Tenant broadband multi-access unified authentication cloud platform, system and method

Through the unified tenant broadband multi-access authentication cloud platform, the problem of campus broadband users being certified multiple times on different platforms is solved, and the unified management of multiple access terminals and multiple network exits is realized, which simplifies user management and improves resource utilization.

CN120263418APending Publication Date: 2025-07-04CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510386701.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the prior art, campus broadband users need to perform multiple certifications on different certification platforms, resulting in management troubles, and each school needs to deploy dial-up equipment, resulting in waste of resources.

Method used

It provides a tenant broadband multi-access unified authentication cloud platform, including tenant management module and tenant module. Identity management, permission management, resource access control and security audit are carried out through a unified platform, realizing unified management of multiple access terminals and multiple network exits, and eliminating the on-campus network access authentication platform and dial-up equipment of each school.

Benefits of technology

It realizes unified management of campus broadband users with multiple access and multiple accounts, simplifies user management, improves resource utilization, reduces operating costs, and realizes permission-based control of multiple network exits.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263418A_ABST
    Figure CN120263418A_ABST
Patent Text Reader

Abstract

The invention discloses a tenant broadband multi-access unified authentication cloud platform, system and method, and relates to the technical field of access authentication of a campus network. The tenant broadband multi-access unified authentication cloud platform comprises a tenant management module and at least one tenant module. The tenant management module is configured to receive request information, wherein the request information comprises identification information of tenants. Identifying identification information of the tenant included in the request information; and determining a corresponding tenant module according to the identification information of the tenant. And forwarding the request information to the corresponding tenant module. And the corresponding tenant module is configured to receive the request information and perform identity management, authority management, resource access control and resource access security auditing according to the request information. According to the invention, cloud centralized authentication and centralized dialing services are provided for multiple schools based on a tenant mode, multi-access multi-account unified management of campus broadband users is realized, and at the same time, intra-campus network access authentication platforms and intra-campus network dialing devices of the schools are eliminated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of campus network authentication, and particularly relates to a unified authentication cloud platform for multi-access of tenant broadband, a unified authentication system for multi-access of tenant broadband, a unified authentication method for multi-access of tenant broadband, a computer device, and a storage medium. Background Art

[0002] The campus network can not only realize the sharing of in-school resources, but also connect to the education network and the Internet, playing an important role in multiple fields such as education, scientific research, management, and social interaction. It is an indispensable infrastructure in the modern education system. By effectively utilizing the campus network, the teaching quality can be improved, information sharing can be promoted, the campus management efficiency can be enhanced, and a more intelligent and efficient campus environment can be constructed. The basic telecommunications enterprises (hereinafter referred to as operators) cooperate with schools to operate the campus network, which can fully integrate their respective advantages to provide better network services for teachers and students.

[0003] For accessing different network resources, identity authentication and authorization need to be performed according to the permissions of the visitors. Therefore, it is necessary to build an identity authentication platform (usually based on the RADIUS protocol) to complete the corresponding process operations, and specific network devices are used to execute the access control of network resources.

[0004] Currently, in the campus network, it is usually the school that builds its own identity authentication platform to perform identity authentication and authorization for in-school network resources and education network resources, while the operator authenticates and authorizes the access to Internet network resources through a broadband access identity authentication platform, and the broadband remote access server (BRAS) is used to execute the access control. At the same time, through methods such as account binding and proxy dialing, the integrated operation of multiple exits of the campus network (such as the education network and the Internet) can be realized. For example, the operator can adopt a PPPoE (Point-to-Point Protocol Over Ethernet) proxy dialing solution to jointly operate the campus network with the school by deploying the PPPoE proxy dialing function on the in-school BRAS device or the PPPoE proxy dialing gateway device.

[0005] Although the prior art has to some extent solved the problem of the integrated operation of campus broadband multi-access, there are still some drawbacks. On the one hand, multiple access accounts of campus broadband users (such as educational network, Internet) need to be authenticated on different authentication platforms (such as in-school authentication platform, operator authentication platform). In addition to the access service provider (such as the operator) needing to build an authentication platform, the school also needs to build an in-school authentication platform. At the same time, the user Internet access information is stored in different systems respectively, which also brings management troubles to the campus broadband operation. On the other hand, deploying dialing proxy devices (or authentication gateways) in the campus network of each school will also cause waste of resources. Summary of the Invention

[0006] The technical problem to be solved by the present invention is that in the integrated operation solution of the prior art, multiple access accounts of campus broadband users need to be authenticated on different authentication platforms, which brings management troubles to the campus broadband operation, and each school needs to deploy dialing proxy devices, which will cause waste of resources.

[0007] In view of the above deficiencies of the prior art, the following solutions are provided:

[0008] In a first aspect, the present invention provides a unified authentication cloud platform for multi-access of tenant broadband, including a tenant management module and at least one tenant module. Among them, the tenant management module is configured to: receive request information, where the request information includes the identification information of the tenant. Identify the identification information of the tenant included in the request information. Determine the corresponding tenant module according to the identification information of the tenant. And forward the request information to the corresponding tenant module. Among them, the request information received by the tenant management module is forwarded by any one of at least one broadband remote access server (BRAS) in response to receiving the request information from any user of any tenant among at least one tenant. The corresponding tenant module is configured to: receive the request information, and perform identity management, permission management, resource access control, and resource access security audit according to the request information. The corresponding tenant module is one tenant module among at least one tenant module, and the tenant modules in at least one tenant module correspond one-to-one with the tenants in at least one tenant.

