Method and system for realizing access authentication of internal and external networks of campus broadband, and medium
Through the control-forwarding separation network architecture and MAC address binding technology, the problems of insufficient network architecture and multiple network access in the existing campus broadband internal and external network access authentication are solved, and non-perceptual multi-network access is achieved and the user process is simplified.
Patent Information
- Application Number
- CN202510866621.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-09-16
AI Technical Summary
The existing campus broadband intranet and intranet access authentication method is based on a three-layer wired network authentication using a portal server. This method suffers from insufficient network architecture evolution capabilities and an inability to implement multi-network access. This forces users to manually enter their account and password multiple times, reducing the user experience and increasing security risks.
Adopting a network architecture with separated forwarding and control, the pre-authentication domain IP address is obtained through the broadband core network user plane BNC-UP and redirected to the Portal server to enter the account and password. The Portal server binds the terminal MAC address and synchronizes it with the AAA server. Subsequent access is carried out based on the MAC address without perception of authentication, simplifying the user process.
Users only need to enter their account and password once when they first access the Internet, and no manual authentication is required for subsequent access. This enables seamless multi-network access, improving user experience and network management efficiency.
Smart Images

Figure CN120658474A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network technology, and in particular to a method, system and medium for implementing campus broadband intranet and extranet access authentication. Background Art
[0002] In traditional campus IPoE (IP over Ethernet) and Web (World Wide Web) authentication environments, users must manually enter their username and password to complete authentication each time they access the network. This process is not only cumbersome and complex, but also significantly degrades the user's online experience. Campus broadband users, in particular, often require access to both the campus network and the internet. They hope to achieve subsequent dual-domain access through a single broadband account and a single network access authentication.
[0003] Currently, multiple authentication processes are required on campus. Users need to use different accounts and passwords to access the Internet and the campus network, and each access requires re-authentication, which results in cumbersome and inefficient operations. Frequent authentication operations interrupt the user's Internet access process and reduce the user experience. Multi-account management and multiple authentications increase the complexity of network management and also increase security risks.
[0004] The existing method for realizing campus broadband intranet and extranet access authentication is mainly based on the three-layer wired network authentication of the Portal server. In the three-layer wired network authentication system, the Portal server can find out the gateway device of the terminal access and further obtain the MAC (Media Access Control, Media Access Control layer) address.
[0005] Find the matching target authentication record to achieve non-perception authentication. However, this method has
[0006] In the following question:
[0007] (1) Outdated network architecture: Existing technologies only describe how to implement non-perception authentication through access devices and gateway devices under the traditional three-layer network architecture, lacking network architecture evolution;
[0008] (2) Unable to achieve multi-network access: The existing technology only describes the user's non-perception access authentication process for accessing the Internet, which cannot meet the current campus users' demand for multi-network integrated access to the Internet and campus network at the same time. Summary of the Invention
[0009] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the existing technology and provide a method, system and medium for realizing campus broadband intranet and extranet access authentication, so as to solve the problem that the existing method for realizing campus broadband intranet and extranet access authentication is mainly based on the three-layer wired network authentication of the Portal server, which has insufficient network architecture evolution capability and cannot realize multi-network access.
[0010] In a first aspect, the present invention provides a method for implementing campus broadband intranet and extranet access authentication, the method comprising:
[0011] The broadband core network user plane (BNC-UP) obtains the pre-authentication domain Internet Protocol (IP) address assigned by the Dynamic Host Configuration Protocol (DHCP) server based on the terminal's initial access request. The pre-authentication domain IP address is used to access the Portal server.
[0012] The BNC-UP redirects the first access request of the terminal to the Portal server based on the pre-authentication domain IP address, so that the terminal pops up a Portal page for entering the campus broadband account and password;
[0013] The Portal server sends the input campus broadband account and password to the broadband core network control plane BNC-CP;
[0014] The BNC-CP obtains the post-authentication domain IP address assigned by the DHCP server after the campus broadband account and password are authenticated, and the post-authentication domain IP address is used to access the Internet or the campus network;
[0015] The BNC-CP sends the post-authentication domain IP address to the terminal, so that the terminal starts to access the Internet based on the post-authentication domain IP address;
[0016] The Portal server stores the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronizes it to the authentication, authorization and accounting AAA server;
[0017] When the terminal accesses again subsequently, the AAA server authorizes the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand.
[0018] Furthermore, the broadband core network user plane BNC-UP obtains a pre-authentication domain Internet Protocol IP address assigned by a Dynamic Host Configuration Protocol DHCP server based on the first access request of the terminal, specifically including:
[0019] The BNC-UP receives the first access request of the terminal and forwards it to the BNC-CP;
[0020] The BNC-CP sends the first access request of the terminal to the DHCP server;
[0021] The DHCP server allocates the pre-authentication domain IP address according to the first access request of the terminal and sends it to the BNC-CP;
[0022] The BNC-CP sends the pre-authentication domain IP address to the BNC-UP;
[0023] The BNC-UP receives the pre-authentication domain IP address.
[0024] Furthermore, the BNC-CP obtains the post-authentication domain IP address assigned by the DHCP server after the campus broadband account and password are authenticated, specifically including:
[0025] The BNC-CP initiates a first authentication request to the AAA server based on the campus broadband account and password;
[0026] The AAA server authenticates the campus broadband account and password based on the first authentication request;
[0027] In response to the authentication being successful, the AAA server authorizes the post-authentication domain IP address and returns an authentication successful message to the BNC-CP;
[0028] The BNC-CP notifies the DHCP server to allocate the post-authentication domain IP address based on the authentication pass message;
[0029] The DHCP server allocates the post-authentication domain IP address and sends it to the BNC-CP;
[0030] The BNC-CP receives the post-authentication domain IP address.
