Address management method, device and equipment and computer readable storage medium
By adjusting the IP address lease duration based on the authentication status of the user device, the problem of IP address exhaustion caused by frequent IP address requests by user devices is solved, thereby improving IP address utilization and network experience.
Patent Information
- Application Number
- CN202410460868.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-12
- Publication Date
- 2025-10-21
AI Technical Summary
When user devices frequently request IP addresses, the number of available IP addresses in the network is quickly exhausted, causing new access devices to be unable to obtain IP addresses and affecting the network experience.
Based on the authentication status of user devices, shorten the lease duration of IP addresses for unauthenticated devices, release unused IP addresses, and improve the utilization rate of IP addresses.
By flexibly adjusting the IP address lease duration, the IP address usage of unauthenticated devices can be reduced, the utilization rate of IP addresses can be improved, and the network experience of newly connected devices can be enhanced.
Smart Images

Figure CN120825486A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to an address management method, apparatus, device, and computer-readable storage medium. Background Art
[0002] In the field of communications technology, when a user device requests access to a network such as an enterprise campus network or a campus network, it must first be authenticated. Only after passing authentication can the user device access the network. In some cases, the user device authentication process includes requesting an Internet Protocol (IP) address from an address device and then performing interactive authentication with the authentication device based on the assigned IP address.
[0003] If a user device requests an IP address from the address management device multiple times within a short period of time, frequently accessing the network based on the IP address, the network's available IP addresses will be quickly depleted. The address management device will be unable to assign IP addresses to newly connected user devices, resulting in a poor user experience. Therefore, an address management method is urgently needed to allocate IP addresses to user devices. Summary of the Invention
[0004] This application provides an address management method, apparatus, device, and computer-readable storage medium for allocating IP addresses to user devices. The technical solution is as follows:
[0005] In a first aspect, an address management method is provided, the method comprising: obtaining an address request sent by a user device, the address request being used to request allocation of an IP address used in a communication process of the user device; obtaining an authentication status of the user device; and shortening a lease duration of an IP address allocated to the user device when the authentication status indicates that the user device has not passed authentication.
[0006] The address management method provided in this application is highly flexible and selects unauthenticated user devices from the user devices to shorten their leases based on whether the user device has been authenticated. If the user device has not been authenticated, the user device is considered an unauthorized illegal device. The lease duration of the IP address used by the illegal device is shortened, allowing the IP address used by the illegal device to expire quickly and be released. The released IP address can then be allocated to a newly connected user device, thereby improving the utilization rate of the IP address.
[0007] In a possible implementation, the authentication status includes a first status, where the first status is used to indicate whether the user equipment passes authentication at a first moment, where the first moment is earlier than a moment when the user equipment obtains an IP address.
[0008] In one possible implementation, obtaining the authentication status of the user device includes: obtaining a device identifier of the user device; and determining a first status of the user device based on the device identifier. The first status of the user device can be found based on the device identifier, which simplifies the determination process and increases the efficiency.
[0009] In one possible implementation, the user device's failure to authenticate includes the user device's failure to authenticate at the first moment or failure to authenticate at the first moment, the address request includes a lease duration, and the lease duration indicates the duration for which the user device requests to use the IP address; shortening the lease duration of the IP address corresponding to the user device includes: shortening the lease duration carried in the address request to obtain a modified address request; and sending the modified address request to the address device, the modified address request being used to instruct the address device to allocate an IP address to the user device according to the shortened lease duration. In the process of allocating an IP address to the user device, the lease duration of the allocated IP address can be shortened, and the allocation of the IP address and the shortening of the lease duration are performed simultaneously, resulting in high processing efficiency.
[0010] In one possible implementation, after shortening the lease of an IP address assigned to a user device, the method further includes: when the user device uses the IP address with the shortened lease for authentication, and if the authentication is successful, sending a lease recovery request to the address device, the recovery request instructing the address device to extend the lease of the IP address assigned to the user device. For user devices that pass authentication, the lease of the IP address used by the user device is promptly extended, thereby preventing the user device from frequently applying for IP addresses due to IP address expiration, controlling the number of IP address applications by the user device, and reducing network load.
[0011] In a possible implementation, the authentication status includes a second status, where the second status is used to indicate whether the user equipment has passed the authentication at a second moment, where the second moment is later than the moment when the user equipment obtains the IP address.
[0012] This application does not limit the authentication status obtained. It can be a first status used to describe historical authentication situations, or a second status used to describe current authentication situations, which is highly flexible.
[0013] In one possible scenario, obtaining the authentication status of a user device includes obtaining an authentication result sent by an authentication device and obtaining a second status based on the authentication result. The authentication result is obtained by the user device interacting with the authentication device based on the IP address. The second status can be obtained based on the interaction with the authentication device. The process of obtaining the second status is simple and efficient.
[0014] In one possible implementation, the user device's failure to pass authentication includes the user device failing authentication at a second moment, thereby shortening the lease duration of the IP address assigned to the user device, including: sending an IP address release request to the address device, the release request being used to instruct the address device to release at least one IP address that has been assigned to the user device and whose lease duration has not expired. Even if the IP address has already been assigned to the user device, the IP address lease duration of the user device can be shortened by releasing the IP address, thereby preventing the user device from occupying the IP address for a long time. Furthermore, after the second state indicates that the authentication has failed, a release request will be sent promptly to release the IP address, and the release is highly immediate.
[0015] In one possible implementation, before sending the IP address release request to the address device, the process also includes: counting the number of authentication failures of the user device during a reference period; and obtaining an IP address release request if the number of failures is not less than a failure threshold. After the user device fails authentication, the process further determines the number of failures. Only when the number of failures is not less than the failure threshold is the IP address released, allowing for more precise timing of IP address release.
[0016] In one possible implementation, the method further includes: restricting the user device from continuing to request a new IP address from the address device. In addition to releasing the occupied IP address, the method also restricts the user device from applying for a new IP address, providing a more comprehensive restriction policy for the user device.
[0017] In one possible implementation, the communication requirements of the user device indicate that the user device requests access to a reference network with authentication requirements, and the user device's authorization authentication requirements include authentication requirements for access rights to the reference network. The address management method provided in this application is also applicable to access scenarios of the reference network and has high versatility.
[0018] In the second aspect, an address management device is provided, which includes: an acquisition module for acquiring an address request sent by a user device, the address request being used to request allocation of an IP address used in the communication process of the user device; the acquisition module is also used to acquire the authentication status of the user device; and a shortening module is used to shorten the lease duration of the IP address allocated to the user device when the authentication status indicates that the user device has not passed the authentication.
[0019] In a possible implementation, the authentication status includes a first status, where the first status is used to indicate whether the user equipment passes authentication at a first moment, where the first moment is earlier than a moment when the user equipment obtains an IP address.
[0020] In a possible implementation, the acquisition module is configured to acquire a device identifier of the user equipment; and determine the first state of the user equipment according to the device identifier.
[0021] In one possible implementation, the user device fails to pass authentication, including the user device failing to authenticate at the first moment or failing to pass authentication at the first moment, the address request includes a lease duration, and the lease duration indicates the duration for which the user device requests to use the IP address; a shortening module is used to shorten the lease duration carried in the address request to obtain a modified address request; and the modified address request is sent to the address device, where the modified address request is used to instruct the address device to allocate an IP address to the user device according to the shortened lease duration.
[0022] In one possible implementation, the device also includes: an extension module, which is used to send a lease recovery request to the address device when the user device uses the IP address with a shortened lease time for authentication and the authentication is passed. The recovery request is used to instruct the address device to extend the lease time of the IP address allocated to the user device.
[0023] In a possible implementation, the authentication status includes a second status, where the second status is used to indicate whether the user equipment has passed the authentication at a second moment, where the second moment is later than the moment when the user equipment obtains the IP address.
