Information transmission method, system and device and storage medium
By synchronizing IP-MAC bindings through a network interface controller, the method addresses the issue of multiple authentications due to dynamic IPv6 addresses in SLAAC, improving network resource utilization and user experience.
Patent Information
- Application Number
- CN202410020247.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-05
- Publication Date
- 2025-07-08
AI Technical Summary
In web authentication scenarios, terminals using IPv6 addresses assigned via SLAAC may experience multiple authentication due to dynamic and unpredictable address changes, leading to inefficient resource utilization and poor user experience.
Implement a method where a network interface controller synchronizes IP-MAC bindings to a network access server (NAS), allowing terminals to access networks based on pre-established relationships, enabling single authentication for multiple IP addresses.
This approach enhances network resource utilization and user experience by allowing a terminal to access networks with different IP addresses after a single authentication, reducing redundant authentication processes.
Smart Images

Figure CN120281491A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to an information transmission method, system, device and storage medium. Background Art
[0002] Terminal IPv6 (Internet Protocol Version 6) address acquisition defines two methods: stateful automatic configuration mechanism and stateless address autoconfiguration (SLAAC) mechanism. Stateful address autoconfiguration uses DHCPv6 (Dynamic Host Configuration Protocol for IPv6) to dynamically assign IPv6 addresses to hosts. The DHCPv6 protocol is a network protocol used to configure the IP address, IP prefix and / or other configurations required by IPv6 hosts working on IPv6 networks. Stateless address autoconfiguration SLAAC is implemented through the ND (Neighbor Discovery Protocol) protocol. The host generates a global unicast address by receiving the RA (Router Advertisement) sent by the router on the link and combining it with the interface identifier. RA mainly contains content messages such as prefix, MTU (Maximum Transmission Unit), and routing information selection. Since the stateless address is generated in disguise from the terminal's MAC (Media Access Control Address), in order to protect user privacy, some terminal systems will generate temporary addresses for communication to avoid being tracked. Therefore, there may be a terminal with multiple IPv6 addresses (the number is not fixed), and the IPv6 address may change randomly.
[0003] Web authentication is the network assigning an IP (Internet Protocol Address) address to the user terminal for accessing the portal website. The user enters the user name and password in the login window, and then authenticates the authentication server through the client. If the authentication is successful, the client is triggered to re-initiate an address allocation request and assign the user an IP address that can access the external network. When the user goes offline, the client initiates an offline request.
[0004] In the web authentication scenario, since the terminal may access the network using different IP addresses, the same terminal may need to undergo multiple permission authentications. For example, in the case where the terminal uses Stateless Address Autoconfiguration (SLAAC) to obtain an IPv6 address, since the IPv6 address assigned to the terminal each time is not fixed, when performing permission authentication, because the Network Attached Server (NAS) cannot perceive the changing IPv6 address of the terminal's SLAAC, multiple authentications are caused, which not only affects the user experience but also wastes network resources. Summary of the Invention
[0005] The main purpose of the embodiments of the present application is to provide an information transmission method, system, device, and storage medium, which realizes that for the same terminal, after one permission authentication, it can access the target network resources using different IP addresses, improving network resource utilization and the user experience.
[0006] In a first aspect, the embodiments of the present application provide an information transmission method, which is applied to a Network Attached Server (NAS). The method includes: in response to an access request sent by a target terminal to a target network using a current IP address, determining a target MAC address bound to the current IP address according to a preset relationship library, where the preset relationship library includes the binding relationships between the MAC addresses and corresponding IP addresses of at least one terminal, and the binding relationships are obtained through a network controller; when there is an authenticated IP address among the bound IP addresses corresponding to the target MAC address, allowing the target terminal to access the target network.
[0007] In one embodiment, after determining the target MAC address bound to the current IP address according to the preset relationship library, it further includes: when there is no authenticated IP address among the bound IP addresses corresponding to the target MAC address, performing permission authentication on the terminal according to the current IP address; after the terminal successfully passes the permission authentication, sending a pass-through policy regarding the target terminal to the router and storing the binding relationship between the target MAC address and the current IP address in the preset relationship library.
[0008] In one embodiment, before determining the target MAC address bound to the current IP address according to the preset relationship library, the method further includes: when there is no target MAC address bound to the current IP address in the preset relationship library and the current IP address is not authenticated, performing permission authentication on the terminal according to the current IP address; after the terminal successfully passes the permission authentication, sending the authenticated current IP address to the network controller; receiving the MAC address corresponding to the current IP address returned by the network controller, sending a pass-through policy for the target terminal to the router, and storing the binding relationship between the current IP address and the MAC address in the preset relationship library.
[0009] In a second aspect, an embodiment of the present application provides an information transmission method applied to a network controller. The method includes: in response to an IP address configuration event of a target terminal, obtaining a binding relationship between a first IP address of the target terminal and a target MAC address of the target terminal; sending the binding relationship to a Network Access Server (NAS) to instruct the NAS to send a pass-through policy for the target terminal to the router according to the binding relationship.
[0010] In one embodiment, the obtaining the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal includes: obtaining the binding relationship between the current IP address of the target terminal and the target MAC address of the target terminal through an access device of the target terminal, where the access device is deployed with a source address verification function.
[0011] In one embodiment, the obtaining the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal includes: obtaining the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal through a gateway device of the target terminal, where the gateway device is deployed with a source address verification function.
[0012] In one embodiment, the sending the binding relationship to the Network Access Server (NAS) includes: when it is determined that the target terminal has passed the permission authentication, sending the binding relationship to the Network Access Server (NAS).
[0013] In one embodiment, determining that the target terminal has passed the authority authentication includes: receiving first terminal information sent by the NAS; wherein the first terminal information carries the first IP address, and the first IP address is used to indicate that the target terminal has passed the authority authentication; or, receiving second terminal information sent by the NAS; determining that the MAC address bound to the second IP address carried in the second terminal information is the target MAC address; wherein the second IP address is used to indicate that the target terminal corresponding to the target MAC address has passed the authority authentication.
[0014] In a third aspect, an embodiment of the present application provides an information transmission device, applied to a network access server NAS, the device comprising:
[0015] a determination module, configured to determine, in response to an access request issued by a target terminal to a target network using a current IP address, a target MAC address bound to the current IP address according to a preset relationship library, wherein the preset relationship library includes a binding relationship between a MAC address of at least one terminal and a corresponding IP address, and the binding relationship is obtained through a network controller;
[0016] The permission module is used to allow the target terminal to access the target network when there is an authenticated IP address in the bound IP address corresponding to the target MAC address.
[0017] In one embodiment, it also includes: a first authentication module, which is used to perform authority authentication on the terminal according to the current IP address after determining the target MAC address bound to the current IP address according to a preset relationship library, if there is no authenticated IP address in the bound IP address corresponding to the target MAC address; a sending module, which is used to send a release policy for the target terminal to the router after the terminal successfully passes the authority authentication; and a storage module, which is used to store the binding relationship between the target MAC address and the current IP address in the preset relationship library.
[0018] In one embodiment, it further includes: a second authentication module, configured to perform permission authentication on the terminal according to the current IP address before determining the target MAC address bound to the current IP address in the preset relationship library, when there is no target MAC address bound to the current IP address in the preset relationship library and the current IP address is not authenticated; a second sending module, configured to send the authenticated current IP address to a network controller after the terminal successfully passes the permission authentication; a first receiving module, configured to receive the MAC address corresponding to the current IP address returned by the network controller, send a pass-through policy for the target terminal to a router, and store the binding relationship between the current IP address and the MAC address in the preset relationship library.
[0019] In a fourth aspect, an information transmission device provided by an embodiment of the present application is applied to a network controller, and the device includes;
[0020] An obtaining module, configured to obtain the binding relationship between the current IP address of the target terminal and the target MAC address of the target terminal in response to an IP address configuration event of the target terminal.
[0021] A synchronization module, configured to send the binding relationship to a Network Access Server (NAS) to instruct the NAS to send a pass-through policy for the target terminal to a router according to the binding relationship.
[0022] In one embodiment, the obtaining module is configured to obtain the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal through an access device of the target terminal, and the access device is deployed with a source address verification function.
[0023] In one embodiment, the obtaining module is configured to obtain the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal through a gateway device of the target terminal, and the gateway device is deployed with a source address verification function.
[0024] In one embodiment, the synchronization module is configured to send the binding relationship to the Network Access Server (NAS) when it is determined that the target terminal has passed the permission authentication.
[0025] In one embodiment, it further includes: a second receiving module, configured to receive the first terminal information sent by the NAS; wherein, the first terminal information carries the first IP address, and the first IP address is used to indicate that the target terminal has passed the permission authentication; or, receive the second terminal information sent by the NAS; determine the MAC address bound to the second IP address carried in the second terminal information as the target MAC address; wherein, the second IP address is used to indicate that the target terminal corresponding to the target MAC address has passed the permission authentication.
[0026] In a fifth aspect, an embodiment of the present application provides an information transmission system, including: a network controller and a Network Access Server (NAS), wherein:
[0027] The network controller is configured to, in response to an IP address configuration event of a target terminal, obtain the binding relationship between the current IP address of the target terminal and the target MAC address of the target terminal; synchronize the binding relationship to the Network Access Server (NAS), so as to instruct the NAS to issue a pass-through policy for the target terminal to the router according to the binding relationship;
[0028] The NAS is configured to receive the binding relationship between the target MAC address and the current IP address sent by the network controller; and in response to an access request sent by the target terminal to a target network using the current IP address, determine the MAC address bound to the current IP address as the target MAC address according to the binding relationship; and allow the target terminal to access the target network using the current IP address when there is an authenticated IP address among the binding IP addresses corresponding to the target MAC address.
[0029] In a sixth aspect, an embodiment of the present application provides an electronic device, including:
[0030] At least one processor; and
[0031] A memory communicatively connected to the at least one processor;
[0032] Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the electronic device to execute the method described in any of the above aspects.
[0033] In a seventh aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when a processor executes the computer-executable instructions, the method described in any of the above aspects is implemented.
[0034] In an eighth aspect, an embodiment of the present application provides a computer program product, including a computer program which, when executed by a processor, implements the method described in any of the above aspects.