[0031] Furthermore, the Portal server stores the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronizes it to the authentication, authorization and accounting AAA server, specifically including:
[0032] The Portal server sends a query request to the DHCP server;
[0033] The DHCP server queries the MAC address corresponding to the terminal IP address according to the query request and returns it to the Portal server;
[0034] The Portal server binds the received MAC address to the campus broadband account and synchronizes it to the AAA server.
[0035] Furthermore, when the terminal subsequently accesses again, the AAA server authorizes the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains an Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand, specifically including:
[0036] When the terminal accesses again subsequently, the BNC-CP initiates a second authentication request to the AAA server based on the MAC address of the terminal;
[0037] The AAA server queries the MAC address of the terminal based on the second authentication request whether there is a binding relationship with the campus broadband account, and if so, determines that the authentication is successful and authorizes the post-authentication domain IP address;
[0038] The DHCP server allocates the post-authentication domain IP address so that the terminal obtains an Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet as needed.
[0039] Furthermore, each campus network corresponds to a pre-authentication domain IP address and a post-authentication domain IP address.
[0040] Furthermore, the post-authentication domain IP address is a private network address assigned by the operator, which is interconnected with the campus network routing. When accessing the Internet, the private network address is mapped to a public network address and port through network address translation NAT for access.
[0041] In a second aspect, the present invention provides a system for implementing campus broadband intranet and extranet access authentication, including a broadband core network user plane BNC-UP, a Portal server, a broadband core network control plane BNC-CP, an authentication, authorization and accounting AAA server, and a dynamic host configuration protocol DHCP server;
[0042] The BNC-UP is used to obtain the pre-authentication domain Internet Protocol IP address assigned by the DHCP server based on the first access request of the terminal, wherein the pre-authentication domain IP address is used to access the Portal server;
[0043] The BNC-UP is further configured to redirect the first access request of the terminal to the Portal server based on the pre-authentication domain IP address, so that the terminal pops up a Portal page for entering the campus broadband account and password;
[0044] The Portal server is used to send the input campus broadband account and password to the BNC-CP;
[0045] The BNC-CP is used to obtain the post-authentication domain IP address assigned by the DHCP server after the campus broadband account and password are authenticated. The post-authentication domain IP address is used to access the Internet or the campus network;
[0046] The BNC-CP is further configured to send the post-authentication domain IP address to the terminal, so that the terminal starts to access the Internet based on the post-authentication domain IP address;
[0047] The Portal server is also used to save the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronize it to the AAA server;
[0048] When the terminal accesses again subsequently, the AAA server is used to authorize the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand.
[0049] Furthermore, the BNC-UP is further configured to receive an initial access request from the terminal and forward the request to the BNC-CP;
[0050] The BNC-CP is further configured to send the first access request of the terminal to the DHCP server;
[0051] The DHCP server is used to allocate the pre-authentication domain IP address according to the first access request of the terminal and send it to the BNC-CP;
[0052] The BNC-CP is further configured to send the pre-authentication domain IP address to the BNC-UP;
[0053] The BNC-UP is further configured to receive the pre-authentication domain IP address.
[0054] In a third aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method for implementing campus broadband intranet and extranet access authentication as described in the first aspect above is implemented.
[0055] The present invention provides a method, system and medium for realizing campus broadband intranet and extranet access authentication. First, BNC-UP obtains the pre-authentication domain IP address assigned by the DHCP server based on the first access request of the terminal, wherein the pre-authentication domain IP address is used to access the Portal server; and redirects the first access request of the terminal to the Portal server based on the pre-authentication domain IP address, so that the terminal pops up a Portal page for inputting the campus broadband account and password; then the Portal server sends the input campus broadband account and password to the broadband core network control plane BNC-CP; the BNC-CP obtains the post-authentication domain IP address assigned by the DHCP server after the campus broadband account and password are authenticated. The post-authentication domain IP address is used to access the Internet or the campus network; the BNC-CP then sends the post-authentication domain IP address to the terminal, so that the terminal starts to access the Internet based on the post-authentication domain IP address; at the same time, the Portal server saves the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronizes it to the authentication, authorization and billing AAA server; finally, when the terminal accesses again subsequently, the AAA server authorizes the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand. The present invention is based on a network architecture with separated forwarding and control, so that campus broadband users only need to enter the campus broadband account and password once when they first access the Internet. There is no need to manually enter any authentication information for each subsequent network access, and the authentication process can be automatically completed, thereby realizing truly imperceptible authentication and multi-network access to the Internet and campus network, solving the problem that the existing method for realizing campus broadband intranet and extranet access authentication is mainly based on the three-layer wired network authentication of the Portal server, and there are insufficient network architecture evolution capabilities and the inability to realize multi-network access. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 A flowchart of an existing authentication method for a three-layer wired network based on a Portal server;
[0057] Figure 2 This is a flow chart of a method for implementing campus broadband intranet and extranet access authentication according to embodiment 1 of the present invention;
[0058] Figure 3 A schematic diagram of the network topology of a system for implementing campus broadband intranet and extranet access authentication according to an embodiment of the present invention;
[0059] Figure 4 This is an authentication flow chart for a user accessing the system for the first time according to an embodiment of the present invention;
[0060] Figure 5This is a flowchart of the authentication process for the second to Nth access of a user according to an embodiment of the present invention;
[0061] Figure 6 This is a structural diagram of a system for implementing campus broadband intranet and extranet access authentication according to embodiment 2 of the present invention. DETAILED DESCRIPTION
[0062] In order to enable those skilled in the art to better understand the technical solutions of the present invention, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.
[0063] It should be understood that the specific embodiments and drawings described herein are only used to explain the present invention rather than to limit the present invention.
[0064] It is understood that, in the absence of conflict, the various embodiments of the present invention and the various features in the embodiments may be combined with each other.
[0065] It can be understood that, for the convenience of description, the drawings of the present invention only show parts related to the present invention, while parts unrelated to the present invention are not shown in the drawings.
