Authentication method, system and related device

Through 802.1x account and password authentication and negotiation of identity keys, certificates are automatically applied for and installed, solving the problems of convenience and security in obtaining certificates in existing technologies and achieving efficient and secure network access without the perception of terminal devices.

CN120692546APending Publication Date: 2025-09-23HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410342630.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-21
Publication Date
2025-09-23

AI Technical Summary

Technical Problem

The existing 802.1x authentication method has convenience issues in the certificate acquisition process. In particular, the 'username/password' method is vulnerable to attacks by counterfeit access nodes, while the 'certificate' method requires cumbersome manual operations, affecting the security and convenience of terminal devices accessing the network.

Method used

Through 802.1x account and password authentication, identity keys are negotiated and certificates are automatically applied for and installed, automating the identity authentication and certificate application processes. Terminal devices can obtain and install certificates without being aware of the process, improving security and convenience.

Benefits of technology

It enables terminal devices to automatically obtain and install certificates without any perception, improves the security of network access, avoids spoofing attacks by counterfeit APs, and enhances the convenience and security of authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692546A_ABST
    Figure CN120692546A_ABST
Patent Text Reader

Abstract

The invention discloses an authentication method, system and related device, and relates to the technical field of communication. The method comprises the steps that the terminal equipment sends first information, the first information is used for triggering 802.1 x account password authentication, and the first information comprises a first account and a first password; and the terminal equipment receives a response of the first information, wherein the response of the first information comprises the first identity key. And the terminal equipment sends second information, the second information is used for applying for the first certificate, the first certificate is used for performing 802.1 x certificate authentication, and the second information comprises the first account and the first identity key, so that the process of obtaining the first certificate by the terminal equipment is very convenient. In addition, under the condition that the terminal equipment obtains the first certificate, a series of operations such as automatic installation of the first certificate and automatic network access can be completed, and the terminal equipment can access the network more safely.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to an authentication method, system and related devices. Background Art

[0002] While the rapid development of communications technology has brought convenience to people's lives and work, it has also introduced security issues, including network security, system security, information dissemination security, and information content security. To address the network security concerns raised by terminal access, various authentication methods have been designed, such as 802.1x authentication, network admission control (NAC) authentication, and media access control address (MAC) authentication.

[0003] The aforementioned 802.1x authentication method offers high security and low network deployment costs, making it widely used in security-critical scenarios such as finance, insurance, and securities trading. 802.1x authentication can be performed using either a username / password or a certificate. However, the username / password method is vulnerable to spoofing attacks by counterfeit access points (APs). Therefore, the certificate method is often used for 802.1x authentication. However, the ease of obtaining certificates is a concern when using the certificate method. Summary of the Invention

[0004] The present application provides an authentication method, system and related devices, which relate to the field of communication technology. The authentication method provided by the present application negotiates an identity key for applying for a certificate (the certificate is used for 802.1x certificate authentication) through 802.1x account and password authentication, which can associate the identity authentication with the certificate application process, and can realize operations such as automatic application for certificates, automatic acquisition of certificates and automatic installation of certificates, thereby completing the issuance and installation of certificates efficiently and conveniently. Furthermore, the terminal device can perform 802.1x certificate authentication based on the installed certificate, thereby improving the security of the terminal accessing the network.

[0005] In a first aspect, the present application provides an authentication method, applied to a terminal device, comprising: sending first information, the first information being used to trigger 802.1x account and password authentication, the first information including a first account and a first password; receiving a response to the first information, the response including a first identity key; and sending second information, the second information being used to apply for a first certificate, the first certificate being used for 802.1x certificate authentication, the second information including the first account and the first identity key.

[0006] In the authentication method provided in the present application, the 802.1x protocol is an access control and authentication protocol based on the client (client) / server (server), which can restrict unauthorized users / devices from accessing the local area network / wireless local area network through the network access port. 802.1x authentication includes an authentication method through an account and password and an authentication method through a certificate. For the sake of convenience of description, the authentication method through an account and password is referred to as 802.1x account and password authentication, and the authentication method through a certificate is referred to as 802.1x certificate authentication. The terminal device obtains a first identity key by sending a first message for performing 802.1x account and password authentication. After receiving the first identity key, the terminal device also sends a second message for applying for a first certificate to obtain the first certificate. Among them, the second information includes the first identity key and the first account carried in the first information. When the server receives the second information, it can determine whether the first account has completed the 802.1x account password authentication. If the first account has not completed the 802.1x account password authentication, it is prohibited to apply for a certificate through the first account. Otherwise, the first account is allowed to apply for a certificate, and further determine whether the first identity key is correct. If the first identity key is also correct, the first certificate is sent to the terminal device. Obviously, when the terminal device sends the first information, it needs to accept the operation of the user entering the account / password, and the information required for the terminal device to send the second information is already stored on the terminal device, so that the terminal device can automatically send the second information. For example, when the terminal device receives the first identity key, it triggers the process of sending the second information, making the process of the terminal device obtaining the first certificate very convenient. In addition, when the terminal device obtains the first certificate, it can also complete a series of operations such as automatic installation of the first certificate and automatic network access, so as to achieve more secure access to the network for the terminal device.

[0007] Optionally, the above-mentioned first information also includes a first service set identifier (SSID), and the first SSID is used to configure 802.1x account and password authentication. After installing the first certificate, the above-mentioned first SSID can continue to be used to configure 802.1x certificate authentication, thereby realizing automatic configuration of the certificate, and thus making the terminal user unaware of the configuration process of 802.1x certificate authentication. Furthermore, the terminal device can complete identity authentication and network access operations through 802.1x certificate authentication, and the terminal user is also unaware of the process. Obviously, the authentication method provided in this application can perform 802.1x certificate authentication without the terminal user being aware of it. This process is not only convenient and efficient, but also can avoid deception attacks by counterfeit APs, and has higher security.

[0008] Optionally, the above-mentioned first information also includes the media access control (MAC) address of the terminal device, so that the controller can record the MAC address of the device logged in by the first account, so that the device whose MAC address meets the conditions can complete the 802.1x account and password authentication, thereby further improving the security of 802.1x authentication.

[0009] Optionally, the above-mentioned second information also includes the MAC address of the terminal device, which is used to allow the controller to check the account and MAC address at the same time to determine whether the terminal device has passed the 802.1x authentication, avoiding the terminal device that only completes the 802.1x authentication for the account but has not completed the authentication for the MAC address to apply for the first certificate, thereby further improving the security of the authentication.

[0010] Optionally, in this application, a series of operations such as the terminal device sending the first information, the second information, receiving the response to the first information, the response to the second information, obtaining the first certificate, and installing the first certificate are all implemented based on a client that can perform 802.1x authentication.

[0011] Optionally, the client used by the terminal device for 802.1x account and password authentication can be system pre-installed or installed offline, or it can be downloaded online through an unauthenticated Wi-Fi network when the terminal device is given access rights to the controller. The client is, for example, software or a driver installed on a device such as a personal computer (PC), a mobile phone, or a portable Android device (PAD). The client supports multiple authentication methods, such as protected extensible authentication protocol (PEAP) or transport layer security (TLS). The client can also establish a hypertext transfer protocol secure (HTTPs) link with the controller.

[0012] Optionally, the terminal device accesses the network using a PEAP method, such as PEAP-mschapv2 (also known as PEAP-EAP-MS-CHAPv2) or PEAP-TLS (also known as PEAP-EAP-TLS). For example, when the terminal device uses the PEAP-mschapv2 authentication method, the controller can encrypt and transmit the first identity key to the terminal device.

[0013] In a possible implementation manner of the first aspect, the sending of the second information further includes: the terminal device receiving a redirection authorization, where the redirection authorization is used to instruct the terminal device to send the second information, and sending the second information.

[0014] In the above implementation, redirection is a network technology used to transfer a terminal device's request from one address to another. Redirection authorization authorizes the terminal device to redirect the address it is accessing to the target address when initiating access to any address. By allowing the terminal device to send the second information through redirection authorization, on the one hand, the terminal device can automatically send the second information, and on the other hand, it can send the second information to the latest address of the controller, avoiding the situation where the controller address has changed and the controller address cannot be obtained in time.

[0015] Optionally, the terminal device initiating access to any address may be automatically triggered. For example, when the terminal device receives the first identity key, the terminal device is triggered to initiate access to any address.

[0016] In another possible implementation of the first aspect, the terminal device sends prompt information, where the prompt information is used to remind the user of the remaining validity period of the first certificate.

[0017] In the above implementation, the terminal device sends a prompt message to remind the user of the remaining validity period of the first certificate, so that the user can update the first certificate in time when the remaining validity period of the first certificate is short, avoiding the phenomenon that the terminal device cannot access the network.

[0018] Optionally, the terminal device may send the above-mentioned prompt message when the remaining validity period of the first certificate is less than a first threshold, thereby avoiding reminding the user when the remaining validity period of the first certificate is sufficient, thereby affecting the user's user experience. The first threshold is greater than 0, for example, the first threshold is 10 days, that is, the terminal device may send the above-mentioned prompt message when the remaining validity period of the first certificate is less than 10 days.

[0019] Optionally, the reminder frequency of the above-mentioned reminder information can also be set, for example, once a day, or once every two days, etc. By setting the reminder frequency, it is possible to avoid interference of frequent reminders on the user.

[0020] In another possible implementation of the first aspect, when the remaining validity period of the first certificate is less than a first threshold and the terminal device receives a first operation from the user, or when the remaining validity period of the first certificate is equal to 0, the terminal device sends third information. The third information is used to trigger 802.1x account and password authentication, the first threshold is greater than 0, and the first operation is used to instruct the terminal device to send third information, the third information including a second account and a second password. The terminal device receives a response to the third information, the response to the third information including a second identity key, and sends fourth information for applying for a second certificate, the second certificate being used for 802.1x certificate authentication, the fourth information including the second account and the second identity key.

[0021] In the above embodiment, if the remaining validity period of the first certificate is less than the first threshold and the terminal device receives a first operation from the user, for example, the terminal device sends a prompt message indicating that the remaining validity period of the first certificate is insufficient, and the user enters an account number / password, thereby triggering the terminal device to send the third information. If the remaining validity period of the first certificate is equal to 0, for example, the terminal device automatically sends the third information upon detecting that the remaining validity period of the first certificate is equal to 0, both of the above scenarios allow the terminal device to apply for the second certificate in a timely manner, thereby avoiding the situation where the terminal device cannot perform 802.1x certificate authentication.

[0022] Optionally, the second account may be the same as or different from the first account, and similarly, the second password may be the same as or different from the first password.

[0023] Optionally, the third information further includes a second SSID. The description of the second SSID can refer to the introduction of the first SSID, which will not be repeated here. The beneficial effects of this embodiment can also refer to the description of the embodiment corresponding to the first SSID, which will not be repeated here.

[0024] Optionally, the third information further includes a MAC address of the terminal device. The beneficial effects of this embodiment can be referred to the description of the embodiment corresponding to the first information including the MAC address of the terminal device, which will not be repeated here.

[0025] Optionally, the fourth information further includes the MAC address of the terminal device. The beneficial effects of this embodiment can be referred to the description of the embodiment corresponding to the second information including the MAC address of the terminal device, which will not be repeated here.

[0026] In another possible implementation of the first aspect, the sending of the fourth information includes: the terminal device receiving a redirection authorization, where the redirection authorization is used to instruct the terminal device to send the fourth information.

