Network authentication method, device, equipment, system, storage medium and program product
By using a proxy device to simulate a terminal for IPoE authentication, the problem of terminals being unable to access both the intranet and the extranet simultaneously in the campus network was solved. This enabled efficient joint authentication and data traffic mapping, improving network access efficiency.
Patent Information
- Application Number
- CN202410538212.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-26
- Publication Date
- 2025-10-28
AI Technical Summary
In the campus network, terminal devices cannot simultaneously authenticate with the internal network when accessing the external network, resulting in the inability to access internal network resources, increasing authentication complexity and inefficiency.
By using a proxy dialing device to simulate a terminal to initiate IPoE authentication, joint authentication of intranet and extranet is achieved. The IPoE dialing command and extranet authentication information provided by the intranet authentication server are used to perform extranet authentication on behalf of the terminal, and a mapping relationship between intranet address and extranet address is established to achieve bidirectional data traffic conversion.
It improves the efficiency of network authentication, reduces the authentication complexity of terminals accessing the intranet and the extranet, and enables terminals to access the intranet and the extranet simultaneously.
Smart Images

Figure CN120856360A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to network authentication methods, devices, equipment, systems, storage media, and program products. Background Technology
[0002] With the development of communication technology, campuses typically build internal networks, such as those for data centers and teaching / research areas in schools. Telecom operators also build external networks within campuses for internet access. Access to the internal network requires network authentication from the internal gateway, while access to the internet requires network authentication from the external gateway. Therefore, implementing network authentication in scenarios involving both internal and external networks is a pressing issue that needs to be addressed. Summary of the Invention
[0003] This application provides a network authentication method, apparatus, device, system, storage medium, and program product for implementing intranet authentication and extranet authentication of terminals.
[0004] Firstly, a network authentication method is provided. Taking a dial-up device executing the method as an example, the method includes: when the terminal is authenticated through the intranet, receiving an Internet Protocol over Ethernet (IPoE) dialing command and the terminal's external network authentication information sent by the intranet authentication server; interacting with the external network gateway based on the IPoE dialing command and the external network authentication information to realize the terminal's IPoE external network authentication; when the terminal is authenticated through the IPoE external network, receiving the terminal's external network address sent by the external network gateway, the external network address being used by the terminal to access the external network.
[0005] This method, when the terminal has passed intranet authentication, enables the proxy dialing device to initiate IPoE extranet authentication on behalf of the terminal through IPoE dialing commands and the terminal's extranet authentication information, thereby realizing both intranet authentication and IPoE extranet authentication for the terminal. This allows the terminal to pass intranet authentication while simultaneously passing IPoE extranet authentication, thus enabling the terminal to access both the intranet and the extranet at the same time. This improves the efficiency of network authentication and reduces the authentication complexity for the terminal to access both the intranet and the extranet.
[0006] In one possible implementation, the method of achieving IPoE external network authentication for the terminal by interacting with the external network gateway based on IPoE dialing commands and the terminal's external network authentication information may include: sending an IPoE dialing request to the external network gateway based on the IPoE dialing command; receiving a portal authentication address sent by the external network gateway based on the IPoE dialing request; and sending a portal authentication request to the portal authentication server through the portal authentication address. The portal authentication request includes the terminal's external network authentication information, and the portal authentication request is used by the portal authentication server to interact with the external network gateway to achieve IPoE external network authentication for the terminal.
[0007] Therefore, the proxy device interacts with the external network gateway to achieve portal authentication of the terminal. This enables the proxy device to perform portal authentication on behalf of the terminal in scenarios where portal authentication is required during the IPoE external network authentication process, thereby increasing the success rate of the proxy device in performing IPoE external network authentication on behalf of the terminal.
[0008] In one possible implementation, the process of sending a portal authentication request to the portal authentication server via the portal authentication address may include: parsing the portal authentication address, adding the terminal's external network authentication information to the parsed authentication page, generating a portal authentication request based on the authentication page with the added external network authentication information, and sending the portal authentication request to the portal authentication server. In other words, the proxy device has the ability to parse the portal authentication address and automatically fill in the external network authentication information on behalf of the terminal, thus improving the success rate of the proxy device performing portal authentication on behalf of the terminal.
[0009] In one possible implementation, after receiving the external network address of the terminal sent by the external network gateway, upon receiving external network access traffic sent by the terminal based on the internal network address, the internal network address is mapped to an external network address according to a first mapping relationship, and the external network access traffic is forwarded based on the external network address. The first mapping relationship includes the correspondence between internal network addresses and external network addresses. Upon receiving external network data traffic sent to the terminal based on the external network address, the external network address is mapped to an internal network address according to the first mapping relationship, and the external network data traffic is forwarded to the terminal based on the internal network address.
[0010] Therefore, the proxy dialing device enables the terminal to access both the internal and external networks by mapping the terminal's internal network address to the external network address, thus improving the convenience and efficiency of the terminal's access to the internal and external networks.