[0035] When receiving an access request from a target terminal to a target network, the information transmission method, system, device, and storage medium provided by the embodiments of the present application search for the target MAC address bound to the current IP address of the target terminal in a preset relationship library, and determine whether there is an authenticated IP address among the bound IP addresses corresponding to the target MAC address. If there is an authenticated IP address corresponding to the MAC address of the target terminal, it indicates that the target terminal has passed the permission authentication and can be directly released to access the target network. Among them, the preset relationship library is established based on the binding relationship between the MAC addresses and corresponding IP addresses of at least one terminal synchronized by the network controller. In this way, it is ensured that for the same terminal, after one permission authentication, it can access the target network resources using different IP addresses, improving the network resource utilization rate and the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] The drawings here are incorporated into the description and form a part of this description, showing embodiments consistent with the present application, and are used together with the description to explain the principles of the present application. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0037] Figure 1 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application;
[0038] Figure 2 It is a schematic diagram of a stateless address autoconfiguration (SLAAC) process provided by an embodiment of the present application;
[0039] Figure 3 It is a schematic diagram of the architecture of a web authentication deployment solution provided by an embodiment of the present application;
[0040] Figure 4 It is a schematic diagram of the basic process of web authentication provided by an embodiment of the present application;
[0041] Figure 5 It is a schematic diagram of the architecture of a cross-layer three-tier web authentication deployment provided by an embodiment of the present application;
[0042] Figure 6A It is a schematic diagram of the architecture of an information transmission system provided by an embodiment of the present application;
[0043] Figure 6B It is a schematic diagram of the specific deployment topology of an information transmission system provided by an embodiment of the present application;
[0044] Figure 6C Schematic diagram of the principle of the SAVI function provided by an embodiment of the present application;
[0045] Figure 7A Schematic flowchart of an information transmission method provided by an embodiment of the present application;
[0046] Figure 7B Schematic diagram of the storage form of IP-MAC binding data provided by an embodiment of the present application;
[0047] Figure 8A Schematic flowchart of an information transmission method provided by an embodiment of the present application;
[0048] Figure 8B Schematic flowchart of an information transmission method provided by an embodiment of the present application;
[0049] Figure 9A Schematic diagram of the interaction signaling of an information transmission method provided by an embodiment of the present application;
[0050] Figure 9B Schematic diagram of the interaction of each component based on the IP-MAC binding relationship provided by an embodiment of the present application;
[0051] Figure 10 Schematic diagram of the structure of an information transmission device provided by an embodiment of the present application;
[0052] Figure 11 Schematic diagram of the structure of an information transmission device provided by an embodiment of the present application.
[0053] Through the above-mentioned drawings, the clear embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed implementation manners
[0054] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application.
[0055] The term "and / or" in this article is used to describe the association relationship of associated objects, and specifically represents three relationships that may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone.
[0056] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or refuse.
[0057] To clearly describe the technical solutions of the embodiments of this application, the following first gives the definitions of the nouns involved in this application:
[0058] Radius: Remote Authentication Dial In User Service, a remote user dial-in authentication system.
[0059] HTTP: Hypertext Transfer Protocol, a hypertext transfer protocol.
[0060] TCP, Transmission Control Protocol, a transmission control protocol.
[0061] UDP: User Datagram Protocol, a user datagram protocol.
[0062] IPv4: Internet Protocol Version4, the fourth version of the Internet Protocol.
[0063] IPv6: Internet Protocol Version 6, the sixth version of the Internet Protocol.
[0064] DHCP: Dynamic Host Configuration Protocol, a dynamic host configuration protocol.
[0065] DHCPv6: A stateful address autoconfiguration protocol, a network protocol used to configure the IP addresses, IP prefixes, and / or other configurations required for IPv6 hosts operating on an IPv6 network.
[0066] DUID: DHCPv6 Unique ID, the unique identifier of a DHCPv6 participating node.
[0067] SLAAC: Sateless Address Autoconfiguration, stateless address autoconfiguration.
[0068] ARP: Address Resolution Protocol, the Address Resolution Protocol.
[0069] ND: Neighbor Discovery Protocol, the Neighbor Discovery Protocol.
[0070] ND Snooping: A security feature for IPv6 ND used in a Layer 2 switching network environment. ND Snooping is a security feature for IPv6 ND used in a Layer 2 switching network environment. By listening to the Neighbor Solicitation (NS) messages of the user's Duplicate Address Detection (DAD) process, the ND Snooping dynamic binding table is established, thereby recording information such as the source IPv6 address, source MAC address, belonging VLAN, ingress port, etc., to prevent subsequent ND message attacks that impersonate users and gateways.
[0071] IP: Internet Protocol Address, the Internet Protocol address.
[0072] RA: Router Advertisement, the Router Advertisement message.
[0073] RS: Router Solicitation, the Router Solicitation message.
[0074] DAD: Duplicate Address Detect, Duplicate Address Detection.
[0075] NS: Neighbor solicitation, the Neighbor Request.
[0076] MTU: Maximum Transmission Unit, the Maximum Transmission Unit.
[0077] MAC: Media Access Control Address, the Media Access Control address.
[0078] NAS: Network Access Server, a Network Access Server, a remote access device.
[0079] CHAP: Challenge-Handshake Authentication Protocol, the Challenge-Handshake Authentication Protocol, an encrypted authentication method.
[0080] SDN: Software Defined Network, Software Defined Network.
[0081] EUI: End-System Unique Identifier, End-System Unique Identifier.
[0082] SAVI: Source Address Validation Improvements, Source Address Validation Improvements.
[0083] VLAN: Virtual Local Area Network, Virtual Local Area Network.
[0084] TCP: Transmission Control Protocol, Transmission Control Protocol.
[0085] PRC: Remote Procedure Call Protocol, Remote Procedure Call Protocol.
[0086] SSH: Secure Shell, Secure Shell, is a network security protocol that enables secure access and file transfer services through encryption and authentication mechanisms.
[0087] TLS: Transport Layer Security Protocol, Transport Layer Security Protocol.
[0088] YANG: Yet Another Next Generation, is a data model definition language that can be used to describe the interaction model between clients and servers communicating based on the Netconf protocol.
[0089] IID: Interface ID, Interface ID, refers to the unique identifier used to identify network interfaces in a computer network.
[0090] IPoE: IP over Ethernet, a broadband access authentication system that implements IP user session mechanisms, IP data stream classification mechanisms, IP session authentication, and management mechanisms.
[0091] Such as Figure 1 As shown, this embodiment provides an electronic device 1, including: at least one processor 11 and a memory 12, Figure 1Take a processor as an example. The processor 11 and the memory 12 are connected through the bus 10. The memory 12 stores instructions that can be executed by the processor 11. The instructions are executed by the processor 11 so that the electronic device 1 can execute all or part of the processes of the methods in the following embodiments, so as to enable the same terminal to access the target network resources using different IP addresses after one authentication of permissions, improving the utilization rate of network resources and the user experience.
[0092] In a possible embodiment, the electronic device 1 can be a network device such as a base station, a switch, a router, or a gateway, or can be a mobile phone, a tablet computer, a laptop computer, a desktop computer, or a large computing system composed of multiple computers.
[0093] The method provided by the embodiments of the present application can be implemented by the electronic device 1 executing corresponding software code.
[0094] The technical solutions provided by the embodiments of the present application can be applied to various systems, especially communication systems with IPv4 / IPv6.
[0095] The terminal device involved in the embodiments of the present application can be a device that provides voice and / or data connectivity to users, a handheld device with a wireless connection function, or other processing devices connected to a wireless modem, etc. In different systems, the name of the terminal device may also be different. For example, in a 5G system, the terminal device can be called a user equipment (UE). The wireless terminal device can communicate with one or more core networks (CN) via a radio access network (RAN). The wireless terminal device can be a mobile terminal device, such as a mobile phone (or a "cellular" phone) and a computer with a mobile terminal device. For example, it can be a portable, pocket-sized, handheld, computer-integrated, or vehicle-mounted mobile device that exchanges language and / or data with the radio access network.
[0096] An IP address is a unified address format provided by the IP protocol. It assigns a logical address to each network and each host on the Internet to mask the differences in physical addresses.
[0097] In an actual scenario, the acquisition of a terminal's IPv6 (Internet Protocol Version 6) address defines two methods: the stateful and stateless address auto-configuration mechanisms. The stateful address auto-configuration uses the DHCPv6 (Dynamic Host Configuration Protocol for IPv6) protocol to dynamically assign IPv6 addresses to hosts. The DHCPv6 protocol is a network protocol used to configure the IP addresses, IP prefixes, and / or other configurations required for IPv6 hosts operating on an IPv6 network. The stateless address auto-configuration is implemented through the ND (Neighbor Discovery Protocol). A host generates a globally unique unicast address by receiving RA (Router Advertisement) messages sent by routers on the link and combining them with the interface identifier. The RA mainly contains information such as prefix, MTU (Maximum Transmission Unit), and routing information options.
[0098] In a possible embodiment, the stateless address auto-configuration (SLAAC) process is as Figure 2 shown and may include:
[0099] 1. When the terminal accesses the network where the router is located and enables the IPv6 protocol, it first generates a local link address for this interface based on the local prefix FE80:: / 64 and the EUI-64 interface identifier.
[0100] 2. After the terminal configures the local link address, it sends an RS (Router Solicitation) message to request the prefix information of the router. For example, by default, 3 RS messages can be sent.
[0101] 3. After receiving the RS message, the router sends a unicast RA message in response to the RS message, carrying the prefix information for stateless address auto-configuration.
[0102] Of course, the router can also periodically send multicast RA messages, and the sending of multicast RA messages does not require receiving an RS message as a prerequisite.
[0103] 4. After receiving the RA message, the terminal generates a temporary globally unique unicast address based on the prefix information and configuration information. At the same time, it starts the DAD (Duplicate Address Detection) process and sends an NS (Neighbor Solicitation) message to verify the uniqueness of the temporary address. At this time, the address is in a temporary state. Here, the configuration information can include the interface ID configuration information of the terminal. For example, if the prefix information contains a 64-bit network prefix, a 64-bit interface ID (abbreviation "IID") is also required to generate a globally unique unicast address.
[0104] The terminal can create its own unique IID in the following two ways:
[0105] 1) An IID can be created using the terminal's MAC address.
[0106] 2) Randomly generated, the 64-bit IID can be a value randomly generated by the terminal operating system.
[0107] 5. After receiving the DAD detection message, other terminals on the link discard the message if they do not use the address. Otherwise, they generate a NA message in response to NS.
[0108] 6. If the terminal does not receive the NA message detected by DAD, it means that the address is globally unique, and the interface is initialized with the temporary address. At this time, the address enters the valid state.
[0109] After the address is automatically configured, the router can start NUD detection and periodically send NS messages to detect whether the address is reachable.
[0110] Advantages of using stateless addresses: Terminals are plug-and-play, deployment is simple, and all terminals support it.
