication on the target terminal; or, If the current time has passed the expiration date of the target broadband account, then execute the blacklist filtering policy.
8. A blacklist management device for broadband network access authentication, characterized in that, It includes: A transceiver unit, configured to obtain an authentication blacklist and an authentication gray list pre-stored in a broadband authentication platform, where the authentication gray list includes a number of broadband accounts, and the authentication blacklist includes a number of digest information; receive a target authentication request from a target terminal, where the target authentication request is used to request broadband access authentication for the target terminal, and the target authentication request carries key information of the target terminal, namely a target broadband account, a target account password, a target network line, and a target MAC address; A processing unit, configured to allow the target terminal to be normally authenticated by a BRAS (Broadband Remote Access Server) when it is determined that the target broadband account is in the authentication gray list; When it is determined that the target broadband account is not in the authentication gray list, execute the following blacklist filtering policy: Extract the key information of the target terminal from the target authentication request, calculate the target digest information of the target terminal according to the key information; when it is determined that the target digest information is in the authentication blacklist, return an authentication failure result to the target terminal.
9. A communication device, characterized in that, It includes: A memory and a processor, where instructions are stored in the memory, and the instructions are loaded and executed by the processor to implement the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and when the computer program runs on a computer, the method according to any one of claims 1-7 is implemented.