[0011] In one possible implementation, before mapping the internal network address to the external network address according to the first mapping relationship, the system receives the terminal's internal network address from the internal network authentication server. This internal network address is assigned to the terminal by the internal network gateway after the internal network authentication information has been successfully authenticated. The first mapping relationship is then obtained based on the terminal's internal network address and its external network address. In this case, after the terminal passes internal network authentication, the internal network authentication server also synchronizes the terminal's internal network address with the proxy dialing device, enabling the proxy dialing device to achieve the mapping between the terminal's internal network address and its external network address.
[0012] Secondly, a network authentication method is provided. Taking the execution of the method by an intranet authentication server as an example, the method includes: when the terminal is authenticated through the intranet, sending an IPoE dialing command and the terminal's external network authentication information to the proxy dialing device. The IPoE dialing command and the terminal's external network authentication information are used by the proxy dialing device to interact with the external network gateway to realize the terminal's IPoE external network authentication.
[0013] In one possible implementation, before sending the IPoE dialing command and the terminal's external network authentication information to the proxy dialing device, the terminal's external network authentication information is obtained based on a second mapping relationship and the terminal's internal network authentication information. The second mapping relationship includes the correspondence between internal network authentication information and external network authentication information. Therefore, the terminal's external network authentication information can be quickly obtained through the second mapping relationship.
[0014] In one possible implementation, the method further sends the terminal's internal network address to the proxy dialing device. The terminal's internal network address is used by the proxy dialing device to obtain a first mapping relationship based on the terminal's external network address. The first mapping relationship includes the correspondence between the internal network address and the external network address.
[0015] Thirdly, a network authentication method is provided. Taking the execution of this method by an external network gateway as an example, the method includes: when the proxy dialing device receives the IPoE dialing instruction sent by the internal network authentication server and the external network authentication information of the terminal, it interacts with the proxy dialing device to realize the IPoE external network authentication of the terminal; when the terminal passes the IPoE external network authentication, it sends the external network address of the terminal to the proxy dialing device, and the external network address is used by the terminal to realize external network access.
[0016] In one possible implementation, the process of interacting with the proxy dialing device to achieve IPoE external network authentication for the terminal may include: receiving an IPoE dialing request sent by the proxy dialing device based on the IPoE dialing command; sending a portal authentication address to the proxy dialing device based on the IPoE dialing request, wherein the portal authentication address is used by the proxy dialing device to send a portal authentication request to the portal authentication server, the portal authentication request including the terminal's external network authentication information, and the portal authentication request being used by the portal authentication server to interact with the external network gateway to achieve IPoE external network authentication for the terminal.
[0017] Fourthly, a network authentication device is provided, which includes a transceiver module and a processing module.
[0018] The transceiver module is used to perform receiving and / or sending related operations performed in the first aspect or any possible implementation of the first aspect; the processing module is used to perform other operations besides receiving and / or sending related operations in the first aspect or any possible implementation of the first aspect.
[0019] Alternatively, the transceiver module is used to perform the receiving and / or sending related operations performed in the second aspect or any possible implementation of the second aspect; the processing module is used to perform other operations besides the receiving and / or sending related operations in the second aspect or any possible implementation of the second aspect.
[0020] Alternatively, the transceiver module is used to perform the receiving and / or sending related operations performed in the third aspect or any possible implementation of the third aspect; the processing module is used to perform other operations besides the receiving and / or sending related operations in the third aspect or any possible implementation of the third aspect.
[0021] In one possible implementation, the transceiver module includes a receiving module and / or a sending module. The receiving module is used to perform receiving-related operations, and the sending module is used to perform sending-related operations.
[0022] The transceiver module is used to perform receiving and / or sending related operations performed in the first aspect or any possible implementation of the first aspect; the processing module is used to perform other operations besides receiving and / or sending related operations in the first aspect or any possible implementation of the first aspect.
[0023] In one possible implementation, the transceiver module is configured to receive an IPoE dialing command and external network authentication information sent by the internal network authentication server when the terminal has passed internal network authentication; interact with the external network gateway based on the IPoE dialing command and external network authentication information to achieve IPoE external network authentication for the terminal; and receive the external network address of the terminal sent by the external network gateway when the terminal has passed IPoE external network authentication, the external network address being used by the terminal to access the external network.
[0024] In one possible implementation, the transceiver module is configured to send an IPoE dialing request to an external network gateway based on an IPoE dialing command; receive a portal authentication address sent by the external network gateway based on the IPoE dialing request; and send a portal authentication request to a portal authentication server via the portal authentication address. The portal authentication request includes the terminal's external network authentication information, and the portal authentication request is used by the portal authentication server and the external network gateway to achieve IPoE external network authentication for the terminal.
[0025] In one possible implementation, the processing module is used to parse the portal authentication address, add the terminal's external network authentication information to the parsed authentication page, generate a portal authentication request based on the authentication page after adding the terminal's external network authentication information, and the transceiver module is used to send the portal authentication request to the portal authentication server.
[0026] In one possible implementation, the processing module is further configured to, upon receiving external network access traffic sent by the terminal based on an internal network address, map the internal network address to an external network address according to a first mapping relationship; the transceiver module is further configured to forward the external network access traffic based on the external network address, the first mapping relationship including the correspondence between internal network addresses and external network addresses. The processing module is further configured to, upon receiving external network data traffic sent to the terminal based on an external network address, map the external network address to an internal network address according to the first mapping relationship; the transceiver module is further configured to forward the external network data traffic to the terminal based on the internal network address.