[0009] Optionally, the corresponding tenant module includes an identity management unit, a permission management unit, a resource access control unit, and a resource access security audit unit. Among them, the identity management unit is configured to: determine the role of the user of the corresponding tenant according to the request information, and perform identity management and login management on the users of the tenant according to the role of the user. Among them, the roles of the user include customer and account. The customer corresponds to the broadband account of the operator where the customer is located. One customer is associated with at least one account. The permission management unit is configured to: authenticate and manage the access permissions of the multi-access terminals and multi-network exits of the users of the tenant according to the role of the user. The resource access control unit is configured to: control the accessible resources of the users of the tenant according to the role of the user. The resource access security audit unit is configured to: monitor, record, and analyze the activities of the users of the tenant for resource access.

[0010] Optionally, the identity management unit is further configured to: in the case where the user of the tenant logs in to the tenant system for the first time using any of their accounts, bind the account used by the user of the tenant to the broadband account of the operator where the user is located, and through the account mapping method, perform associated authentication and maintenance on the ID, terminal mark, service mark, and broadband account of the user of the tenant, so as to establish the association relationship between the account of the user of the tenant and the customer of the user of the tenant.

[0011] Optionally, the identity management unit is further configured to: in response to receiving a single sign-on request from the tenant system, verify the login information of the user of the tenant. In response to the login information of the user of the tenant passing the verification, return an access token to the tenant system. In response to receiving a user role request or a menu request from the tenant system, verify the validity of the access token, and if the verification passes, return the user role or menu data to the tenant system. In response to receiving a request to call a service interface from the tenant system, perform secondary authentication on the access token. If the access token is valid, return service data to the tenant system. If the access token is invalid, mark the access token as discarded and return unauthorized to the tenant system. And, in response to receiving an access token logout request from the tenant system, forcibly discard the access token and return a logout success message to the tenant system. Among them, the single sign-on request is sent by the tenant system after the user of the tenant initiates an access request to the tenant system. The user role request or menu request carries the access token. The access token logout request is sent by the tenant system after the user of the tenant initiates a logout request to the tenant system.

[0012] Optionally, the permission management unit is further configured to: determine the authentication domain where the user of the tenant is located, and manage the access permissions of the user of the tenant according to the authentication domain where the user of the tenant is located. Among them, the authentication domain where the user of the tenant is located is one of the multiple authentication domains divided by the permission management unit for the user of the tenant according to the user requirements of the tenant.

[0013] Optionally, the permission management unit is further configured to: set a pre - authentication domain and a post - authentication domain. Before the user authentication of the tenant, the user is located in the pre - authentication domain, and after the user authentication of the tenant, the user is located in the post - authentication domain. Also, according to the authentication domain where the tenant's user is located, perform authentication interaction with the tenant's user through the portal page. Among them, the tenant's user located in the pre - authentication domain has the permission to access the portal page. The tenant's user located in the post - authentication domain has the permission to access the entire network.

[0014] Optionally, the permission management unit is further configured to: query the media access control of the tenant's user device from the Dynamic Host Configuration Protocol (DHCP) server, and bind the tenant's user with the media access control of the tenant's user device.

[0015] In a second aspect, the present invention provides a tenant broadband multi - access unified authentication system, including the above - mentioned tenant broadband multi - access unified authentication cloud platform and at least one BRAS. Wherein, each BRAS is used to be respectively connected to at least one tenant and the tenant broadband multi - access unified authentication cloud platform, and is used to receive the request information from any user of any tenant among at least one tenant, and is used to connect and forward the request information from any user of any tenant among at least one tenant to the tenant broadband multi - access unified authentication cloud platform.

[0016] In a third aspect, the present invention provides a tenant broadband multi - access unified authentication method, which is applied to the above - mentioned tenant broadband multi - access unified authentication platform. The method includes: receiving request information; identifying the identification information of the tenant included in the request information; and determining the tenant module corresponding to the identification information of the tenant according to the request information, so that the corresponding tenant module performs identity management, permission management, resource access control, and resource access security audit according to the request information. Among them, the request information is forwarded by any one of at least one BRAS in response to receiving the request information from any user of any tenant among at least one tenant. The request information includes the identification information of the tenant. The corresponding tenant module is one tenant module among at least one tenant module, and the tenant modules in at least one tenant module correspond one - to - one with the tenants in at least one tenant.

[0017] In a fourth aspect, the present invention provides a computer device, including a memory and a processor. A computer program is stored in the memory. When the processor runs the computer program stored in the memory, the processor executes the above - mentioned tenant broadband multi - access unified authentication method.

[0018] In a fifth aspect, the present invention provides a computer - readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor executes the above - mentioned tenant broadband multi - access unified authentication method.

[0019] The tenant broadband multi-access unified authentication cloud platform, system and method provided by the present invention provide cloud-based centralized authentication and centralized proxy-dialing services for multiple schools based on the tenant mode, realizing unified management of multiple accesses and multiple accounts of campus broadband users, realizing unified control of access to multiple network exits (such as the education network and the Internet) of campus broadband users, achieving the purpose of one-time authentication for campus broadband user network access services and connecting multiple network exits (such as the education network and the Internet) according to permissions. At the same time, the in-school network access authentication platforms of each school are eliminated, and the proxy-dialing devices in the school campus network are eliminated. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 It is a structural diagram of a tenant broadband multi-access unified authentication cloud platform in an embodiment of the present invention;

[0021] Figure 2 It is a structural diagram of another tenant broadband multi-access unified authentication cloud platform in an embodiment of the present invention;

[0022] Figure 3 It is a structural diagram of yet another tenant broadband multi-access unified authentication cloud platform in an embodiment of the present invention;

[0023] Figure 4 It is a structural diagram of yet another tenant broadband multi-access unified authentication cloud platform in an embodiment of the present invention;

[0024] Figure 5 It is a structural diagram of yet another tenant broadband multi-access unified authentication cloud platform in an embodiment of the present invention;

[0025] Figure 6 It is a structural diagram of a tenant broadband multi-access unified authentication system in an embodiment of the present invention;

[0026] Figure 7 It is a flowchart of a tenant broadband multi-access unified authentication method in an embodiment of the present invention;

[0027] Figure 8 It is a structural diagram of a computer device in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0028] To enable those skilled in the art to better understand the technical solutions of the present invention, the embodiments of the present invention will be further described in detail below in conjunction with the accompanying drawings.