[0066] It can be understood that each unit and module involved in the embodiments of the present invention may correspond to only one physical structure, or may be composed of multiple physical structures, or multiple units and modules may be integrated into one physical structure.
[0067] It can be understood that the terms "first", "second", etc. in the embodiments of the present invention are used to distinguish different objects, or to distinguish different processing of the same object, rather than to describe a specific order of objects.
[0068] It will be understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of the present invention may occur in an order different from that marked in the drawings.
[0069] It is understood that the flowcharts and block diagrams of the present invention illustrate the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to various embodiments of the present invention. Each box in the flowchart or block diagram may represent a unit, module, program segment, or code, which contains executable instructions for implementing the specified functions. Moreover, each box or combination of boxes in the block diagram and flowchart may be implemented using a hardware-based system that implements the specified functions, or may be implemented using a combination of hardware and computer instructions.
[0070] It can be understood that the units and modules involved in the embodiments of the present invention can be implemented by software or hardware. For example, the units and modules can be located in a processor.
[0071] Application Overview
[0072] At present, in the authentication system of the three-layer wired network, when the Portal server receives the imperceptible query request sent by the access device after intercepting the HTTP (Hyper Text Transfer Protocol) request of any terminal, it can determine the gateway device to which the terminal is connected from the network division information of each gateway device based on the terminal IP (Internet Protocol) address it carries, and then request the MAC address of the terminal from the gateway device, and then use the MAC address of the terminal to find the matching target authentication record from the authentication record set, and then perform imperceptible authentication on the terminal based on the target authentication record. Figure 1 As shown, the specific steps are as follows:
[0073] 1. Portal intercepts HTTP non-aware query requests from any terminal;
[0074] 2. Based on the terminal IP address carried in the non-perception query request, determine the gateway device to which the terminal is connected from the pre-stored network division information of each gateway device;
[0075] 3. Send a MAC address acquisition request to the gateway device through the portal;
[0076] 4. When it is determined that a target authentication record matching the terminal MAC address exists in the authentication record set maintained by AAA (Authentication, Authorization and Accounting), the terminal is authenticated without perception based on the target authentication record.
[0077] Relevant examples of existing technologies include terminals, gateway devices, access devices, portal servers, and AAA servers. Terminal users are devices that can access a wired network, such as computers and tablets. Gateway devices are network devices that connect terminals to a Layer 3 network. These network devices can be switches or routers. Gateway devices can learn the matching relationship between the MAC address and IP address of connected terminals through ARP (Address Resolution Protocol) and provide a query interface for querying the terminal's MAC address based on the terminal's IP address. Access devices are network devices at the core layer of a Layer 3 network, typically core switches or core routers. Portal servers also support pre-collection of network partition information for each gateway device. AAA servers are responsible for terminal access authentication.
[0078] However, existing methods for implementing campus broadband intranet and extranet access authentication have problems such as insufficient network architecture evolution capabilities and inability to achieve multi-network access.
[0079] In response to the above technical problems, the idea of this application is to provide a method, system and medium for realizing campus broadband internal and external network access authentication. Based on the network architecture with separated forwarding and control, campus broadband users only need to enter the campus broadband account and password once when they first go online. Thereafter, there is no need to manually enter any authentication information for each network access, and the authentication process can be completed automatically, thus realizing truly imperceptible authentication and multi-network access to the Internet and campus network.
[0080] After introducing the basic principles of the present application, various non-limiting embodiments of the present application will be described in detail with reference to the accompanying drawings.
[0081] Example 1:
[0082] This embodiment provides a method for implementing campus broadband intranet and extranet access authentication, such as Figure 2 As shown, the method includes:
[0083] Step S101: The Broadband Core Network-User Plane (BNC-UP) obtains a pre-authentication domain IP address assigned by a DHCP (Dynamic Host Configuration Protocol) server based on the terminal's first access request. The pre-authentication domain IP address is used to access the Portal server.
[0084] In this embodiment, when a terminal user accesses the network for the first time through a wired or WIFI method, the ONU (Optical Network Unit) is configured in bridging mode, and the terminal's first access request is transparently transmitted to the upper-layer core switch. The core switch forwards the terminal's first access request to the BNC-UP. Based on the terminal's first access request, the BNC-UP obtains the pre-authentication domain IP address assigned by DHCP. The pre-authentication domain refers to the network area where the user device is located before completing the authentication authorization when accessing the network through the BRAS (Broadband Remote Access Server). Usually, it can only obtain a restricted IP address and access limited network resources (such as the Portal server), and cannot access the Internet and the campus network. The pre-authentication domain IP address is assigned by the DHCP server.
[0085] Optionally, the broadband core network user plane BNC-UP obtains a pre-authentication domain Internet Protocol IP address allocated by a Dynamic Host Configuration Protocol DHCP server based on an initial access request of the terminal, specifically including:
[0086] The BNC-UP receives the first access request of the terminal and forwards it to the BNC-CP (Broadband Core Network-Control Plane, broadband core network control plane);
[0087] The BNC-CP sends the first access request of the terminal to the DHCP server;
[0088] The DHCP server allocates the pre-authentication domain IP address according to the first access request of the terminal and sends it to the BNC-CP;
[0089] The BNC-CP sends the pre-authentication domain IP address to the BNC-UP;
[0090] The BNC-UP receives the pre-authentication domain IP address.
[0091] In this embodiment, when a terminal first accesses the network, it sends an initial access request to the DHCP server via BNC-UP and BNC-CP. After receiving the initial access request, the DHCP server allocates a pre-authentication domain IP address based on the user account (i.e., each terminal that initiates the initial access request is allocated a "pre-authentication domain" IP address). The user account format is usually "mobile number@domain name", and the same school domain name is the same.