[0027] The beneficial effects and possible implementations of the above implementations can be found in the relevant introduction of the implementations corresponding to the above second information, which will not be repeated here.

[0028] In another possible implementation of the first aspect, the method further includes: receiving a response to the second message, the response to the second message including the first certificate; installing the first certificate and configuring the 802.1x certificate authentication based on the first SSID; and sending fifth information, the fifth information being used to trigger the 802.1x certificate authentication.

[0029] In the above implementation, after installing the first certificate, the terminal device can continue to use the above first SSID to configure 802.1x certificate authentication, thereby realizing automatic configuration of the certificate, and thus making the terminal user unaware of the configuration process of 802.1x certificate authentication. Furthermore, the terminal device can complete identity authentication and network access and other operations through 802.1x certificate authentication, and the terminal user is also unaware of the process. Obviously, the authentication method provided by the present application can perform 802.1x certificate authentication without the terminal user being aware of it. This process is not only convenient and efficient, but also can avoid deception attacks by counterfeit APs, and has higher security.

[0030] Optionally, when the terminal device obtains the first certificate, the certificate can also be used for other applications, such as secure socket layer (SSL) virtual private network (VPN) or Internet protocol security (IPSec) VPN.

[0031] In a second aspect, the present application provides an authentication method, applied to a controller, comprising: receiving first information from a terminal device, the first information being used to trigger 802.1x account and password authentication, the first information including a first account and a first password. The controller sending a response to the first information to the terminal device, the response including a first identity key and a redirection authorization, the redirection authorization being used to instruct the terminal device to send second information. The controller receives second information from the terminal device, the second information being used to apply for a first certificate, the first certificate being used for 802.1x certificate authentication, the second information including a first account and a first identity key.

[0032] In the authentication method provided in the present application, the controller is used to process the above-mentioned first information or second information and generate a corresponding response. For example, the controller includes a remote authentication dial-inuser service (RADIUS) server, a built-in certificate authority (CA), a built-in lightweight directory access protocol (LDAP) server or a built-in active directory (AD) server, etc. Among them, the RADIUS server is used to implement functions such as authentication, authorization and account management of the terminal, the built-in CA is used to issue the identity integer of the controller for establishing an HTTPs link or for issuing the above-mentioned first certificate or second certificate, and the built-in AD / LDAP server is used to implement authentication of the account password. Optionally, the controller can also connect to an external CA through an interface to allow the external CA to issue a certificate. Optionally, the controller can also interact with an external AD / LDAP server to implement authentication of the above-mentioned account password.

[0033] Upon receiving the first message, the controller verifies the first account and the first password. If the verification is successful, the controller sends a response to the first message to the terminal device. The response includes the first identity key and redirect authorization. The redirect authorization is used to instruct the terminal device to send the second message, and the first identity key is used for identity authentication to confirm that the first account has completed 802.1x authentication, thereby preventing accounts that have not been authenticated by 802.1x from obtaining certificates. Obviously, the controller sending a response to the first message to the terminal device can, on the one hand, enable the terminal device to connect to the controller, and on the other hand, enable the terminal device to automatically apply for a certificate from the controller, thereby improving the convenience and security of applying for a certificate.

[0034] Optionally, the first information further includes a first SSID, and the first SSID is used to cooperate with the first account to complete 802.1x account and password authentication.

[0035] Optionally, the first information also includes the MAC address of the terminal device, so that the controller records the MAC address of the device logged in by the first account, so that the device whose MAC address meets the conditions can complete the 802.1x account and password authentication, further improving the security of 802.1x authentication.

[0036] Optionally, the above-mentioned second information also includes the MAC address of the terminal device, which is used to allow the controller to check the account and MAC address at the same time to determine whether the terminal device has passed the 802.1x authentication, avoiding the terminal device that only completes the 802.1x authentication for the account but has not completed the authentication for the MAC address to apply for the first certificate, thereby further improving the security of the authentication.

[0037] Optionally, the controller sends the first identity key and redirection authorization to the terminal device through a radius-accept message.

[0038] Optionally, the controller sends a redirection authorization to the terminal device. For example, the controller sends a redirection authorization for the terminal device to a network device (the network device is used to connect the terminal device and the controller). When the terminal device accesses any address, the network device sends the redirection authorization to the terminal device, so that the terminal device can send an access request (second information) to the address corresponding to the controller.

[0039] In a possible implementation of the second aspect, the controller sends a response of the second information to the terminal device, the response of the second information including the first certificate, and receives fifth information from the terminal device, the fifth information being used to trigger 802.1x certificate authentication.

[0040] In the above implementation, the controller sends the first certificate to the terminal, which enables the terminal to perform 802.1x certificate authentication, thereby improving the security of the terminal device accessing the network.

[0041] Optionally, the controller sends the first certificate to the terminal device through an HTTPs channel.

[0042] Optionally, after completing 802.1x certificate authentication of the terminal device, the controller authorizes the terminal device to have normal network access rights.

[0043] Optionally, the application scenarios corresponding to the first and second aspects are that the terminal device is within the coverage of an 802.1x-authenticated network, for example, the terminal device is within the coverage of an 802.1x-authenticated Wi-Fi signal. For another example, the terminal device can be connected to the 802.1x-authenticated network via a wired connection.

[0044] In a third aspect, the present application provides an authentication method for a terminal device, the method comprising: the terminal device establishing an HTTPs secure channel with a controller through a client, and mutually completing security authentication between the terminal device and the controller. The terminal device sends a sixth message to the controller, the sixth message being used to obtain a first certificate, the sixth message including a first account and a first password. The terminal device receives a response to the sixth message, the response including the first certificate. The terminal device automatically installs the first certificate and uses it for 802.1x certificate authentication.

[0045] In the authentication method provided herein, a terminal device can establish a secure channel with a controller by accessing any network. For example, when the terminal device is connected to the network, the controller's address is entered into the terminal device's client, thereby establishing a secure channel between the terminal device and the controller. For example, the secure channel may be an HTTPs secure channel. The terminal device then sends sixth information to the controller via the established secure channel to obtain a first certificate. The sixth information includes a first account number and a first password, which the controller verifies. If verification is successful, the controller returns the first certificate. Upon receiving the first certificate, the terminal device can automatically install the certificate and use it for 802.1x certificate authentication. Obviously, at the user level, simply entering the first account number, first password, and the controller's website address into the client completes the installation of the first certificate, allowing the client to authenticate via 802.1x certificate authentication during subsequent network access. Therefore, the authentication method provided herein makes it very convenient for a terminal device to obtain the first certificate. Furthermore, once the terminal device obtains the first certificate, it can also complete a series of operations, such as automatically installing the first certificate and automatically accessing the network, enabling more secure network access for the terminal device.

[0046] Optionally, the controller sends the first certificate to the terminal device through the above-mentioned HTTPs secure channel to ensure the security of the transferred certificate.

[0047] Optionally, the sixth information also includes the MAC address of the terminal device, which allows the controller to record the MAC address of the terminal device that sends the sixth information, thereby preventing other unrecorded devices from applying for the first certificate through the first account and first password, thereby improving the security of issuing the certificate.

[0048] Optionally, when the terminal device obtains the first certificate, the certificate may also be used by other applications, such as SSL VPN or IPSec VPN.

[0049] In a fourth aspect, the present application provides an authentication method, applied to a controller, comprising: establishing an HTTPs secure channel between the controller and a terminal device, and performing mutual security authentication between the controller and the terminal device. The controller receives sixth information from the terminal device, the sixth information being used to obtain a first certificate, the sixth information including a first account and a first password. The controller sends a response to the sixth information to the terminal device, the response including the first certificate.

[0050] In the authentication method provided by the present application, a secure channel is established between the terminal device and the controller, and the first account and the first password for authentication are transmitted. When the controller completes the authentication of the first account, the first certificate is returned to the terminal device for the terminal device to perform 802.1x certificate authentication. Obviously, at the user level, it is only necessary to input the first account, the first password and the URL of the controller to the client to completely install the first certificate, and then allow the client to authenticate through 802.1x certificate authentication in the subsequent network access process. It can be seen that the authentication method provided by the present application can make the process of the terminal device obtaining the first certificate very convenient. In addition, when the terminal device obtains the first certificate, it can also complete a series of operations such as automatic installation of the first certificate and automatic network access, so as to achieve more secure access to the network for the terminal device.

[0051] Optionally, the sixth information also includes the MAC address of the terminal device, which allows the controller to record the MAC address of the terminal device that sends the sixth information, thereby preventing other unrecorded devices from applying for the first certificate through the first account and first password, thereby improving the security of issuing the certificate.

[0052] In a fifth aspect, the present application also provides a communication device, which includes a unit for executing any method of the first aspect.

[0053] In one possible design, the apparatus includes:

[0054] The sending unit is used to send first information, where the first information is used to trigger 802.1x account and password authentication, and the first information includes a first account and a first password.

[0055] The receiving unit is configured to receive a response to the first information, where the response to the first information includes a first identity key.

[0056] The sending unit is further configured to send second information, where the second information is used to apply for a first certificate, the first certificate is used to perform 802.1x certificate authentication, and the second information includes a first account number and a first identity key.

[0057] Optionally, the first information further includes a first SSID.

[0058] Optionally, the first information also includes the MAC address of the terminal device.

[0059] Optionally, the second information also includes the MAC address of the terminal device.

[0060] Optionally, the client used for 802.1x account and password authentication may be system pre-installed or installed offline, or may be downloaded online through an unauthenticated Wi-Fi network when the terminal device is allowed to access the controller.

[0061] In a possible implementation of the fifth aspect, the receiving unit is further configured to receive a redirection authorization, where the redirection authorization is used to instruct the terminal device to send the second information.

[0062] In another possible implementation of the fifth aspect, the sending unit is further configured to send a prompt message, where the prompt message is used to remind the user of the remaining validity period of the first certificate.

[0063] In another possible implementation of the fifth aspect, the receiving unit is further configured to receive a first operation from the user, where the first operation is configured to instruct the terminal device to send third information, where the third information includes a second account number and a second password.

[0064] Optionally, the third information further includes a second SSID.

[0065] Optionally, the third information also includes the MAC address of the terminal device.

[0066] Optionally, the second account may be the same as or different from the first account, and similarly, the second password may be the same as or different from the first password.

[0067] In another possible implementation of the fifth aspect, the above-mentioned sending unit is specifically used to send the third information when the remaining validity period of the first certificate is less than the first threshold and the receiving unit receives the first operation of the user, or when the remaining validity period of the first certificate is equal to 0, and the above-mentioned first threshold is greater than 0.

[0068] In another possible implementation of the fifth aspect, the receiving unit is further configured to receive a response to the third information, the response to the third information including the second identity key. The sending unit is further configured to send fourth information, the fourth information being used to apply for a second certificate, the second certificate being used for 802.1x certificate authentication, the fourth information including the second account number and the second identity key.

[0069] Optionally, the fourth information also includes the MAC address of the terminal device.

[0070] In another possible implementation of the fifth aspect, the receiving unit is specifically configured to receive a redirection authorization, where the redirection authorization is used to instruct the terminal device to send the fourth information.

[0071] In another possible implementation of the fifth aspect, the receiving unit is further configured to receive a response to the second information, where the response to the second information includes the first certificate.

[0072] In another possible implementation of the fifth aspect, the communication device further includes a processing unit, configured to install the first certificate and configure the 802.1x certificate authentication based on the first SSID.

[0073] The sending unit is further configured to send fifth information, where the fifth information is used to trigger 802.1x certificate authentication.