[0027] In one possible implementation, the transceiver module is further configured to receive the terminal's intranet address sent by the intranet authentication server. The intranet address is an address assigned to the terminal by the intranet gateway when the intranet authentication information passes intranet authentication. The processing module is configured to obtain a first mapping relationship based on the terminal's intranet address and the terminal's external network address.
[0028] The transceiver module is used to perform receiving and / or sending related operations as performed in the second aspect or any possible implementation of the second aspect; the processing module is used to perform other operations besides receiving and / or sending related operations in the second aspect or any possible implementation of the second aspect.
[0029] In one possible implementation, the transceiver module is used to send an IPoE dialing command and the terminal's external network authentication information to the proxy dialing device when the terminal has been authenticated through the internal network. The IPoE dialing command and the terminal's external network authentication information are used by the proxy dialing device to interact with the external network gateway to realize the terminal's IPoE external network authentication.
[0030] In one possible implementation, the processing module is used to obtain the external network authentication information of the terminal based on the second mapping relationship and the terminal's internal network authentication information. The second mapping relationship includes the correspondence between the internal network authentication information and the external network authentication information.
[0031] In one possible implementation, the transceiver module is further configured to send the terminal's intranet address to the proxy dialing device. The terminal's intranet address is used by the proxy dialing device to obtain a first mapping relationship based on the terminal's external network address. The first mapping relationship includes the correspondence between the intranet address and the external network address.
[0032] The transceiver module is used to perform receiving and / or sending related operations as performed in the third aspect or any possible implementation of the third aspect; the processing module is used to perform other operations besides receiving and / or sending related operations in the third aspect or any possible implementation of the third aspect.
[0033] In one possible implementation, the transceiver module is used to interact with the proxy device to achieve IPoE external network authentication of the terminal when the proxy device receives the IPoE dialing command sent by the intranet authentication server and the external network authentication information of the terminal; and when the terminal passes the IPoE external network authentication, it sends the terminal's external network address to the proxy device, which is used by the terminal to access the external network.
[0034] In one possible implementation, the transceiver module is configured to receive an IPoE dialing request sent by the proxy dialing device based on the IPoE dialing command; and to send a portal authentication address to the proxy dialing device based on the IPoE dialing request. The portal authentication address is used by the proxy dialing device to send a portal authentication request to the portal authentication server. The portal authentication request includes the terminal's external network authentication information. The portal authentication request is used by the portal authentication server to interact with the external network gateway to achieve IPoE external network authentication of the terminal.
[0035] Fifthly, a network device is provided, comprising: a processor coupled to a memory, the memory storing at least one program instruction or code, the at least one program instruction or code being loaded and executed by the processor to enable the network device to implement the network authentication method as described in any of the first, second, or third aspects above.
[0036] Optionally, the processor may be one or more, and the memory may be one or more.
[0037] Optionally, the memory may be integrated with the processor, or the memory may be separated from the processor.
[0038] In the specific implementation process, the memory can be a non-transitory memory, such as read-only memory (ROM), which can be integrated with the processor on the same chip or set on different chips. This application does not limit the type of memory or the way the memory and processor are set.
[0039] Sixthly, a network authentication system is provided, which includes a dial-up device, an intranet authentication server, and an extranet gateway;
[0040] The proxy dialing device is used to perform the method described in the first aspect or any possible implementation of the first aspect; the intranet authentication server is used to perform the method described in the second aspect or any possible implementation of the second aspect; and the extranet gateway is used to perform the method described in the third aspect or any possible implementation of the third aspect.
[0041] In a seventh aspect, a computer-readable storage medium is provided, the storage medium storing at least one instruction, the instruction being loaded and executed by a processor to cause a computer to implement the method of the first aspect or any possible implementation of the first aspect, or to implement the method of the second aspect or any possible implementation of the second aspect, or to implement the method of the third aspect or any possible implementation of the third aspect.
[0042] Eighthly, a computer program (product) is provided, the computer program (product) comprising: computer program code, which, when executed by a computer, causes the computer to perform the methods described in the preceding aspects.
[0043] In a ninth aspect, a chip is provided, including a processor for retrieving and executing instructions stored in a memory, causing a communication device on which the chip is mounted to perform the methods of the foregoing aspects.
[0044] In a tenth aspect, another chip is provided, comprising: an input interface, an output interface, a processor, and a memory, wherein the input interface, the output interface, the processor, and the memory are connected via an internal connection path, and the processor is used to execute code in the memory, wherein when the code is executed, the processor is used to perform the methods in the foregoing aspects.
[0045] It should be understood that the beneficial effects of the technical solutions of the second to tenth aspects of this application and the corresponding possible implementations can be referred to the above-described technical effects of the first aspect and its corresponding possible implementations, and will not be repeated here. Attached Figure Description
[0046] Figure 1 A schematic diagram illustrating the implementation environment of a network authentication method provided in this application embodiment;
[0047] Figure 2 An interactive schematic diagram of a network authentication method provided in an embodiment of this application;
[0048] Figure 3 A schematic diagram of a campus network provided for an embodiment of this application;
[0049] Figure 4 An interactive schematic diagram of another network authentication method provided in an embodiment of this application;
[0050] Figure 5 This is a schematic diagram of the structure of a network authentication device provided in an embodiment of this application;
[0051] Figure 6 This application provides a schematic diagram of the structure of a network device according to an embodiment of the present application.