[0029] It can be understood that the specific embodiments and drawings described herein are only used to explain the present invention, rather than to limit the present invention.

[0030] It can be understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.

[0031] It is understood that for ease of description, only the parts related to the present invention are shown in the drawings of the present invention, while the parts unrelated to the present invention are not shown in the drawings.

[0032] It is understood that each unit and module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures. Alternatively, multiple units and modules may also be integrated into one entity structure.

[0033] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of the present invention may occur in a different order from that marked in the drawings.

[0034] It is understood that in the flowcharts and block diagrams of the present invention, the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to the various embodiments of the present invention are shown. Among them, each block in the flowchart or block diagram may represent a unit, module, program segment, or code, which contains executable instructions for implementing the specified function. Moreover, each block or combination of blocks in the block diagram and flowchart may be implemented by a hardware-based system for implementing the specified function, or may be implemented by a combination of hardware and computer instructions.

[0035] It is understood that the units and modules involved in the embodiments of the present invention may be implemented in software or in hardware. For example, the units and modules may be located in the processor.

[0036] Some embodiments of the present invention provide a tenant broadband multi-access unified authentication cloud platform, as Figures 1 to 6 shown, the tenant broadband multi-access unified authentication cloud platform 00 includes a tenant management module 01 and at least one tenant module 02. Among them, the tenant management module 01 is configured to: receive request information, where the request information includes the identification information of the tenant. Identify the identification information of the tenant included in the request information. Determine the corresponding tenant module according to the identification information of the tenant. And forward the request information to the corresponding tenant module. Among them, the request information received by the tenant management module is forwarded by any one of at least one broadband remote access server (BRAS) in response to receiving the request information from any user of any tenant among at least one tenant. The corresponding tenant module 02 is configured to: receive the request information, and perform identity management, permission management, resource access control, and resource access security auditing according to the request information. Among them, the corresponding tenant module is one tenant module among at least one tenant module, and the tenant modules in at least one tenant module correspond one-to-one with the tenants in at least one tenant.

[0037] Understandably, the tenant management module 01 is a customer management module for all tenant customers of the operator. The tenant management module 01 can manage different tenants (users or customers) and serve them in a multi-tenant environment, and forward the access authentication request and related Internet access information to the corresponding tenant module 02 for processing according to the tenant identification information (such as link information, domain name information, etc.). The multi-tenant architecture allows at least one tenant module 02 to share the same infrastructure, applications, and databases while maintaining data isolation and security. Effective tenant management can ensure the security, availability, and performance of the multi-tenant environment. Through reasonable policies and tools, organizations can optimize resource utilization, improve user satisfaction, and reduce operational risks.

[0038] Understandably, any one of the at least one tenant module has the same structural function as the corresponding tenant module 02. Each tenant module 02 is a tenant broadband operation module provided to each school by the unified authentication cloud platform in tenant mode.

[0039] Understandably, the BRAS can provide tenant service access, control the public network access and private network access of the tenants' users, and any one of the at least one BRAS and the tenant broadband multi-access unified authentication cloud platform 00 are deployed in the same operator.

[0040] Exemplarily, the tenant broadband can refer to campus broadband, and the at least one tenant can refer to at least one campus, or the tenant broadband can also refer to the internal broadband of the enterprise park, and the at least one tenant can also refer to at least one enterprise in the enterprise park. In the following embodiments, the tenant broadband is campus broadband and the at least one tenant is multiple campuses as an example.

[0041] In some embodiments, as Figure 2 shown, the corresponding tenant module 02 includes an identity management unit 21, a permission management unit 22, a resource access control unit 23, and a resource access security audit unit 24.

[0042] The identity management unit 21 is configured to: determine the role of the user of the corresponding tenant according to the request information, and perform identity management and login management on the user of the tenant according to the role of the user. Among them, the role of the user includes customer and account. The customer corresponds to the broadband account of the operator. One customer is associated with at least one account.

[0043] Understandably, the identity management unit 21 introduces a hierarchical role concept, divides roles into two levels: customers and accounts, associates a one-to-many relationship between customers and accounts, and determines the mapping relationship between customers and broadband accounts on the operator side to maintain the relationship between customers and accounts. When generating a bill, all accounts under the customer can be aggregated to form a unified bill. The account forms a corresponding relationship with the actual Internet terminal, Internet student number, Internet identification, etc., so as to form an independent mark in management.

[0044] Exemplarily, if a dormitory in a school contains six students, a customer number can be set for this dormitory. When the six students access the Internet, they can be required to enter their student numbers on the portal website to access the Internet. In this way, a tree-like association relationship can be formed, and at the same time, certain control capabilities can be possessed, such as unified speed limit for six accounts, restricting several of them from passing authentication, etc.

[0045] Understandably, the identity management unit 21 improves security and efficiency by centrally managing user identities and access rights. Its main goal is to simplify user management and ensure consistent authentication and authorization mechanisms.