[0074] Regarding the beneficial effects brought about by the fifth aspect and any possible implementation method, please refer to the description of the beneficial effects corresponding to the first aspect and the corresponding implementation method, and no further details will be given here.

[0075] In a sixth aspect, the present application also provides another communication device, which includes a unit for executing any method of the second aspect.

[0076] In one possible design, the apparatus includes:

[0077] The receiving unit is configured to receive first information, where the first information is used to trigger 802.1x account and password authentication, and the first information includes a first account and a first password.

[0078] The processing unit is configured to verify the first account and the first password.

[0079] The processing unit is further configured to generate a first identity key when the first account and the first password are successfully verified.

[0080] A sending unit is used to send a response to the first information, where the response to the first information includes a first identity key and a redirection authorization, and the redirection authorization is used to instruct the terminal device to send the second information.

[0081] The receiving unit is further configured to receive second information, the second information being used to apply for a first certificate, the first certificate being used to perform 802.1x certificate authentication, and the second information including a first account number and a first identity key.

[0082] Optionally, the first information further includes a first SSID.

[0083] Optionally, the first information further includes a MAC address of the terminal device, and the processing unit is further configured to verify the MAC address of the terminal device.

[0084] Optionally, the second information further includes a MAC address of the terminal device, and the processing unit is further configured to verify the MAC address of the terminal device.

[0085] Optionally, the sending unit sends the first identity key through a radius-accept message.

[0086] In a possible implementation manner of the sixth aspect, the sending unit is further configured to send a response to the second information, where the response to the second information includes the first certificate.

[0087] The receiving unit is further configured to receive fifth information, where the fifth information is used to trigger 802.1x certificate authentication.

[0088] Optionally, the sending unit sends the first certificate through an HTTPs channel.

[0089] In another possible implementation of the sixth aspect, the processing unit is further configured to authorize the terminal device to have normal network access rights after completing 802.1x certificate authentication.

[0090] Regarding the beneficial effects brought about by the seventh aspect and any possible implementation method, please refer to the description of the beneficial effects corresponding to the second aspect and the corresponding implementation method, which will not be repeated here.

[0091] In a seventh aspect, the present application also provides another communication device, which includes a unit for executing any method of the third aspect.

[0092] In one possible design, the apparatus includes:

[0093] The sending unit is used to send a request for establishing a secure channel to a target address.

[0094] The receiving unit is used to receive the CA certificate.

[0095] A processing unit used to verify the CA certificate.

[0096] The sending unit is further configured to send sixth information, where the sixth information is used to obtain the first certificate, and the sixth information includes the first account and the first password.

[0097] The receiving unit is further configured to receive a response to the sixth information, where the response to the sixth information includes a first certificate, and the first certificate is used for 802.1x certificate authentication.

[0098] Optionally, the sending unit is further configured to send the first certificate via the HTTPs secure channel to ensure security of the certificate transfer.

[0099] Optionally, the sixth information also includes the MAC address of the terminal device.

[0100] Regarding the beneficial effects brought about by the seventh aspect and any possible implementation method, please refer to the description of the beneficial effects corresponding to the third aspect and the corresponding implementation method, which will not be repeated here.

[0101] In an eighth aspect, the present application also provides another communication device, which includes a unit for executing any method of the fourth aspect.

[0102] In one possible design, the apparatus includes:

[0103] The receiving unit is configured to receive a request for establishing a secure channel.

[0104] The sending unit is used to send the CA certificate.

[0105] The receiving unit is further configured to receive sixth information, where the sixth information is used to obtain the first certificate, and the sixth information includes the first account and the first password.

[0106] The processing unit is configured to verify the first account and the first password.

[0107] The sending unit is further configured to send a response to the sixth information if the verification by the processing unit is successful, wherein the response to the sixth information includes the first certificate.

[0108] Optionally, the sixth information also includes the MAC address of the terminal device.

[0109] Regarding the beneficial effects brought about by the eighth aspect and any possible implementation method, please refer to the description of the beneficial effects corresponding to the fourth aspect and the corresponding implementation method, which will not be repeated here.

[0110] In a ninth aspect, an embodiment of the present application provides a communication device, comprising a processor. The processor is coupled to a memory and can be configured to execute instructions in the memory to implement the method of any of the first to fourth aspects and any possible implementation methods described above. Optionally, the communication device further comprises a memory. Optionally, the communication device further comprises a communication interface, the processor being coupled to the communication interface.

[0111] In a tenth aspect, an embodiment of the present application provides a communication device, comprising: a logic circuit and a communication interface. The communication interface is configured to receive or send information; the logic circuit is configured to receive or send information via the communication interface, so that the communication device executes the method of any one of the first to fourth aspects and any possible implementation thereof.

[0112] In the eleventh aspect, an embodiment of the present application provides a computer-readable storage medium, which is used to store a computer program (also referred to as code, or instructions); when the computer program is run on a computer, the method of any one of the above-mentioned aspects from the first to the fourth aspect and any possible implementation method is implemented.

[0113] In the twelfth aspect, an embodiment of the present application provides a computer program product, which includes: a computer program (also referred to as code, or instructions); when the computer program is run, it enables the computer to execute any one of the above-mentioned aspects 1 to 4 and any possible implementation method.

[0114] In a thirteenth aspect, an embodiment of the present application provides a chip, comprising a processor configured to execute instructions. When the processor executes the instructions, the chip performs the method of any one of the first to fourth aspects and any possible implementation methods described above. Optionally, the chip further comprises a communication interface configured to receive or transmit signals.

[0115] In the fourteenth aspect, an embodiment of the present application provides a communication system, which includes at least one communication device as described in aspects five to eight, or the communication device described in aspect nine, or the communication device described in aspect ten, or the chip described in aspect thirteen.

[0116] In a fifteenth aspect, an embodiment of the present application provides a communication system, comprising at least one of a terminal device, a network device, and a controller, wherein the terminal device is configured to execute a method according to any possible implementation of the first and second aspects, and the controller is configured to execute a method according to any possible implementation of the third and fourth aspects. The network device is configured to connect the terminal device and the controller and control the terminal device according to an access policy authorized by the controller.

[0117] In addition, in the process of executing the method described in any one of the first to fourth aspects and any possible implementation methods, the process of sending information and / or receiving information in the above method can be understood as the process of the processor outputting information and / or the process of the processor receiving input information. When outputting information, the processor can output the information to the transceiver (or communication interface, or sending module) so that it can be transmitted by the transceiver. After the information is output by the processor, it may also need to undergo other processing before it reaches the transceiver. Similarly, when the processor receives input information, the transceiver (or communication interface, or sending module) receives the information and inputs it into the processor. Furthermore, after the transceiver receives the information, the information may need to undergo other processing before it is input into the processor.

[0118] Based on the above principles, for example, the sending of information mentioned in the above method can be understood as the processor outputting information. For another example, the receiving of information can be understood as the processor receiving input information.

[0119] Optionally, for the operations such as transmission, sending and receiving involved in the processor, if there is no special explanation, or if they do not conflict with their actual functions or internal logic in the relevant description, they can be more generally understood as processor output, reception, input and other operations.

[0120] Optionally, in the process of executing the method described in any aspect of the first to fourth aspects and any possible implementation method, the processor may be a processor specifically used to execute these methods, or a processor that executes these methods by executing computer instructions in a memory, such as a general-purpose processor. The memory may be a non-transitory memory, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or may be separately provided on different chips. The embodiments of the present application do not limit the type of memory and the configuration of the memory and the processor.

[0121] In a possible implementation, the at least one memory is located outside the device.

[0122] In yet another possible implementation, the at least one memory is located within the device.

[0123] In another possible implementation, part of the at least one memory is located inside the device, and another part of the memory is located outside the device.

[0124] In an embodiment of the present application, the processor and the memory may also be integrated into one device, that is, the processor and the memory may also be integrated together. BRIEF DESCRIPTION OF THE DRAWINGS

[0125] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the background technology, the drawings required for use in the embodiments of the present application or the background technology will be described below.

[0126] Figure 1 A schematic diagram of a scenario provided in an embodiment of the present application;

[0127] Figure 2 A schematic diagram of an 802.1x authentication system provided in an embodiment of the present application;

[0128] Figure 3 A flowchart of an authentication method provided in an embodiment of the present application;

[0129] Figure 4 A flowchart of another authentication method provided in an embodiment of the present application;

[0130] Figure 5A flowchart of another authentication method provided in an embodiment of the present application;

[0131] Figure 6 A flowchart of another authentication method provided in an embodiment of the present application;

[0132] Figure 7 A flowchart of another authentication method provided in an embodiment of the present application;

[0133] Figures 8A-8F A schematic diagram of a client interface provided for an application embodiment;

[0134] Figure 9 A schematic diagram of the logical structure of a communication device provided in an embodiment of the present application;

[0135] Figure 10 A schematic diagram of the physical device structure of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0136] In order to make the purpose, technical solutions and advantages of this application clearer, the embodiments of this application will be described below in conjunction with the drawings in the embodiments of this application.

[0137] The terms "first" and "second" in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units that are inherent to the process, method, product, or device.

[0138] The “embodiment” mentioned herein means that the specific features, structures or characteristics described in conjunction with the embodiment may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It can be understood explicitly and implicitly by those skilled in the art that in the various embodiments of the present application, unless otherwise specified and there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced to each other, and the technical features in different embodiments can be combined to form a new embodiment according to their inherent logical relationship.

[0139] It should be understood that in the present application, "at least one (item)" refers to one or more, "more than one" refers to two or more, "at least two (items)" refers to two or three and more than three, and "and / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0140] It should be noted that in this application, "indication" can include direct indication, indirect indication, explicit indication, and implicit indication. When describing that a certain indication information is used to indicate A, it can be understood that the indication information carries A, directly indicates A, or indirectly indicates A.

[0141] In this application, the information indicated by the indication information is referred to as the information to be indicated. In specific implementations, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or an index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, where the other information is associated with the information to be indicated. Alternatively, only a portion of the information to be indicated can be indicated, while the rest of the information to be indicated is known or agreed upon in advance. For example, the indication of specific information can be achieved by using a pre-agreed (e.g., protocol-specified) order of the various information, thereby reducing indication overhead to a certain extent. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. The transmission period and / or transmission timing of these sub-information can be the same or different. The specific transmission method is not limited in this application. The transmission period and / or transmission timing of these sub-information can be pre-defined, for example, according to a protocol, or can be configured by the transmitting device sending configuration information to the receiving device.

[0142] It should be noted that in this application, "send" can be understood as "output" and "receive" can be understood as "input". "Send information to A", where "to A" only indicates the direction of information transmission, A is the destination, and does not limit "sending information to A" to direct transmission on the air interface. "Sending information to A" includes sending information directly to A, and also includes sending information indirectly to A through a transmitter, so "sending information to A" can also be understood as "outputting information to A". Similarly, "receiving information from A" indicates that the source of the information is A, including receiving information directly from A, and also including receiving information indirectly from A through a receiver, so "receiving information from A" can also be understood as "inputting information from A".

[0143] Before introducing the present application, some of the terms used in the embodiments of the present application are briefly explained to facilitate understanding by those skilled in the art.