[0052] Figure 7 This is a schematic diagram of the structure of another network device provided in an embodiment of this application;
[0053] Figure 8 This is a schematic diagram of the structure of a server provided in an embodiment of this application. Detailed Implementation
[0054] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0055] For campus networks, which include both internal and external networks, authentication of user terminals is required for access to both networks to facilitate control over user terminal network access behavior. Optionally, the internal network can refer to a self-built network within the campus, connecting to the campus data center; the external network can refer to a network built by an operator within the campus, connecting to the internet, metropolitan area network (MAN), or wide area network (WAN) outside the campus. The campus includes, but is not limited to, companies, campuses, science parks, or industrial parks. The internal network can be simply referred to as the intranet, and the external network as the extranet.
[0056] For example, in a school setting, the entire campus network is constructed in two parts: the school's internal campus network and the telecom operator's external campus network. The school's internal campus network connects to the school's data center, where on-campus business systems such as course selection and online classrooms are deployed. The school builds an internal network authentication platform within the campus to authenticate users accessing campus resources. The telecom operator's external campus network connects to the internet, and the operator builds an external network authentication platform outside the campus to authenticate users accessing the internet within the campus. Typically, the operator shares a single external network authentication platform across multiple campuses.
[0057] Optionally, user terminals on the campus intranet access the school's data center through intranet authentication, while user terminals on the campus extranet access the internet through extranet authentication. In this scenario, while terminals on the campus extranet access the internet through extranet authentication, they cannot access the school's data center because they lack intranet authentication. Therefore, how to enable terminals to access the school's data center simultaneously with accessing the internet is a pressing issue that needs to be addressed.
[0058] This application provides a network authentication method. When a terminal accesses the external network, it first performs internal network authentication. After the terminal passes the internal network authentication, a proxy dialing device acts on behalf of the terminal to perform external network authentication, so that the terminal accessing the external network can simultaneously access the internal network. The external network authentication method is deployed using IPoE, meaning the proxy dialing device can simulate the terminal's ability to initiate IPoE authentication.
[0059] See Figure 1 , Figure 1 This is a schematic diagram illustrating the implementation environment of a network authentication method provided in an embodiment of this application. For example... Figure 1As shown, the park includes an internal network built by the park itself and an external network built by the operator. The internal network includes an access network, an internal network gateway, an internal network authentication server, and a park data center. The external network includes an access network and dial-up devices. The access network includes access points (APs), access switches, and aggregation switches. Terminals authenticate through the access network. The aggregation switches of the external network are connected to the internal network gateway, providing physical connections for external network terminals to access the internal network. The area outside the park includes an external network gateway, a portal authentication server, an external network authentication server, and the Internet. IPoE access authentication is achieved through interaction between the dial-up devices and the external network gateway, and portal authentication is achieved through interaction between the dial-up devices and the portal authentication server.
[0060] Optionally, the internal or external network gateway can be a core switch, a broadband remote access server (BRAS), a broadband network gateway (BNG), or a virtual BNG (vBNG), etc. The internal or external network authentication server can be a remote authentication dial-in user service (RAD) server or an on-campus authentication, authorization, and accounting (AAA) server, etc. Portal authentication is also known as web authentication.
[0061] This application does not limit the type of terminal used for network authentication. The terminal can be any electronic product that can interact with the user through one or more methods such as a keyboard, touchpad, touchscreen, remote control, voice interaction, or handwriting device. For example, the terminal can be a smartphone, wearable device, tablet computer, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal, or IoT terminal, etc.
[0062] See Figure 2 , Figure 2 A flowchart of a network authentication method provided in this application embodiment, the method can be as follows: Figure 1 In the implementation environment shown, taking the interaction between the intranet authentication server, the proxy device, and the external network gateway to execute the method as an example, the network authentication method includes, but is not limited to, the following steps 201-205.
[0063] Step 201: If the terminal is authenticated through the intranet, the intranet authentication server sends the IPoE dialing command and the terminal's external network authentication information to the proxy dialing device.
[0064] In this embodiment, for authentication requests initiated by a terminal when accessing a network from an external network, internal network authentication is performed first. Optionally, the terminal's internal network authentication is implemented through interaction between the internal network gateway and the internal network authentication server. For example, using... Figure 1 Taking the network topology shown as an example, the terminal initiates an authentication request on the external network. The authentication request includes the terminal's internal network authentication information. The authentication request is sent to the internal network gateway via the external network's AP, access switch, and aggregation switch. The internal network gateway interacts with the internal network authentication server based on the internal network authentication information to achieve internal network authentication of the terminal. If the terminal passes the internal network authentication, the internal network gateway assigns an internal network address to the terminal, such as a campus Internet Protocol (IP) address. The internal network gateway then returns this internal network address to the terminal.