[0046] In some embodiments, the identity management unit 21 is configured as follows: in the case where a tenant's user logs in to the tenant system for the first time using any of their accounts, the account used by the tenant's user is bound to the broadband account of the operator where the tenant is located. Through the account mapping method, the ID, terminal mark, service mark, and broadband account of the tenant's user are associated for authentication and maintenance, so as to establish the association relationship between the tenant's user's account and the tenant's user's customer.

[0047] Exemplarily, in view of the characteristics of multiple accounts of campus users, the identity management unit 21 can establish a peer-to-peer association relationship between multiple accounts, rather than a master-slave account or account binding relationship, to ensure that when a tenant's user accesses the network using any account, the processing of other associated accounts can be triggered as needed. For example, there can be multiple customers in the role of campus users, such as teachers, students, etc. When accessing the network, these customers can be immediately associated with the operator's broadband account through the student number or teacher number. The identity management unit 21 improves security, user experience, and management efficiency through centralized management and automated processes, and is a crucial part of the modern enterprise information technology (IT) architecture, especially in multi-application and multi-cloud environments.

[0048] Exemplarily, in the identity management unit 21, after the Operation Support System (OSS) side receives an account opening request for Customer Business (CB), it will distribute according to the specific type of the service to be activated. If it is a fixed network broadband service, its activation process will be directed to the Authentication, Authorization and Accounting (AAA) system. If it is a campus service, it will be activated to the tenant broadband multi-access unified authentication cloud platform 00.

[0049] It can be understood that by operating in a multi-tenant manner, the identity management unit 21 can provide account association authentication and related value-added services for different schools. This multi-tenant mode means that the tenant broadband multi-access unified authentication cloud platform 00 can perform independent account management and service provision for multiple schools on a unified platform. The accounts and services between different schools are isolated from each other, while at the same time sharing some basic resources and functions of the platform.

[0050] Exemplarily, when the tenant is a school, the school can pre-open the campus accounts for this year in advance, that is, create the accounts before the students actually use them, so that the students can use them directly after enrollment. In addition, the school also needs to have the ability to verify the student identity to verify the authenticity and legality of the student identity, ensuring that only eligible students can use the campus network service.

[0051] It can be understood that when a student logs in for the first time, they can bind their campus account with the broadband account through the portal page. The purpose of doing this is to associate the student's identity identifier in the campus network with the specific broadband access service, facilitating unified identity authentication and service management. For example, when a student uses the broadband service of the campus network, through this binding relationship, the identity management unit 21 can accurately identify the student's identity and permissions and provide corresponding network services for them.

[0052] It can be understood that the identity management unit 21 maintains the association of information such as the student ID number, terminal marker, service marker, and broadband account of the school through account mapping. This means that the identity management unit 21 will establish a complex mapping relationship table to correspond different types of information with each other. In this way, the tenant broadband multi-access unified authentication cloud platform 00 can comprehensively master various relevant information of the students and achieve refined management of the students' accounts and services. For example, when a student uses a specific terminal to access a certain service of the campus network, the tenant module 02 can quickly and accurately perform identity verification, permission judgment, and service provision based on these associated information.

[0053] In some embodiments, as Figure 3 shown, the identity management unit 21 is configured to: upon receiving a single sign-on request from the tenant system, verify the login information of the tenant's user. Upon the login information of the tenant's user being verified, return an access token to the tenant system. Upon receiving a user role request or a menu request from the tenant system, verify the validity of the access token, and if the verification passes, return user role or menu data to the tenant system. Upon receiving a request to call a service interface from the tenant system, perform secondary authentication on the access token, and if the access token is valid, return service data to the tenant system. If the access token is invalid, mark the access token as discarded and return unauthorized (such as "401 Unauthorized") to the tenant system. Also, upon receiving an access token logout request from the tenant system, forcefully discard the access token and return a logout success message to the tenant system. Among them, the single sign-on request is sent by the tenant system after the tenant's user initiates an access request to the tenant system. The user role request or the menu request carries the access token. The access token logout request is sent by the tenant system after the tenant's user initiates a logout request to the tenant system.

[0054] Exemplarily, the identity management unit 21 can use open standards (JSON Web Token, JWT) and session authentication methods to provide login authentication for application programming interface (API) callers, and the authentication attributes include account and password. The client must first obtain an access token and a session identifier (JSESSIONID) through a single sign-on interface, and then use the access token to call the API that requires identity authentication, use the JSESSIONID to access the pages and interfaces bound to system permissions. When the client obtains the access token, it will obtain the expiration time (expires_in) data of the access token in the corresponding parameters, indicating how many seconds the currently obtained token will become invalid. When the client calls the API that requires authentication, it must include the access_token in the request header. When the specified number of seconds has passed and the access_token has expired, the client needs to obtain a new access_token to call the corresponding API. If the client uses an expired / invalid access_token to access the API interface again, the unified authentication cloud platform returns an INVALID_TOKEN error for the invalid token.

[0055] Understandably, the identity management unit 21 provides an authentication process for the users of the tenant by offering a single sign-on service, allowing the users of the tenant to log in to multiple applications and systems with one account without having to enter the username and password separately for each application. Based on the multi-account peer association relationship of campus users established through unified user identity management, when a campus user accesses the network using any account and passes the authentication and obtains the access permission to the network resources corresponding to that account, the automatic authentication of other associated accounts can be triggered as needed to seamlessly access the network resources corresponding to these associated accounts. The single sign-on service improves the user experience and enterprise security by simplifying the user login process and centrally managing identity authentication.

[0056] The permission management unit 22 is configured to: authenticate and manage the access permissions of the multi-access terminals and multi-network exits of the users of the tenant according to the roles of the users.