[0144] 1) Terminal device, which is a device that provides voice and / or data connectivity to users. In the embodiments of the present application, the terminal device may be referred to as user equipment (UE), terminal device, terminal, mobile station (MS), mobile terminal (MT), etc. For example, the terminal device may include a handheld device with a wireless connection function, or a communication device connected to a wireless modem. The terminal device can initiate 802.1x authentication by starting the 802.1x client installed on the terminal device, wherein the 802.1x client is hereinafter referred to as the client, which can be software or a driver installed on the terminal device, and has the following functions: it can perform 802.1x authentication, support authentication methods such as PEAP, extensible authentication protocol (EAP) or TLS, can establish an HTTPs secure channel with the server, and can realize automatic installation and configuration of certificates.

[0145] Some examples of terminal devices include: mobile stations (MS), subscriber units (subscriberunit), cellular phones, smart phones, wireless data cards, personal digital assistants (PDAs), computers, tablet computers, wireless modems, handsets, laptop computers, machine type communication (MTC) terminals, wearable devices, and vehicle-mounted terminal devices. Terminal devices also include constrained devices, such as devices with low power consumption, limited storage capacity, or limited computing power. Terminal devices also include information sensing devices such as barcodes, radio frequency identification (RFID), sensors, global positioning systems (GPS), and laser scanners.

[0146] The functions of the terminal device can be implemented by hardware components within the terminal device, and the above-mentioned hardware components can be a processor and / or a programmable chip within the above-mentioned terminal device. Optionally, the chip can be implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The above-mentioned PLD can be any one of a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), a system on a chip (SOC), or any combination thereof.

[0147] 2) The 802.1x protocol is a client / server (referred to as the controller in this article) access control and authentication protocol that restricts unauthorized users and devices from accessing the LAN / WLAN through access ports. Before accessing the various services provided by the network device, 802.1x authenticates the user and device connecting to the network device. Before authentication is successful, 802.1x only allows PEAP / EAP traffic to pass through the network device to which the terminal device is connected. After authentication is successful, the terminal device can access the network normally.

[0148] 802.1x authentication is divided into 802.1x account and password authentication and 802.1x certificate authentication. 802.1x account and password authentication uses an account and password, while 802.1x certificate authentication uses a certificate. In some scenarios, 802.1x account and password authentication is vulnerable to spoofing attacks by counterfeit APs, posing the risk of account and password leakage. Therefore, 802.1x certificate authentication is generally recommended. However, 802.1x certificate authentication requires installing a certificate on the terminal device, which is complex and carries the risk of certificate leakage.

[0149] In light of this, this application provides an authentication method that first obtains an identity key issued by the controller through 802.1x account and password authentication. This method then uses the identity key and account to apply for a certificate from the controller. This method then automatically obtains and installs the certificate, allowing for network access. This convenient and secure process ensures more secure network access for terminal devices.

[0150] See also Figure 1 , Figure 1 A schematic diagram of a scenario provided in an embodiment of the present application is provided. Figure 1 It includes terminal devices, campus networks and enterprise intranet data centers (DCs), etc. Among them, the terminal devices can refer to the description of "terminal devices" in the above technical terms, which will not be repeated here. The campus network includes firewalls, wireless controllers, switches or access points (APs), etc. Terminal devices can access the wide area network through wireless (for example, Wi-Fi) and AP connections, and can also access the wide area network through direct wired connections to switches. Wireless controllers (wireless access point controllers, WACs) are used to manage APs. When the terminal device is connected to the wide area network, it can interact with the RADIUS server, certificate server or AD / LDAP server to complete the relevant operations of 802.1x authentication. Among them, the RADIUS server is used to perform policy management and implement operations such as authentication or authorization of terminal devices. The AD / LDAP server is used to implement account verification. The certificate server is responsible for operations such as providing certificates and verifying certificates.

[0151] See also Figure 2 , Figure 2 A schematic diagram of an 802.1x authentication system provided in an embodiment of the present application. Figure 2It includes terminal devices, network devices and controllers. For the description of terminal devices, please refer to the relevant introduction in the technical terminology section above, which will not be repeated here. Network devices can provide network admission control (NAC) to connect the network between terminal devices and controllers, carry network traffic, and manage terminal devices according to the control policy issued by the controller. For example, network devices can be LAN switches (LSW) or APs. The controller includes one or more of AD / LDAP servers, certificate servers or RADIUS servers. For the description of AD / LDAP servers, certificate servers or RADIUS servers, please refer to the above Figure 1 The introduction of , will not be repeated here.

[0152] Optionally, the controller will also be connected to an external AD / LDAP server or an external certificate server. For ease of distinction, this application refers to the AD / LDAP server included in the controller as a built-in AD / LDAP server, and the authentication server included in the controller as a built-in authentication server. The built-in AD / LDAP server and the external AD / LDAP server are functionally the same. Users may choose to use different AD / LDAP servers for security or enterprise scale considerations. For example, when the company has a large number of employees, users may choose to use an external AD / LDAP server to store employee accounts and passwords. Similarly, the built-in certificate server and the external certificate server are functionally the same. Users may choose to use different authentication servers for security or ease of management considerations. For example, when the company has high security requirements for terminal access to the network, users may choose to use an external certificate server.

[0153] See also Figure 3 , Figure 3 This is a flowchart of an authentication method provided in an embodiment of the present application. The authentication method is applied in the field of communication technology and includes but is not limited to the following steps:

[0154] S301: The terminal device sends first information to the controller. Correspondingly, the controller receives the first information from the terminal device.

[0155] The description of the terminal device and the controller can refer to the above Figure 2 The description of the terminal device and controller shown in will not be repeated here.

[0156] The first information includes a first account and a first password. The first information is used to trigger the controller to perform 802.1x account and password authentication on the first account and the first password. Accordingly, the controller verifies the first account and the first password. For example, the controller verifies the first account and the first password using its built-in AD / LDAP server. For another example, the controller may also verify the first account and the first password using an external AD / LDAP server.

[0157] S302: The controller sends a response to the first information to the terminal device. Correspondingly, the terminal device receives the response to the first information from the controller.

[0158] Depending on the result of the 802.1x account and password authentication, the response to the first message may include different content. For example, if the 802.1x account and password authentication result is successful, the response to the first message may include: "Authentication result is successful" or "First identity key." For another example, if the 802.1x account and password authentication result is failed, the response to the first message may include "Authentication result is failed." The first identity key is an identifier used to verify identity and can be used to authenticate the first account's access to the controller again.

[0159] S303: The terminal device sends second information to the controller. Correspondingly, the controller receives the second information from the terminal device.

[0160] The second message is used to request the first certificate and includes the first identity key and the first account. The first certificate is used for 802.1x certificate authentication. Upon receiving the second message, the controller can verify the first identity key and the first account, respectively. For example, the controller verifies the first account to determine whether it has passed 802.1x account and password authentication, thereby preventing accounts that have not passed authentication from applying for the first certificate. If the first account passes 802.1x account and password authentication, the controller verifies the first identity key to further verify the identity of the first account and prevent certificate leakage. It should be noted that the RADIUS server in the controller is typically used to generate and verify the first identity key and manage accounts. Therefore, verification of the first account and the first identity key can be completed through the RADIUS server in the controller, eliminating the need for interaction between the RADIUS server and the AD / LDAP server. Obviously, the operations of sending a response to the first message or sending the second message can be automated, making the process of obtaining the first certificate by the terminal device very convenient and imperceptible to the end user. In addition, when the terminal device obtains the first certificate, it can also complete a series of operations such as automatically installing the first certificate and automatically accessing the network, thereby enabling the terminal device to access the network more securely.

[0161] Optionally, the first identity key may be used as a condition for triggering the terminal device to send the second information. For example, when the terminal device receives the first identity key, the terminal device is triggered to send the second information to the controller.

[0162] Optionally, the above-mentioned first information also includes a first SSID, which is used to configure 802.1x account and password authentication. After the terminal device installs the first certificate, it can continue to use the above-mentioned first SSID to configure 802.1x certificate authentication, thereby realizing automatic configuration of the certificate, and thus making the terminal user unaware of the configuration process of 802.1x certificate authentication. Furthermore, the terminal device can complete identity authentication and network access and other operations through 802.1x certificate authentication, and the terminal user is also unaware of the process. Obviously, the authentication method provided in this application can perform 802.1x certificate authentication without the terminal user being aware of it. This process is not only convenient and efficient, but also can avoid deception attacks by counterfeit APs, and has higher security.

[0163] Optionally, the first information also includes the MAC address of the terminal device, so that devices whose MAC addresses meet the preset conditions can complete the 802.1x account and password authentication, further improving the security of 802.1x authentication. In addition, since the MAC address is unique, a MAC address usually belongs to only one terminal device. By verifying the MAC address, the terminal device that has passed the 802.1x account and password authentication can be uniquely determined. For example, in some scenarios, there are multiple terminal devices that can log in with the first account and the first password. The controller can determine which terminal device has logged in with the first account and the first password through the MAC address included in the first information.

[0164] Optionally, the controller sends a response to the first information to the terminal device via a radius-accept message.

[0165] Optionally, the above-mentioned second information also includes the MAC address of the terminal device, which is used to allow the controller to check the account and MAC address at the same time to determine whether the terminal device has passed the 802.1x authentication, avoiding the terminal device that only completes the 802.1x authentication for the account but has not completed the authentication for the MAC address to apply for the first certificate, thereby further improving the security of the authentication.

[0166] Optionally, in this application, a series of operations such as the terminal device sending the first information, the second information, receiving the response to the first information, the response to the second information, obtaining the first certificate, and installing the first certificate are all implemented based on a client that can perform 802.1x authentication.

[0167] Optionally, the client used by the terminal device for 802.1x account and password authentication can be pre-installed or installed offline. Alternatively, it can be downloaded online over an unauthenticated Wi-Fi network, granting the terminal device access to the controller. For example, the client is software or a driver installed on a device such as a PC, mobile phone, or tablet. The client supports multiple authentication methods, such as PEAP and TLS. The client can also establish an HTTPs connection with the controller.

[0168] Optionally, the terminal device accesses the network using a PEAP method, such as PEAP-mschapv2 (also known as PEAP-EAP-MS-CHAPv2) or PEAP-TLS (also known as PEAP-EAP-TLS). The terminal device uses the PEAP-mschapv2 authentication method, which enables the controller to encrypt and transmit the first identity key to the terminal device.

[0169] In one possible implementation, the terminal device sending the second information to the controller includes: the terminal device receiving a redirection authorization instructing the terminal device to send the second information, and the terminal device sending the second information to the controller. Accordingly, the controller sends the redirection authorization to the terminal device and receives the second information from the terminal device. Optionally, the redirection authorization is included in a response to the first information.

[0170] In the above implementation, redirection is a network technology used to transfer a terminal device's request from one address to another. Redirection authorization authorizes the terminal device to redirect the address it is accessing to the target address when initiating access to any address. By allowing the terminal device to send the second information through redirection authorization, on the one hand, the terminal device can automatically send the second information, and on the other hand, it can send the second information to the latest address of the controller, avoiding the situation where the controller address has changed and the controller address cannot be obtained in time.

[0171] Optionally, the terminal device initiating access to any address may be automatically triggered. For example, when the terminal device receives the first identity key, the terminal device is triggered to initiate access to any address.

[0172] In another possible implementation, the terminal device sends a prompt message, where the prompt message is used to remind the user of the remaining validity period of the first certificate.

[0173] In the above embodiment, the prompt information can be a picture, sound or light, etc. For example, the terminal device sends the prompt information on the human-computer interaction interface, or the terminal device sends the prompt information by voice, or the terminal device can also send the prompt information to the user by SMS or email.