[0111] Disadvantages of using stateless addresses: Since stateless addresses can be generated in disguised form from MAC addresses, in order to protect user privacy, some terminal systems will continuously generate temporary addresses for communication to avoid being tracked. Therefore, there will be multiple IPv6 addresses (the number is not fixed) for a terminal. For example, some devices may have multiple IPv6 addresses generated by SLAAC at the same time, and some devices may only have one temporary IPv6 address at the same time, and the IPv6 address will change randomly.
[0112] During the terminal authorization authentication process, NAS often fails to perceive the changing IPv6 address of the terminal SLAAC, causing it to authenticate the terminal multiple times, which not only affects the user experience but also wastes network resources.
[0113] Take the web authentication scenario as an example. In the web authentication scenario, the network assigns an address to the user terminal for accessing the portal website. The user enters the user name and password in the login window, and then authenticates the Radius server through the Radius client. If the authentication is successful, the client is triggered to re-initiate an address allocation request and assign the user an address that can access the external network. When the user goes offline, an offline request is initiated through the client.
[0114] In one embodiment, the web authentication deployment solution can be as follows Figure 3As shown in the figure, Layer 2 IPoE (IP over Ethernet, a broadband access authentication system that implements an IP user session mechanism, a hierarchical mechanism for IP data streams, and an IP session authentication and management mechanism) can deploy a NAS running a Radius client / authentication enforcement point at the user gateway (core switch), and deploy a Radius server and a Portal (portal website) server in the server area. However, in some scenarios, such as Layer 3 IPoE, the NAS can be deployed at a non-gateway location. For example, in the scenario of basic education, the NAS is deployed at the exit router of each school system, and school users (such as dormitory area users or office area users) connect to the education management system through a FW (firewall) and an Internet dedicated line. The education management system needs to perform unified web authentication for the users of each school for outbound access, and can support IPv6 lines and IPv4 lines.
[0115] In an actual scenario, when an unauthenticated user uses a browser to access the Internet, the network device will force the browser to access a specific site, that is, the web authentication server. The web authentication server is a general term and can include a Portal server and a Radius server. In some small scenarios, the functions of the Portal server and the Radius server are integrated on one device; in some large scenarios, the Portal server and the Radius server are two separate hardware devices deployed separately, and these two hardware devices are collectively referred to as the web authentication server. Taking the scenario of deploying a separate external server to perform Portal authentication page push and authentication page jump as an example, the server that should perform Portal authentication is usually called the Portal server. Users can access the services on the Portal server without authentication, such as downloading security patches and reading announcement information. When users need to access other network resources outside the authentication server, they must authenticate their identities on the Portal server through a browser, and can only use the network resources after authentication.
[0116] In one embodiment, the basic web authentication process can be as Figure 4 shown, and the process includes:
[0117] 1. The Portal Client (user terminal) requests to access the network using the current IP address and is forcibly redirected to the Portal authentication page by the NAS device.
[0118] 2. The Portal Server pushes the authentication page to the Portal Client.
[0119] 3. The Portal Client triggers a connection authentication request through the HTTP protocol.
[0120] 4. After receiving the authentication request, the Portal sever first sends a Challenge request message to the NAS device and starts a timer to wait for the response from the NAS device. If it does not receive the response message from the NAS device within a certain period of time, it will retransmit this message. If there is still no response after reaching the maximum number of retransmissions, it will notify the Portal Client that the authentication has failed.
[0121] 5. After receiving the Challenge request message, the NAS device checks the legality of the message, responds to the legal message, and allocates a Challenge.
[0122] 6. After receiving the response message of the Challenge request message, the Portal Server calculates the CHAP-PASSWORD according to the CHAP algorithm, then sends a request authentication message to the NAS device and starts a timer to wait for the response from the NAS device. If it does not receive the response message from the NAS device within the specified time, the Portal Server will resend the authentication request message a certain number of times. When there is still no response after reaching the maximum number of retransmissions, it will notify the user that the authentication has failed.
[0123] 7. After receiving the request authentication message, the NAS device first performs a legality check and authenticates the legal message, that is, constructs a Radius authentication request message according to the authentication method (CHAP) and sends it to the Radius server.
[0124] 8. The Radius server responds with the authentication result.
[0125] 9. The NAS device sends an authentication request response message to the Portal sever according to the authentication result. The NAS device records the authentication result of the current IP address.
[0126] 10. The Portal Server notifies the Portal Client whether the authentication is successful according to the authentication result (success or failure) indicated by the authentication request response message, and displays the corresponding page according to the authentication result.
[0127] 11. The Portal Server confirms to the NAS that it has received the authentication result.
[0128] It can be seen that when the terminal accesses network resources using an IP address, it needs to be authenticated by a specific site (such as a Portal server or a Radius server). If the terminal uses a fixed IP address, after the IP address passes the first authentication by a specific site, the NAS records the IP address information. The next time the terminal uses this IP address to access, it will not go to the specific site for authentication again, and the NAS can directly release it.
[0129] In the web authentication scenario, with the development of communication technologies, terminals that support multiple Internet protocols simultaneously are becoming increasingly common. For example, dual-stack terminals that support both IPv6 and IPv4. When a dual-stack terminal performs web authentication, since it may access the network using different IP addresses, the same terminal may need to authenticate at a specific site multiple times. In the related art, the IPoE+Web (Portal) authentication scheme can be used to implement the permission authentication of dual-stack terminals.
[0130] IPoE is a DHCP+ authentication technology. It can insert various DHCP Option (selection) information into DHCP protocol packets by an intermediate device during the process of a user applying for an IP address through the DHCP protocol, and combine with other authentication technologies such as Web authentication to perform operations such as user binding and service binding.
[0131] The functional points implemented by combining Web authentication and IPoE technology in the related art are as follows:
[0132] 1. Terminal dual-stack authentication
[0133] To achieve the transition from an IPv4 network to an IPv6 network, a user network can deploy a terminal dual-stack mode (obtaining both an IPv4 address and an IPv6 address) and access V4 or V6 egress resources based on different types of addresses. Here, dual-stack authentication is involved. To avoid two independent and repeated authentications for a terminal to access V4 or V6 resources, it is necessary to combine IPoE technology. When the terminal applies for an IP address, the NAS node also obtains the terminal MAC address based on IPoE (for example, inserting the terminal MAC address information into the DHCP option). The IPv4 and IPv6 are jointly bound by the MAC address. After one of them is successfully authenticated for the first time, the NAS node can also issue the address binding of the other party to the hardware for execution policies through the MAC address, so that one authentication can release both stacks.
[0134] 2. Layer 2 authentication deployment solution
[0135] NAS can be deployed at the gateway and in the same Layer 2 network as the terminal. For example, in the scenario of higher education campus, Layer 2 networks are generally deployed, and the gateway performs centralized authentication. In this scenario, NAS is deployed on the gateway device, and it can directly obtain the MAC address, ND address (similar to the ARP address of IPv4), etc. on the device. This information can quickly integrate the MAC+IPv6 address information. Even if the terminal IPv6 address changes frequently, the changing ND table entries will be generated in real time on the gateway. Therefore, under Layer 2 authentication, NAS can combine the ARP, ND, and MAC table entries of the gateway to easily obtain the binding relationship between the MAC address and the IPv4 and IPv6 addresses, and realize one-time authentication and dual-stack release of the terminal. This solution is suitable for terminals to obtain IP addresses through DHCPv4, DHCPv6 (stateful address) or SLAAC (stateless address).
[0136] 3. Three-layer authentication deployment solution
[0137] Some user scenarios require a three-layer authentication solution, for example: users perform exit authentication on the egress router (terminals can access campus intranet resources, but authentication is required to access egress resources). General education users deploy the authentication NAS in the education management unit system, and the school network gateway is connected to the education management unit system through a carrier dedicated line. The school terminal needs to cross three layers to the NAS of the education management unit system for authentication and access to Internet resources.
[0138] In one embodiment, the cross-three-tier web authentication deployment can be as follows Figure 5 As shown in the figure, the terminal can be a dual-stack terminal, and can randomly initiate IPv4 authentication or IPv6 authentication through a browser. The gateway deploys DHCP Relay and DHCPv6 Relay. The Relay message can carry the terminal's MAC address to the server through Option. The MAC address is used for IPv4 and IPv6 authentication linkage, so that one-time authentication and dual-stack release are achieved. As the authentication execution point, the NAS device needs to redirect the HTTP message of unauthenticated users to the Portal server for authentication and execute the authentication policy locally. At the same time, the egress router needs to deploy DHCP Server and DHCPv6 Server. The Server needs to feed back the MAC address synchronized by the gateway to the NAS, and the NAS will uniformly perform IPv4 and IPv6 authentication linkage for the entire network.
[0139] Portal server: provides the authentication interface and related operations for web authentication. The Portal server accepts HTTP-based authentication requests from authentication clients, extracts account information from them, sends this information to the Radius server for authentication, and then informs users and NAS devices of the authentication results.
[0140] Radius Server: It provides remote user authentication based on the Radius protocol. The Portal server obtains the user's authentication account information from HTTP and then requests authentication from the Radius server through the Radius protocol. The Radius server feedbacks the authentication result to the Portal server through the Radius protocol.
[0141] In one embodiment, the Web cross-three-layer authentication process can be as follows:
[0142] 1. When the terminal first accesses the network, it needs to obtain IP addresses (temporary addresses that can communicate with the internal network server) from the DHCP Server and DHCPv6 Server respectively.
[0143] 2. The terminal initiates IPv4 or IPv6 authentication and sends an HTTP message to the NAS.
[0144] 3. The NAS device initiates a redirection, and the redirection address is the Portal server.
[0145] 4. The terminal establishes a connection with the Portal server according to the redirection address and fills in the authentication information.
[0146] 5. The Portal server returns the authentication information to the NAS, and the NAS makes an authentication request interaction with the Radius server.
[0147] 6. The NAS returns the authentication result to the Portal server, and the Portal server returns the authentication result interface to the terminal.
[0148] 7. If the authentication is successful, the terminal can access the Internet normally.
[0149] The principle of one-time authentication and dual-stack release for the terminal:
[0150] When the terminal applies for an IPv4 or IPv6 address, the gateway device Relay-related messages will bring the device's MAC address to the Server side in the form of Option or DUID. Then the Server synchronizes the information to the NAS, and the NAS realizes the linkage of each address of the terminal with the MAC address as the key. One-time authentication can achieve dual-stack release.