[0057] Understandably, the permission management unit 22 simplifies permission management, enhances security, and reduces management complexity by centrally managing user permissions and access control policies. The multi-access multi-exit (such as the education network and the Internet) access permissions of campus users are all managed in the unified authentication cloud platform. Unified permission management improves the efficiency, security, and compliance of permission management through centralized management and automated processes, and is an important part of ensuring the information security and effective operation of the organization, especially important in complex IT environments and multi-cloud architectures.

[0058] In some embodiments, the permission management unit 22 is configured to: determine the authentication domain where the user of the tenant is located, and manage the access permissions of the user of the tenant according to the authentication domain where the user of the tenant is located. Among them, the authentication domain where the user of the tenant is located is one of the multiple authentication domains divided by the permission management unit according to the needs of the user of the tenant.

[0059] Exemplarily, the unified authentication cloud platform 00 for multi-access of tenant broadband docks with the BRAS. Based on the school being divided into different authentication domains, it meets the authentication requirements of multiple terminals for fixed-network broadband users and meets the dual-domain access requirements. Proxy authentication can be deployed, and the backend is docked with the campus network AAA. When a customer accesses the pre-covered Wi-Fi on campus: the customer searches for the dedicated SSID, and the campus network BRAS initiates an authentication redirection requirement, and can access the Internet through authentication by the campus integration authentication platform.

[0060] Exemplarily, the information of WI-FI is obtained through the HyperText Transfer Protocol (HTTP). The following is a case. This solution obtains the SSID of a case, and makes a mapping association of the SSID to the corresponding binding information of the cloud tenant. For example, in this case, HTTP is:

[0061] http: / / 180.95.155.10:8081 / index.do?wlanacname=LZ-ZYY-MSE=&wlanacip=115.85.246.233&wlanuserip=172.17.240.2&usermac=80-b6-55-ef-a2-9f&ssid=CFCC-EDA&userlocation=trunk / 6 / 1 / 1:3993.70

[0062] Then the SSID = CFCC-EDA, and CFCC-EDA can be marked as the school name of a certain school.

[0063] In the above HTTP, the field descriptions are as follows:

[0064] Wlanacname: AC name

[0065] Wlanacip: AC device IP address

[0066] wlanuserIP: terminal IP address

[0067] usermac: terminal MAC address

[0068] SSID: access point ID

[0069] UserLocation: logical link port number

[0070] If it is a fixed network access, each broadband user authenticates to access the Internet, and there is quintuple information, namely BRASIP, BRAS slot, BRAS port information, SVLAN, and CVLAN. This quintuple information is logical information. From this quintuple information, the logical unique physical address of the user can be obtained. For example, for the BRAS IP in Guangzhou, since the IP address is a globally unique public network address, its uniqueness is determined. The slot and port number of the BRAS device are used to confirm the slot and port number of the device, plus SVLAN and CVLAN, the product of five Xs. The possibility of repetition does not exist.

[0071] Understandably, both CVLAN and SVLAN are types of virtual local area networks (VLANs), and they are located differently in the network. Among them, CVLAN is the inner layer of VLAN, while SVLAN is the outer layer of VLAN. CVLAN refers to using VLAN technology to divide a physical network segment into multiple logically independent virtual networks within a physical network, and hosts within each virtual network communicate with each other. CVLAN is the inner layer of VLAN, indicating that the VLAN identifier of the transmitted data frame is in the header information of the frame, and this information is located in the 802.1Q / 802.1P tag of the Ethernet frame. SVLAN is the outer layer of VLAN, which means that in a multi-layer switching network, a physical network is further divided into multiple logically independent virtual networks by using VLAN technology. SVLAN technology is mainly used to solve network isolation problems in scenarios such as multi-tenancy, data centers, and cloud computing. Usually, when using SVLAN, different customers or services are divided into different SVLANs, and the CVLANs within each SVLAN are isolated from each other for communication.

[0072] Therefore, CVLAN is the inner layer of VLAN, while SVLAN is the outer layer of VLAN. Both use VLAN technology for network segmentation. CVLAN is mainly applied to scenarios where physical network subnets are logically segmented, while SVLAN is mainly applied to scenarios where VLANs are further segmented to meet requirements such as network isolation. In practical applications, according to different network scales and requirements, both CVLAN and SVLAN can be used simultaneously to achieve more efficient network resource utilization and management.

[0073] In some embodiments, the permission management unit 22 is further configured to: set a pre-authentication domain and a post-authentication domain. Before a tenant's user authentication, the user is in the pre-authentication domain, and after the tenant's user authentication, the user is in the post-authentication domain. Also, according to the authentication domain where the tenant's user is located, authentication interaction is carried out with the tenant's user through the portal page. Among them, the tenant's user located in the pre-authentication domain has the permission to access the portal page. The tenant's user located in the post-authentication domain has the permission to access the entire network.

[0074] Exemplarily, the permission management unit 22 can set 1 pre-authentication domain and 1 post-authentication domain for a campus network. The pre-authentication domain assigns private network addresses to student accounts (only able to access the portal page, not the public network or the private network). The post-authentication domain releases the access permission (full network access)

[0075] In some embodiments, the permission management unit 22 is further configured to: query the Media Access Control (MAC) address of the tenant's user device from a Dynamic Host Configuration Protocol (DHCP) server, and bind the tenant's user to the MAC address of the tenant's user device.

[0076] Understandably, the permission management unit 22 can have the Portal authentication interaction capability, and at the same time have the ability to query the MAC address from the DHCP and perform MAC binding.

[0077] The resource access control unit 23 is configured to: control the accessible resources of the tenant's users according to the roles of the users.