[0024] In a possible implementation, the acquisition module is configured to acquire an authentication result sent by the authentication device and obtain the second state according to the authentication result, wherein the authentication result is obtained by the user device interacting with the authentication device based on the IP address.
[0025] In one possible implementation, the user equipment fails to pass the authentication, including the user equipment fails to pass the authentication at the second moment, and the shortening module is used to send a release request of the IP address to the address device, and the release request is used to instruct the address device to release at least one IP address that has been allocated to the user equipment and the lease duration has not expired.
[0026] In a possible implementation, the acquisition module is further configured to count the number of authentication failures of the user equipment during the reference period; and to acquire a release request for the IP address when the number of failures is not less than a failure threshold.
[0027] In a possible implementation, the apparatus further includes: a restriction module, configured to restrict the user equipment from continuing to request a new IP address from the address device.
[0028] In a possible implementation, the communication requirement of the user equipment indicates that the user equipment requests access to a reference network having authentication requirements, and the authority authentication requirements of the user equipment include authentication requirements for access rights to the reference network.
[0029] In a third aspect, an address management device is provided, comprising a processor configured to load and execute at least one instruction so that the address management device performs the method in the first aspect or any possible implementation of the first aspect.
[0030] In a possible implementation, the device includes a memory coupled to a processor, and the memory stores at least one instruction.
[0031] In a fourth aspect, a computer-readable storage medium is provided, in which at least one instruction is stored. The instruction is loaded and executed by a processor to implement the address management method in the first aspect or any possible implementation of the first aspect.
[0032] In a fifth aspect, a computer program (product) is provided, which includes a computer program / instructions, and the computer program / instructions are executed by a processor to enable a computer to implement the address management method in the first aspect or any possible implementation of the first aspect.
[0033] In a sixth aspect, a communication device is provided, comprising: a transceiver, a memory, and a processor. The transceiver, the memory, and the processor communicate with each other via an internal connection path. The memory is configured to store instructions, and the processor is configured to execute the instructions stored in the memory to control the transceiver to receive signals and to control the transceiver to transmit signals. When the processor executes the instructions stored in the memory, the processor performs the method according to the first aspect or any possible implementation of the first aspect.
[0034] Optionally, there are one or more processors and one or more memories.
[0035] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
[0036] In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated on the same chip as the processor or be set on different chips. This application does not limit the type of memory and the setting method of the memory and the processor.
[0037] In a seventh aspect, a chip is provided, comprising a processor for calling and executing program instructions or codes stored in a memory, so that a communication device equipped with the chip executes the methods in the above aspects.
[0038] In an eighth aspect, another chip is provided, comprising: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected through an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the processor is used to execute the methods in the above aspects.
[0039] It should be understood that the beneficial effects achieved by the technical solutions of the second to eighth aspects of this application and the corresponding possible implementation methods can be referred to the technical effects of the first aspect and its corresponding possible implementation methods mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 A schematic diagram of an implementation environment provided for an embodiment of the present application;
[0041] Figure 2 A schematic diagram of another implementation environment provided for an embodiment of the present application;
[0042] Figure 3 A flowchart of an address management method provided in an embodiment of the present application;
[0043] Figure 4 An interactive flow chart for shortening the lease duration of an IP address provided in an embodiment of the present application;
[0044] Figure 5 Another interactive flow chart for shortening the lease time of an IP address provided in an embodiment of the present application;
[0045] Figure 6 A schematic diagram of the structure of an address management device provided in an embodiment of the present application;
[0046] Figure 7 A schematic diagram of the structure of a network device provided in an embodiment of the present application;
[0047] Figure 8 A schematic diagram of the structure of another network device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0048] The terms used in the embodiments of this application are only used to explain the specific embodiments of this application and are not intended to limit this application. To make the purpose, technical solutions and advantages of this application clearer, the embodiments of this application will be further described in detail below with reference to the accompanying drawings.
[0049] In the field of communications technology, when a user uses a user device to communicate with other devices, they first request an IP address from an address device. Based on the allocated IP address, they send and receive data packets with the other device, completing communication with the other device. A user device can be any terminal capable of interacting with a user, and an address device can be, for example, a Dynamic Host Configuration Protocol (DHCP) server or other device for managing IP addresses. Alternatively, when the other device with which the user device communicates is a network device configured in the network, the process of communication between the user device and the network device can be referred to as the user device accessing the network.
[0050] In one possible scenario, the user device requires authentication. For example, if the network other devices are located on is a highly secure enterprise campus network, a school network, or a business district network, the user device will first undergo security authentication and only after passing authentication will it be allowed to communicate with other devices configured in the network. Therefore, after being assigned an IP address, the user device will first interact with the authentication device to verify the security of the user device. Only after passing authentication can the user device access the network based on the IP address.
[0051] Because the user device's request for an IP address from the address device occurs before the user device is authenticated, for example, when a user device uses a portal authentication method, it obtains an IP address before authentication. Therefore, regardless of whether the user device passes authentication, it can obtain an IP address on the network and retains the right to use the IP address for the duration of the IP address lease. The IP address remains occupied by the user device. For example, if an unauthenticated user device is an unauthorized terminal and the address device is a DHCP server, when many unauthorized terminals access the wireless network, the DHCP server will assign an IP address to each unauthorized terminal and sign an address lease with the unauthorized terminal. The unauthorized terminal will retain the right to use the IP address for the duration of the lease. This situation can lead to a rapid depletion of available IP addresses in times of high user turnover. If multiple unauthorized terminals occupy multiple IP addresses, the DHCP server will be unable to assign IP addresses to newly connected terminals, impacting the wireless network experience for newly connected terminals.
[0052] The embodiment of the present application provides an address management method for managing the IP address allocated to the user equipment. Figure 1, which shows a schematic diagram of the implementation environment of the address management method provided by the embodiment of the present application. The implementation environment includes user equipment 01, access device 02, authentication device 03 and address device 04. Among them, user equipment 01 establishes communication connections with authentication device 03 and address device 04 respectively through access device 02. Figure 1 The connection relationship shown in FIG can be implemented through a wired or wireless network.
[0053] Optionally, user device 01 sends an address request to address device 04 to request allocation of an IP address. After obtaining the IP address, user device 01 can interact with authentication device 03 based on the allocated IP address to implement permission authentication. During the interaction between user device 01, address device 04, and authentication device 03, access device 02 can execute the address management method provided in the embodiment of the present application and adjust the lease duration of the IP address allocated to user device 01 by address device 04 based on the authentication status of user device 01.
[0054] In one possible implementation, when authentication device 03 and address device 04 can communicate directly, the address management method provided in the embodiment of the present application can also be executed by other devices such as address device 04. For example, address device 04 receives the authentication result sent by authentication device 03 to obtain the authentication status of user device 01, and adjusts the lease duration of the IP address corresponding to user device 01 based on the authentication status of user device 01.
[0055] For example, user equipment 01 refers to a physical device used to access a communication network or a computing system. User equipment 01 may be Figure 2 Any terminal device shown includes but is not limited to a desktop computer, a laptop computer, a tablet computer, or a smart phone. Optionally, the user device 01 may also be a server, such as a central server, an edge server, or a local server in a local data center. The server may be a physical server or a cloud server providing cloud computing services.
[0056] Optionally, the access device 02 may be Figure 2 As shown, the access control point configured at the access network, such as a wireless access point (AP) or a local area network switch (LSW), provides network admission control (NAC) capabilities, connects terminals with data centers, servers, and other networks, carries network traffic, and manages user device 01 based on different access policies authorized by different users.