[0151] However, in a cross-three-layer scenario, since NAS cannot directly obtain the relevant information of the terminal through layer-2 information. Therefore, the above cross-three-layer solution is only applicable to the case where the terminal obtains an IP address through DHCPv4 or DHCPv6 (stateful address). The gateway deploys DHCP Relay and DHCPv6 Relay, the egress router side deploys NAS, DHCPServer, and DHCPv6 Server, and the Server is deployed on the egress router to facilitate NAS to obtain the terminal MAC and IP address information in Option. When the terminal initiates an egress resource access based on IPv4 or IPv6, the packet passes through the egress router, triggering NAS to perform a redirect to the Portal server. The detailed authentication process, compared with the basic web authentication process shown in the foregoing Figure 4 In the
[0152] Problem points of cross-three-layer web authentication:
[0153] The above cross-three-layer web authentication cannot be used in the case of SLAAC. The specific reasons are as follows:
[0154] 1. When a dual-stack terminal performs the first IPv4 authentication and then makes the first egress access with the IPv6 address obtained by SLACC, since the terminal has not accessed external network resources using the IPv6 address yet, there is no record of this IPv6 address in NAS, and NAS cannot directly obtain the relevant information of the terminal through layer-2 information. Therefore, this IPv6 address does not exist in NAS's MAC-IP binding table, and at this time, the terminal must perform authentication for the second time.
[0155] 2. When a dual-stack terminal performs the first authentication with IPv6, although NAS has already stored the terminal's IPv6 address, due to the nature of the SLACC mechanism, the terminal's MAC address is not sent to NAS, and NAS cannot directly obtain the relevant information of the terminal through layer-2 information. Therefore, NAS cannot store the MAC address. Therefore, when the terminal makes an egress access with IPv4 again, it still needs to perform re-authentication for the second time.
[0156] 3. When the terminal connects to the network for the first time, it usually sends HTTP packets. When communicating with an application on the Internet, for privacy reasons, the terminal will use a newly generated IPv6 address to communicate with the application. At this time, the packet used for communication with the application may not necessarily be an HTTP packet; it could be a TCP, UDP packet, etc. Therefore, after the terminal's IPv6 authentication is successful, if the terminal's IPv6 address changes midway and it communicates with the new address, since the later changed IPv6 address will not use the HTTP packet for the first communication, it will not be possible to trigger the HTTP redirection of the NAS for re - authentication.
[0157] Conclusion: When the terminal uses the IPv6 address obtained by SLAAC for dual - stack authentication, it will result in two authentications, and when the IPv6 changes later, it will also cause the new IPv6 address to be unable to communicate with the external network.
[0158] Based on the Web cross - layer three - layer authentication process, for the terminal to be able to achieve the above - mentioned web authentication, it must support DHCP and DHCPv6. Most terminals support DHCP. From the research of the current mainstream operating systems as shown in Table 1 below, it can be seen that wireless Android terminals do not support DHCPv6 and only support SLAAC. Other operating systems can support both DHCPv6 and SLAAC. Therefore, when deploying cross - layer three - layer authentication for dual - stack terminals, wireless Android terminals will not be able to meet the business requirements.
[0159] Table 1: IPv6 Support Status of Mainstream Operating Systems
[0160]
[0161] In the relevant solutions for dual - stack terminal authentication, the SLAAC ND entries of wireless Android terminals can be synchronized to the NAS on the AC (Access Controller) to solve the problem that the NAS cannot obtain the binding relationship between the terminal's MAC address and the SLAAC IPv6 address.
[0162] There are mainly several problems with this solution:
[0163] 1. To synchronize the ND entries on the AC, it is necessary to forcibly bundle the AC product.
[0164] 2. In the wired scenario, other terminals also need to support SLAAC (most dual - stack terminals will be configured with DHCPv4 IPv4, DHCPv6 IPv6, and SLAAC IPv6 addresses at the same time). If it is only implemented on the AC, the SLAAC addresses of terminals in the wired scenario will not support cross - layer three - layer authentication.
[0165] In the related art, when users encounter the situation of deploying SLAAC in scenarios, the following centralized avoidance solutions are mainly adopted:
[0166] 1. Deploy wireless and wired terminals separately. For wired terminals, deploy DHCP and DHCPv6 for cross-layer three authentication, and for wireless terminals, only deploy DHCP and do not deploy DHCPv6.
[0167] 2. Some users enable dual-stack for both wired and wireless terminals, but do not authenticate the IPv6 addresses, and access to the egress resources can be released.
[0168] 3. Some users enable dual-stack for both wired and wireless terminals, but publicize to users that IPv6 address Internet access for wireless Android terminals is not supported.
[0169] It can be seen that the above related solutions cannot solve the problem that the terminal cannot achieve cross-layer three web authentication for obtaining the IPv6 SLAAC address in wired and wireless scenarios.
[0170] To solve the above problems, an information transmission solution is provided in an embodiment of the present application. When receiving an access request from a target terminal to a target network, look up the target MAC address bound to the current IP address of the target terminal in a preset relationship library, and determine whether there is an already authenticated IP address among the bound IP addresses corresponding to the target MAC address. If there is an authenticated IP address corresponding to the MAC address of the target terminal, it means that the target terminal has passed the permission authentication and can be directly released to allow access to the target network. Among them, the preset relationship library is established based on the binding relationship between the MAC addresses and corresponding IP addresses of at least one terminal synchronized by the network controller. In this way, it is ensured that for the same terminal, after one permission authentication, different IP addresses can be used to access the target network resources, improving the network resource utilization rate and the user experience.
[0171] The following will describe in detail some embodiments of the present application with reference to the accompanying drawings. Without conflict between the embodiments, the embodiments and the features in the embodiments can be combined with each other. In addition, the step timing in the following method embodiments is only an example and is not strictly limited.
[0172] Please refer to Figure 6A , which is an information transmission system 600 according to an embodiment of the present application, including: a network controller and a network access server NAS, where:
[0173] The network controller is used to respond to an IP address configuration event requested by a user through a target terminal, obtain the binding relationship between the current IP address of the target terminal and the target MAC address of the target terminal, and synchronize the binding relationship to the network access server NAS to instruct NAS to issue a pass-through policy for the target terminal to the router according to the binding relationship.
[0174] The NAS is used to receive the binding relationship between the target MAC address and the current IP address sent by the network controller. And in response to an access request sent by the target terminal to the target network using the current IP address, determine that the MAC address bound to the current IP address is the target MAC address according to the binding relationship, and allow the target terminal to access the target network using the current IP address when there is an authenticated IP address among the bound IP addresses corresponding to the target MAC address.
[0175] Please refer to Figure 6B , which is a specific deployment topology schematic diagram of the information transmission system 600 according to an embodiment of the present application. Taking the topology model diagram of the IPv6-based SLAAC cross-layer authentication scheme as an example, and taking the SDN controller as an example for the network controller, where:
[0176] The egress router deploys the NAS, DHCP Server, and DHCPv6 Server to connect the IPv6 line and the IPv4 line. The gateway enables SLAAC and deploys DHCP Relay and DHCPv6 Relay. The Radius and Portal servers are used for Web authentication. The network controller SDN controller can be used as a visual centralized authentication and management control in the authentication scheme. In the embodiment scheme of the present application, the SDN controller also serves as a third-party component to collect the ND or ND Snooping entry information of the entire network and synchronize the IP-MAC relationship table (mainly the SLAAC address information of the terminal) of the authenticated terminal to the NAS. Among them, ND Snooping: is a security feature for IPv6 ND and is used in the layer 2 switching network environment. By listening to the neighbor solicitation message NS (Neighbor Solicitation) of the user's duplicate address detection DAD (Duplicate Address Detection) process, the NDSnooping dynamic binding table is established, thereby recording information such as the source IPv6 address, source MAC address, belonging VLAN, and ingress port of the message to prevent subsequent ND message attacks by spoofing users and spoofing gateways. The access device (i.e., Figure 6B the access switch in) enables the SAVI (Source Address Validation Improvements) function to verify the validity of the source address, prevent terminal IP address spoofing attacks, and ensure the accuracy of the IP-MAC relationship table received by the NAS. Additionally, other devices may also be included, such as other servers and firewalls.
[0177] In this embodiment, in this scenario, the wired terminal enables dual-stack and simultaneously obtains DHCP IPv4, DHCPv6 IPv6, and SLAAC IPv6 addresses. The IOS system of the wireless terminal obtains DHCP IPv4, DHCPv6 IPv6, and SLAAC IPv6 addresses. The Android system of the wireless terminal obtains DHCP IPv4 and SLAAC IPv6 addresses.
[0178] As Figure 6C shown, the core principle of the SAVI function is to establish a source address-based binding relationship on the access device, so as to determine the validity of the source address of the packet received from the specified port of the access device. Taking the switch S1 as the access device as an example, it can be specifically as follows:
[0179] 1. Host A receives the RA advertisement from switch S1 and automatically generates an IPv6 address after obtaining the prefix.
[0180] 2. After host A automatically generates the address, it sends a DAD NS duplicate address check packet. If the switch does not receive a response within the specified time, an IPv6+MAC+PORT (port)+VLAN binding relationship is established.
[0181] 3. ND packets without binding information will not be forwarded.
[0182] If the access device in some scenarios does not support the SAVI function, the gateway can be docked with the SDN controller to only synchronize the ND entries. However, since SLAAC is usually constructed by the terminal itself, it is more likely to cause IP address spoofing and being attacked. Therefore, in the solution of this application embodiment, the access device synchronizes the ND Snooping entries to the SDN controller. If the gateway is directly connected to the terminal, it also needs to enable the SAVI function to perform entry synchronization. This solution is more compatible with the requirements of different customer scenarios.
[0183] Figure 6B The dotted arrow in
[0184] represents the interaction based on the Netconf protocol. Introduction to the Netconf protocol:
[0185] 1. Security transport layer
[0186] Netconf stipulates that a secure encryption channel is required, such as SSH, TLS, etc. Currently, SSH (TCP port 830 for the SDN controller to connect to the device side) is generally used.
[0187] 2. Message layer (PRC layer)
[0188] The RPC layer provides a mechanism independent of the transport protocol and defines three types of message: hello, rpc, rpc-reply, and notification. Hello completes the exchange of client & server session establishment capabilities. Rpc completes the encapsulation of request and response data. Notification completes message notification in a subscription manner.
[0189] 3. Operation layer
[0190] Netconf comprehensively defines nine basic operations. Get and get-config are used to obtain values from the device. Edit-config, copy-config, and delete-config are used to configure device parameters. Lock and unlock are lock behaviors to prevent confusion caused by concurrency during device operations. Close-session and kill-session end a session.