[0078] Understandably, the resource access control unit 23 controls access to various resources (such as applications, data, systems, and services) through centralized management and unified policies. Its main goals are to enhance security, simplify management processes, and ensure compliance. Unified resource access control improves the security and efficiency of resource access through centralized management and automated processes, and is an important part of ensuring the information security and effective management of an organization, playing a key role in complex IT environments and multi-cloud architectures.

[0079] Exemplarily, the way of decentralized domains can be adopted to control the accessible resources for accounts. Specifically, first, the identities of the personnel using the accounts are defined. For example, in the school dimension, they are usually defined as students and faculty members. Students can be further subdivided according to groups, such as freshmen, sophomores, student union students, students of XXX groups, etc. According to different personnel identities, the permissions for a specific type of account to access resources are set through permission templates. For accounts without access permissions, an invisible method is used to prevent their access. Such permission settings can be visually maintained through the administrator portal. When the resources change, through the adjustment of the background permissions, it can be quickly synchronized to various accounts, thus realizing the immediate effect of unified permission control. Regarding the database storage problem, a unified database can be used for data storage. To avoid data inter-access between different tenants, permission policies are also used to control the data. First, when the data is stored, corresponding tags are set for each piece of data according to information such as tenants, roles, and customer relationships. When accessing the data, only users with corresponding tag permissions can access the data within the permissions, which can prevent the occurrence of data security problems.

[0080] The resource access security audit unit 24 is configured to: monitor, record, and analyze the activities of the tenant's users accessing resources.

[0081] In some embodiments, the resource access security audit unit 24 monitors, records, and analyzes the user's resource access activities to ensure security, compliance, and traceability.

[0082] It can be understood that resource access security auditing is an important part of ensuring organizational information security. Through meticulous monitoring, recording, and analysis, potential security threats can be effectively identified and responded to, while ensuring compliance. By implementing an effective auditing mechanism, an organization can enhance its overall security protection level and protect sensitive resources.

[0083] Exemplarily, the resource access security audit unit 24 can collect the operation logs of each resource for unified storage and recording. First, the audit objectives need to be clarified, which include two aspects: 1. The asset list included in the audit scope, and 2. The audit reference for each asset. Generally, it is necessary to refer to existing audit standards for rule-making, and at the same time, the audit strategy can also be customized according to the actual needs of users. After clarifying the above information, a complete hierarchical implementation mechanism for auditing needs to be established, including: fully recording access logs, real-time detecting abnormal behaviors, automatically blocking and alarming, and generating compliance audit reports. By deploying technical tools in layers, establishing automated analysis rules, and linking with the permission management system, a closed-loop access audit system can be constructed. Special attention should be paid to the integrity and immutability of the logs, and at the same time, the risk model should be customized in combination with the business scenario. For the realization of the traceability ability, the resource access security audit unit 24 will record the IP address used by the user when accessing the network currently, which is guaranteed through communication with the access device during the access stage. Through the IP address, the resources accessed by the user can be traced. It is divided into two forms: online traceability and offline traceability. Online traceability means that when the current user is online and the user accesses a certain resource, the resource can identify the source address information of the user accessing the resource. According to the time point of accessing the resource, the resource can initiate a request to obtain the user's identity to the identity management unit 21, so as to realize the positioning of the subject information. Offline traceability is that after the user has gone offline, during the subsequent audit process, after determining a certain access source address and time information through the access record, the resource access security audit unit 24 initiates a request for subject identity positioning to the identity management unit 21 to obtain relevant user information.

[0084] In summary, the beneficial effects of a tenant broadband multi-access unified authentication cloud platform 00 provided by some embodiments of the present invention include:

[0085] The tenant broadband multi-access unified authentication cloud platform 00 provides services in a centralized and shared manner, concentrating all business processing, data storage, and service logic in a unified architecture. Each school and user shares the resources and functions of the platform. This approach helps improve resource utilization, reduce operating costs, and facilitates unified management and maintenance, ensuring service consistency and stability. For example, the platform can centrally perform software upgrades, security protection, etc., without the need for separate deployment and management for each school.

[0086] The tenant broadband multi-access unified authentication cloud platform 00 is built using a microservices architecture and a mature and advanced technology system. From the perspective of identity management and operation, there are multiple roles in the user identity vision, providing rich functions such as identity management, authentication and authorization, access control, permission management, and log auditing for internal and external users. The operator's account is associated in the user role, enabling the management and single-point secure access to enterprise application resources and system resources. At the same time, new capabilities such as visualization, service call chain monitoring, and operation and maintenance are built.

[0087] The tenant broadband multi-access unified authentication cloud platform 00 provides cloud-based centralized authentication and centralized proxy services for multiple schools based on the tenant model, realizing unified management of multiple accesses and multiple accounts for campus broadband users, and realizing unified control of access by campus broadband users to multiple network exits (such as the education network and the Internet), achieving the goal of single authentication for campus broadband user network access services and connection of multiple network exits (such as the education network and the Internet) according to permissions. At the same time, the in-school network access authentication platforms of each school and the proxy devices within the school campus network are eliminated.

[0088] Some embodiments of the present invention also provide a tenant broadband multi-access unified authentication system, as Figure 4 shown, the tenant broadband multi-access unified authentication system 04 includes a tenant broadband multi-access unified authentication cloud platform 00 and at least one BRAS 41. Each BRAS 41 is used to connect to at least one tenant and the tenant broadband multi-access unified authentication cloud platform respectively, for receiving request information from the users of any tenant among at least one tenant, and for connecting and forwarding the request information from the users of any tenant among at least one tenant to the tenant broadband multi-access unified authentication cloud platform.