[0057] For example, the authentication device 03 may be Figure 2The authentication server includes a policy control module and functional modules corresponding to the remote authentication dial-in user service server (RADIUS server). The policy control module is used to configure access control policies, and the RADIUS server is used to determine whether to authorize a request from user device 01 based on the configured access control policies. For example, the RADIUS server searches the access control policy based on factors such as the identity information of the user using user device 01, device information of user device 01, and the network connection type used by user device 01 to determine whether to authorize the request from user device 01. In some cases, the authentication server can also perform authorization and billing after completing authentication of user device 01.
[0058] Optionally, the address device 04 can be Figure 2 The DHCP server shown includes a DHCP address allocation management module for centralized management and allocation of IP addresses, enabling network devices in the network environment to dynamically obtain information such as IP addresses, gateway addresses, and domain name server (DNS) addresses. Dynamic address allocation effectively improves address utilization.
[0059] Furthermore, user device 01, access device 02, authentication device 03, and address device 04 may not only be independent devices but also components on the devices, such as transceivers, processors, or chips. In one possible scenario, authentication device 03 and address device 04 may be independent network devices or integrated into the same network device, i.e., components corresponding to authentication device 03 and components corresponding to address device 04 may be configured on the same network device.
[0060] The present invention provides an address management method, which can be applied to the above Figure 1 or Figure 2 The implementation environment shown in FIG. 1 is shown in FIG. 1 , and the method is applied to an access device as an example. The flow chart of the method is as follows: Figure 3 As shown, including S301-S303.
[0061] S301: Acquire an address request sent by a user equipment, where the address request is used to request allocation of an IP address used by the user equipment during communication.
[0062] For example, the user equipment may be any terminal that interacts with the user, see Figure 2, the terminal is, for example, a desktop computer, a laptop, a tablet or a mobile phone, etc. Regardless of the user device, when the user uses the user device to communicate with other devices in the network, the user will first interact with the address device and send an address request to the address device to request allocation of an IP address.
[0063] In one possible scenario, a user device sends an address request to an address device based on communication requirements. Sending an address request based on communication requirements may refer to selecting an address device to receive the address request based on the communication requirements. For example, if the user device's communication requirements include requesting network access, the user device may send an address request to an address device in the network to be accessed. For example, the address request may be broadcast to multiple address devices configured in the network. If the network is a local area network, the address device may be an address server used to allocate private IP addresses.
[0064] Optionally, the user device may also generate an address request based on communication requirements and send the address request carrying communication requirement information. The communication requirement information carried in the address request may be the network identifier of the network the user device requests access to, or device information of the network device for which a communication connection is being established. After generating the address request based on the communication requirements, the user device sends the address request to the address device, requesting that the address device allocate an IP address usable during communication based on the user device's communication requirements. For example, if the communication requirement is to request access to any network, the address device may allocate the IP address corresponding to that network to the user device based on the IP addresses it manages.
[0065] Regardless of the method in which the user equipment sends the address request to the address device, the access device can receive the address request sent by the user equipment. Figure 2 Because the interaction between the user device and the address device is implemented based on the access device, the user device first sends an address request to the access device, which then sends the address request to the address device. In this case, the access device can receive the address request sent by the user device while the user device is sending the address request.
[0066] Alternatively, the access device enables the DHCP snooping function to intercept the address request sent by the user device to the address device. Figure 4 An interactive diagram of address allocation provided in an embodiment of the present application is provided in Figure 4 For example, the user device is a terminal and the address device is a DHCP server. The address request sent by the terminal to the access device is a DHCP request message. The DHCP request message carries the terminal's media access control (MAC) address. The access device enables DHCP Snooping and receives the DHCP request message.
[0067] S302: Obtain the authentication status of the user device.
[0068] In one possible implementation, the access device can determine whether the user device requires authorization based on a received address request. For example, the network the user device requests access to is determined based on the address request; and whether the user device requires authorization based on the network requested. For example, in the case of a user device selecting an address device to receive an address request based on communication requirements, the address device is a device on the network the user device requests access to, and the access device is responsible for connecting the user device to that network. Therefore, upon receiving the address request from the user device, the access device determines that the network the user device requests access to is a managed network.
[0069] In the event that a user device includes communication requirement information in an address request, the access device can parse the received address request and determine the network the user device requests to access based on the communication requirement information carried in the address request. For example, the access device can determine the network the user device requests to access based on a network identifier, or determine the network device for which a communication connection is being requested based on device information, and then determine the network on which the network device is located as the network the user device requests to access. Regardless of how the access device determines the network the user device requests to access, it can determine whether the user device requires authorization based on the network requested to access.
[0070] In one possible scenario, the network requested by a user device is a reference network for which authentication requirements exist. The access device then determines that the user device is a user device to be authenticated, and the existing authentication requirements include authentication requirements for access rights to the reference network. Examples of reference networks include enterprise campus networks, school networks, and business district networks. Due to the high security of reference networks, user devices requesting access to the reference networks must be authenticated to determine whether they have access rights. This prevents unauthorized devices with low security from accessing the reference networks, potentially leading to data leaks or other security risks within the reference networks.
[0071] Next, examples are given to illustrate the complete process of the access device determining whether the user device has an authorization authentication requirement based on the received address request when the user device sends an address request based on communication requirements in different ways. In the case where the user device selects an address device to send an address request based on communication requirements, the access device is used to connect the user device and the reference network and manage the user device's access to the reference network. In this case, the access device determines the user device that sent the address request as a user device to be authenticated for the received address request. In the case where the address request sent by the user device carries communication requirements, the access device can parse the address request and determine the network that the user device requests to access. In the case where the network requested to be accessed is a reference network with authentication requirements, the user device is determined to be a user device to be authenticated.
[0072] Regardless of how the access device determines whether a user device requires authorization authentication, the access device can, if the user device does not require authorization authentication, directly send the user device's address request to the address device. Furthermore, if the user device requires authorization authentication, the access device can obtain the user device's authentication status to manage the lease duration of the IP address allocated to the user device based on the authentication status.
[0073] The embodiment of the present application does not limit the authentication status obtained by the access device. Based on the different acquisition moments, it can be divided into a first state and a second state. Among them, the first state is used to indicate whether the user device has passed the authentication at the first moment, and the second state is used to indicate whether the user device has passed the authentication at the second moment. The first moment is earlier than the moment when the user device obtains the IP address, and the second moment is later than the moment when the user device obtains the IP address. That is, the first state is used to reflect the authentication status of the user device at a historical moment, and the second state is used to reflect the authentication status performed by the user device based on the currently obtained IP address. The following describes the methods for obtaining different authentication states.
[0074] Acquisition method 1: Acquire a device identifier of a user device; and determine a first state of the user device according to the device identifier.
[0075] Exemplarily, the device identifier may be any information used to identify different user devices, and may be a physical address of the user device, such as a MAC address, or a device name. In one possible implementation, the access device may obtain a device identifier sent separately by the user device, for example, by sending an identifier acquisition request to the user device and receiving a device identifier returned by the user device.
[0076] In one possible scenario, when a user device sends an address request to an address device to request an IP address, the user device will carry a device identifier in the address request. After the address device selects an IP address that can be assigned to the user device, it can establish a correspondence between the device identifier and the IP address to clarify the user device to which the IP address is assigned. In this case, the access device can also parse the obtained address request, extract the device identifier of the user device from the parsed result, and obtain the device identifier. For example Figure 4 In the case of configuring wireless AP and LSW in the access network, the access device extracts the MAC address in the DHCP request message and obtains the device identification of the user device. Figure 4 The access device that interacts with the terminal may be a wireless AP. The interaction between the wireless AP and the authentication device may be implemented based on the LSW. That is, an LSW is also configured between the access device and the authentication device.