[0065] The embodiments of this application do not limit the authentication method of intranet authentication implemented through the interaction between the intranet gateway and the intranet authentication server, and any access authentication method can be used. For example, intranet authentication can be IPoE authentication or point-to-point protocol over Ethernet (PPPOE) authentication.
[0066] Optionally, the intranet authentication server may have pre-registered intranet authentication information for different terminals. The intranet gateway's interaction with the intranet authentication server based on the intranet authentication information in the authentication request to achieve intranet authentication for the terminal may include: the intranet gateway sending the terminal's intranet authentication information to the intranet authentication server; if the intranet authentication information pre-registered in the intranet authentication server includes the terminal's intranet authentication information, the server returns a successful intranet authentication result to the intranet gateway; if the intranet authentication information pre-registered in the intranet authentication server does not include the terminal's intranet authentication information, the server returns a failed intranet authentication result to the intranet gateway. The terminal's intranet authentication information may be the campus account and password registered by the user using the terminal.
[0067] When a terminal successfully authenticates within the intranet, it obtains its intranet address, thus gaining intranet access privileges. The intranet authentication server then sends an IPoE dialing command and the terminal's external network authentication information to a proxy device, allowing the proxy device to initiate further IPoE external network authentication on behalf of the terminal. In one possible implementation, before sending the IPoE dialing command and the terminal's external network authentication information to the proxy device, the intranet authentication server obtains the terminal's external network authentication information based on a second mapping relationship and the terminal's intranet authentication information. This second mapping relationship includes the correspondence between intranet authentication information and external network authentication information. In other words, the intranet authentication server extracts and stores the second mapping relationship so that, when the terminal successfully authenticates within the intranet, it can determine the external network authentication information corresponding to the terminal's intranet authentication information from the second mapping relationship.
[0068] This application does not limit the method by which the intranet authentication server sends IPoE dialing commands and the terminal's external network authentication information to the proxy device. For example, taking a RADIUS server as the intranet authentication server, the RADIUS server and the proxy device communicate via the RADIUS protocol. In this case, the intranet authentication server sends IPoE dialing commands and the terminal's external network authentication information to the proxy device via the RADIUS protocol.
[0069] Step 202: The proxy dialing device receives the IPoE dialing command sent by the intranet authentication server and the terminal's external network authentication information.
[0070] The proxy dialing device is independently deployed between the intranet and extranet of the campus, connecting to the intranet authentication server and the extranet gateway. This application does not limit the proxy dialing device; it only needs to be able to replace the terminal in interacting with the extranet gateway to achieve IPoE extranet authentication for the terminal. For example, the proxy dialing device can be a network device such as a switch, router, or gateway.
[0071] Step 203: Based on the IPoE dialing command and external network authentication information, the dialing device interacts with the external network gateway to realize the terminal's IPoE external network authentication.
[0072] Optionally, the process of the proxy dialing device interacting with the external network gateway to achieve IPoE external network authentication for the terminal may include: the proxy dialing device sending an IPoE dialing request to the external network gateway based on the IPoE dialing command; the external network gateway sending a portal authentication address to the proxy dialing device based on the received IPoE dialing request; and the proxy dialing device sending a portal authentication request to the portal authentication server through the received portal authentication address. The portal authentication request includes the terminal's external network authentication information and is used by the portal authentication server to interact with the external network gateway to achieve IPoE external network authentication for the terminal.
[0073] The proxy dialing device is configured with Hypertext Transfer Protocol (HTTP) or Hypertext Transfer Protocol Secure (HTTPS), enabling it to generate HTTP or HTTPS request messages. Therefore, based on IPoE dialing commands, the proxy dialing device sends HTTP or HTTPS request messages to the external network gateway to initiate an IPoE dialing request. Upon receiving the IPoE dialing request, the external network gateway redirects the proxy dialing device to the portal authentication address. The portal authentication address can refer to a Uniform Resource Locator (URL).
[0074] In one possible implementation, sending a portal authentication request to a portal authentication server via the portal authentication address may include: parsing the portal authentication address; adding the terminal's external network authentication information to the parsed authentication page; generating a portal authentication request based on the authentication page with the added external network authentication information; and sending the portal authentication request to the portal authentication server. Optionally, the proxy dialing device is configured with a web component, which can be used to parse the portal authentication address.
[0075] In scenarios where a terminal performs portal authentication, the terminal parses the portal authentication address to obtain an authentication page, which is then displayed through a browser. The authentication page includes fields for users to fill in authentication information. In this embodiment, since a proxy device simulates the terminal for portal authentication, the proxy device can simulate the terminal parsing the portal authentication address and automatically add the external network authentication information to the parsed authentication page. For example, the proxy device parses the portal authentication address to obtain the code corresponding to the authentication page, determines the fields for filling in authentication information within the code, and adds the terminal's external network authentication information to the fields to be filled. Optionally, the terminal's external network authentication information can be the operator account and operator password registered by the user using the terminal.