[0092] Step S102: The BNC-UP redirects the first access request of the terminal to the Portal server based on the pre-authentication domain IP address, so that the terminal pops up a Portal page for entering the campus broadband account and password;
[0093] In this embodiment, BNC-UP redirects the terminal access request to the Portal server (ie, to the pre-authentication domain IP address), and the terminal pops up a Portal page, which facilitates the user to enter the campus broadband account and password on the page.
[0094] Step S103: The Portal server sends the input campus broadband account and password to the BNC-CP;
[0095] Step S104: The BNC-CP obtains the post-authentication domain IP address assigned by the DHCP server after the campus broadband account and password are authenticated. The post-authentication domain IP address is used to access the Internet or the campus network.
[0096] In this embodiment, the BNC-CP is the control plane device in a network architecture with separate forwarding and control, responsible for user session management and signaling control. After the campus broadband account and password entered are successfully authenticated, the BNC-CP obtains a post-authentication domain IP address. The post-authentication domain refers to the network area where the user is located after successful authentication and authorization. The user is then assigned a formal service IP address, allowing access to the internet and campus network. The post-authentication domain IP address is assigned by the DHCP server.
[0097] Optionally, the BNC-CP obtains the post-authentication domain IP address assigned by the DHCP server after the campus broadband account and password are authenticated, specifically including:
[0098] The BNC-CP initiates a first authentication request to the AAA server based on the campus broadband account and password;
[0099] The AAA server authenticates the campus broadband account and password based on the first authentication request;
[0100] In response to the authentication being successful, the AAA server authorizes the post-authentication domain IP address and returns an authentication successful message to the BNC-CP;
[0101] The BNC-CP notifies the DHCP server to allocate the post-authentication domain IP address based on the authentication pass message;
[0102] The DHCP server allocates the post-authentication domain IP address and sends it to the BNC-CP;
[0103] The BNC-CP receives the post-authentication domain IP address.
[0104] In this embodiment, the AAA server authorizes the user to obtain a post-authentication domain IP address after passing authentication. Authorizing the post-authentication domain IP address means that the user is granted the legal authority to obtain the post-authentication domain IP address, but the address is not actually allocated. The allocation of the post-authentication domain IP address is actually allocated and issued by DHCP based on the user's legal authority.
[0105] Step S105: The BNC-CP sends the post-authentication domain IP address to the terminal, so that the terminal starts to access the Internet based on the post-authentication domain IP address;
[0106] In this embodiment, the BNC-CP notifies the BNC-UP of the assigned post-authentication domain IP address, and the BNC-UP sends it to the terminal user. The user obtains the Internet access address and starts to access the Internet.
[0107] Step S106: The Portal server saves the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronizes it to the authentication, authorization and accounting AAA server.
[0108] In this embodiment, the Portal server queries the DHCP server for the terminal MAC address, binds the account and the MAC address, and synchronizes with the AAA server.
[0109] Optionally, the Portal server stores the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronizes it to the authentication, authorization, and accounting AAA server, specifically including:
[0110] The Portal server sends a query request to the DHCP server;
[0111] The DHCP server queries the MAC address corresponding to the terminal IP address according to the query request and returns it to the Portal server;
[0112] The Portal server binds the received MAC address to the campus broadband account and synchronizes it to the AAA server.
[0113] In this embodiment, the Portal server initiates a query request to the DHCP server. The DHCP server queries the MAC address of the authentication terminal based on the IP address, binds it to the campus broadband account, and synchronizes it with the AAA server.
[0114] Step S107: When the terminal accesses again subsequently, the AAA server authorizes the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand.
[0115] In this embodiment, when the user subsequently accesses and authenticates, there is no need to manually enter any authentication information. Non-perception authentication access and multi-network access to the Internet and campus network can be performed directly through the MAC address.
[0116] Optionally, when the terminal subsequently accesses again, the AAA server authorizes the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains an Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand, specifically including:
[0117] When the terminal accesses again subsequently, the BNC-CP initiates a second authentication request to the AAA server based on the MAC address of the terminal;
[0118] The AAA server queries the MAC address of the terminal based on the second authentication request whether there is a binding relationship with the campus broadband account, and if so, determines that the authentication is successful and authorizes the post-authentication domain IP address;
[0119] The DHCP server allocates the post-authentication domain IP address so that the terminal obtains an Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet as needed.
[0120] In this embodiment, when the terminal accesses again subsequently, the AAA server extracts the terminal's MAC address from the second authentication request and queries its binding relationship with the campus broadband account. If a binding relationship exists, the authentication is passed and the post-authentication domain IP address is authorized. At the same time, the DHCP server allocates the post-authentication domain IP address so that the user can obtain an Internet access address based on the post-authentication domain IP address, access the campus network and the Internet on demand, and achieve network switching without perception.
[0121] Optionally, each campus network corresponds to a pre-authentication domain IP address and a post-authentication domain IP address. The post-authentication domain IP address is a private network address assigned by the operator, which is interconnected with the campus network routing. When accessing the Internet, the private network address is mapped to a public network address and port through NAT (Network Address Translation).
[0122] In this embodiment, each campus network corresponds to a pre-authentication domain IP address and a post-authentication domain IP address. The post-authentication domain IP address is a private network address assigned by the operator, which is interconnected with the campus network routing, so that the campus network can be accessed; when accessing the public network, the private network address is mapped to the public network address + port through NAT for access.
[0123] It should be noted that the method provided by the present invention for realizing campus broadband intranet and extranet access authentication is based on a network architecture with separated switching and control, and significantly improves the user's convenience and satisfaction by simplifying the user access process. Specifically, the present invention adopts an efficient MAC address-based fast authentication mechanism. Under this mechanism, users only need to enter their campus broadband account and password once when they go online for the first time, and thereafter, they will no longer need to manually enter any authentication information each time they access the network. The system will intelligently and automatically complete the authentication process, realizing truly imperceptible authentication and multi-network access to the Internet and campus network.