[0077] Regardless of how the access device obtains the device identification of the user device, since there is a correspondence between the device identification of the user device and the authentication status, the access device can search for the correspondence based on the device identification to determine whether the user device has been authenticated at the first moment. If the user device has not been authenticated at the first moment, the first status indicates that the user device has not been authenticated. If the user device has been authenticated at the first moment, the access device further obtains the authentication result to determine whether the user device has been authenticated. The obtained first status indicates whether the user device has been authenticated at the first moment. The above process corresponds to Figure 4 In the operation, check the terminal authentication status based on the MAC address.
[0078] Since the first moment refers to any historical moment prior to the user device obtaining an IP address based on an address request, the first moment may also include one or more historical moments based on the number of authentications performed by the user device at different historical moments. If the user device has only authenticated once, the access device may determine the first status based on the result of that authentication. If the user device has authenticated multiple times, the access device may count a first number of authentication failures and a second number of authentication successes during the multiple authentications. If the first number is not less than the second number, the first status is determined to indicate that the user device failed authentication at the first moment; if the first number is less than the second number, the first status is determined to indicate that the user device passed authentication at the first moment. Alternatively, the access device may determine whether any authentications during the multiple authentications performed by the user device have failed. If so, the first status is determined to be authentication failure; if not, the first status is determined to be authentication success. Alternatively, the access device may determine the most recent authentication result from the current moment. If the authentication result is authentication success, the first status is determined to be authentication success; otherwise, if the authentication result is authentication failure, the first status is determined to be authentication failure.
[0079] Acquisition method 2: Acquire the authentication result sent by the authentication device and obtain the second state according to the authentication result. The authentication result is obtained by the user device interacting with the authentication device based on the IP address.
[0080] The acquisition process in the second state occurs after the address device assigns an IP address to the user device based on the received address request. In other words, the second state describes the authentication result obtained by the user device interacting with the authentication device based on the assigned IP address. The process of the user device requesting an IP address and interacting with the authentication device is described in S303 and will not be repeated here.
[0081] In one possible scenario, after the authentication device determines whether the user device has passed authentication, it can send the authentication result to the access device, which then forwards the authentication result to the user device. Alternatively, based on the fact that the user device and the access device can communicate directly, the authentication device can Figure 5 As shown, the authentication result is sent directly to the user device, and based on this, another authentication result is sent to the access device. Regardless of how the access device obtains the authentication result sent by the authentication device, it can parse the received authentication result to determine whether the user device has passed the authentication and obtain the second status. Figure 5 Description of the access device and Figure 4 The description of the access device is similar, and reference may be made to the above embodiment, which will not be repeated here.
[0082] S303: When the authentication status indicates that the user equipment has not passed authentication, shorten the lease duration of the IP address allocated to the user equipment.
[0083] Given that the process of obtaining the authentication status in S302 can occur before or after the IP address is assigned, the access device can also shorten the lease duration of the IP address corresponding to the user device in various ways. The IP address corresponding to the user device refers to the IP address assigned to the user device by the access device, and the lease duration refers to the period of use of the IP address by the user device. During the lease duration, even if the user device does not use the assigned IP address for communication, the IP address will not be assigned to another device requesting an IP address.
[0084] If the authentication status includes the first status, the user device failing authentication includes the user device failing authentication at the first moment or failing authentication at the first moment. Because the address device has not yet allocated an IP address to the user device based on the address request when the access device reaches the first status, the access device can shorten the IP address to be allocated to the user device during the IP address allocation process by the address device to shorten the lease of the IP address obtained by the user device and prevent the user device from occupying the IP address for a long time.
[0085] Exemplarily, when the address request includes a lease duration, and the lease duration indicates the duration for which the user device requests to use the IP address, the process of shortening the lease duration by the access device based on the first state includes: shortening the lease duration carried in the address request to obtain a modified address request; sending the modified address request to the address device, and the modified address request is used to instruct the address device to allocate an IP address to the user device according to the shortened lease duration.
[0086] Continue with Figure 4 For example, after checking that the first state of the terminal is that the terminal is not authenticated, the access device modifies the lease duration in the DHCP request message. For example, the value of the IP Address Lease Time field in the DHCP message is modified from the initial value to the reference value. The initial value indicates the duration that the terminal expects to use the IP address, which can be obtained by the user operating the user device. The reference value is in minutes based on experience, and the initial value is greater than the reference value. After modifying the DHCP request message, the access device sends the modified DHCP request message to the DHCP server. The DHCP server selects an IP address from at least one assignable IP address based on the MAC address carried in the DHCP request message and assigns it to the terminal that sent the DHCP request message, and modifies the IP Address Lease Time of the corresponding terminal to minutes.
[0087] In one possible case, when the first state indicates that the user equipment has been authenticated and passed at the first moment, the access device may not modify the received address request, but directly forward the address request to the address device. Regardless of the situation of the address request received by the address device, the address device may Figure 5 As shown, a DHCP response message is returned to the terminal, the DHCP response message including the IP address allocated to the terminal. The terminal can parse the DHCP response message to obtain the IP address, and interact with the authentication device based on the allocated IP address. Figure 5 In the embodiment, the DHCP message obtained by the access device includes at least one of a DHCP request message and a DHCP response message.
[0088] Optionally, continuing to take the user equipment as a terminal as an example, based on Figure 5 The following example illustrates the interactive authentication process between the user device and the authentication device. The terminal sends a hypertext transfer protocol (HTTP) request to the access device, and accesses the authentication page of the portal website based on the HTTP request. The terminal can adopt an active authentication method to obtain the IP address of the portal website, and actively log in to the portal website through an HTTP request for authentication. Optionally, the terminal can also adopt a redirect authentication method, that is, the access address in the HTTP request sent by the terminal is not the IP address of the portal website, and the HTTP request sent by the terminal is as follows: Figure 5 As shown in the figure, the access device redirects to the portal website.
[0089] Regardless of how the user device accesses the portal website, the authentication device can begin authorization authentication when the user device accesses the portal website. For example, the authentication device sends a portal authorization request to the access device based on an HTTP request, notifying the access device to begin authorization authentication. The access device then sends a portal authorization response to the authentication device, notifying the authentication device that it can begin authorization authentication. In one possible scenario, the portal authorization response returned by the access device also includes a random number generated by the access device. The authentication device can then verify whether authorization is possible based on the generated random number.
[0090] Taking the example of an authentication device comprising a portal server and a RADIUS server, the process of the authentication device authenticating a user device based on a random number is described. The portal server provides portal services and an authentication interface, such as the portal website described in the above embodiment. The interaction between the portal server and the access device is used to obtain the user device's authentication information, while the interaction between the RADIUS server and the access device is used to complete the authentication, authorization, and billing of the user device. The portal server obtains the password entered by the user device on the portal website, parses the random number carried in the portal authorization response, performs a hash operation on the password and the random number to obtain a ciphertext, and returns the ciphertext to the access device. The access device then sends the received ciphertext and a locally generated random number to the RADIUS server for authentication. The RADIUS server performs a hash operation based on the received random number and the user's password to obtain another ciphertext. The server compares the calculated ciphertext with the received ciphertext to determine if they are consistent. If they are not consistent, the authentication is determined to be successful. If not, the authentication is determined to be unsuccessful.
[0091] The user device can also interact with the authentication device in other ways. For example, the user device can interact with the authentication authorization and accounting (AAA) server through the access device to authenticate access rights. Regardless of the method used by the user device to interact with the authentication device, the user device communicates with the authentication device based on the assigned IP address. For example, the authentication result returned by the authentication device to the user device has the destination address of the IP address assigned to the user device by the authentication device.
[0092] Optionally, after interacting with the user device to obtain an authentication result, the authentication device not only notifies the user device of the authentication result but also sends the authentication result to the access device. The access device thereby obtains the second state of the user device. For a detailed description of how the access device obtains the second state, see the second acquisition method in S302. After obtaining the second state, the access device may shorten the lease duration of the IP address corresponding to the user device if the second state indicates that the user device has failed authentication.