[0076] After the proxy device sends a portal authentication request to the portal authentication server, the portal authentication server interacts with the external network gateway to achieve IPoE external network authentication for the terminal based on the external network authentication information included in the portal authentication request. For example, the portal authentication server sends a portal authentication request to the external network gateway; the external network gateway obtains the terminal's external network authentication information based on the received portal authentication request, and sends the terminal's external network authentication information to the external network authentication server; the external network authentication server has pre-registered external network authentication information for different terminals. If the pre-registered external network authentication information on the external network authentication server includes the terminal's external network authentication information, the server returns a successful IPoE external network authentication result to the external network gateway; if the pre-registered external network authentication information does not include the terminal's external network authentication information, the server returns a failed IPoE external network authentication result to the external network gateway; the external network gateway synchronizes the terminal's IPoE external network authentication result with the portal authentication server.
[0077] Step 204: If the terminal is authenticated via IPoE external network, the external network gateway sends the terminal's external network address to the proxy dialing device. The external network address is used by the terminal to access the external network.
[0078] After the terminal successfully completes IPoE external network authentication, the external network gateway can assign an external network address to the terminal, such as a carrier IP address. Since the proxy device performs the IPoE external network authentication on behalf of the terminal, the external network gateway sends the terminal's external network address to the proxy device so that the terminal can obtain external network access.
[0079] Step 205: The dialing device receives the external network address of the terminal sent by the external network gateway.
[0080] In one possible implementation, when the terminal is authenticated via the intranet, the intranet authentication server, in addition to sending the IPoE dialing command and the terminal's external network authentication information to the proxy dialing device, also sends the terminal's intranet address to the proxy dialing device. In this case, the proxy dialing device also receives the terminal's intranet address sent by the intranet authentication server. Thus, the proxy dialing device can obtain the terminal's intranet address and external network address, and subsequently obtain a first mapping relationship based on the terminal's intranet address and external network address. The first mapping relationship includes the correspondence between intranet addresses and external network addresses, that is, the correspondence between intranet addresses and external network addresses of different terminals.
[0081] After the terminal completes the aforementioned network authentication, it can send and receive both intranet and extranet access traffic. Optionally, when the proxy device receives extranet access traffic sent by the terminal based on an intranet address, it maps the intranet address to an extranet address according to a first mapping relationship and forwards the extranet access traffic based on the extranet address; when it receives extranet data traffic sent to the terminal based on an extranet address, it maps the extranet address to an intranet address according to the first mapping relationship and forwards the extranet data traffic to the terminal based on the intranet address.
[0082] Through steps 201-205 above, the terminal only needs to initiate an authentication request once on the external network. The terminal can achieve both internal network authentication and IPoE external network authentication through the proxy dialing device. This means that the terminal can access the campus data center while accessing the Internet through the external network.
[0083] For example, taking the park as a campus, combined with Figure 3 and Figure 4 The network authentication method provided in the embodiments of this application will be illustrated with examples. Figure 3 In the campus networking scenario shown, the campus intranet corresponds to the school's self-built teaching area network, the intranet gateway corresponds to the campus BRAS, the intranet authentication server corresponds to the campus RADIUS server, and the intranet authentication information corresponds to the campus account. The campus extranet corresponds to the operator's dormitory area network, the extranet gateway corresponds to the operator's BRAS, the extranet authentication server corresponds to the operator's RADIUS server, and the extranet authentication information corresponds to the operator's account. The proxy device communicates with the school's RADIUS server via the RADIUS protocol, interacts with the operator's BRAS via IPoE access, and interacts with the operator's portal server via portal authentication. This enables the proxy device to proxy users to access the operator's network via IPoE and portal authentication.
[0084] The user has already opened an account with the operator, and therefore the user information has been entered into both the operator's RADIUS and the campus network's RADIUS. For example, the user information includes the mapping relationship between the user's campus account and operator account. Figure 4 As shown, the user's terminal initiates an IPoE authentication request on the dormitory network; the campus BRAS and the campus RADIUS server interact for authentication, for example, by exchanging the user's campus account; if the terminal successfully passes the campus authentication (internal network authentication), the terminal obtains a campus IP address (internal network address) and permission to access the campus intranet. This completes the campus-side authentication.
[0085] The campus RADIUS server sends an instruction to the independently deployed proxy dialing device to perform IPoE access to the operator's BRAS on behalf of the terminal (i.e., an IPoE dialing instruction), and synchronizes the user's operator account information. The proxy dialing device, on behalf of the terminal, initiates an IPoE dialing request to the operator's BRAS via HTTP / HTTPS request messages. The operator's BRAS redirects the portal URL to the proxy dialing device, i.e., pushes the portal URL to the proxy dialing device. The proxy dialing device parses the portal URL through its built-in web component and automatically fills in the operator's account information on behalf of the user through an auto-fill function. Then, it sends the filled-in operator account information to the operator's portal server via a portal authentication request (REQ_AUTH) message. After receiving the portal authentication request message, the operator's portal server initiates a portal authentication request to the operator's BRAS. The operator's BRAS and operator RADIUS server perform authentication interactions, such as exchanging the user's operator account information. If the terminal successfully passes operator authentication (i.e., external network authentication), the operator's BRAS notifies the operator's portal server of the authentication result. The operator's BRAS assigns the user's operator IP address (i.e., external network address) to the proxy dialing device. The proxy dialing device performs network address translation (NAT) between the user's campus IP address and operator IP address. Address translation (NAT) mapping. This completes the carrier-side authentication.