[0191] 4. Content layer
[0192] Netconf uses YANG to model data and uses XML to transmit data.
[0193] Please refer to Figure 7A which is the information transmission method of an embodiment of this application. This method can be executed by the electronic device 1 shown in Figure 1 and can be applied to the application scenario of the communication system shown in Figures 2 - 6C to achieve that for the same terminal, after one permission authentication, different IP addresses can be used to access target network resources, improving network resource utilization and user experience. Taking the network access server NAS as the execution end in this embodiment, the method includes the following steps:
[0194] Step 701: In response to an access request sent by the target terminal to the target network using the current IP address, determine the target MAC address bound to the current IP address according to the preset relationship library.
[0195] In this step, the preset relationship library includes the binding relationships between the MAC addresses and the corresponding IP addresses of at least one terminal, and the binding relationships are obtained by the network controller through synchronization. Taking the SDN controller as an example of the network controller, when a target terminal applies for an IP address to access the network, the SDN obtains in real time the binding relationship between the IP address and the MAC address of the target terminal and synchronizes it to the NAS. For example, the binding relationship can be represented in the form of an ND Snooping entry. Based on the ND Snooping entry synchronized by the SDN, the NAS adds the ND Snooping entry of the target terminal to the preset binding relationship library.
[0196] The target terminal refers to the terminal that initiates an access request. For example, it can be the user's mobile phone. When receiving an access request initiated by the target terminal to the target network using the current IP address, the NAS searches for the target MAC address of the terminal in the binding relationship library based on the ND Snooping entry synchronized by the SDN.
[0197] In one embodiment, the access device supporting the SAVI function can be used to monitor the ND or ND Snooping entry information of the entire network, generate the binding relationship of the IP+MAC+port Snooping entry, and issue a hardware execution filtering policy (to prevent terminal IP address spoofing). At the same time, the newly generated ND Snooping entry is synchronized to the SDN controller in real time.
[0198] In one embodiment, the gateway device supporting the SAVI function can also be used to monitor the ND entry information and synchronize it to the SDN controller.
[0199] In one embodiment, the IP-MAC binding data stored in the preset relationship library of the NAS can be in the form of an IP+MAC storage table as Figure 7B shown. For the authenticated terminal and the unauthenticated terminal, the IP and MAC information of the authenticated terminal or unauthenticated terminal obtained through the Option of DHCP and DHCPv6 can be directly cached locally. The IP+MAC information of the SLAAC terminal synchronized by the controller is filtered or passed through by the controller, and the NAS database is compatible and supported. For example, multiple IP addresses of the same terminal (authenticated terminal or unauthenticated terminal) and the configuration protocols followed by each IP address can be bound under the MAC address of the terminal. Figure 7B Taking the example of binding 4 IP addresses to the MAC address of one terminal, the IPv4 address is bound to the DHCP protocol, the IPv6 address 1 is bound to the DHCPv6 protocol, the IPv6 address 2 is bound to the SLAAC protocol, and the IPv6 address 3 is bound to the SLAAC protocol.
[0200] Step 702: Determine whether there is an authenticated IP address among the bound IP addresses corresponding to the target MAC address. If so, proceed to Step 703; otherwise, proceed to Step 704.
[0201] In this step, using the MAC address as the key, determine whether there is an authenticated IP address among the bound addresses corresponding to the target MAC address. Assume that the bound IP addresses corresponding to the target MAC address include: the IPv4 address of the target terminal, the DHCPv6 IPv6 address, and the SLAAC IPv6 address. Then determine whether there is an authenticated IP address among them. As long as there is an authenticated IP address, it indicates that the target terminal has passed the permission authentication, and proceed to Step 703; otherwise, proceed to Step 704.
[0202] Step 703: Allow the target terminal to access the target network.
[0203] In this step, if there is an authenticated IP address among the bound IP addresses, it indicates that the target terminal has passed the permission authentication and can be directly released to allow access to the network. A pass-through policy regarding the target terminal can be sent to the egress router. In this way, with one authentication, multiple IP addresses of the terminal can communicate with the external network.
[0204] Step 704: Perform permission authentication on the terminal based on the current IP address.
[0205] In this step, if during the process of the terminal applying for the current IP address, after the SDN detects the MAC + current IP binding relationship of the terminal, it will be automatically synchronized to the NAS without filtering. When the terminal later accesses the external network using this current IP address, the NAS will find that this current IP address already exists for the target MAC address. However, there is no authenticated IP address under this target MAC address, indicating that the terminal corresponding to this target MAC address has not passed the permission authentication and it is determined that the terminal is accessing for the first time. Therefore, if there is no authenticated IP address among the bound IP addresses, it is determined that the terminal is accessing for the first time and has not been authenticated, then the terminal is forced to perform permission authentication using the current IP address. Assume the current IP address is the SLACC IPv6 address. Taking web authentication as an example, the NAS forces the target terminal to perform web authentication using the SLACC IPv6 address. In one embodiment, the specific process of the authentication process may include: the target terminal initiates a web authentication, sends an HTTP message to the NAS, the NAS redirects the HTTP message to the Portal server, the Portal interacts with the terminal for the account and password, and then sends it to the NAS for an authentication request. The NAS then sends the authentication request to the Radius server, and the Radius server authenticates and returns the result. The NAS returns the authentication result to the terminal through the Portal and issues an execution policy to the egress router for authentication and release.
[0206] For example, after the terminal completes web authentication using the SLACC IPv6 address for the first time, the NAS can establish an authentication information database for MAC + IPv6 addresses in combination with the ND entries synchronized by the controller. For the new IPv4 address and DHCPv6 IPv6 address applied for by the terminal subsequently, the authentication information database can be added through the message attributes of the Relay.
[0207] Step 705: After the terminal successfully passes the permission authentication, send a pass-through policy for the target terminal to the router.
[0208] In this step, after the target terminal successfully passes the web authentication, the execution policy is sent to the egress router for authentication and release.
[0209] In one embodiment, after step 705, it may further include:
[0210] Step 706: Send the binding relationship between the current IP address and the target MAC address to the network controller to inform the network controller that the terminal corresponding to the target MAC address has passed the permission authentication.
[0211] In this embodiment, after the target terminal that accesses the external network for the first time successfully passes the web authentication, the NAS can synchronize the binding relationship between the newly added current IPv6 address and the target MAC address to the SDN controller to inform the SDN that the terminal corresponding to the target MAC address has passed the permission authentication based on the current IPv6 address, so that the SDN controller discovers the newly added authenticated terminal, and the SDN controller backs up the IP and MAC address binding relationship of the newly added authenticated terminal. So that in the case where the SDN controller enables the filtering function subsequently, the filtering of invalid information synchronization can be performed according to the above binding relationship, that is, when the SDN subsequently receives a new IP address related to the MAC address that has passed the above authentication, the new IP address + MAC address can be synchronized to the NAS in a timely manner.
[0212] In one embodiment, before determining the target MAC address bound to the current IP address according to the preset relationship library, the method further includes: when there is no target MAC address bound to the current IP address in the preset relationship library and the current IP address is not authenticated, perform permission authentication on the terminal according to the current IP address; after the terminal successfully passes the permission authentication, send the authenticated current IP address to the network controller; receive the MAC address corresponding to the current IP address returned by the network controller, send a pass-through policy for the target terminal to the router, and bind the relationship between the current IP address and the MAC address in the preset relationship library.
[0213] In a possible embodiment, if the target MAC address bound to the current IP address does not exist in the NAS and the current IP address is not an authenticated IP address, it may be because the network controller SDN end has configured a filtering synchronization policy, that is, the IP+MAC binding relationship of unauthenticated terminals will not be immediately synchronized to the NAS but cached in the SDN. At this time, it can be determined that the terminal is accessing for the first time and has not been authenticated. Then the NAS forces the terminal to perform permission authentication using the current IP address. Assuming the current IP address is the SLACC IPv6 address, taking web authentication as an example, the NAS forces the target terminal to perform web authentication using the SLACC IPv6 address. After the target terminal successfully passes the web authentication, the NAS issues a pass-through policy for the target terminal to the router, and the NAS can synchronize the newly authenticated current IPv6 address to the SDN controller, so that the SDN controller can discover the MAC address of the corresponding newly authenticated terminal based on the current IPv6 address. The SDN controller backs up the binding relationship between the current IP address and the MAC address of the newly authenticated terminal for filtering invalid information synchronization. If the SDN controller has locally cached the IP+MAC binding relationship of the newly authenticated terminal, the SDN can synchronize the IP+MAC binding relationship of the newly authenticated terminal to the NAS, and the NAS uniformly adds the IP+MAC binding relationship of the newly authenticated terminal to the preset binding relationship library, which is convenient for the subsequent NAS to implement the functions of terminal single authentication and dual-stack pass-through.
[0214] For the above information transmission method, when receiving an access request from a target terminal to a target network, look up the target MAC address bound to the current IP address of the target terminal in the preset relationship library, and determine whether there is an already authenticated IP address among the binding IP addresses corresponding to the target MAC address. If there is an authenticated IP address corresponding to the MAC address of the target terminal, it means that the target terminal has passed the permission authentication and can be directly released to allow access to the target network. The preset relationship library is established based on the binding relationship between the MAC addresses of at least one terminal synchronized by the network controller and the corresponding IP addresses. In this way, it is ensured that for the same terminal, after one permission authentication, it can access the target network resources using different IP addresses, improving the network resource utilization rate and the user experience.
[0215] Please refer to Figure 8A , which is the information transmission method of an embodiment of the present application. This method can be executed by the Figure 1 electronic device 1 shown in the figure and can be applied to the application scenario of the communication system shown in Figures 2 - 6C to achieve that for the same terminal, after one permission authentication, it can access the target network resources using different IP addresses, improving the network resource utilization rate and the user experience. In this embodiment, taking the network controller SDN as the execution end as an example, the method includes the following steps:
[0216] Step S01: In response to an IP address configuration event of a target terminal, obtain the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal.
[0217] In this step, the IP address configuration event of the target terminal may be an event in which the target terminal requests an IP address from an access device or a gateway device. The first IP address is the IP address currently configured by the target terminal. Taking the IPv6 SLAAC cross-layer authentication process of the target terminal as an example, the target terminal sends an RS request message to the gateway, and the gateway replies with an RA advertisement, carrying relevant parameter information such as a prefix. The target terminal initiates DAD detection. If there is no conflict, it generates a SLAAC IPv6 address. In response to this IP address configuration event, the SDN obtains the binding relationship "IPv6 address + MAC" between the current IPv6 address (i.e., the first IP address) of the target terminal and the target MAC address of the target terminal.