[0093] Because the second state is acquired later than the time when the user device is allocated an IP address, that is, the access device adjusts the IP address already allocated to the user device based on the second state, in this case, the access device can release the already allocated IP address to shorten the lease duration. In one possible scenario, the access device sends an IP address release request to the address device, instructing the address device to release at least one IP address that has been allocated to the user device and whose lease duration has not expired, where the at least one IP address includes the IP address allocated to the user device based on the address request.
[0094] Optionally, the access device may directly release the IP address used by the user device when the second status indicates that the user device has failed authentication. Alternatively, it may first be determined whether the user device has frequently accessed the device, and if the determination result indicates that the user device has frequently accessed the device, the IP address used by the user device may be released. The process by which the access device determines whether the user device has frequently accessed the device includes, but is not limited to: counting the number of failed authentication attempts by the user device during a reference period; and if the number of failures is not less than a failure threshold, determining that the user device has frequently accessed the device and starting to obtain a release request for the IP address.
[0095] The reference period and failure threshold can be set based on experience and the implementation environment. For example, if the retry time for user device authentication failure is 5 minutes, that is, after a user device authentication fails, it must wait 5 minutes before re-authenticating. The access device can therefore set the reference period to 20 minutes and the failure threshold to 4. If the user device fails authentication at least 4 times within 20 minutes, it means that the user device repeatedly applies for re-authentication after each authentication failure, the user device has frequent access behavior, and the user device has applied for and occupied a large number of IP addresses in a short period of time.
[0096] Regardless of how the access device triggers the release of the user device's IP address, it generates an IP address release request and sends it to the address device to release the IP address. Optionally, the access device can search for the IP address corresponding to the user device based on the user device's device identifier, generate a release request including the IP address corresponding to the user device, and send the release request to the address device. The address device then parses the received release request and identifies the IP address carried in the release request as the IP address to be released.
[0097] For example, the access device may also add the device identifier of the user device in the release request, and the subsequent address device may search for the IP address assigned to the user device according to the device identifier and determine the IP address found as the IP address to be released. Figure 5 , Figure 5 The DHCP Release (Relase) command corresponds to the release request, and the DHCP Relase includes the MAC address of the terminal that failed authentication.
[0098] In addition, the embodiments of the present application do not limit the IP addresses released by the access device control address device. It can be all unexpired IP addresses allocated to the user device, or it can be the IP address allocated to the user device most recently at the current moment, that is, the IP address used for authentication to obtain the second state.
[0099] Optionally, the access device may choose to shorten the lease duration of the IP address being allocated during the process of allocating the IP address based on the first state, for example Figure 4 As shown, based on the first state that the authentication fails, the lease duration in the DHCP message is modified to the minute level, and the modified DHCP request message is sent to the DHCP server. The DHCP server modifies the lease duration of the corresponding terminal based on the modified DHCP request message so that the IP address allocated to the user equipment is in the minute level. The access device can also choose to shorten the lease duration of the allocated IP address based on the second state, for example Figure 5As shown in the figure, when the terminal requests an IP address, the access device normally transmits the DHCP request message and the DHCP response message, and does not modify the lease duration in the DHCP request message. Instead, after the user device and the authentication device interact, the access device sends a DHCP Release command based on the authentication result to notify the DHCP server to release the IP address allocated to the user device.
[0100] In one possible scenario, the access device may combine the two aforementioned methods and shorten the IP address lease duration in different ways at different times based on the first and second states. For example, the access device may first shorten the lease duration of the IP address assigned by the address device to the user device during the process of allocating the IP address to the user device. The user device then interacts with the authentication device based on the IP address with the shortened lease duration. Based on the second state indicating authentication failure, the access device may send an IP address release request to the address device, thereby releasing the IP address with a minute-level lease duration that has not yet expired.
[0101] In addition, when the second status of the user equipment indicates that the user equipment authentication has failed, the access device can not only release the occupied IP address, but also restrict the user equipment from continuing to request a new IP address from the address device. Figure 5 As shown, the access device locks the account of the user device, and the account lock duration can be set based on experience, for example, set to DHCPLease Time. By locking the account of the user device, after receiving a new address request sent by the user device, the forwarding operation will no longer be performed, thereby restricting the user device from occupying a new IP address. In addition, similar to the process of releasing the IP address based on the second state, the access device can directly restrict the user device from obtaining a new IP address when the second state of the user device indicates that the authentication has failed. It is also possible to determine the number of failed authentication attempts of the user device within the reference time period, so that the user device is restricted from obtaining a new IP address only when the user device has frequent access behaviors.
[0102] In one possible scenario, the second state of the user device indicates that the user device has passed authentication. In this case, the access device does not shorten the IP address used by the user device. If the IP address used by the user device in the process of obtaining the second state through authentication is an IP address with a shortened lease duration based on the first state, the access device may send a lease duration recovery request to the address device, and the recovery request is used to instruct the address device to extend the lease duration of the IP address allocated to the user device. The extension may be to adjust the lease duration from a reference value to an initial value, for example Figure 4As shown, the access device continuously detects the terminal authentication status. If the authentication status is authentication passed, it determines to restore the lease time of the terminal's IP address to the initial value and sends a DHCP request message as an extension request to the DHCP server. The DHCP request message indicates to restore the lease time to the initial value. Based on the received DHCP request message, the DHCP server modifies the IP Address Lease Time of the corresponding terminal to the initial value. If the user device is authenticated, the lease time of the IP address currently used by the user device is promptly extended to prevent the IP address of the user device that has been authenticated and can be accessed normally from expiring quickly. This ensures that the user device will not be interrupted due to the expiration of the IP address during the communication based on the IP address, thereby ensuring the interactive experience of the authenticated user device.
[0103] In summary, the address management method provided in the embodiment of the present application automatically senses the authentication status of the user device, and selects the user device that has not passed the authentication from the user device to adjust the lease duration according to whether the user device has passed the authentication, and has high flexibility. In the case that the user device has not passed the authentication, the user device is an unauthorized illegal device, and the lease duration of the IP address used by the illegal device is shortened, so that the IP address used by the illegal device can be quickly expired and released, and then the released IP address can be allocated to the newly connected user device, and the utilization rate of the IP address is high. In addition, by adjusting the lease duration based on the authentication status, it is possible to avoid setting the lease duration of the legal device that has passed the authentication and is allowed normal access to be shorter, which causes the IP address used by the legal device to expire quickly, avoids the legal device from requesting the IP address multiple times, and controls the network load. There is no limit on the time when the lease duration of the IP address is shortened, and it can be during the process of allocating the IP address or after the IP address is allocated, and it is widely applicable.
[0104] The above describes the address management method of the embodiment of the present application. Corresponding to the above method, the embodiment of the present application also provides an address management device. Figure 6 This is a schematic diagram of the structure of an address management device provided in an embodiment of the present application. Figure 6 As shown in the following multiple modules, the Figure 6 The address management device shown is capable of performing the above Figure 3 It should be understood that the device may include more additional modules than the modules shown or omit some of the modules shown, and the embodiments of the present application are not limited to this. Figure 3 As shown, the device includes:
[0105] An acquisition module 601 is configured to acquire an address request sent by a user equipment, where the address request is used to request allocation of an IP address used by the user equipment during communication;
[0106] The acquisition module 601 is further used to obtain the authentication status of the user device;
[0107] The shortening module 602 is configured to shorten the lease duration of the IP address allocated to the user equipment when the authentication status indicates that the user equipment has not passed authentication.
[0108] In a possible implementation, the authentication status includes a first status, where the first status is used to indicate whether the user equipment passes authentication at a first moment, where the first moment is earlier than a moment when the user equipment obtains an IP address.
[0109] In a possible implementation, the acquisition module 601 is configured to acquire a device identifier of the user equipment; and determine a first state of the user equipment according to the device identifier.