[0124] In a specific embodiment, in order to realize the non-perception authentication of one account in the internal and external network under the network architecture of separation of forwarding and control, a system for realizing the authentication of campus broadband internal and external network access is provided. The network topology diagram of the system is shown as follows: Figure 3As shown, it includes ONU, BNC-UP, BNC-CP, Portal, DHCP, AAA server, etc. The following describes each part:
[0125] 1) ONU: Bridge mode, completes business process forwarding.
[0126] ONU is an access device in the optical fiber access network. It provides access services to user Internet terminals through Ethernet and WIFI interfaces, and supports bridging or routing mode for service data forwarding.
[0127] 2) BNC-UP: This is the user plane device in a network architecture with separated forwarding and control. It is responsible for aggregating and forwarding user data and redirecting HTTP access requests from terminals to the Portal server. The BNC-UP must be configured with pre-authentication and post-authentication domain IP addresses. The pre-authentication domain IP address can only access the Portal, while the post-authentication domain IP address can access both the internet and the campus network. The campus side ensures reachable routing between the BNC-UP and the on-campus network.
[0128] It should be noted that each campus network has one pre-authentication domain and one post-authentication domain. The pre-authentication domain assigns a private network address to the student account, and the pre-authentication domain can only access the Portal page (cannot access the public network or the private network); the post-authentication domain opens up access rights (can access the public network and the private network), and performs NAT conversion when accessing the public network. After authentication, the user can directly access the campus network through the VPN (Virtual Private Network) channel with the private network IP address assigned to the user.
[0129] Specifically, the pre-authentication domain refers to the network area where the user device is located before authentication and authorization are completed when accessing the network through the BRAS. Usually, it can only obtain a restricted IP address and access limited network resources (such as Portal), and cannot access the Internet or other business networks. The post-authentication domain refers to the network area where the user is located after successfully passing the authentication and authorization. The user is assigned a formal business IP address and can access the Internet or other authorized services. The BRAS will apply the corresponding QoS (Quality of Service) policy and billing policy based on the user's attributes.
[0130] 3) BNC-CP: This is the control plane device in a network architecture with separated forwarding and control. It is responsible for user session management and signaling control. It can also configure user authentication method priority, prioritizing MAC authentication or IPoE (IP over Ethernet). IPoE is used in scenarios where home broadband users can watch high-definition IPTV (Internet Protocol Television) through dial-up internet access using an optical modem.
[0131] 4) DHCP: Completes student business address allocation and has the ability to respond to Portal queries for MAC addresses through a dedicated process.
[0132] Specifically, the DHCP server supports allocating IP addresses to terminals and provides the Portal server with the terminal MAC address query capability.
[0133] 5) Portal: It has the ability to interact with portal authentication, and also has the ability to query MAC and MAC binding from DHCP.
[0134] Specifically, the Portal server can push customized Portal pages to terminals, support Portal authentication, and query the terminal MAC address through a dedicated process with the DHCP server, complete the account and terminal MAC address binding, and synchronize it to the AAA server.
[0135] 6)AAA: Verify the legitimacy of student broadband account access authentication and return authentication and authorization results.
[0136] Specifically, the AAA server supports authentication of the terminal's account and password, and also supports non-perception authentication of the terminal's MAC address.
[0137] The access process is as follows: After the terminal user accesses the network for the first time via wired or WIFI, the ONU is configured in bridging mode and transparently transmits user data (i.e., Internet access request / access request) to the upper-layer core switch. The core switch forwards the user data to BNC-UP, and BNC-UP redirects it to the Portal server (i.e., to the pre-authentication domain IP address). The terminal user pops up the Portal page and enters the account and password for authentication on the web page. After the AAA server authenticates the user, it authorizes the user to the post-authentication domain IP address. After the user obtains the IP address through the DHCP server, he can access the Internet and campus network. The Portal server queries the terminal MAC from the DHCP server based on the terminal's IP address and passes the binding relationship to the AAA server. The Portal page will no longer pop up during subsequent authentication, and non-perception authentication is achieved directly based on the terminal MAC.
[0138] It should be noted that in a network architecture with separated forwarding and control, single-account authentication for both internal and external networks is accomplished through the combination of Portal authentication and MAC address binding. The basic principles are as follows:
[0139] (1) When a user goes online for the first time, they need to initiate portal account and password authentication. After the authentication is passed, AAA authorizes the user to authenticate the domain IP address.
[0140] (2) The Portal server queries the DHCP server for the terminal MAC address, binds the account to the MAC address, and synchronizes the information with the AAA server.
[0141] (3) BNC-UP configures multiple network egress control policies for internal and external networks for the post-authentication domain;
[0142] BNC-UP distinguishes between internet and campus network access based on the user's destination address. After authentication, the domain IP address is a private network address assigned by the carrier, which is interoperable with the campus network router, allowing access to the campus network. When accessing the public network, NAT maps the private network address to a public network address and port.
[0143] (4) When the user subsequently accesses the system for authentication, there is no need to enter an account number, and authentication can be performed directly through the MAC address without any perception.
[0144] Specifically, based on Figure 3 As shown in the network topology diagram, the method for implementing campus broadband intranet and extranet access authentication includes:
[0145] S1. Authentication process for first-time user access:
[0146] like Figure 4 As shown, the authentication process for the user's first access includes the following steps:
[0147] (1) The terminal accesses the network and obtains the pre-authentication domain IP address through DHCP;
[0148] Specifically, a terminal initiates an Internet access request / access request, which is forwarded to DHCP via BNC-UP and BNC-CP. DHCP then assigns a pre-authentication domain IP address based on the user account (i.e., each terminal is assigned a "pre-authentication domain" IP address the first time it initiates an Internet access request / access request). User accounts are typically formatted as "mobile number@domain name," with domain names varying from school to school.