[0218] In one embodiment, step S01 may specifically include: obtaining the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal through the access device of the target terminal, and the access device is deployed with an active address verification function.
[0219] In this embodiment, the access device (such as an access switch) supporting the SAVI function can be used to listen to the whole network ND or ND Snooping entry information. The access device enables the SAVI function, listens to ND messages such as RS, RA, and DAD, generates the Snooping entry binding relationship of IP+MAC+port, and issues a hardware execution filtering policy to prevent terminal IP address spoofing. At the same time, the newly generated ND Snooping entry is synchronously sent to the SDN controller in real time.
[0220] In one embodiment, step S01 may specifically include: obtaining the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal through the gateway device of the target terminal, and the gateway device is deployed with an active address verification function.
[0221] In this embodiment, the gateway device supporting the SAVI function can also be used to listen to the ND entry information. The gateway device enables the SAVI function, listens to ND messages such as RS, RA, and DAD, generates the Snooping entry binding relationship of IP+MAC+port, and issues a hardware execution filtering policy to prevent terminal IP address spoofing. At the same time, the newly generated ND Snooping entry is synchronously sent to the SDN controller in real time.
[0222] For example, the gateway device can synchronize the ND entries (to prevent congestion and resource waste caused by the synchronization of invalid gateway ND entries across the entire network) in the VLAN that needs to enable web cross-three-layer authentication to access the external network to the controller through Netconf. The gateway device synchronizes the newly generated ND to the controller in real time to ensure that the terminal can communicate in real time when the IPv6 address changes. The aged ND entries can be synchronized periodically to reduce the amount of real-time synchronization data. For example, the real-time synchronization performance of a single device can be 400 per second.
[0223] Step S02: Send the binding relationship to the Network Access Server (NAS).
[0224] In this embodiment, the SDN monitors the IP address configuration event of the terminal, and synchronizes the binding relationship between the monitored terminal MAC address and the IP address to the NAS, so as to instruct the NAS to issue a pass-through policy for the target terminal to the router according to the binding relationship, and solve the problem that the NAS cannot obtain the terminal MAC address.
[0225] The pass-through policy issued here includes two situations: Situation 1, the target terminal has not performed any IP address authentication before. At this time, the target terminal needs to perform the first IP address authentication, and at the same time, determine the MAC address corresponding to the IP address according to the binding relationship synchronized by the SDN, and complete the pass-through; Situation 2, the target terminal has performed IP address authentication before, and the binding relationship between the authenticated IP address and its own MAC address is stored in the preset relationship library. At this time, after receiving the new binding relationship between the IP address and the MAC address sent by the SDN, it can determine the previously authenticated IP address with the MAC address as the key, so as to judge that the new IP address is also legally passable.
[0226] In one embodiment, step S02 may specifically include: when it is determined that the target terminal has passed the permission authentication, send the binding relationship to the Network Access Server (NAS).
[0227] In this embodiment, the SDN can filter the current binding relationship. Here, the filtering means that only when it is determined that the target terminal has passed the permission authentication, the SDN will send the above binding relationship to the Network Access Server (NAS). This avoids wasting resources caused by blindly synchronizing ND Snooping entries to the NAS.
[0228] In one embodiment, the following method can be used to determine whether the target terminal has passed the authentication, which may include:
[0229] Method 1: Receive the first terminal information sent by the NAS; wherein, the first terminal information carries a first IP address, and the first IP address is used to indicate that the target terminal has passed the permission authentication. Or,
[0230] Method 2: Receive the second terminal information sent by the NAS; and determine that the MAC address corresponding to the second IP address carried in the second terminal information is the target MAC address; where the second IP address is used to indicate that the target terminal corresponding to the target MAC address has passed the permission authentication. Here, the second IP address may be the IP address received by the SDN before receiving the first IP address.
[0231] If the SDN enables the filtering function, when the target terminal has not passed the authentication, the binding relationship obtained in step S01 can be cached. When receiving the first terminal information or the second terminal information sent by the NAS, it indicates that the target terminal has passed the permission authentication. At this time, the binding relationship between the first IP address and the target MAC address can be sent to the NAS. In this way, it is possible to avoid wasting resources caused by blindly synchronizing the ND Snooping entries to the NAS.
[0232] In the above information transmission method, when the target terminal applies for an IP address to access the network, the SDN can obtain the binding relationship between the current IP address of the target terminal and the target MAC address of the target terminal in real time, and synchronize the binding relationship corresponding to the target terminal to the network access server NAS, so as to instruct the NAS to issue a pass-through policy for the target terminal to the router according to the binding relationship, ensuring that for the same terminal, after passing the permission authentication once, it can use different IP addresses to access the target network resources, improving the network resource utilization rate and the user experience.
[0233] Please refer to Figure 8B , which is the information transmission method of an embodiment of the present application. This method can be executed by Figure 1 the electronic device 1 shown, and can be applied to the application scenario of the communication system shown in Figures 2 - 6C to achieve that for the same terminal, after passing the permission authentication once, it can use different IP addresses to access the target network resources, improving the network resource utilization rate and the user experience. In this embodiment, taking the network controller SDN as the execution end and the SDN enabling the filtering function as an example, the method includes the following steps:
[0234] Step 801: In response to the IP address configuration event of the target terminal, obtain the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal.
[0235] Step 802: Determine whether the target terminal has passed the permission authentication. If so, go to step 803; otherwise, go to step 804.
[0236] In this step, the SDN controller obtains the ND Snooping entries of the terminals applying for IP addresses in real time, and filters the obtained ND Snooping entries. If the MAC corresponding to the ND Snooping entry is that of a terminal that has passed the permission authentication, go to step 803; otherwise, go to step 804.
[0237] In one embodiment, step 802 may specifically include: receiving the authenticated first terminal information sent by the NAS, and determining whether there is a first IP address in the first terminal information. When there is a first IP address in the first terminal information, it is determined that the target terminal has successfully passed the permission authentication. Furthermore, the SDN controller may determine the MAC address corresponding to the target terminal as the target MAC address according to the first IP address and the binding relationship. In this embodiment, the SDN controller filters the currently synchronized ND Snooping entries of the access device based on the authenticated terminal information synchronized by the NAS. The SDN controller compares the currently synchronized ND Snooping entries with the authenticated ND Snooping entries synchronized by the NAS. For the case where the terminal accesses the external network for the first time, if the first IP address is already in the authenticated ND Snooping entries, or for the case where the terminal is not accessing the external network for the first time, if it is found after SDN filtering that the target MAC address of the target terminal is already in the authenticated ND Snooping entries, it indicates that the target terminal has passed the authentication.
[0238] For example, the SDN filtering situation: If a terminal applies for IP address 1, the SDN detects IP address 1 and the terminal MAC address; the SDN filters and analyzes and finds that the terminal is not authenticated, and caches the binding relationship IP address 1 + MAC address. The terminal uses IP address 1 to access the external network. The NAS finds that the terminal accesses the external network for the first time and forces the terminal to authenticate based on IP address 1. After the authentication of IP address 1 passes, the NAS releases the terminal and sends the authenticated information of IP address 1 to the SDN. The SDN finds that IP address 1 is authenticated and synchronizes IP address 1 + MAC address to the NAS. If the terminal is not accessing the external network for the first time, the SDN filters and analyzes and finds that there is already a MAC address + IP address 2 (authenticated), then directly sends MAC + IP address 1 to the NAS.
[0239] In addition, if the current IP address does not exist in the authenticated ND Snooping entries, it indicates that the target terminal has not passed the permission authentication.
[0240] Step 803: Synchronize the binding relationship to the network access server NAS to instruct the NAS to issue a pass-through policy for the target terminal to the router according to the binding relationship.
[0241] In this step, when it is determined that the target terminal has passed the permission authentication according to the target MAC address, that is, the NAS stores the previously authenticated IP address of the target terminal + the target MAC address information. At this time, the SDN synchronizes the new IP address (i.e., the first IP address) + the target MAC binding relationship to the NAS. The NAS can use the same target MAC as the key to determine that the target terminal is an authenticated terminal, so that the NAS can perceive the changes in the IPv6 address and MAC address information of the effective terminal SLAAC, and issue a pass-through policy for the target terminal to the router, allowing the target terminal to access the target network.
[0242] In one embodiment, the SDN controller manages the gateway devices and NAS devices of the entire network, receives the ND entry information synchronized by the gateway devices of the entire network, and synchronizes the new ND entries to the NAS in real time. The aged entries can be synchronized periodically.
[0243] In one embodiment, the gateway device can generate the ND entries or ND Snooping entries of the SDN controller. The NAS device receives the ND or ND Snooping entries of the SDN controller as the authentication basis, and according to the IPv6 address and MAC address information in the ND entries, joins / creates an authenticated terminal database, uses the MAC address as the key, and binds the IPv4 address, DHCPv6 IPv6 address, and SLAAC IPv6 address of the terminal, so that one authentication can enable the three types of addresses of the terminal to communicate externally at the same time.
[0244] Step 804: If the target terminal fails to pass the permission authentication, cache the current binding relationship of the target terminal. Then go to step 805.
[0245] In this step, the SDN controller filters the current ND Snooping entries synchronized by the access device or gateway device based on the authenticated terminal information synchronized by the NAS. If the target MAC address corresponding to the current ND Snooping entry has not passed the permission authentication, the IP+MAC binding information can be saved and not synchronized to the NAS temporarily. This avoids wasting resources caused by blindly synchronizing the ND Snooping entries to the NAS.
[0246] Step 805: Receive the information of the third terminal with new authentication sent by the NAS. Then go to step 806.
[0247] In this step, if the target terminal fails to pass the permission authentication, the target terminal may be accessing for the first time, and the NAS needs to force it to perform web authentication. The process of web authentication can refer to the description of step 704 in the foregoing embodiment.
[0248] Assume that when the target terminal accesses the external network for the first time, it accesses the network using the current IPv6 address (e.g., the third IP address). After the target terminal successfully passes the web authentication based on the current IPv6 address, the NAS can synchronize the newly authenticated current IPv6 address (i.e., the newly authenticated third terminal information, which may include the newly authenticated ND Snooping entry) to the SDN controller, and the SDN controller receives the newly authenticated ND Snooping entry.
[0249] Step 806: Determine whether the target terminal has passed the authentication according to the third terminal information. If it has passed, go to Step 807.
[0250] In this step, the SDN controller determines whether the MAC address corresponding to the third IP address is the target MAC address. If it is, it means that the target terminal has passed the authentication and go to Step 807. Otherwise, it means that the target terminal still has not passed the permission authentication.