[0174] The terminal device sends a prompt message to remind the user of the remaining validity period of the first certificate, so that the user can update the first certificate in time when the remaining validity period of the first certificate is short, avoiding the phenomenon that the terminal device cannot access the network.

[0175] Optionally, the terminal device may send the above-mentioned prompt message when the remaining validity period of the first certificate is less than a first threshold, thereby avoiding reminding the user when the remaining validity period of the first certificate is sufficient, thereby affecting the user's user experience. The first threshold is greater than 0, for example, the first threshold is 10 days, that is, the terminal device may send the above-mentioned prompt message when the remaining validity period of the first certificate is less than 10 days.

[0176] Optionally, the reminder frequency of the above-mentioned reminder information can also be set, for example, once a day, or once every two days, etc. By setting the reminder frequency, it is possible to avoid interference of frequent reminders on the user.

[0177] In another possible implementation, when the remaining validity period of the first certificate is less than the first threshold and the terminal device receives a first operation from the user, or when the remaining validity period of the first certificate is equal to 0, the terminal device sends a third message. The third message is used to trigger 802.1x account and password authentication, the above-mentioned first threshold is greater than 0, and the above-mentioned first operation is used to instruct the terminal device to send a third message, and the third message includes a second account and a second password. A response to the third message is received, and the response to the third message includes a second identity key; and fourth message is sent, and the fourth message is used to apply for a second certificate, and the second certificate is used for 802.1x certificate authentication, and the fourth message includes a second account and a second identity key. Accordingly, the controller receives the third message and sends a response to the third message to the terminal device. The controller also receives fourth message.

[0178] In the above embodiment, if the remaining validity period of the first certificate is less than the first threshold and the terminal device receives a first operation from the user, for example, the terminal device sends a prompt message indicating that the remaining validity period of the first certificate is insufficient, and the user enters an account number / password, thereby triggering the terminal device to send the third information. If the remaining validity period of the first certificate is equal to 0, for example, the terminal device automatically sends the third information upon detecting that the remaining validity period of the first certificate is equal to 0, both of the above scenarios allow the terminal device to apply for the second certificate in a timely manner, thereby avoiding the situation where the terminal device cannot perform 802.1x certificate authentication.

[0179] The descriptions of the third information, the response to the third information and the fourth information can refer to the introductions of the first information, the response to the first information and the second information mentioned above, and will not be repeated here.

[0180] Optionally, the second account may be the same as or different from the first account, and similarly, the second password may be the same as or different from the first password.

[0181] Optionally, the third information further includes a second SSID. The description of the second SSID can refer to the introduction of the first SSID, which will not be repeated here. The beneficial effects of this embodiment can also refer to the description of the embodiment corresponding to the first SSID, which will not be repeated here.

[0182] Optionally, the third information further includes a MAC address of the terminal device. The beneficial effects of this embodiment can be referred to the description of the embodiment corresponding to the first information including the MAC address of the terminal device, which will not be repeated here.

[0183] Optionally, the fourth information further includes the MAC address of the terminal device. The beneficial effects of this embodiment can be referred to the description of the embodiment corresponding to the second information including the MAC address of the terminal device, which will not be repeated here.

[0184] In another possible implementation, the sending of the fourth information includes: the terminal device receiving a redirection authorization, the redirection authorization being used to instruct the terminal device to send the fourth information; and the terminal device sending the fourth information to the controller. Accordingly, the controller sends the redirection authorization to the terminal device and receives the fourth information from the terminal device. Optionally, the response to the third information includes the redirection authorization.

[0185] The beneficial effects and possible implementations of the above implementations can be found in the relevant introduction of the implementations corresponding to the above second information, which will not be repeated here.

[0186] In another possible implementation, the method further includes: the terminal device receiving a response to the second information, the response to the second information including the first certificate; the terminal device installing the first certificate and configuring the 802.1x certificate authentication based on the first SSID; the terminal device sending fifth information, the fifth information being used to trigger the 802.1x certificate authentication; and the controller accordingly sending a response to the second information, and receiving the fifth information from the terminal device.

[0187] As can be seen from the preceding, the second message is used to request the controller to send the first certificate. Before sending the first certificate, the controller verifies the first account, first identity key, or MAC address of the terminal device, etc., included in the second message. If the verification is successful, the controller generates the first certificate and includes the first certificate in the response to the second message. For example, if the verification is successful, the controller can generate the first certificate using a built-in / external certificate server and send the first certificate to the terminal device via the HTTPs channel.

[0188] After installing the first certificate, the terminal device can continue to use the above-mentioned first SSID to configure 802.1x certificate authentication, thereby realizing automatic configuration of the certificate, and thus making the terminal user unaware of the configuration process of 802.1x certificate authentication. Furthermore, the terminal device can complete identity authentication and network access and other operations through 802.1x certificate authentication, and the terminal user is also unaware of the process. Obviously, the authentication method provided by this application can perform 802.1x certificate authentication without the terminal user being aware of it. This process is not only convenient and efficient, but also can avoid deception attacks by counterfeit APs, and has higher security.

[0189] Optionally, when the terminal device obtains the first certificate, the certificate can also be used for other applications, such as secure socket layer (SSL) virtual private network (VPN) or Internet protocol security (IPSec) VPN.

[0190] See also Figure 4 , Figure 4 This is a flow chart of another authentication method provided in the embodiment of the present application. It is understandable that the steps in the embodiment of the present application can be regarded as the above Figure 3 Alternatively, it is understood that the authentication method in the embodiment of the present application can also be regarded as an embodiment that can be executed independently, and the present application does not limit this. The authentication method provided in the embodiment of the present application is applied to the field of communication technology, such as 802.1x authentication.

[0191] It is understood that the terminal device involved in the authentication method provided in the embodiment of the present application can refer to the above Figure 2 The terminal devices shown in the figure, network devices can refer to the above Figure 2 The network devices shown in the figure can refer to the controller above. Figure 2 The controller shown in .

[0192] The authentication method may include one or more steps from S401A to S414. It should be understood that for the sake of convenience, the description here is based on the order of S401A to S414, and is not intended to limit the execution to the above order. The embodiment of the present application does not limit the order of execution, execution time, and number of executions of the above one or more steps. S401A to S414 are as follows:

[0193] S401A: The terminal device pre-installs or installs the client offline. For example, the client is pre-installed on the terminal device, or the client is installed offline on the terminal device based on a client installation package stored on the terminal device.

[0194] S401B: The terminal device downloads the client from the controller online through an open or restricted network. For example, deploy a Wi-Fi network that does not require authentication and grant the terminal device partial access to the controller, allowing the client to connect to the controller and download the client online.

[0195] The above S401A and S401B are two optional steps. This application does not limit how to install the client on the terminal device. It is sufficient to ensure that the client is installed on the client.

[0196] S402: The terminal device sends first information to the controller for performing 802.1x account and password authentication. Correspondingly, the controller receives the first information from the terminal device.

[0197] The first information includes a first account and a first password.

[0198] Optionally, the first information also includes the first SSID or the MAC address of the terminal device, etc.

[0199] Optionally, an encrypted channel may be created between the terminal device and the controller via PEAP (eg, PEAP-mschapv2) to provide additional security for the authentication process.

[0200] S403: The controller sends authentication success and redirection authorization to the network device. Correspondingly, the network device receives authentication success and redirection authorization information from the controller.

[0201] For example, when the controller receives the first information, it can verify the first account and the first password through the built-in AD / LDAP server or the external AD / LDAP server. If the verification result is successful, the RADIUS server will record the first account as an account that has been authenticated by 802.1x. Optionally, if the first information includes a MAC address and the verification result is successful, the RADIUS server will also record the first account corresponding to the MAC address as an account that has been authenticated by 802.1x. Optionally, if the first information includes a first SSID, the first SSID also needs to be verified in conjunction with the first account and the first password.

[0202] If the authentication result is successful, the controller sends an authentication success and redirect authorization message to the network device. The redirect authorization is used to redirect the terminal device's access address to the controller when the terminal device initiates access to any address, and force the terminal device to send a request for obtaining a certificate.

[0203] Optionally, the network device may also send authentication success information to the terminal device. Further, the terminal device may send authentication success information to the terminal user through a human-computer interaction interface.

[0204] Of course, there is also a case where the authentication result fails, in which case the controller does not perform the above-mentioned S803 operation. Regarding the operation performed by the controller in this case, this application does not limit it. For example, if the authentication result fails, the controller sends a message indicating that the authentication result has failed to the network device.

[0205] S404: The controller generates an identity key. If the authentication result is successful, the controller generates an identity key for use in identity verification when the terminal device applies for a certificate. Exemplarily, the controller generates a first identity key through a RADIUS server.

[0206] Optionally, both S403 and S404 can be executed when the authentication result is successful. This application does not limit the order of executing S403 and S404.

[0207] S405: The controller sends the identity key to the terminal device. In response, the terminal device receives the identity key from the controller. For example, the controller sends the identity key to the terminal device via a RADIUS message. For example, the controller sends the identity key to the terminal device via a RADIUS-ACCEPT message.

[0208] S406. The terminal device stores the received identity key.

[0209] S407: The terminal device sends a request to access any address to the network device. Correspondingly, the network device receives the request from the terminal device to access any address. Exemplarily, S407 can be automatically executed. For example, after the terminal device completes S406, it triggers the initiation of an access request to any IP address. Optionally, the access request sent by the terminal device to any IP address is an HTTPs access. It should be noted that the terminal user is unaware of this step, that is, the operation is not displayed on the human-computer interaction interface of the terminal device.

[0210] S408: The network device authorizes the terminal device to redirect the Uniform Resource Locator (URL). Accordingly, the terminal device receives the URL authorized by the network device. The URL authorized by the network device to the terminal device is the controller's URL, so that any IP address sent by the network device will be directed to the access controller. It should be noted that after obtaining the certificate, the terminal device does not need to be directed to the controller when initiating an access request again.

[0211] S409: The terminal device sends a second message to the controller to request a certificate. In response, the controller receives the second message from the terminal device. The certificate requested by the terminal device from the controller, for example, the first certificate described above, is used for 802.1x certificate authentication. Exemplarily, an HTTPs link is established between the terminal device and the controller. Through this HTTPs link, the terminal device sends the second message to the controller to request the first certificate. The second message includes information such as the first account number and the first identity key. Optionally, the second message also includes the MAC address of the terminal device.

[0212] S410, the controller performs identity authentication. For example, the controller can verify whether the first account has passed the 802.1x authentication through the RADIUS server to prevent the terminal device from applying for a certificate through an account that has not been authenticated by 802.1x. The controller can also perform further verification through the first identity key, and can only send the first certificate if the first identity key verification is passed. Optionally, when the second information includes the MAC address of the terminal device, the controller can also verify the first account and the MAC address of the terminal device through the RADIUS server to determine whether the terminal device corresponding to the MAC address has completed the 802.1x authentication, so as to prevent the terminal device that has not completed the 802.1x authentication from applying for a certificate.

[0213] S411. The controller generates a certificate. For example, the controller can generate a certificate using its built-in certificate server, or it can generate a certificate using an external certificate server through an application programming interface (API). For example, a certificate can be requested from the external certificate server using the Simple Certificate Enrollment Protocol (SCEP).

[0214] S412: The controller sends the certificate to the terminal device, and the terminal device receives the certificate from the controller. For example, the controller sends the certificate to the terminal device via the HTTPs secure channel established in S409, and the terminal device receives the certificate from the terminal device via the HTTPs secure channel established in S409.