[0089] Exemplarily, in the case where the tenant is a campus, as Figure 5As shown in the figure, the terminals of campus-side users are connected through a wired network (such as a wired local area network (LAN), an optical line terminal (OLT)) or a wireless network (such as a wireless local area network (WLAN), also known as Wi-Fi), and have the need to access the campus network, the education network, and the Internet. Through limited access routing settings, the network access requests of users are forwarded to the tenant broadband multi-access unified authentication cloud platform 00.

[0090] If the campus-side user uses a school-internal account (for example, accesses the education network using a student ID), after the tenant broadband multi-access unified authentication cloud platform 00 authenticates the user successfully, it uses the Remote Authentication Dial-In User Service (RADIUS) protocol (if the campus router supports the RADIUS protocol) or the network management protocol (for example, the Network Configuration Protocol (NETCONF) protocol, and in this case, the tenant broadband multi-access unified authentication cloud platform 00 needs to be docked with the network platform) to open the user's access to the education network according to the user's permissions. At the same time, if the user has an associated operator broadband account and its subscription information determines that the access to the Internet is also opened, single sign-on is achieved through the proxy dialing service to open the user's access to the Internet. If the user uses an operator broadband account, the access to the Internet is first opened, and then the access to the education network is opened as needed.

[0091] It can be understood that schools in different regions are respectively connected to the centrally deployed BRAS (providing integrated proxy dialing service at the same time) responsible for each region. The authentication requests from schools in each domain are aggregated to the tenant broadband multi-access unified authentication cloud platform 00 and are processed through tenant management and assigned to the corresponding tenant functions. The tenant broadband multi-access unified authentication cloud platform 00 can realize multi-domain and multi-school access and multi-operator integration of campus broadband operations.

[0092] It can be understood that in the actual operation scenario, there may also be a situation where the users of the tenant use non-cooperating operator broadband services, and the tenant broadband multi-access unified authentication system 04 can also support multi-operator integration.

[0093] Exemplarily, the logical architecture of multi-operator integration is as Figure 6As shown in the figure, information interaction can be carried out between different operators through their respective BRASs. For example, the first BRAS is the BRAS of the campus broadband operator of the cooperation party, and the second BRAS is the BRAS of other operators. In the multi-operator convergence scenario, the on-campus account (such as student ID) of campus users is registered through the first BRAS on the tenant broadband multi-access unified authentication cloud platform 00 of the campus broadband operator. The campus users can also use the broadband services of other operators through the first BRAS and the second BRAS. However, if they need to use the unified authentication service of multi-operator convergence, they need to register the broadband accounts opened by them with other operators to the tenant broadband multi-access unified authentication cloud platform 00 as well.

[0094] In the tenant broadband multi-access unified authentication system 04, the specific solution and related description of the tenant broadband multi-access unified authentication cloud platform 00 can refer to the above embodiments and will not be elaborated here.

[0095] Some embodiments of the present invention provide a tenant broadband multi-access unified authentication system 04, which constructs an enterprise-level identity-centric authentication platform, covering internal and external user systems, and gradually accessing device, network, application, service, and data identity systems, providing diversified identity management and authentication service capabilities for the included application resources and system resources, solving problems such as scattered identity data, cross-system identity mutual trust and recognition, and poor user experience, and ensuring the application information security of the enterprise.

[0096] Some embodiments of the present invention provide a tenant broadband multi-access unified authentication method, which is applied to the above tenant broadband multi-access unified authentication system 00. As Figure 7 shown, the tenant broadband multi-access unified authentication method includes steps 701 to 703.

[0097] Step 701, receive request information.

[0098] In step 701, the request information is forwarded by any one of at least one BRAS in response to receiving the request information from any user of any tenant among at least one tenant. The request information includes the identification information of the tenant.

[0099] Step 702, identify the identification information of the tenant included in the request information.

[0100] Step 703, determine the tenant module corresponding to the identification information of the tenant according to the request information, so that the corresponding tenant module performs identity management, permission management, resource access control, and resource access security audit according to the request information.

[0101] In step 703, the corresponding tenant module is one tenant module among at least one tenant module, and the tenant modules in at least one tenant module correspond one by one to the tenants in at least one tenant.

[0102] Understandably, for the specific solutions and beneficial effects of steps 701 to 703, reference may be made to the relevant descriptions of a tenant broadband multi-access unified authentication cloud platform provided in some embodiments of the present invention, which will not be elaborated here.

[0103] Some embodiments of the present invention provide a computer device, such as Figure 8 As shown, the computer device 800 includes a memory 801 and a processor 802. A computer program is stored in the memory 801. When the processor 802 runs the computer program stored in the memory 801, the processor 802 executes the above-mentioned tenant broadband multi-access unified authentication method.

[0104] For the specific solutions and beneficial effects of a computer device provided in some embodiments of the present invention, reference may be made to the relevant descriptions of a tenant broadband multi-access unified authentication cloud platform provided in some embodiments of the present invention, which will not be elaborated here.

[0105] Some embodiments of the present invention provide a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor executes the above-mentioned tenant broadband multi-access unified authentication method.

[0106] For the specific solutions and beneficial effects of a computer-readable storage medium provided in some embodiments of the present invention, reference may be made to the relevant descriptions of a tenant broadband multi-access unified authentication cloud platform provided in some embodiments of the present invention, which will not be elaborated here.

[0107] It can be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principles of the present invention. However, the present invention is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also regarded as the protection scope of the present invention.