[0110] In one possible implementation, the user device fails to pass authentication, including the user device fails to authenticate at the first moment or fails to pass authentication at the first moment, the address request includes a lease duration, and the lease duration indicates the duration for which the user device requests to use the IP address; the shortening module 602 is used to shorten the lease duration carried in the address request to obtain a modified address request; the modified address request is sent to the address device, and the modified address request is used to instruct the address device to allocate an IP address to the user device according to the shortened lease duration.
[0111] In one possible implementation, the device also includes: an extension module, which is used to send a lease recovery request to the address device when the user device uses the IP address with a shortened lease time for authentication and the authentication is passed. The recovery request is used to instruct the address device to extend the lease time of the IP address allocated to the user device.
[0112] In a possible implementation, the authentication status includes a second status, where the second status is used to indicate whether the user equipment has passed the authentication at a second moment, where the second moment is later than the moment when the user equipment obtains the IP address.
[0113] In a possible implementation, the acquisition module 601 is configured to acquire an authentication result sent by an authentication device and obtain the second state according to the authentication result, where the authentication result is obtained by the user device interacting with the authentication device based on the IP address.
[0114] In one possible implementation, the user device fails to pass the authentication, including the user device fails to pass the authentication at the second moment, and the shortening module 602 is used to send an IP address release request to the address device, and the release request is used to instruct the address device to release at least one IP address that has been allocated to the user device and the lease period has not expired, and the at least one IP address includes an IP address allocated based on the address request.
[0115] In a possible implementation, the acquisition module 601 is further configured to count the number of authentication failures of the user equipment during the reference period; and obtain a release request for the IP address when the number of failures is not less than a failure threshold.
[0116] In a possible implementation, the apparatus further includes: a restriction module, configured to restrict the user equipment from continuing to request a new IP address from the address device.
[0117] In a possible implementation, the communication requirement of the user equipment indicates that the user equipment requests access to a reference network having an authentication requirement, and the authority authentication requirement includes an authentication requirement for access rights to the reference network.
[0118] The above-mentioned device selects unauthenticated user devices from the user devices and adjusts the lease duration based on the authentication status of the user device, thereby providing high flexibility. If the user device fails authentication, the user device is considered an unauthorized illegal device, and the lease duration of the IP address used by the illegal device is shortened, allowing the IP address used by the illegal device to expire and be released quickly. The released IP address can then be allocated to a newly connected user device, thereby improving the utilization rate of the IP address.
[0119] It should be understood that the above Figure 6 The provided device is illustrated only by the division of the above-mentioned functional modules when implementing its functions. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the device and method embodiments provided in the above embodiments are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0120] See also Figure 7 , Figure 7 A schematic structural diagram of a network device 700 provided in an exemplary embodiment of the present application is shown. Figure 7 The network device 700 shown is used to perform the above Figure 3 The operations involved in the address management method shown are as follows: The network device 700 is, for example, a switch, a router, etc. The network device 700 can be implemented by a general bus architecture.
[0121] like Figure 7 As shown, the network device 700 includes at least one processor 701 , a memory 703 , and at least one communication interface 704 .
[0122] The processor 701 is, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural-network processing units (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the solution of the present application. For example, the processor 701 includes an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The PLD is, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. It can implement or execute the various logic blocks, modules, and circuits described in conjunction with the disclosure of the embodiments of the present application. The processor can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.
[0123] Optionally, the network device 700 further includes a bus. The bus is used to transmit information between the components of the network device 700. The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.
[0124] The memory 703 is, for example, a read-only memory (ROM) or other type of static storage device that can store static information and instructions, or a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 703 is, for example, independent and connected to the processor 701 via a bus. The memory 703 can also be integrated with the processor 701.
[0125] The communication interface 704 uses any transceiver-like device for communicating with other devices or communication networks. The communication network can be Ethernet, a radio access network (RAN), or a wireless local area network (WLAN). The communication interface 704 can include a wired communication interface and a wireless communication interface. Specifically, the communication interface 704 can be an Ethernet interface, a fast Ethernet (FE) interface, a gigabit Ethernet (GE) interface, an asynchronous transfer mode (ATM) interface, a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In the embodiment of the present application, the communication interface 704 can be used for the network device 700 to communicate with other devices.
[0126] In a specific implementation, as an embodiment, the processor 701 may include one or more CPUs, such as Figure 7 0 and CPU1 are shown in FIG. Each of these processors can be a single-CPU processor or a multi-CPU processor. A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0127] In a specific implementation, as an embodiment, the network device 700 may include multiple processors, such as Figure 7 1 and 705. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor here can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0128] In a specific implementation, as an embodiment, the network device 700 may further include an output device and an input device. The output device communicates with the processor 701 and can display information in a variety of ways. For example, the output device can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector. The input device communicates with the processor 701 and can receive user input in a variety of ways. For example, the input device can be a mouse, a keyboard, a touch screen device, or a sensor device.
[0129] In some embodiments, the memory 703 is used to store program code 710 for executing the solution of the present application, and the processor 701 can execute the program code 710 stored in the memory 703. That is, the network device 700 can implement the address management method provided by the method embodiment through the processor 701 and the program code 710 in the memory 703. The program code 710 may include one or more software modules. Optionally, the processor 701 itself may also store program code or instructions for executing the solution of the present application.
[0130] In a specific embodiment, the network device 700 of the embodiment of the present application may correspond to the computing device in the above-mentioned various method embodiments.
[0131] in, Figure 3 Each step of the address management method shown is completed by the hardware integrated logic circuit or software instructions in the processor of the network device 700. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software modules in the processor. The software module can be located in a mature storage medium in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.
[0132] See also Figure 8 , Figure 8 FIG. 8 is a schematic structural diagram of a network device 800 provided in another exemplary embodiment of the present application. Figure 8 The network device 800 shown is used to perform the above Figure 3 All or part of the operations involved in the address management method shown. The network device 800 is, for example, a switch, a router, etc. The network device 800 can be implemented by a general bus architecture.
[0133] like Figure 8 As shown, the network device 800 includes: a main control board 810 and an interface board 830 .
[0134] The main control board 810, also known as the main processing unit (MPU) or route processor card, is used to control and manage various components in network device 800, including routing calculation, device management, device maintenance, and protocol processing. The main control board 810 includes a central processing unit 811 and a memory 812.
[0135] Interface board 830 is also known as a line processing unit (LPU), line card, or service board. It provides various service interfaces and implements data packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces and POS (Packet over SONET / SDH) interfaces. Ethernet interfaces, for example, are Flexible Ethernet Clients (FlexE Clients). Interface board 830 includes a central processing unit (CPU) 831, a network processor (NPU) 832, a forwarding table memory 834, and a physical interface card (PIC) 833.
[0136] The central processing unit 831 on the interface board 830 is used to control and manage the interface board 830 and communicate with the central processing unit 811 on the main control board 810 .
[0137] The network processor 832 is used to implement message forwarding processing. The network processor 832 can be in the form of a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented using an application-specific integrated circuit (ASIC) or a field programmable gate array (FPGA). Specifically, the network processor 832 is used to forward received messages based on the forwarding table stored in the forwarding entry memory 834. If the destination address of the message is the address of the network device 800, the message is sent to the CPU (such as the central processing unit 831) for processing. If the destination address of the message is not the address of the network device 800, the next hop and outgoing interface corresponding to the destination address are searched in the forwarding table based on the destination address, and the message is forwarded to the outgoing interface corresponding to the destination address. The processing of uplink messages may include processing the message input interface and forwarding table lookup; the processing of downlink messages may include forwarding table lookup, etc. In some embodiments, the central processing unit may also perform the functions of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, thereby eliminating the need for a forwarding chip in the interface board.