[0215] S413. The terminal device automatically installs (configures) the certificate. For example, the terminal device automatically installs the certificate after receiving it. The terminal device can also use the configuration used for the above-mentioned 802.1x account and password authentication for 802.1x certificate authentication. For example, the terminal device uses the first SSID shown in S403 to configure the 802.1x certificate authentication mode.

[0216] S414: The terminal device initiates 802.1x certificate authentication to the controller. In response, the controller receives the 802.1x certificate authentication from the terminal device. Furthermore, the controller authorizes the terminal device to have normal network access rights, and the terminal device completes network access.

[0217] pass Figure 4 The authentication method shown makes it very convenient for the terminal device to obtain the first certificate. It can also complete a series of operations such as automatic certificate installation, automatic certificate configuration, and automatic network access, thereby enabling the terminal device to access the network more securely.

[0218] above Figure 4 The authentication method shown here allows a terminal device to authenticate and log in via 802.1x certificates. After logging in, the user no longer needs to enter their username and password each time they log off and back on, achieving seamless authentication. However, certificates are valid for a limited time, and expired certificates cannot be used for 802.1x authentication. Therefore, a certificate renewal mechanism must be considered after obtaining a certificate with one click.

[0219] See also Figure 5 , Figure 5 This is a flow chart of another authentication method provided by this application. It can be understood that the steps in the embodiment of this application can be regarded as the above Figure 3 or Figure 4 Alternatively, it is understood that the authentication method in the embodiment of the present application can also be regarded as an embodiment that can be executed independently, and the present application does not limit this. The authentication method provided in the embodiment of the present application is applied to the field of communication technology, such as 802.1x authentication.

[0220] It is understood that the terminal device involved in the authentication method provided in the embodiment of the present application can refer to the above Figure 2 The terminal devices shown in the figure, network devices can refer to the above Figure 2 The network devices shown in the figure can refer to the controller above. Figure 2 The controller shown in .

[0221] The authentication method may include one or more steps from S501 to S514. It should be understood that for the sake of convenience, the description here is based on the order of S501 to S514, and is not intended to limit the execution to the above order. The embodiment of the present application does not limit the order of execution, execution time, and number of executions of the above one or more steps. S501 to S514 are as follows:

[0222] S501. The terminal device reminds the user of the certificate's validity period. For example, the terminal device reminds the user of the certificate's validity period on a human-computer interaction interface, or through voice, or through text messages or emails. For example, the terminal device reminds the user of the certificate's validity period of one day or one hour.

[0223] S502A, the terminal device sends a third message to the controller for performing 802.1x account and password authentication (manual), and accordingly, the controller receives the third message from the terminal device. For example, after the terminal user receives the reminder shown in S501, the terminal user manually enters the account / password through the client of the terminal device for 802.1x account and password authentication. The terminal device receives the account and password entered by the terminal user and sends the account and password to the controller for the controller to perform 802.1x account and password authentication on it. Optionally, the validity period of the certificate is greater than 0 and less than a first threshold, and the first threshold is greater than 0. For example, the first threshold is 5 days.

[0224] S502B: The terminal device sends third information to the controller for performing 802.1x account and password authentication (automatically). In response, the controller receives the third information from the terminal device. For example, when the validity period of the certificate is equal to 0, or when the certificate is invalid, the terminal device is automatically triggered to send the third information to the controller for performing 802.1x account and password authentication.

[0225] S503: The controller sends authentication success and redirection authorization to the network device. Correspondingly, the network device receives authentication success and redirection authorization information from the controller. Specific implementation methods can refer to the above S403 and will not be repeated here.

[0226] S504: The controller generates a new identity key. The specific implementation method can refer to the above S404 and will not be repeated here.

[0227] S505: The controller sends a new identity key to the terminal device, and correspondingly, the terminal device receives the new identity key from the controller. Specific implementation methods can refer to the above S405 and will not be repeated here.

[0228] S506. The terminal device stores the received new identity key.

[0229] S507: The terminal device sends a request to access any address to the network device. Correspondingly, the network device receives the request from the terminal device to access any address. The specific implementation method can be referred to above S407 and will not be repeated here.

[0230] S508: The network device authorizes the terminal device to redirect the URL. Correspondingly, the terminal device receives the URL authorized by the network device. The specific implementation method can be referred to above S408, which will not be repeated here.

[0231] S509: The terminal device sends fourth information to the controller for applying for a new certificate. Correspondingly, the controller receives the fourth information from the terminal device. Specific implementation methods can refer to the above S409 and will not be repeated here.

[0232] S510: The controller performs identity authentication. The specific implementation method can refer to the above S410 and will not be repeated here.

[0233] S511: The controller generates a new certificate. The specific implementation method can refer to the above S411 and will not be repeated here.

[0234] S512: The controller sends a new certificate to the terminal device. Correspondingly, the terminal device receives the new certificate from the controller. The specific implementation method can refer to the above S412 and will not be repeated here.

[0235] S513: The terminal device automatically installs (configures) a new certificate. Specific implementations can refer to the above S413 and will not be described in detail here.

[0236] S514: The terminal device initiates 802.1x certificate authentication to the controller. Correspondingly, the controller receives the 802.1x certificate authentication from the terminal device. Specific implementations can refer to the above S414 and will not be repeated here.

[0237] pass Figure 5 The authentication method shown enables the terminal device to obtain a new certificate in a timely manner when the first certificate is about to expire or has expired, thereby avoiding the situation where the terminal device cannot perform 802.1x certificate authentication. In addition, Figure 5 The process of updating the certificate in the authentication method shown can be one-click acquisition (S502A) or automatic acquisition (S502B), and the updating process is simple and convenient.

[0238] In some scenarios, the terminal device is not covered by the 802.1x network, that is, it cannot pass the above Figure 3-Figure 5 The authentication method shown completes one-click certificate acquisition. Therefore, this application provides another authentication method that allows terminal devices to directly apply for certificates using an account / password when they are not in the enterprise campus network. For example, in remote access or remote office scenarios, you can directly apply for a certificate using an account / password. This allows the terminal to directly access the network when entering the enterprise campus, or use the applied certificate for other scenarios such as remote VPN access.

[0239] See also Figure 6 , Figure 6 This is a flowchart of another authentication method provided by an embodiment of the present application. The authentication method provided by an embodiment of the present application is applied to the field of communication technology, such as 802.1x authentication.

[0240] It is understood that the terminal device involved in the authentication method provided in the embodiment of the present application can refer to the above Figure 2 The terminal devices shown in the figure, network devices can refer to the above Figure 2 The network devices shown in the figure can refer to the controller above. Figure 2 The controller shown in .

[0241] The authentication method may include one or more steps from S601 to S609. It should be understood that for the sake of convenience, the description here is made in the order of S601 to S609, and it is not intended to limit the execution to the above order. The embodiment of the present application does not limit the order of execution, execution time, and number of executions of the above one or more steps. S601 to S609 are as follows:

[0242] S601: The terminal device accesses the network in any manner. For example, the terminal device may access the network through public Wi-Fi, home Wi-Fi, or home wired network, so that the terminal device can access the public network address of the controller.

[0243] S602: The terminal device registers with the controller. For example, the terminal device accesses the controller through a client and then registers the client with the controller for subsequent configuration, upgrades, or maintenance. Furthermore, a secure channel can be established between the terminal device and the controller. For example, asymmetric encryption can be used, with the terminal device holding the public key and the server holding the private key. This ensures that information sent by the terminal device to the controller can only be decrypted by the controller, thereby improving communication security between the terminal device and the controller.

[0244] S603: The controller sends the CA certificate to the terminal device. Correspondingly, the terminal device receives the CA certificate from the controller. For example, the CA certificate is used by the terminal device to verify the legitimacy of the server to prevent the terminal device from connecting to an illegal server and leaking the account password.

[0245] S604: The terminal device establishes an HTTPs secure channel with the controller. For example, if the controller is legitimate, the terminal device and the controller interact using the public key and private key, determine a secret key for subsequent communication, and then establish an HTTPs secure channel.

[0246] S605: The terminal device sends sixth information to the controller to apply for a certificate. In response, the controller receives the sixth information from the terminal device. The sixth information includes information such as the first account number and the first password. Optionally, the sixth information also includes the MAC address of the terminal device. It should be noted that S605 can be triggered manually to apply for a certificate, or it can be triggered automatically by pre-storing the account number and password information on the terminal device.

[0247] S606: The controller performs identity authentication. For example, the controller verifies the first account and password using a built-in / external AD / LDAP server and sends the verification result back to the RADIUS server in the controller. Of course, if the sixth information includes the MAC address of the terminal device, the RADIUS server will also record the authentication result corresponding to the MAC address.

[0248] S607: The controller generates a certificate. The specific implementation method can refer to the above S411 and will not be repeated here.

[0249] S608: The controller sends the certificate to the terminal device. Correspondingly, the terminal device receives the certificate from the controller. The specific implementation can refer to S412 above and will not be repeated here. Optionally, the certificate requested by the controller can also be used in other scenarios such as remote VPN access.

[0250] S609: The terminal device automatically installs (configures) the certificate. The specific implementation method can be referred to above S413, which will not be repeated here.

[0251] Optionally, when the terminal device enters the campus network, the terminal device initiates 802.1x certificate authentication to the controller, and accordingly, the controller receives the 802.1x certificate authentication from the terminal device. Specific implementations can be referred to above S414 and will not be repeated here.

[0252] pass Figure 6The authentication method shown enables a terminal device to obtain a certificate in advance before connecting to the enterprise campus network, and automatically join the network when the terminal device connects to the enterprise campus network. Figure 6 The process of obtaining a certificate using the authentication method shown is very convenient. It can also complete a series of operations such as automatic certificate installation, automatic certificate configuration, and automatic network access, enabling terminal devices to access the network more securely.

[0253] above Figure 6 The authentication method shown here allows a terminal device to authenticate and log in via 802.1x certificates. After logging in, the user no longer needs to enter their username and password each time they log off and back on, achieving seamless authentication. However, certificates are valid for a limited time, and expired certificates cannot be used for 802.1x authentication. Therefore, a certificate renewal mechanism must be considered after obtaining a certificate with one click.

[0254] See also Figure 7 , Figure 7 This is a flow chart of another authentication method provided by this application. It can be understood that the steps in the embodiment of this application can be regarded as the above Figure 6 Alternatively, it is understood that the authentication method in the embodiment of the present application can also be regarded as an embodiment that can be executed independently, and the present application does not limit this. The authentication method provided in the embodiment of the present application is applied to the field of communication technology, such as 802.1x authentication.

[0255] It is understood that the terminal device involved in the authentication method provided in the embodiment of the present application can refer to the above Figure 2 The terminal devices shown in the figure, network devices can refer to the above Figure 2 The network devices shown in the figure can refer to the controller above. Figure 2 The controller shown in .

[0256] The authentication method may include one or more steps from S701 to S710. It should be understood that for the sake of convenience, the description here is made in the order of S701 to S710, and it is not intended to limit the execution to the above order. The embodiment of the present application does not limit the order of execution, execution time, and number of executions of the above one or more steps. S701 to S710 are as follows:

[0257] S701. The terminal device reminds the user of the certificate's validity period. For example, the terminal device reminds the user of the certificate's validity period on a human-computer interaction interface, or through voice, or through text messages or emails. For example, the terminal device reminds the user of the certificate's validity period, such as one day or one hour.