Claims

1. A unified authentication cloud platform for multi-access of tenant broadband, characterized in that Including: A tenant management module, configured to: receive request information, where the request information includes identification information of a tenant; identify the identification information of the tenant included in the request information; determine a corresponding tenant module according to the identification information of the tenant; and forward the request information to the corresponding tenant module; wherein, the request information received by the tenant management module is forwarded by any one of at least one Broadband Remote Access Server (BRAS) in response to receiving request information from any user of any one of at least one tenant; and At least one tenant module; wherein, the corresponding tenant module is configured to: receive the request information, and perform identity management, permission management, resource access control, and resource access security auditing according to the request information; the corresponding tenant module is one of the at least one tenant module, and the tenant modules in the at least one tenant module correspond one-to-one with the tenants in the at least one tenant.

2. The tenant broadband multi-access unified authentication cloud platform according to claim 1, wherein The corresponding tenant module includes: An identity management unit, configured to: determine the role of the user of the corresponding tenant according to the request information, and perform identity management and login management on the user of the tenant according to the role of the user; wherein, the role of the user includes a customer and an account; the customer corresponds to the broadband account of the operator where the customer is located; one customer is associated with at least one account; A permission management unit, configured to: perform authentication management on the access permissions of the multi-access terminals and multi-network exits of the users of the tenant according to the role of the user; A resource access control unit, configured to: control the accessible resources of the users of the tenant according to the role of the user; and A resource access security auditing unit, configured to: monitor, record, and analyze the activities of the users of the tenant for resource access.

3. The tenant broadband multi-access unified authentication cloud platform according to claim 2, wherein, The identity management unit is further configured to: in the case where the user of the tenant logs in to the tenant system for the first time using any one of its accounts, bind the account used by the user of the tenant with the broadband account of the operator where the user is located, and through the method of account mapping, perform associated authentication and maintenance on the ID, terminal mark, service mark, and broadband account of the user of the tenant, so as to establish an association relationship between the account of the user of the tenant and the customer of the user of the tenant.

4. The tenant broadband multi-access unified authentication cloud platform according to claim 2, characterized in that, The identity management unit is further configured to: Respond to receiving a single sign-on request from the tenant system, and verify the login information of the user of the tenant; wherein, the single sign-on request is sent by the tenant system after the user of the tenant initiates an access request to the tenant system; Respond to the login information of the user of the tenant being verified, and return an access token to the tenant system; Respond to receiving a user role request or a menu request from the tenant system, verify the validity of the access token, and if the verification is passed, return user role or menu data to the tenant system; wherein, the user role request or menu request carries the access token; In response to receiving a service interface call request from the tenant system, perform secondary authentication on the access token. If the access token is valid, return service data to the tenant system; if the access token is invalid, mark the access token as discarded and return unauthorized to the tenant system; and In response to receiving an access token logout request from the tenant system, forcibly discard the access token and return a logout success message to the tenant system; wherein, the access token logout request is sent by the tenant system after the user of the tenant initiates a logout request for the tenant system.

5. The tenant broadband multi-access unified authentication cloud platform according to claim 2, characterized in that, The permission management unit is further configured to: Determine the authentication domain where the user of the tenant is located, and manage the access permissions of the user of the tenant according to the authentication domain where the user of the tenant is located; wherein, the authentication domain where the user of the tenant is located is one of multiple authentication domains divided by the permission management unit for the user of the tenant according to the user requirements of the tenant.

6. The tenant broadband multi-access unified authentication cloud platform according to claim 2, wherein The permission management unit is further configured to: Set a pre-authentication domain and a post-authentication domain. The user of the tenant is located in the pre-authentication domain before authentication and in the post-authentication domain after authentication; wherein, the user of the tenant located in the pre-authentication domain has the permission to access the portal page; the user of the tenant located in the post-authentication domain has the permission to access the entire network; and Perform authentication interaction with the user of the tenant through the portal page according to the authentication domain where the user of the tenant is located.

7. The tenant broadband multi-access unified authentication cloud platform according to claim 2, characterized in that, The permission management unit is further configured to: Query the media access control of the user device of the tenant from the Dynamic Host Configuration Protocol (DHCP) server, and bind the user of the tenant with the media access control (MAC) address of the user device of the tenant.

8. A unified authentication system for multi-access of tenant broadband, characterized in that, Comprising: The tenant broadband multi-access unified authentication cloud platform according to any one of claims 1 to 7, and At least one BRAS, each BRAS is used to be respectively connected with at least one tenant and the tenant broadband multi-access unified authentication cloud platform, for receiving request information from the user of any tenant among the at least one tenant, and for connecting and forwarding the request information from the user of any tenant among the at least one tenant to the tenant broadband multi-access unified authentication cloud platform.

9. A unified authentication method for multi-access of tenant broadband, characterized in that, Applied to the tenant broadband multi-access unified authentication platform according to any one of claims 1 to 7, the method comprises: Receive request information; wherein, the request information is forwarded by any one of at least one BRAS in response to receiving request information from any user of any tenant among at least one tenant; the request information includes the identification information of the tenant. Identify the identification information of the tenant included in the request information; and Determine a tenant module corresponding to the identification information of the tenant according to the request information, so that the corresponding tenant module performs identity management, permission management, resource access control, and resource access security auditing according to the request information; wherein, the corresponding tenant module is one of the at least one tenant modules, and the tenant modules in the at least one tenant modules correspond one by one to the tenants in the at least one tenant.

10. A computer device, characterized in that, It includes a memory and a processor. A computer program is stored in the memory. When the processor runs the computer program stored in the memory, the processor executes the tenant broadband multi-access unified authentication method according to claim 9.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the processor executes the tenant broadband multi-access unified authentication method according to claim 9.