[0086] In summary, the method provided in this application, when the terminal has passed intranet authentication, enables the proxy dialing device to initiate IPoE extranet authentication on behalf of the terminal through IPoE dialing commands and the terminal's extranet authentication information, thereby realizing both intranet authentication and IPoE extranet authentication for the terminal. This allows the terminal to pass intranet authentication while simultaneously passing IPoE extranet authentication, thus enabling the terminal to access both the intranet and the extranet at the same time, improving the efficiency of network authentication and reducing the authentication complexity for the terminal to access both the intranet and the extranet.
[0087] The above describes the network authentication method of the embodiments of this application. Corresponding to the above method, the embodiments of this application also provide a network authentication device. Figure 5 This is a schematic diagram of the structure of a network authentication device provided in an embodiment of this application, based on... Figure 5 The following modules are shown. Figure 5 The network authentication device shown can perform Figure 2 The method performs all or part of the operations. It should be understood that the apparatus may include more additional modules than those shown, or may omit some of the modules shown; this application embodiment does not impose limitations in this regard. Figure 5 As shown, the device includes a transceiver module 501 and a processing module 502.
[0088] Transceiver module 501 is used to perform... Figure 2 In the method shown, the receiving and / or sending related operations performed by the dialing device are handled by the processing module 502, which is used to execute... Figure 2 Other operations performed by the dialing device in the illustrated method besides the receiving and / or sending related operations. Alternatively, transceiver module 501 is used to perform... Figure 2 In the method shown, the receiving and / or sending related operations performed by the intranet authentication server are handled by the processing module 502, which is used to execute... Figure 2 The methods shown include operations other than those related to receiving and / or sending performed by the intranet authentication server. Alternatively, transceiver module 501 is used to perform... Figure 2 In the method shown, the receiving and / or sending related operations performed by the external network gateway are handled by the processing module 502, which is used to execute... Figure 2 Other operations performed by the external network gateway in the method shown, besides the receiving and / or sending related operations.
[0089] In one possible implementation, the transceiver module 501 includes a receiving module and / or a sending module. The receiving module is used to perform receiving-related operations, and the sending module is used to perform sending-related operations.
[0090] In the transceiver module 501, it is used to perform... Figure 2 In the method shown, the receiving and / or sending related operations performed by the dialing device are handled by the processing module 502, which is used to execute... Figure 2 In the case of other operations performed by the dispatching device besides the receiving and / or sending related operations in the method shown.
[0091] In one possible implementation, the transceiver module 501 is configured to receive an IPoE dialing command sent by the intranet authentication server and the terminal's external network authentication information when the terminal has passed intranet authentication; interact with the external network gateway based on the IPoE dialing command and external network authentication information to realize the terminal's IPoE external network authentication; and receive the terminal's external network address sent by the external network gateway when the terminal has passed IPoE external network authentication, the external network address being used by the terminal to access the external network.
[0092] In one possible implementation, the transceiver module 501 is configured to send an IPoE dialing request to an external network gateway based on an IPoE dialing command; receive a portal authentication address sent by the external network gateway based on the IPoE dialing request; and send a portal authentication request to a portal authentication server through the portal authentication address. The portal authentication request includes the terminal's external network authentication information, and the portal authentication request is used by the portal authentication server and the external network gateway to interact and implement the terminal's IPoE external network authentication.
[0093] In one possible implementation, the processing module 502 is used to parse the portal authentication address, add the terminal's external network authentication information to the parsed authentication page, and generate a portal authentication request based on the authentication page after adding the terminal's external network authentication information; the transceiver module 501 is used to send the portal authentication request to the portal authentication server.
[0094] In one possible implementation, processing module 502 is further configured to, upon receiving external network access traffic sent by a terminal based on an internal network address, map the internal network address to an external network address according to a first mapping relationship; transceiver module 501 is further configured to forward external network access traffic based on the external network address, the first mapping relationship including the correspondence between internal network addresses and external network addresses. Processing module 502 is further configured to, upon receiving external network data traffic sent to the terminal based on an external network address, map the external network address to an internal network address according to the first mapping relationship; transceiver module 501 is further configured to forward external network data traffic to the terminal based on the internal network address.
[0095] In one possible implementation, the transceiver module 501 is further configured to receive the terminal's intranet address sent by the intranet authentication server. The intranet address is the address assigned to the terminal by the intranet gateway when the intranet authentication information passes intranet authentication. The processing module 502 is configured to obtain a first mapping relationship based on the terminal's intranet address and the terminal's external network address.
[0096] In the transceiver module 501, it is used to perform... Figure 2 In the method shown, the receiving and / or sending related operations performed by the intranet authentication server are handled by the processing module 502, which is used to execute... Figure 2 In the case of operations other than receiving and / or sending related operations performed by the intranet authentication server in the method shown.
[0097] In one possible implementation, the transceiver module 501 is used to send an IPoE dialing command and the terminal's external network authentication information to the proxy dialing device when the terminal has been authenticated through the intranet. The IPoE dialing command and the terminal's external network authentication information are used by the proxy dialing device to interact with the external network gateway to realize the terminal's IPoE external network authentication.