[0258] S702: The terminal device accesses the network in any manner. For the specific implementation, please refer to the relevant description of S601 above, which will not be repeated here.

[0259] S703: The terminal device registers with the controller. For the specific implementation, please refer to the relevant description of S602 above, which will not be repeated here.

[0260] S704: The controller sends the CA certificate to the terminal device. Correspondingly, the terminal device receives the CA certificate from the controller. For the specific implementation, please refer to the relevant description of S603 above, which will not be repeated here.

[0261] S705: The terminal device establishes an HTTPs secure channel with the controller. Specific implementation methods can refer to the relevant description of S604 above, which will not be repeated here.

[0262] It should be noted that the execution order of the above S701 may also be after S705.

[0263] S706A, the terminal device sends the sixth information to the controller for applying for a certificate (manually), and accordingly, the controller receives the sixth information from the terminal device. For example, after the terminal user receives the reminder shown in S701, the terminal user manually enters the account / password through the client of the terminal device for 802.1x account and password authentication. The terminal device receives the account and password entered by the terminal user and sends the account and password to the controller for the controller to perform 802.1x account and password authentication on it. Optionally, the validity period of the certificate is greater than 0 and less than a first threshold, and the first threshold is greater than 0. For example, the first threshold is 5 days.

[0264] S706B: The terminal device sends the sixth information to the controller for applying for a certificate (automatically). In response, the controller receives the sixth information from the terminal device. For example, when the validity period of the certificate is equal to 0, or when the certificate is invalid, the terminal device is automatically triggered to send the sixth information to the controller for 802.1x account and password authentication.

[0265] S707: The controller performs identity authentication. For the specific implementation, please refer to the relevant description of S606 above, which will not be repeated here.

[0266] S708: The controller generates a new certificate. For the specific implementation, please refer to the relevant description of S607 above, which will not be repeated here.

[0267] S709: The controller sends the new certificate to the terminal device. Accordingly, the terminal device receives the new certificate from the controller. For specific implementations, reference can be made to the description of S608 above, which will not be repeated here. Optionally, the certificate requested by the controller can also be used in other scenarios such as remote VPN access.

[0268] S710: The terminal device automatically installs (configures) the certificate. For the specific implementation, please refer to the relevant description of S609 above, which will not be repeated here.

[0269] Optionally, when the terminal device enters the campus network, the terminal device initiates 802.1x certificate authentication to the controller, and accordingly, the controller receives the 802.1x certificate authentication from the terminal device. Specific implementations can be referred to above S414 and will not be repeated here.

[0270] pass Figure 7 The authentication method shown enables the terminal device to obtain a new certificate in a timely manner when the first certificate is about to expire or has expired, thereby avoiding the situation where the terminal device cannot perform 802.1x certificate authentication. In addition, Figure 7 The process of updating the certificate in the authentication method shown can be one-click acquisition (S706A) or automatic acquisition (S707B), and the updating process is simple and convenient.

[0271] The client used for 802.1x authentication may be an endpoint detection and response (EDR) client, an iNode smart client, or a Ruijie authentication client. The following uses the EDR client as an example to exemplify the authentication method provided in this application.

[0272] like Figure 8A As shown, the EDR client login interface 801 includes the EDR client's slogan "EDR makes the network more secure" and a login control 802. The user can complete the EDR client login by clicking the login control 802. The EDR client login methods include: account password, code scanning, or fingerprint. Logging in to the EDR client, for example, can register the client with the controller to facilitate configuration, upgrade, or operation and maintenance management of the client (for example, S602 or S703).

[0273] like Figure 8BAs shown, 802.1x authentication configuration interface 803 can be used to configure 802.1x authentication. For example, SSID selection control 804 can be used to select Tset11 as the SSID, and authentication mode selection control 805 can be used to select PEAP as the authentication mode (also known as the message encryption mode). 802.1x authentication-related configurations may also include interface authorization status, interface access control mode, or MAC bypass authentication. Interface authorization status controls whether users are required to authenticate before accessing network resources. Interface access control modes include authentication-based and MAC-based. MAC bypass authentication enables authentication of terminals that cannot install or use a client.

[0274] like Figure 8C As shown, 802.1x account and password authentication can be performed in the 802.1x authentication interface 806. For example, the account and password to be authenticated (for example, S402 or S502B) can be entered through the control 807 for entering the account and password to perform 802.1x account and password authentication. The authentication process after entering the account and password can refer to the above Figure 3-Figure 7 Obviously, based on the authentication method provided by this application, the 802.1x authentication before the terminal device enters the network is 802.1x certificate authentication.

[0275] like Figure 8D As shown, the EDR client will also remind the remaining validity period of the certificate, for example, the information prompt interface 808 of the EDR client includes information such as "Hello! The remaining validity period of the certificate is 5 days!" When the remaining validity period is insufficient, the user can Figure 8C Re-enter your account and password on the interface shown to obtain a new certificate. When a certificate expires, the client can automatically send information such as the account and password to the controller to obtain a new certificate.

[0276] like Figure 8E As shown, the user can also enter the IP address of the controller through the search bar 809 on the EDR client to establish an HTTPs secure channel between the terminal device and the controller (for example, S603 and S604, S704 and S705). After the HTTPs secure channel between the terminal device and the controller is established, you can manually / automatically jump to the following Figure 8F In the certificate application interface 810 shown, the account and password to be authenticated (eg, S605 or S706A) are input through the control 811 for inputting the account and password to complete operations such as obtaining the certificate and installing the certificate.

[0277] Combined with the above Figures 8A to 8FAs can be seen from the description, users do not need to download certificates, install certificates, or complete 802.1x certificate authentication operations. In addition, operations such as obtaining certificates, installing certificates, and joining the network for terminal devices are very simple and convenient, which greatly reduces the complexity of operations and simplifies the difficulty of operation and maintenance, making the 802.1x certificate authentication method easy to deploy.

[0278] The above mainly introduces the authentication method provided in the embodiment of the present application. It is understandable that, in order to realize the corresponding functions mentioned above, each control unit or device includes a hardware structure and / or software module corresponding to the execution of each function. In combination with the units and steps of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0279] The embodiment of the present application can divide the functional modules of the device according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one module. The above integrated modules can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical function division. In actual implementation, there may be other division methods.

[0280] In the case of dividing each functional module according to each function, an embodiment of the present application also provides an apparatus for implementing any of the above methods, for example, providing an apparatus including units (or means) for implementing each step in any of the above methods.

[0281] For example, see Figure 9 , which is a schematic diagram of the logical structure of the communication device provided in an embodiment of the present application. Figure 9 The communication device 900 shown may be used to implement the above Figures 3 to 5 The terminal device in any embodiment of the present invention. The communication device 900 may include a sending unit 901, a receiving unit 902 and a processing unit 903.

[0282] The sending unit 901 is configured to send first information, where the first information is used to trigger 802.1x account and password authentication. The first information includes a first account and a first password.

[0283] The receiving unit 902 is configured to receive a response to the first information, where the response to the first information includes a first identity key.

[0284] The sending unit 901 is further configured to send second information, where the second information is used to apply for a first certificate, where the first certificate is used to perform 802.1x certificate authentication, and the second information includes a first account and a first identity key.

[0285] Optionally, the first information further includes a first SSID.

[0286] Optionally, the first information also includes the MAC address of the terminal device.

[0287] Optionally, the second information also includes the MAC address of the terminal device.

[0288] Optionally, the client used for 802.1x account and password authentication may be system pre-installed or installed offline, or may be downloaded online through an unauthenticated Wi-Fi network when the terminal device is allowed to access the controller.

[0289] In a possible implementation, the receiving unit 902 is further configured to receive a redirection authorization, where the redirection authorization is used to instruct the terminal device to send the second information.

[0290] In another possible implementation, the sending unit 901 is further configured to send a prompt message, where the prompt message is used to remind the user of the remaining validity period of the first certificate.

[0291] In another possible implementation, the receiving unit 902 is further configured to receive a first operation from a user, where the first operation is configured to instruct the terminal device to send third information, where the third information includes a second account number and a second password.

[0292] Optionally, the third information further includes a second SSID.

[0293] Optionally, the third information also includes the MAC address of the terminal device.

[0294] Optionally, the second account may be the same as or different from the first account, and similarly, the second password may be the same as or different from the first password.

[0295] In another possible implementation, the sending unit 901 is specifically used to send the third information when the remaining validity period of the first certificate is less than the first threshold and the receiving unit 902 receives the user's first operation, or when the remaining validity period of the first certificate is equal to 0, and the first threshold is greater than 0.

[0296] In another possible implementation, the receiving unit 902 is further configured to receive a response to the third information, the response to the third information including the second identity key. The sending unit 901 is further configured to send fourth information, the fourth information being used to apply for a second certificate, the second certificate being used for 802.1x certificate authentication, the fourth information including the second account number and the second identity key.

[0297] Optionally, the fourth information also includes the MAC address of the terminal device.

[0298] In another possible implementation, the receiving unit 902 is specifically configured to receive a redirection authorization, where the redirection authorization is used to instruct the terminal device to send the fourth information.

[0299] In another possible implementation, the receiving unit 902 is further configured to receive a response to the second information, where the response to the second information includes the first certificate.

[0300] In another possible implementation, the communication device further includes a processing unit 903 configured to install the first certificate and configure the 802.1x certificate authentication based on the first SSID.

[0301] The sending unit 901 is further configured to send fifth information, where the fifth information is used to trigger 802.1x certificate authentication.

[0302] exist Figure 9 In the described communication device 900, upon receiving the first identity key, the terminal device triggers the process of sending the second information, making the process of the terminal device obtaining the first certificate very convenient. Furthermore, upon obtaining the first certificate, the terminal device can also complete a series of operations such as automatically installing the first certificate and automatically joining the network, thereby achieving more secure network access for the terminal device.

[0303] For example, please refer to Figure 9 , Figure 9 The communication device 900 shown may be used to implement the above Figures 3 to 5 The controller of any embodiment of the present invention. The communication device 900 may include a sending unit 901, a receiving unit 902 and a processing unit 903.

[0304] The receiving unit 902 is configured to receive first information, where the first information is used to trigger 802.1x account and password authentication, and the first information includes a first account and a first password.

[0305] The processing unit 903 is configured to verify the first account and the first password.

[0306] The processing unit 903 is further configured to generate a first identity key when the first account and the first password are successfully verified.

[0307] The sending unit 901 is used to send a response to the first information, where the response to the first information includes a first identity key and a redirection authorization, and the redirection authorization is used to instruct the terminal device to send the second information.

[0308] The receiving unit 902 is further configured to receive second information, where the second information is used to apply for a first certificate, the first certificate is used to perform 802.1x certificate authentication, and the second information includes a first account and a first identity key.

[0309] Optionally, the first information further includes a first SSID.

[0310] Optionally, the first information further includes a MAC address of the terminal device, and the processing unit 903 is further configured to verify the MAC address of the terminal device.

[0311] Optionally, the second information further includes a MAC address of the terminal device, and the processing unit 903 is further configured to verify the MAC address of the terminal device.

[0312] Optionally, the sending unit 901 sends the first identity key through a radius-accept message.

[0313] In a possible implementation, the sending unit 901 is further configured to send a response to the second information, where the response to the second information includes the first certificate.

[0314] The receiving unit 902 is further configured to receive fifth information, where the fifth information is used to trigger 802.1x certificate authentication.

[0315] Optionally, the sending unit 901 sends the first certificate through an HTTPs channel.