[0138] Physical interface card 833 implements physical layer connectivity. Raw traffic enters interface board 830 through this card, and processed messages are sent from this physical interface card 833. Physical interface card 833, also known as a daughter card, can be installed on interface board 830. It converts optical and electrical signals into messages, performs a validity check on these messages, and then forwards them to network processor 832 for processing. In some embodiments, central processing unit 831 can also perform the functions of network processor 832, such as implementing software forwarding based on a general-purpose CPU. Therefore, network processor 832 is no longer required in physical interface card 833.
[0139] Optionally, the network device 800 includes multiple interface boards. For example, the network device 800 further includes an interface board 840. The interface board 840 includes a central processing unit 841, a network processor 842, a forwarding table entry memory 844, and a physical interface card 843. The functions and implementation of each component in the interface board 840 are the same as or similar to those of the interface board 830 and are not described in detail here.
[0140] Optionally, network device 800 further includes a switching fabric board 820. Switching fabric board 820 may also be referred to as a switch fabric unit (SFU). If network device 800 includes multiple interface boards, switching fabric board 820 is used to exchange data between the interface boards. For example, interface board 830 and interface board 840 can communicate via switching fabric board 820.
[0141] The main control board 810 is coupled to the interface board. For example, the main control board 810, the interface board 830, the interface board 840, and the switching network board 820 are connected to the system backplane via a system bus to achieve intercommunication. In one possible implementation, an inter-process communication (IPC) channel is established between the main control board 810 and the interface boards 830 and 840, and communication is performed between the main control board 810 and the interface boards 830 and 840 via the IPC channel.
[0142] Logically, network device 800 includes a control plane and a forwarding plane. The control plane includes a main control board 810 and a central processing unit 811. The forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 834, a physical interface card 833, and a network processor 832. The control plane performs functions such as routing, generating forwarding tables, processing signaling and protocol messages, and configuring and maintaining the network device's status. The control plane sends the generated forwarding tables to the forwarding plane. On the forwarding plane, the network processor 832 forwards messages received by the physical interface card 833 based on the forwarding tables sent by the control plane. The forwarding tables sent by the control plane can be stored in the forwarding table entry memory 834. In some embodiments, the control plane and forwarding plane can be completely separate and not located on the same network device.
[0143] It's worth noting that there may be one or more main control boards (SPUs), which can include both active and standby SPUs. There may also be one or more interface boards. The higher the network device's data processing capabilities, the more interface boards it provides. Interface boards can also have one or more physical interface cards. There may be no SPUs, one or more SPUs, and multiple SPUs can provide load balancing and redundancy. In a centralized forwarding architecture, network devices may not require SPUs; the interface boards handle service data processing for the entire system. In a distributed forwarding architecture, network devices may have at least one SPU, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, network devices with distributed architectures have greater data access and processing capabilities than those with centralized architectures. Alternatively, a network device can consist of a single card, without a switching fabric board (SFB), integrating the functions of the interface board and the main control board. In this case, the central processing unit (CPU) on the interface board and the CPU on the main control board can be combined into a single CPU on this card, performing the combined functions of the two. This type of network device has lower data exchange and processing capabilities (for example, low-end network devices such as switches or routers). The specific architecture used depends on the specific network deployment scenario and is not specified here.
[0144] In a specific embodiment, the network device 800 corresponds to the above Figure 6 In some embodiments, Figure 6 The shortening module 602 in the address management apparatus shown is equivalent to the central processor 811 or the network processor 832 in the network device 800 .
[0145] The embodiment of the present application also provides a communication device, which includes: a transceiver, a memory, and a processor. The transceiver, the memory, and the processor communicate with each other through an internal connection path, the memory is used to store instructions, and the processor is used to execute the instructions stored in the memory to control the transceiver to receive signals and control the transceiver to send signals, and when the processor executes the instructions stored in the memory, the processor executes Figure 3 The address management method shown.
[0146] It should be understood that the processor may be a CPU, or other general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor supporting the Advanced Reduced Instruction Set Machine (ARM) architecture.
[0147] Furthermore, in an optional embodiment, the memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. The memory may also include a non-volatile random access memory. For example, the memory may also store device type information.
[0148] The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an EEPROM, or a flash memory. The volatile memory may be a RAM, which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0149] The embodiment of the present application also provides an address management device, which includes a processor configured to load and execute at least one instruction to enable the address management device to implement the following Figure 3 Optionally, the device further comprises a memory coupled to the processor, and the memory is used to store at least one instruction.
[0150] The embodiment of the present application also provides a computer-readable storage medium having at least one instruction stored therein, which is loaded and executed by a processor to enable the computer to implement the following Figure 3 The address management method shown.
[0151] The embodiments of the present application further provide a computer program (product), which, when executed by a computer, can enable a processor or computer to execute the corresponding steps and / or processes in the above method embodiments.
[0152] The embodiment of the present application further provides a chip, which includes a processor for calling and executing instructions stored in a memory, so that a communication device equipped with the chip executes the following Figure 3 The address management method shown.
[0153] The embodiment of the present application also provides another chip, including: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected through an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the processor is used to execute the following Figure 3 The address management method shown.
[0154] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described herein are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive).
[0155] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, storage, display, etc.), and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the address requests involved in this application are all obtained with full authorization.
[0156] Those skilled in the art will appreciate that the various method steps and modules described in conjunction with the embodiments disclosed herein can be implemented in software, hardware, firmware, or any combination thereof. In order to clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0157] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or may be accomplished by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0158] When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer program instructions. As an example, the method of the embodiment of the present application can be described in the context of a machine executable instruction, and the machine executable instruction is such as included in the program module executed in the device on the real or virtual processor of the target. Generally speaking, a program module includes a routine, a program, a library, an object, a class, a component, a data structure, etc., which performs a specific task or realizes a specific abstract data structure. In various embodiments, the function of the program module can be merged or split between the described program modules. The machine executable instruction for the program module can be executed in a local or distributed device. In a distributed device, the program module can be located in both a local and a remote storage medium.
[0159] The computer program code for implementing the method of the embodiment of the present application can be written in one or more programming languages. These computer program codes can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable address management device, so that when the program code is executed by the computer or other programmable address management device, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the computer, partially on the computer, as an independent software package, partially on the computer and partially on a remote computer, or entirely on a remote computer or server.
[0160] In the context of the embodiments of the present application, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, and the like.
[0161] Examples of signals may include electrical, optical, radio, acoustic or other forms of propagated signals, such as carrier waves, infrared signals, etc.
[0162] A machine-readable medium may be any tangible medium that contains or stores a program for or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination thereof. More detailed examples of machine-readable storage media include an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0163] Those skilled in the art will clearly understand that, for the sake of convenience and brevity of description, the specific working processes of the above-described systems, devices, and modules can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0164] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the modules is merely a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or modules, or can be electrical, mechanical or other forms of connection.
[0165] Modules described as separate components may or may not be physically separate, and components displayed as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0166] In addition, the functional modules in the various embodiments of the present application may be integrated into a processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The above-mentioned integrated modules may be implemented in the form of hardware or software functional modules.
[0167] If the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0168] In this application, the terms "first", "second", etc. are used to distinguish between identical or similar items that have substantially the same effects and functions. It should be understood that there is no logical or temporal dependency between "first", "second", and "nth", nor is there any limitation on quantity or execution order. It should also be understood that although the following description uses the terms first, second, etc. to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the various described examples, a first image may be referred to as a second image, and similarly, a second image may be referred to as a first image. Both the first image and the second image may be images, and in some cases, may be separate and different images.
[0169] It should also be understood that in the various embodiments of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0170] In this application, the term "at least one" means one or more, and the term "plurality" means two or more. For example, "plurality of second messages" means two or more second messages. The terms "system" and "network" are often used interchangeably herein.