[0149] (2) BNC-UP redirects the terminal access request to the Portal server;
[0150] (3) The portal page pops up on the terminal, and you enter your campus broadband account and password on the page;
[0151] (4) BNC-CP encapsulates the account and password into a RADIUS (Remote Authentication Dial-In User Service) message and initiates authentication to AAA.
[0152] (5) After AAA authentication is passed, the post-authentication domain IP address is assigned by the DHCP server;
[0153] Specifically, after authentication is successful, the BNC-CP notifies the DHCP server to allocate a post-authentication domain IP address. Authorizing a post-authentication domain IP address indicates that the user has been granted the legal authority to obtain a post-authentication domain IP address, but the address has not actually been allocated. Allocating a post-authentication domain IP address, on the other hand, involves the BRAS / DHCP server actually allocating and issuing a post-authentication domain IP address based on the user's legal authority.
[0154] (6) BNC-CP notifies BNC-UP of the assigned post-authentication domain IP address, which BNC-UP sends to the user. The user obtains the Internet access address and starts surfing the Internet.
[0155] (7) The Portal server sends a query request to the DHCP server, queries the authentication terminal's MAC address based on the IP address, binds it to the campus broadband account, and synchronizes it with the AAA server;
[0156] (8) Users obtain an Internet access address and can access the campus network and the Internet on demand without being aware of network switching.
[0157] Among them, according to the different destination addresses of user access, automatic and imperceptible network switching is achieved, that is, dual-domain access rights exist at the same time, and the specific network accessed is determined according to the user's access behavior.
[0158] It should be noted that when multiple terminals are in the same campus network, the pre-authentication domain and the post-authentication domain are the same.
[0159] S2. Authentication process for user access from the second to the Nth time:
[0160] like Figure 5 As shown, the authentication process for the user's 2nd to Nth access includes the following steps:
[0161] (1) The terminal accesses the network and obtains the pre-authentication domain IP address through DHCP;
[0162] It should be noted that when a terminal accesses the network, it can only obtain the front-end domain address before passing the authentication. After the terminal automatically initiates authentication, the subsequent authentication process begins.
[0163] (2) When the terminal initiates an Internet access request / access request, the BNC-CP initiates authentication with AAA based on the terminal's MAC address.
[0164] (3) AAA queries the binding relationship between the terminal MAC and the campus broadband account, the authentication is successful, and the post-authentication domain IP address is authorized;
[0165] (4) The DHCP server assigns the post-authentication domain IP address;
[0166] (5) Users obtain an Internet access address and can access the campus network and the Internet on demand without being aware of network switching.
[0167] It should be noted that the Internet access address has access to both network exits, with the specific exit being determined by the user's destination address. This means that access to the Internet and the campus network are differentiated based on the user's destination address. The post-authentication domain IP address is a private network address assigned by the carrier, which is interoperable with the campus network router, allowing access to the campus network. When accessing the public network, NAT maps the private network address to a public network address and port.
[0168] It should be noted that the method for implementing campus broadband intranet and extranet access authentication provided by the present invention has the following characteristics:
[0169] a) Imperceptible authentication under a control-forwarding separation network architecture: The present invention proposes a method for imperceptible authentication under a control-forwarding separation network architecture, and describes in detail the authentication process for the first and subsequent access of a terminal to the network. In the control-forwarding separation architecture, the control plane (CP) and the user plane (UP) are separated. The terminal passes the Portal authentication for the first access, and imperceptible authentication is achieved by associating the MAC address with the user account and IP address for subsequent access. Imperceptible authentication improves the user experience, reduces repeated authentication processes, and improves the overall efficiency of the network.
[0170] b) Multiple Network Access: In a network architecture with separate forwarding and control, user plane (UP) devices, based on policy configuration, support access to different network exits for the same user account based on permissions. Through dynamic policy configuration, users can access different network resources based on their permissions, meeting network requirements in multiple scenarios.
[0171] c) Association of MAC address with user account and user IP: The Portal server queries the DHCP server for the terminal MAC address based on the IP address, and completes the association of the terminal MAC address with the user account and user IP, achieving non-perceptual authentication for subsequent access. By associating the MAC address with the user account, user behavior can be accurately traced, facilitating network management and security auditing.
[0172] d) Non-perception network switching: The existing technology only supports non-perception access authentication. On the basis of non-perception access authentication, the present invention further realizes the non-perception network switching of users between accessing the Internet and the campus network, thereby further optimizing the user's Internet experience.
[0173] The embodiment of the present invention provides a method for implementing campus broadband intranet and extranet access authentication. First, the BNC-UP obtains the pre-authentication domain IP address assigned by the DHCP server based on the first access request of the terminal, wherein the pre-authentication domain IP address is used to access the Portal server; and redirects the first access request of the terminal to the Portal server based on the pre-authentication domain IP address, so that the terminal pops up a Portal page for entering the campus broadband account and password; then the Portal server sends the entered campus broadband account and password to the broadband core network control plane BNC-CP; after the BNC-CP obtains the campus broadband account and password and passes the authentication, the DHCP The post-authentication domain IP address assigned by the server is used to access the Internet or campus network; the BNC-CP then sends the post-authentication domain IP address to the terminal, so that the terminal can start surfing the Internet based on the post-authentication domain IP address; at the same time, the Portal server saves the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronizes it to the authentication, authorization and billing AAA server; finally, when the terminal accesses again later, the AAA server authorizes the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand. The present invention is based on a network architecture with separated control and forwarding, so that campus broadband users only need to enter the campus broadband account and password once when they first access the Internet. There is no need to manually enter any authentication information for each subsequent network access, and the authentication process can be automatically completed, thereby realizing true non-perception authentication and multi-network access to the Internet and campus network, solving the problem that the existing method for realizing campus broadband internal and external network access authentication is mainly based on the three-layer wired network authentication of the Portal server, and there are insufficient network architecture evolution capabilities and the inability to realize multi-network access.