[0316] exist Figure 9 In the described communication device 900, the controller sends a response of the first information to the terminal device, which can enable the terminal device to link to the controller on the one hand, and on the other hand, enable the terminal device to automatically apply for a certificate from the controller, thereby improving the convenience and security of applying for a certificate.

[0317] For example, please refer to Figure 9 , Figure 9 The communication device 900 shown may be used to implement the above Figure 6 or Figure 7 The controller of any embodiment of the present invention. The communication device 900 may include a sending unit 901, a receiving unit 902 and a processing unit 903.

[0318] The sending unit 901 is configured to send a request for establishing a secure channel to a target address.

[0319] The receiving unit 902 is configured to receive a CA certificate.

[0320] The processing unit 903 is configured to verify the CA certificate.

[0321] The sending unit 901 is further configured to send sixth information, where the sixth information is used to obtain the first certificate. The sixth information includes the first account and the first password.

[0322] The receiving unit 902 is further configured to receive a response to the sixth information, where the response to the sixth information includes a first certificate, and the first certificate is used for 802.1x certificate authentication.

[0323] Optionally, the sending unit 901 is further configured to send the first certificate through the HTTPs secure channel to ensure security of the certificate transfer.

[0324] Optionally, the sixth information also includes the MAC address of the terminal device.

[0325] exist Figure 9 The communication device 900 described above facilitates the process of obtaining the first certificate for the terminal device. Furthermore, upon obtaining the first certificate, the terminal device can also automatically install the first certificate and automatically access the network, thereby enabling the terminal device to access the network more securely.

[0326] For example, please refer to Figure 9 , Figure 9 The communication device 900 shown may be used to implement the above Figure 6 or Figure 7 The communication device 900 may include a sending unit 901, a receiving unit 902 and a processing unit 903.

[0327] The receiving unit 902 is configured to receive a request for establishing a secure channel.

[0328] The sending unit 901 is configured to send a CA certificate.

[0329] The receiving unit 902 is further configured to receive sixth information, where the sixth information is used to obtain the first certificate, and the sixth information includes the first account and the first password.

[0330] The processing unit 903 is configured to verify the first account and the first password.

[0331] The sending unit 901 is further configured to send a response to the sixth information if the verification by the processing unit 903 is successful, where the response to the sixth information includes the first certificate.

[0332] Optionally, the sixth information also includes the MAC address of the terminal device.

[0333] exist Figure 9 The communication device 900 described above facilitates the process of obtaining the first certificate for the terminal device. Furthermore, upon obtaining the first certificate, the terminal device can also automatically install the first certificate and automatically access the network, thereby enabling the terminal device to access the network more securely.

[0334] exist Figure 9 The communication device 900 described above facilitates the process of obtaining the first certificate for the terminal device. Furthermore, upon obtaining the first certificate, the terminal device can also automatically install the first certificate and automatically access the network, thereby enabling the terminal device to access the network more securely.

[0335] It should be understood that the division of the various units in the above-mentioned communication device 900 is only a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. In addition, the units in the device can be implemented in the form of a processor calling software. For example, the device includes a processor, the processor is connected to a memory, and instructions are stored in the memory. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units of the device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units can be implemented by designing the hardware circuits. The hardware circuit can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of some or all of the above units are implemented by designing the logical relationships between the components within the circuit. For example, in another implementation, the hardware circuit can be implemented by a programmable logic device (PLD), such as a field programmable gate array (FPGA), which can include a large number of logic gate circuits. The connection relationship between the logic gate circuits is configured through a configuration file, thereby realizing the functions of some or all of the above units. All units of the above device can be implemented in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.

[0336] In an embodiment of the present application, a processor is a circuit with data processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a CPU, a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by an ASIC or PLD, such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and implementing the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0337] It can be seen that each unit in the above device can be one or more processors (or processing circuits) configured to implement the above method, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.

[0338] In addition, the various units in the above devices can be fully or partially integrated together, or can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or implementing the functions of the various units of the device. The type of the at least one processor can be different, for example, including a CPU and FPGA, a CPU and an artificial intelligence processor, a CPU and a GPU, etc.

[0339] For example, see Figure 10 , which is a schematic diagram of the physical device structure of the communication device provided by this application. Figure 10 The embodiment of the present application provides a communication device for realizing the above Figures 3 to 7The device may be a network device or a device for a network device. The device for a network device may be a system-on-chip (SoC) or chip within the network device. The SoC may consist of a chip alone or include a chip and other discrete components. The communication device 1000 includes a processor 1001, a memory 1002, and a communication interface 1003. The processor 1001, the communication interface 1003, and the memory 1002 may be interconnected or connected via a bus 1004.

[0340] Exemplarily, the memory 1002 is used to store computer programs and data of the communication device 1000. The memory 1002 may include, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or portable read-only memory (CD-ROM), etc.

[0341] The software or program codes required for all or part of the functions of the communication device in the above method embodiment are stored in the memory 1002 .

[0342] In one possible implementation, if the software or program code required for some functions is stored in the memory 1002, the processor 1001, in addition to calling the program code in the memory 1002 to implement some functions, can also cooperate with other components (such as the communication interface 1003) to jointly complete other functions described in the method embodiment (such as the function of receiving or sending data).

[0343] There may be multiple communication interfaces 1003 , which are used to support the communication device 1000 to perform communication, such as receiving or sending data or signals.

[0344] For example, the processor 1001 may be the CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms. The processor 1001 may be used to read the program stored in the memory 1002 and execute the above-mentioned program. Figures 3 to 7 and operations performed by the communication device in possible embodiments thereof.

[0345] Figure 10 The specific operations and beneficial effects of each unit in the communication device 1000 shown can be found in the corresponding description in the above method embodiment, and will not be repeated here.

[0346] The embodiment of the present application also provides a chip, which includes a processor and a memory. The memory is used to store computer programs or computer instructions, and the processor is used to execute the computer programs or computer instructions stored in the memory, so that the chip performs the above Figures 3 to 7 and operations performed by the terminal device in possible embodiments thereof.

[0347] The embodiment of the present application also provides a chip, which includes a processor and a memory. The memory is used to store computer programs or computer instructions, and the processor is used to execute the computer programs or computer instructions stored in the memory, so that the chip performs the above Figures 3 to 7 and the operations performed by the controller in possible embodiments thereof.

[0348] The present invention also provides a computer-readable storage medium that stores a computer program or computer instructions, which are executed by a processor to implement the above Figures 3 to 7 And the method implemented by the terminal device of its possible embodiment.

[0349] The present invention also provides a computer-readable storage medium that stores a computer program or computer instructions, which are executed by a processor to implement the above Figures 3 to 7 and methods implemented by a controller in its possible embodiments.

[0350] The present application also provides a computer program product. When the computer program product is read and executed by a computer, the above Figures 3 to 7 The method implemented by the terminal device in its possible embodiments will be executed.

[0351] The present application also provides a computer program product. When the computer program product is read and executed by a computer, the above Figures 3 to 7 And the method implemented by the final controller in its possible embodiment will be executed.

[0352] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a high-density digital video disc (DVD)), or a semiconductor medium (eg, a solid state disc (SSD)).

[0353] The units in the above-mentioned various apparatus embodiments completely correspond to the electronic devices in the method embodiments, and the corresponding modules or units perform the corresponding steps. For example, the communication unit (transceiver) performs the receiving or sending steps in the method embodiments, and other steps except sending and receiving can be performed by the processing unit (processor). The functions of the specific units can be referred to the corresponding method embodiments. Among them, there can be one or more processors.

[0354] It is understood that in the embodiments of the present application, the electronic device can perform some or all of the steps in the embodiments of the present application. These steps or operations are merely examples, and the embodiments of the present application can also perform other operations or variations of various operations. In addition, the various steps can be performed in a different order than those presented in the embodiments of the present application, and it is possible that not all operations in the embodiments of the present application need to be performed.

[0355] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0356] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0357] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0358] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0359] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0360] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.

[0361] The above is only a specific implementation method of the present application, but the scope of protection of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the scope of protection of the present application.

Claims

1. An authentication method, characterized in that: Applied to a terminal device, the method includes: Sending first information, where the first information is used to trigger 802.1x account and password authentication, and the first information includes a first account and a first password; receiving a response to the first information, the response to the first information including a first identity key; Sending second information, where the second information is used to apply for a first certificate, the first certificate is used to perform 802.1x certificate authentication, and the second information includes the first account and the first identity key.

2. The method according to claim 1, characterized in that The sending of the second information includes: receiving a redirection authorization, where the redirection authorization is used to instruct the terminal device to send the second information; The second information is sent.

3. The method according to claim 1 or 2, characterized in that The method further comprises: Sending a prompt message, where the prompt message is used to remind the user of the remaining validity period of the first certificate.

4. The method according to claim 3, characterized in that The method further comprises: When the remaining validity period is less than a first threshold and the terminal device receives a first operation from the user, or when the remaining validity period is equal to 0, sending third information; the third information is used to trigger 802.1x account and password authentication, the first threshold is greater than 0, and the first operation is used to instruct the terminal device to send the third information, the third information including the second account and the second password; receiving a response to the third information, wherein the response to the third information includes a second identity key; Sending fourth information, where the fourth information is used to apply for a second certificate, the second certificate is used to perform 802.1x certificate authentication, and the fourth information includes the second account number and the second identity key.

5. The method according to claim 4, characterized in that The sending of the fourth information includes: receiving a redirection authorization, where the redirection authorization is used to instruct the terminal device to send the fourth information; Send the fourth information.

6. The method according to any one of claims 1 to 5, characterized in that The first information further includes a first service set identifier SSID, and the method further includes: receiving a response to the second information, wherein the response to the second information includes the first certificate; Install the first certificate and configure the 802.1x certificate authentication based on the first SSID; Send fifth information, where the fifth information is used to trigger 802.1x certificate authentication.

7. An authentication method, characterized in that: Applied to a controller, the method includes: Receive first information from a terminal device, where the first information is used to trigger 802.1x account and password authentication, and the first information includes a first account and a first password; Sending a response to the first information to the terminal device, where the response to the first information includes a first identity key and a redirection authorization, where the redirection authorization is used to instruct the terminal device to send second information; The second information is received from the terminal device, where the second information is used to apply for a first certificate, the first certificate is used to perform 802.1x certificate authentication, and the second information includes the first account and the first identity key.

8. The method according to claim 7, characterized in that The method further comprises: Sending a response to the second information to the terminal device, where the response to the second information includes the first certificate; Fifth information is received from the terminal device, where the fifth information is used to trigger 802.1x certificate authentication.

9. An authentication system, characterized in that: include: terminal devices and controllers; The terminal device is used to execute the method according to any one of claims 1 to 6, and the controller is used to execute the method according to claim 7 or 8.

10. A communication device, characterized in that: Comprising means for performing the method according to any one of claims 1 to 8.

11. A communication device, characterized in that: The method comprises a processor configured to execute the method according to any one of claims 1 to 8.

12. A communication device, characterized in that: comprising a logic circuit and an interface, wherein the logic circuit and the interface are coupled; The interface is used to input and / or output information, and the logic circuit is used to execute the method according to any one of claims 1 to 8.

13. A computer-readable storage medium, characterized in that The computer-readable storage medium is used to store a computer program. When the computer program is executed, the method according to any one of claims 1 to 8 is performed.

14. A computer program product, characterized in that The computer program product comprises instructions, which, when executed by a processor, enable the method according to any one of claims 1 to 8 to be implemented.