[0251] Step 807: Determine that the target terminal has successfully passed the permission authentication, and synchronize the current binding relationship of the target terminal to the NAS.
[0252] In this step, when it is determined according to the third terminal information that the target terminal has passed the authentication, the SDN can synchronize the IP+MAC binding relationship related to the target terminal to the NAS, and the NAS uniformly adds the IP+MAC binding relationship of the newly authenticated terminal to the preset binding relationship library, which is convenient for the subsequent NAS to implement the functions of terminal one-time authentication and dual-stack release.
[0253] In an embodiment, in the related art, after the IPv6 address authentication under the SLAAC mechanism, the NAS cannot directly obtain the MAC address of the terminal. In this embodiment, the SDN can synchronize the terminal MAC address to the NAS. When a new terminal that accesses the network for the first time uses the new IPv6 address 1 under the SLAAC mechanism to access the network, the NAS will force it to perform web authentication. If the SDN side adopts the policy of synchronizing after filtering the binding relationship, there is still no MAC address of this terminal in the NAS after authentication. The NAS synchronizes the IPv6 address 1 to the SDN, and the SDN can detect the binding relationship between the MAC of the terminal and the IPv6 address 1, and then synchronize the binding relationship to the NAS, so that the NAS will have the MAC of this terminal.
[0254] In one embodiment, the NAS receives the IP+MAC binding information synchronized by the SDN controller and adds it to the generated total IP+MAC binding table. The MAC addresses in this total table correspond to the authenticated terminals, and the IP includes DHCP IPv4 and DHCPv6 IPv6 address information, as well as the newly added SLAAC IPv6 address information. When the SLACC IPv6 address of the terminal changes, the gateway device or the access device monitors and generates a new ND Snooping entry, which is then synchronized to the SDN controller in real time. The SDN controller verifies that the MAC belongs to an authenticated user, synchronizes the IP+MAC binding information to the NAS, and the NAS adds it to the total IP+MAC binding information table (i.e., the preset binding relationship library), and newly distributes the changed SLAAC IPv6 address information to the egress router to execute the pass-through policy, allowing the new address to communicate with the external network.
[0255] In the above information transmission method, when a target terminal applies for an IP address to access the network, the SDN can obtain the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal in real time, filter the binding relationship, and determine whether the target terminal has passed the permission authentication based on the binding relationship. For the target terminal that has passed the permission authentication, the SDN synchronizes the corresponding binding relationship to the network access server NAS, so as to instruct the NAS to issue a pass-through policy for the target terminal to the router according to the binding relationship, ensuring that for the same terminal, after one permission authentication, different IP addresses can be used to access the target network resources, improving the network resource utilization rate and the user experience.
[0256] As Figure 9A shown, it is an interactive signaling schematic diagram of the information transmission method according to an embodiment of the present application. This method can be executed by the interaction of each device in the Figure 6B communication system shown, so as to achieve that for the same terminal, after one permission authentication, different IP addresses can be used to access the target network resources, improving the network resource utilization rate and the user experience. In this embodiment, taking the scenario of the IPv6 SLAAC cross-layer authentication process of the terminal as an example and taking the synchronization of the ND Snooping entry by the access device as an example, the method includes the following steps:
[0257] Step 901: The terminal applies for an IPv6 address and sends an RS request message to the access device.
[0258] Step 902: The access device broadcasts the RS to the gateway.
[0259] Step 903: The gateway responds and sends an RA advertisement to the access device. The RA advertisement carries relevant parameter information such as prefixes.
[0260] Step 904: The access device broadcasts the RA to the terminal.
[0261] Step 905: The terminal starts DAD detection. If there is no conflict, it generates a SLAAC IPv6 address.
[0262] Step 906: The access device with the SAVI function enabled listens to ND packets such as RS, RA, and DAD, generates the binding relationship of the Snooping entry of IP+MAC+port, and issues a hardware execution filtering policy to prevent spoofing of the terminal IP address.
[0263] Step 907: The access device synchronizes the newly generated ND Snooping entry to the SDN controller in real time.
[0264] Step 908: The NAS synchronizes the authenticated terminal information to the SDN. The execution order of Step 908 and Step 907 is only an example, and the embodiments of the present application do not limit the execution order of the two.
[0265] Step 909: Based on the authenticated terminal information synchronized by the NAS, the SDN controller filters the ND Snooping entries synchronized by the access device. If the MAC corresponding to the Snooping entry is an authenticated terminal, it synchronizes the IP+MAC binding relationship to the NAS. If the MAC terminal corresponding to the Snooping entry has not passed authentication, it saves the IP+MAC binding relationship and does not synchronize it to the NAS temporarily.
[0266] Step 910: The NAS receives the IP+MAC binding information synchronized by the SDN controller, and based on the existing IP-MAC binding relationships synchronized by DHCP and DHCPv6 Option, adds it to the total SLAAC-generated IP+MAC binding table. The MAC address of this total table corresponds to the authenticated terminal, and the IP address types include DHCP IPv4 and DHCPv6 IPv6 address information, as well as the newly added SLAAC IPv6 address information. After the total table changes, it issues an execution policy to the NAS hardware egress router to allow the authenticated SLAAC address terminal.
[0267] Step 911: Any terminal A initiates a web authentication and sends an HTTP communication packet to the NAS.
[0268] It should be noted that Step 910 is the execution step of the NAS, and Step 911 is the execution step of terminal A. In the actual scenario, the execution processes of Step 910 and Step 911 can be carried out independently. The step numbers are only examples, and the embodiments of the present application do not limit the execution order of Step 910 and Step 911. For example, in the actual scenario, there may be multiple terminals accessing the external network at the same time. At the same time, a new terminal can initiate authentication, and the NAS can also receive the binding relationships of other terminals synchronized by the SDN at the same time.
[0269] Step 912: Assume that terminal A accesses the external network for the first time. At this time, the IP+MAC binding relationship synchronized by the SDN controller to the NAS in step 909 does not involve terminal A, and terminal A needs to be authenticated. That is, the NAS redirects the HTTP packet to the Portal server.
[0270] Step 913: The web authentication server Portal pushes an authentication page to terminal A and interacts with terminal A for the account and password.
[0271] Step 914: Terminal A sends an authentication request to Portal, carrying the login account and password.
[0272] Step 915: Portal sends an authentication request to the NAS.
[0273] Step 916: The NAS then sends the authentication request to the Radius server.
[0274] Step 917: The Radius server authenticates and returns the result.
[0275] Step 918: The NAS returns the authentication result to Portal.
[0276] Step 919: Portal returns the authentication result to terminal A and issues an execution policy to the egress router for authentication and release. Terminal A can communicate normally.
[0277] Step 920: The NAS synchronizes the information of the newly authenticated terminal A to the SDN controller.
[0278] Step 921: When the SDN controller discovers the newly authenticated terminal A, it will synchronize the locally cached IP+MAC binding information to the NAS. The NAS uniformly generates an IP+MAC total table. After the SLAAC address is first authenticated, the SDN needs to supplement and synchronize the corresponding newly added IP+MAC binding relationship to the NAS. Subsequently, the NAS can implement the function of one-time authentication and dual-stack release for the terminal.
[0279] Step 922: When the SLAAC IPv6 address of terminal A changes, terminal A initiates a DAD detection to generate a new address.
[0280] Step 923: The access device listens and generates a new ND Snooping entry.
[0281] Step 924: The access device synchronizes the new ND Snooping entry to the SDN controller in real time.
[0282] Step 925: The SDN controller verifies that the terminal A corresponding to the new ND Snooping entry is an authenticated terminal, and synchronizes the new IP+MAC binding information to the NAS, so that the NAS adds it to the total IP+MAC binding information table and newly issues the changed SLAAC address information to the egress router to execute the pass-through policy.
[0283] As Figure 9B shown, it is an interaction schematic diagram of each component based on the IP-MAC binding relationship provided by the embodiment of the present application, where:
[0284] ND entry synchronization is mainly for gateway devices, including addition and deletion operations. When a gateway device newly learns an ND entry, it can synchronize the newly added ND entry to the SDN controller in real time to avoid long-term disconnection of the terminal. When the ND entry of the gateway device ages, it can wait for a preset cycle time before performing a batch deletion operation of the ND entry on the SDN controller, which can prevent timing problems caused by entry learning and aging jitter, and reduce the performance consumption of the SDN controller caused by frequent deletion operations.
[0285] ND Snoopig entry synchronization is mainly for access devices and / or gateway devices that support and enable the SAVI function. When an access device and / or gateway device newly adds an ND Snooping entry, it needs to be synchronized in real time, and when the ND Snooping entry ages, it is deleted in batches at regular intervals.
[0286] The SDN controller defines the entry synchronization types for access devices and / or gateway devices, including ND Snooping and ND entries. At the same time, based on the terminal authentication information (authenticated terminal MAC) synchronized by the NAS device in real time, it filters the IP+MAC information and synchronizes the IP+MAC of the authenticated terminal to the NAS in real time (at this time, the data information only includes the binding information of MAC and IP). If the SDN controller does not support the collection of terminal authentication information, it can directly pass through the entries synchronized by the access device and / or gateway device to the NAS.
[0287] In addition, when the NAS device detects that a terminal goes offline, it will actively delete the corresponding terminal entry. For example, it can delete the SLAAC address IP+MAC of the authenticated terminal. At the same time, the NAS device can synchronize the deletion of the authenticated terminal information to the SDN controller, such as synchronizing the deletion of the authenticated terminal MAC.
[0288] In one embodiment, in the absence of an SDN controller, if there are any third-party general components that support Netconf, ND entry, or ND Snooping entry synchronization functions, and / or can perform authentication filtering for the entry synchronization of the entire network in the NAS, the solution of the embodiment of the present application can be implemented. Therefore, the embodiment of the present application is not limited to implementing the synchronization function of the binding relationship through SDN, and has high scalability and a wider scope of application.
[0289] The above information transmission method introduces a new authentication method to solve the technical problem that terminals cannot achieve cross-layer three authentication in the case of IPv6 stateless address autoconfiguration. It has at least the following beneficial effects:
[0290] 1. Architecture innovation: A third-party component, the SDN controller, is added between the NAS and the gateway or access device, which can support SLAAC cross-layer three authentication in both wired and wireless scenarios and is not limited by AC or other product devices. Additionally, based on the existing authentication scenarios (the authentication scenario devices include access, gateway, egress router, SDN controller, etc.), the equipment cost does not need to be increased.