[0174] Example 2:
[0175] like Figure 6 As shown, this embodiment provides a system for implementing campus broadband intranet and extranet access authentication, which is used to execute the above-mentioned method for implementing campus broadband intranet and extranet access authentication, including: a broadband core network user plane BNC-UP11, a portal server 12, a broadband core network control plane BNC-CP13, an authentication, authorization and accounting AAA server 14, and a dynamic host configuration protocol DHCP server 15;
[0176] The BNC-UP 11 is used to obtain the pre-authentication domain Internet Protocol IP address assigned by the DHCP server 15 based on the first access request of the terminal, wherein the pre-authentication domain IP address is used to access the Portal server 12;
[0177] The BNC-UP11 is also used to redirect the terminal's first access request to the Portal server 12 based on the pre-authentication domain IP address, so that the terminal pops up a Portal page for entering the campus broadband account and password;
[0178] The Portal server 12 is used to send the input campus broadband account and password to the BNC-CP 13;
[0179] The BNC-CP13 is used to obtain the post-authentication domain IP address assigned by the DHCP server 15 after the campus broadband account and password are authenticated. The post-authentication domain IP address is used to access the Internet or campus network;
[0180] The BNC-CP13 is further configured to send the post-authentication domain IP address to the terminal, so that the terminal starts to access the Internet based on the post-authentication domain IP address;
[0181] The portal server 12 is also used to save the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronize it to the AAA server 14;
[0182] When the terminal accesses again subsequently, the AAA server 14 is used to authorize the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand.
[0183] Optionally, the BNC-UP11 is further configured to receive an initial access request from the terminal and forward the request to the BNC-CP13;
[0184] The BNC-CP 13 is further configured to send the first access request of the terminal to the DHCP server 15;
[0185] The DHCP server 15 is used to allocate the pre-authentication domain IP address according to the first access request of the terminal and send it to the BNC-CP13;
[0186] The BNC-CP13 is further configured to send the pre-authentication domain IP address to the BNC-UP11;
[0187] The BNC-UP11 is further configured to receive the pre-authentication domain IP address.
[0188] Optionally, the BNC-CP 13 is further configured to initiate a first authentication request to the AAA server 14 based on the campus broadband account and password;
[0189] The AAA server 14 is further configured to authenticate the campus broadband account and password based on the first authentication request;
[0190] The AAA server 14 is further configured to, in response to the authentication being successful, authorize the post-authentication domain IP address and return an authentication success message to the BNC-CP 13;
[0191] The BNC-CP 13 is further configured to notify the DHCP server 15 to allocate the post-authentication domain IP address based on the authentication pass message;
[0192] The DHCP server 15 is further configured to allocate the post-authentication domain IP address and send it to the BNC-CP 13;
[0193] The BNC-CP13 is further configured to receive the post-authentication domain IP address.
[0194] Optionally, the Portal server 12 is further configured to send a query request to the DHCP server 15;
[0195] The DHCP server 15 is further configured to query the MAC address corresponding to the terminal IP address according to the query request and return it to the Portal server 12;
[0196] The Portal server 12 is further configured to bind the received MAC address to the campus broadband account and synchronize it to the AAA server 14 .
[0197] Optionally, when the terminal accesses again subsequently, the BNC-CP 13 is further configured to initiate a second authentication request to the AAA server 14 based on the MAC address of the terminal;
[0198] The AAA server 14 is further configured to query, based on the second authentication request, whether the MAC address of the terminal is bound to the campus broadband account, and if so, determine that the authentication is successful and authorize the post-authentication domain IP address;
[0199] The DHCP server 15 is further configured to allocate the post-authentication domain IP address so that the terminal can obtain an Internet access address based on the post-authentication domain IP address and access the campus network and the Internet as needed.
[0200] Optionally, each campus network corresponds to a pre-authentication domain IP address and a post-authentication domain IP address.
[0201] Optionally, the post-authentication domain IP address is a private network address assigned by the operator, which is interconnected with the campus network routing. When accessing the Internet, the private network address is mapped to a public network address and port through network address translation NAT for access.
[0202] Example 3:
[0203] This embodiment provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method for implementing campus broadband intranet and extranet access authentication in the above-mentioned embodiment 1 is implemented.
[0204] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable read only memory), flash memory or other memory technology, CD-ROM (Compact Disc Read-Only Memory), digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.
[0205] In summary, the method, system and medium for implementing campus broadband intranet and extranet access authentication provided by the embodiment of the present invention first obtain the pre-authentication domain IP address assigned by the DHCP server based on the first access request of the terminal, wherein the pre-authentication domain IP address is used to access the Portal server; and redirect the first access request of the terminal to the Portal server based on the pre-authentication domain IP address, so that the terminal pops up a Portal page for entering the campus broadband account and password; then the Portal server sends the entered campus broadband account and password to the broadband core network control plane BNC-CP; after the BNC-CP obtains the campus broadband account and password and passes the authentication, The DHCP server allocates a post-authentication domain IP address, which is used to access the Internet or campus network; the BNC-CP then sends the post-authentication domain IP address to the terminal, so that the terminal can start surfing the Internet based on the post-authentication domain IP address; at the same time, the Portal server saves the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronizes it to the authentication, authorization and billing AAA server; finally, when the terminal accesses again, the AAA server authorizes the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand. The present invention is based on a network architecture with separated forwarding and control, so that campus broadband users only need to enter the campus broadband account and password once when they first access the Internet. Thereafter, there is no need to manually enter any authentication information for each network access, and the authentication process can be automatically completed, thereby realizing truly imperceptible authentication and multi-network access to the Internet and campus network, solving the problem that the existing method for realizing campus broadband intranet and extranet access authentication is mainly based on the three-layer wired network authentication of the Portal server, and there are insufficient network architecture evolution capabilities and the inability to realize multi-network access.