[0171] It should be understood that the terminology used in the description of the various examples herein is for the purpose of describing particular examples only and is not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0172] It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the listed items. The term "and / or" describes an association between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this application generally indicates that the associated objects are in an "or" relationship.
[0173] It will also be understood that the term “comprise” (also known as “includes,” “including,” “comprises,” and / or “comprising”) when used in this specification specifies the presence of stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0174] It should also be understood that the terms “if” and “if” may be interpreted to mean “when” or “upon” or “in response to determining” or “in response to detecting.” Similarly, the phrases “if it is determined that ” or “if [stated condition or event] is detected” may be interpreted to mean “upon determining ” or “in response to determining ” or “upon detecting [stated condition or event]” or “in response to detecting [stated condition or event],” depending on the context.
[0175] It should be understood that determining B based on A does not mean determining B based solely on A. B can also be determined based on A and / or other information.
[0176] It should also be understood that references throughout this specification to "one embodiment," "an embodiment," or "one possible implementation" mean that specific features, structures, or characteristics associated with that embodiment or implementation are included in at least one embodiment of the present application. Therefore, the appearance of "in one embodiment," "in an embodiment," or "one possible implementation" throughout this specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
Claims
1. An address management method, characterized in that: The method comprises: Obtaining an address request sent by a user device, the address request being used to request allocation of an Internet Protocol (IP) address used by the user device for communication; Obtaining the authentication status of the user equipment; When the authentication status indicates that the user equipment has failed authentication, shortening the lease duration of the IP address allocated to the user equipment.
2. The method according to claim 1, characterized in that The authentication status includes a first status, where the first status is used to indicate whether the user equipment passes authentication at a first moment, where the first moment is earlier than a moment when the user equipment obtains the IP address.
3. The method according to claim 2, characterized in that The obtaining the authentication status of the user equipment includes: Obtaining a device identifier of the user device; A first state of the user equipment is determined according to the equipment identifier.
4. The method according to claim 2 or 3, characterized in that The user equipment failing to pass authentication includes that the user equipment is not authenticated at the first moment or fails authentication at the first moment, and the address request includes a lease duration, where the lease duration indicates a duration for which the user equipment requests to use the IP address; The shortening of the lease duration of the IP address allocated to the user equipment includes: Shorten the lease duration carried in the address request to obtain a modified address request; The modified address request is sent to the address device, where the modified address request is used to instruct the address device to allocate an IP address to the user equipment according to the shortened lease duration.
5. The method according to any one of claims 1 to 4, characterized in that: After shortening the lease duration of the IP address allocated to the user equipment, the method further includes: When the user device uses the IP address with shortened lease time for authentication and the authentication is passed, a request for restoring the lease time is sent to the address device, where the restoration request is used to instruct the address device to extend the lease time of the IP address allocated to the user device.
6. The method according to any one of claims 1 to 5, characterized in that: The authentication status includes a second status, where the second status is used to indicate whether the user equipment has passed authentication at a second moment, where the second moment is later than the moment when the user equipment obtains the IP address.
7. The method according to claim 6, characterized in that The obtaining the authentication status of the user equipment includes: An authentication result sent by an authentication device is obtained, and the second state is obtained according to the authentication result, where the authentication result is obtained by the user device interacting with the authentication device based on the IP address.
8. The method according to claim 6 or 7, characterized in that The user equipment failing to pass authentication includes that the user equipment fails to pass authentication at the second moment, and the shortening of the lease duration of the IP address allocated to the user equipment includes: Sending an IP address release request to the address device, where the release request is used to instruct the address device to release at least one IP address that has been allocated to the user equipment and whose lease duration has not expired.
9. The method according to claim 8, characterized in that Before sending the release request of the IP address to the address device, the method further includes: Counting the number of authentication failures of the user equipment during the reference period; When the number of failures is not less than a failure threshold, a release request for the IP address is obtained.
10. The method according to any one of claims 6 to 9, characterized in that: The method further comprises: The user equipment is restricted from continuing to request a new IP address from the address device.
11. The method according to any one of claims 1 to 10, characterized in that: The communication requirement of the user equipment indicates that the user equipment requests to access a reference network having authentication requirements, and the authority authentication requirements existing in the user equipment include authentication requirements for access rights to the reference network.
12. An address management device, characterized in that: The device comprises: an acquisition module, configured to acquire an address request sent by a user device, wherein the address request is used to request allocation of an Internet Protocol (IP) address used by the user device for communication; The acquisition module is further configured to acquire the authentication status of the user equipment; The shortening module is used to shorten the lease time of the IP address allocated to the user equipment when the authentication status indicates that the user equipment has not passed the authentication.
13. The device according to claim 12, characterized in that The authentication status includes a first status, where the first status is used to indicate whether the user equipment passes authentication at a first moment, where the first moment is earlier than a moment when the user equipment obtains the IP address.
14. The device according to claim 13, characterized in that The acquisition module is configured to acquire a device identifier of the user equipment; and determine a first state of the user equipment according to the device identifier.
15. The device according to claim 13 or 14, characterized in that The user equipment failing to pass authentication includes that the user equipment is not authenticated at the first moment or fails authentication at the first moment, and the address request includes a lease duration, where the lease duration indicates a duration for which the user equipment requests to use the IP address; The shortening module is used to shorten the lease duration carried in the address request to obtain a modified address request; send the modified address request to the address device, and the modified address request is used to instruct the address device to allocate an IP address to the user device according to the shortened lease duration.
16. The device according to any one of claims 12 to 15, characterized in that: The device also includes: an extension module, which is used to send a recovery request for the lease time to the address device when the user equipment uses the IP address with shortened lease time for authentication and the authentication is passed. The recovery request is used to instruct the address device to extend the lease time of the IP address allocated to the user equipment.
17. The device according to any one of claims 12 to 16, characterized in that: The authentication status includes a second status, where the second status is used to indicate whether the user equipment has passed authentication at a second moment, where the second moment is later than the moment when the user equipment obtains the IP address.
18. The device according to claim 17, characterized in that The acquisition module is configured to acquire an authentication result sent by an authentication device, and obtain the second state according to the authentication result, wherein the authentication result is obtained by the user device interacting with the authentication device based on the IP address.
19. The device according to claim 17 or 18, characterized in that The user equipment fails to pass the authentication, including the user equipment fails to pass the authentication at the second moment. The shortening module is used to send an IP address release request to the address device, and the release request is used to instruct the address device to release at least one IP address that has been allocated to the user equipment and the lease duration has not expired.
20. The device according to claim 19, characterized in that The acquisition module is further configured to count the number of authentication failures of the user equipment during a reference period; and to acquire a release request for the IP address when the number of failures is not less than a failure threshold.
21. The device according to any one of claims 17 to 20, characterized in that: The apparatus further includes a restriction module configured to restrict the user equipment from continuing to request a new IP address from the address device.
22. The device according to any one of claims 12 to 21, characterized in that: The communication requirement of the user equipment indicates that the user equipment requests to access a reference network having authentication requirements, and the authority authentication requirements existing in the user equipment include authentication requirements for access rights to the reference network.
23. An address management device, characterized in that: The device includes a processor, and the processor is used to load and execute at least one instruction, so that the address management device implements the address management method according to any one of claims 1 to 11.
24. A computer-readable storage medium, characterized in that The computer-readable storage medium stores at least one instruction, which is loaded and executed by a processor to implement the address management method according to any one of claims 1 to 11.
25. A chip, characterized in that: The chip includes a processor, and the processor is used to run program instructions or codes, so that a device including the chip executes the address management method according to any one of claims 1 to 11.
26. A computer program product, characterized in that The computer program product comprises a computer program / instruction, and the computer program / instruction is executed by a processor to enable a computer to perform the address management method according to any one of claims 1 to 11.