[0291] 2. The SDN controller can synchronize ND entries and ND Snooping entries with the gateway through the standard Netconf protocol, or synchronize ND Snooping entries with the access device through the standard Netconf protocol. Synchronizing ND Snooping can solve the problem of terminal IP address spoofing attacks, as long as the gateway or access device supports the SAVI function. This solution is based on customer scenarios, flexibly configures the docking of the gateway or access device with the SDN controller, and solves the problem of address spoofing attacks.
[0292] 3. In the authentication scenario, the SDN controller also plays the role of authentication visualization control. When synchronizing the ND or NDSnooping entries of the entire network, it can filter the IP-mac binding information based on the existing authenticated terminal information to avoid the NAS receiving too much invalid binding entry information of the entire network and affecting performance.
[0293] For the detailed steps of the above method, reference can be made to the relevant descriptions of the above embodiments, which will not be elaborated here.
[0294] Please refer to Figure 10 , which is the information transmission device 1000 of an embodiment of the present application. This device can be applied to Figure 1 the electronic device 1 shown in Figures 2 - 6C and can also be applied to the network access server NAS in the application scenario of the communication system shown in
[0295] A determination module 1001, configured to, in response to an access request sent by a target terminal to a target network using a current IP address, determine a target MAC address bound to the current IP address according to a preset relationship library, where the preset relationship library includes binding relationships between MAC addresses and corresponding IP addresses of at least one terminal, and the binding relationships are synchronously obtained by a network controller.
[0296] An allowance module 1002, configured to, when there is an authenticated IP address among the bound IP addresses corresponding to the target MAC address, allow the target terminal to access the target network.
[0297] In one embodiment, it further includes: a first authentication module, configured to, after determining the target MAC address bound to the current IP address according to the preset relationship library, and when there is no authenticated IP address among the bound IP addresses corresponding to the target MAC address, perform permission authentication on the terminal according to the current IP address; a sending module, configured to, after the terminal successfully passes the permission authentication, send a pass-through policy regarding the target terminal to a router; a storage module, configured to store the binding relationship between the target MAC address and the current IP address in the preset relationship library.
[0298] In one embodiment, it further includes: a second authentication module, configured to, before determining the target MAC address bound to the current IP address according to the preset relationship library, when there is no bound target MAC address for the current IP address and the current IP address is not authenticated, perform permission authentication on the terminal according to the current IP address; a second sending module, configured to, after the terminal successfully passes the permission authentication, send the authenticated current IP address to the network controller; a first receiving module, configured to receive the MAC address corresponding to the current IP address returned by the network controller, send a pass-through policy regarding the target terminal to the router, and store the binding relationship between the current IP address and the MAC address in the preset relationship library. For a detailed description of the above information transmission device 1000, please refer to the description of the relevant method steps in the above embodiments. Their implementation principles and technical effects are similar, and will not be elaborated here in this embodiment.
[0299] Please refer to Figure 11 which is an information transmission device 1100 according to an embodiment of the present application. This device can be applied to Figure 1 the electronic device 1 shown in Figures 2 - 6C and can be applied to a network controller SDN in the application scenario of the communication system shown in
[0300] An acquisition module 1101, configured to, in response to an IP address configuration event of a target terminal, acquire the binding relationship between the current IP address of the target terminal and the target MAC address of the target terminal.
[0301] A synchronization module 1102 is configured to synchronize the binding relationship to a Network Access Server (NAS) to instruct the NAS to issue a pass-through policy for a target terminal to a router according to the binding relationship.
[0302] In one embodiment, an acquisition module 1101 is configured to acquire the binding relationship between a first IP address of a target terminal and a target MAC address of the target terminal through an access device of the target terminal, where the access device is deployed with a source address verification function.
[0303] In one embodiment, an acquisition module 1101 is configured to acquire the binding relationship between a first IP address of a target terminal and a target MAC address of the target terminal through a gateway device of the target terminal, where the gateway device is deployed with a source address verification function.
[0304] In one embodiment, a synchronization module 1102 is configured to send the binding relationship to a Network Access Server (NAS) when it is determined that the target terminal has passed the permission authentication according to the target MAC address.
[0305] In one embodiment, it further includes: a second receiving module, configured to receive first terminal information sent by the NAS; where the first terminal information carries a first IP address, and the first IP address is used to indicate that the target terminal has passed the permission authentication; or, receive second terminal information sent by the NAS; determine that the MAC address bound to a second IP address carried in the second terminal information is the target MAC address; where the second IP address is used to indicate that the target terminal corresponding to the target MAC address has passed the permission authentication.
[0306] For a detailed description of the above information transmission device 1100, please refer to the description of the relevant method steps in the above embodiments. The implementation principles and technical effects are similar, and will not be elaborated here in this embodiment.
[0307] An embodiment of the present application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the method of any of the foregoing embodiments is implemented.
[0308] An embodiment of the present application further provides a computer program product, including a computer program, which implements the method of any of the foregoing embodiments when executed by a processor.
[0309] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules can be combined or integrated into another system, or some features can be ignored or not executed.
[0310] The integrated module implemented in the form of software function modules can be stored in a computer-readable storage medium. The above software function modules are stored in a storage medium and include several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods of various embodiments of the present application.
[0311] It should be understood that the above processor may be a central processing unit (Central Processing Unit, abbreviated as CPU), and may also be other general-purpose processors, digital signal processors (Digital Signal Processor, abbreviated as DSP), application specific integrated circuits (Application Specific Integrated Circuit, abbreviated as ASIC), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the application can be directly embodied as being executed and completed by a hardware processor, or executed and completed by a combination of hardware and software modules in the processor. The memory may include a high-speed RAM (Random Access Memory, random access memory) memory, and may also include a non-volatile storage NVM (Nonvolatile memory, abbreviated as NVM), such as at least one disk memory, and may also be a USB flash drive, a mobile hard disk, a read-only memory, a magnetic disk or an optical disc, etc.
[0312] The above storage medium may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (Static Random-Access Memory, abbreviated as SRAM), an electrically erasable programmable read-only memory (Electrically Erasable Programmable read only memory, abbreviated as EEPROM), an erasable programmable read-only memory (Erasable Programmable Read-Only Memory, abbreviated as EPROM), a programmable read-only memory (Programmable read-only memory, abbreviated as PROM), a read-only memory (Read-OnlyMemory, abbreviated as ROM), a magnetic memory, a flash memory, a magnetic disk or an optical disc. The storage medium may be any available medium accessible by a general-purpose or special-purpose computer.
[0313] An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an Application Specific Integrated Circuits (ASIC). Of course, the processor and the storage medium can also exist as discrete components in an electronic device or a master device.
[0314] It should be noted that in this document, the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including that element.
[0315] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.
[0316] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods of the various embodiments of the present application.
[0317] In the technical solution of the present application, the processing of collection, storage, use, processing, transmission, provision and disclosure of user data and other information involved all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0318] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application accordingly. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be similarly included in the patent protection scope of the present application.
Claims
1. An information transmission method, characterized in that, Applied to a Network Access Server (NAS), the method includes; In response to an access request sent by a target terminal to a target network using the current IP address, determine the target MAC address bound to the current IP address according to a preset relationship library, where the preset relationship library includes at least one binding relationship between the MAC address of a terminal and the corresponding IP address, and the binding relationship is obtained by a network controller; When there is an authenticated IP address among the bound IP addresses corresponding to the target MAC address, allow the target terminal to access the target network.
2. The method according to claim 1, characterized in that, After determining the target MAC address bound to the current IP address according to the preset relationship library, it further includes: When there is no authenticated IP address among the bound IP addresses corresponding to the target MAC address, perform permission authentication on the terminal according to the current IP address; After the terminal successfully passes the permission authentication, send a pass-through policy regarding the target terminal to the router.
3. The method according to claim 1, characterized in that, Before determining the target MAC address bound to the current IP address according to the preset relationship library, it further includes: When there is no target MAC address bound to the current IP address in the preset relationship library and the current IP address is not authenticated, perform permission authentication on the terminal according to the current IP address; After the terminal successfully passes the permission authentication, send the authenticated current IP address to the network controller; Receive the MAC address corresponding to the current IP address returned by the network controller, send a pass-through policy regarding the target terminal to the router, and store the binding relationship between the current IP address and the MAC address in the preset relationship library.
4. An information transmission method, characterized in that, Applied to a network controller, the method includes; In response to an IP address configuration event of a target terminal, obtain the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal; Send the binding relationship to a Network Access Server (NAS) to instruct the NAS to send a pass-through policy regarding the target terminal to the router according to the binding relationship.
5. The method according to claim 4, wherein The obtaining the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal includes: Through the access device of the target terminal, obtain the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal, where the access device is deployed with a source address verification function; And / or, through the gateway device of the target terminal, obtain the binding relationship between the first IP address of the target terminal and the target MAC address of the target terminal, where the gateway device is deployed with a source address verification function.
6. The method according to claim 4, wherein The sending the binding relationship to the Network Access Server (NAS) includes: When it is determined that the target terminal has passed the permission authentication, send the binding relationship to the Network Access Server (NAS).
7. The method according to claim 6, wherein The determining that the target terminal has passed the permission authentication includes: Receive the first terminal information sent by the NAS; wherein, the first terminal information carries the first IP address, and the first IP address is used to indicate that the target terminal has passed the permission authentication; or, Receive the second terminal information sent by the NAS; determine that the MAC address bound to the second IP address carried in the second terminal information is the target MAC address; wherein, the second IP address is used to indicate that the target terminal corresponding to the target MAC address has passed the permission authentication.
8. An information transmission system, characterized in that, It includes: A network controller and a network access server NAS, wherein: The network controller is configured to, in response to an IP address configuration event of a target terminal, obtain the binding relationship between the current IP address of the target terminal and the target MAC address of the target terminal; synchronize the binding relationship to the network access server NAS to instruct the NAS to issue a pass-through policy for the target terminal to the router according to the binding relationship; The NAS is configured to receive the binding relationship between the target MAC address and the current IP address sent by the network controller; and in response to an access request sent by the target terminal to a target network using the current IP address, determine that the MAC address bound to the current IP address is the target MAC address according to the binding relationship; and allow the target terminal to access the target network using the current IP address when there is an authenticated IP address among the bound IP addresses corresponding to the target MAC address.
9. An electronic device, characterized in that, It includes: At least one processor; And A memory communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to cause the electronic device to execute the method according to any one of claims 1-3 or 4-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, and when the processor executes the computer-executable instructions, the method according to any one of claims 1-3 or 4-7 is implemented.