[0206] It will be understood that the above embodiments are merely exemplary embodiments for illustrating the principles of the present invention, and the present invention is not limited thereto. Those skilled in the art will appreciate that various modifications and improvements can be made without departing from the spirit and substance of the present invention, and such modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A method for implementing campus broadband intranet and extranet access authentication, characterized in that: The method comprises: The broadband core network user plane (BNC-UP) obtains the pre-authentication domain Internet Protocol (IP) address assigned by the Dynamic Host Configuration Protocol (DHCP) server based on the terminal's initial access request. The pre-authentication domain IP address is used to access the Portal server. The BNC-UP redirects the first access request of the terminal to the Portal server based on the pre-authentication domain IP address, so that the terminal pops up a Portal page for entering the campus broadband account and password; The Portal server sends the input campus broadband account and password to the broadband core network control plane BNC-CP; The BNC-CP obtains the post-authentication domain IP address assigned by the DHCP server after the campus broadband account and password are authenticated, and the post-authentication domain IP address is used to access the Internet or the campus network; The BNC-CP sends the post-authentication domain IP address to the terminal, so that the terminal starts to access the Internet based on the post-authentication domain IP address; The Portal server stores the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronizes it to the authentication, authorization and accounting AAA server; When the terminal accesses again subsequently, the AAA server authorizes the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand.
2. The method according to claim 1, characterized in that The broadband core network user plane BNC-UP obtains a pre-authentication domain Internet Protocol IP address assigned by a Dynamic Host Configuration Protocol DHCP server based on the first access request of the terminal, specifically including: The BNC-UP receives the first access request of the terminal and forwards it to the BNC-CP; The BNC-CP sends the first access request of the terminal to the DHCP server; The DHCP server allocates the pre-authentication domain IP address according to the first access request of the terminal and sends it to the BNC-CP; The BNC-CP sends the pre-authentication domain IP address to the BNC-UP; The BNC-UP receives the pre-authentication domain IP address.
3. The method according to claim 1, characterized in that The BNC-CP obtains the post-authentication domain IP address assigned by the DHCP server after the campus broadband account and password are authenticated, specifically including: The BNC-CP initiates a first authentication request to the AAA server based on the campus broadband account and password; The AAA server authenticates the campus broadband account and password based on the first authentication request; In response to the authentication being successful, the AAA server authorizes the post-authentication domain IP address and returns an authentication successful message to the BNC-CP; The BNC-CP notifies the DHCP server to allocate the post-authentication domain IP address based on the authentication pass message; The DHCP server allocates the post-authentication domain IP address and sends it to the BNC-CP; The BNC-CP receives the post-authentication domain IP address.
4. The method according to claim 1, wherein The portal server stores the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronizes it to the authentication, authorization, and accounting AAA server, specifically including: The Portal server sends a query request to the DHCP server; The DHCP server queries the MAC address corresponding to the terminal IP address according to the query request and returns it to the Portal server; The Portal server binds the received MAC address to the campus broadband account and synchronizes it to the AAA server.
5. The method according to claim 1, characterized in that When the terminal subsequently accesses again, the AAA server authorizes the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand, specifically including: When the terminal accesses again subsequently, the BNC-CP initiates a second authentication request to the AAA server based on the MAC address of the terminal; The AAA server queries the MAC address of the terminal based on the second authentication request whether there is a binding relationship with the campus broadband account, and if so, determines that the authentication is successful and authorizes the post-authentication domain IP address; The DHCP server allocates the post-authentication domain IP address so that the terminal obtains an Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet as needed.
6. The method according to claim 5, characterized in that Each campus network corresponds to a pre-authentication domain IP address and a post-authentication domain IP address.
7. The method according to claim 5, characterized in that The post-authentication domain IP address is a private network address assigned by the operator, which is interconnected with the campus network routing. When accessing the Internet, the private network address is mapped to a public network address and port through network address translation NAT for access.
8. A system for realizing campus broadband intranet and extranet access authentication, characterized in that: Including broadband core network user plane BNC-UP, Portal server, broadband core network control plane BNC-CP, authentication, authorization and accounting AAA server, Dynamic Host Configuration Protocol DHCP server; The BNC-UP is used to obtain the pre-authentication domain Internet Protocol IP address assigned by the DHCP server based on the first access request of the terminal, wherein the pre-authentication domain IP address is used to access the Portal server; The BNC-UP is further configured to redirect the first access request of the terminal to the Portal server based on the pre-authentication domain IP address, so that the terminal pops up a Portal page for entering the campus broadband account and password; The Portal server is used to send the input campus broadband account and password to the BNC-CP; The BNC-CP is used to obtain the post-authentication domain IP address assigned by the DHCP server after the campus broadband account and password are authenticated. The post-authentication domain IP address is used to access the Internet or the campus network; The BNC-CP is further configured to send the post-authentication domain IP address to the terminal, so that the terminal starts to access the Internet based on the post-authentication domain IP address; The Portal server is also used to save the binding relationship between the terminal media access control layer MAC address and the campus broadband account and synchronize it to the AAA server; When the terminal accesses again subsequently, the AAA server is used to authorize the post-authentication domain IP address based on the binding relationship between the terminal MAC address and the campus broadband account, so that the terminal obtains the Internet access address based on the post-authentication domain IP address and accesses the campus network and the Internet on demand.
9. The system according to claim 8, characterized in that The BNC-UP is further configured to receive an initial access request from the terminal and forward the request to the BNC-CP; The BNC-CP is further configured to send the first access request of the terminal to the DHCP server; The DHCP server is used to allocate the pre-authentication domain IP address according to the first access request of the terminal and send it to the BNC-CP; The BNC-CP is further configured to send the pre-authentication domain IP address to the BNC-UP; The BNC-UP is further configured to receive the pre-authentication domain IP address.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the method for implementing campus broadband intranet and extranet access authentication according to any one of claims 1 to 7 is implemented.