[0098] In one possible implementation, the processing module 502 is used to obtain the external network authentication information of the terminal based on the second mapping relationship and the terminal's internal network authentication information. The second mapping relationship includes the correspondence between the internal network authentication information and the external network authentication information.
[0099] In one possible implementation, the transceiver module 501 is further configured to send the terminal's intranet address to the proxy dialing device. The terminal's intranet address is used by the proxy dialing device to obtain a first mapping relationship based on the terminal's external network address. The first mapping relationship includes the correspondence between the intranet address and the external network address.
[0100] In the transceiver module 501, it is used to perform... Figure 2 In the method shown, the receiving and / or sending related operations performed by the external network gateway are handled by the processing module 502, which is used to execute... Figure 2 In the case of operations other than receiving and / or sending related operations performed by the external network gateway in the method shown.
[0101] In one possible implementation, the transceiver module 501 is used to interact with the proxy dialing device to achieve IPoE external network authentication of the terminal when the proxy dialing device receives the IPoE dialing command sent by the intranet authentication server and the external network authentication information of the terminal; and when the terminal passes the IPoE external network authentication, it sends the external network address of the terminal to the proxy dialing device, which is used by the terminal to access the external network.
[0102] In one possible implementation, the transceiver module 501 is used to receive an IPoE dialing request sent by the proxy dialing device based on the IPoE dialing command; and to send a portal authentication address to the proxy dialing device based on the IPoE dialing request. The portal authentication address is used by the proxy dialing device to send a portal authentication request to the portal authentication server through the portal authentication address. The portal authentication request includes the terminal's external network authentication information. The portal authentication request is used by the portal authentication server to interact with the external network gateway to realize the terminal's IPoE external network authentication.
[0103] It should be understood that the above Figure 5 The provided device, when implementing its functions, is only illustrated by the division of the above-described functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. Furthermore, the device and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process and beneficial effects are detailed in the method embodiments, and will not be repeated here.
[0104] See Figure 6 , Figure 6 A schematic diagram of the structure of a network device 2000 provided in an exemplary embodiment of this application is shown. Figure 6 The network device 2000 shown is used to perform the above. Figure 2 The network authentication method shown involves the following operations. The network device 2000 is, for example, a switch, a router, etc., and can be implemented using a general bus architecture.
[0105] like Figure 6 As shown, the network device 2000 includes at least one processor 2001, a memory 2003, and at least one communication interface 2004.
[0106] Processor 2001 may be, for example, a general-purpose central processing unit (CPU), a digital signal processor (DSP), a network processor (NP), a graphics processing unit (GPU), a neural-network processing unit (NPU), a data processing unit (DPU), a microprocessor, or one or more integrated circuits for implementing the embodiments of this application. For example, processor 2001 includes application-specific integrated circuits (ASICs), programmable logic devices (PLDs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A PLD may be, for example, a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof. It can implement or execute the various logic blocks, modules, and circuits described in connection with the embodiments of this invention. A processor may also be a combination that implements computational functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0107] Optionally, the network device 2000 also includes a bus. The bus is used to transfer information between the various components of the network device 2000. The bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 6 The symbol is represented by only one line, but this does not mean that there is only one bus or one type of bus.
[0108] Memory 2003 may be, for example, read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions; random access memory (RAM) or other types of dynamic storage devices capable of storing information and instructions; electrically erasable programmable read-only memory (EEPROM); compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.); magnetic disk storage media or other magnetic storage devices; or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Memory 2003 may exist independently and be connected to processor 2001 via a bus. Memory 2003 may also be integrated with processor 2001.
[0109] The communication interface 2004 uses any transceiver-like device for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), or wireless local area networks (WLAN). The communication interface 2004 can include wired and wireless communication interfaces. Specifically, the communication interface 2004 can be an Ethernet interface, a Fast Ethernet (FE) interface, a Gigabit Ethernet (GE) interface, an Asynchronous Transfer Mode (ATM) interface, a WLAN interface, a cellular network communication interface, or a combination thereof. The Ethernet interface can be an optical interface, an electrical interface, or a combination thereof. In this embodiment, the communication interface 2004 can be used by the network device 2000 to communicate with other devices.
[0110] In a specific implementation, as one example, the processor 2001 may include one or more CPUs, such as... Figure 6 The CPUs shown are CPU0 and CPU1. Each of these processors can be a single-core CPU or a multi-core CPU. A processor here can refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).
[0111] In a specific implementation, as one example, the network device 2000 may include multiple processors, such as... Figure 6 The processors shown are 2001 and 2005. Each of these processors can be a single-core CPU or a multi-core CPU. Here, "processor" can refer to one or more devices, circuits, and / or processing cores used to process data (such as computer program instructions).
[0112] In a specific implementation, as one example, the network device 2000 may further include output devices and input devices. The output device communicates with the processor 2001 and can display information in various ways. For example, the output device may be a liquid crystal display (LCD), a light-emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device communicates with the processor 2001 and can receive user input in various ways. For example, the input device may be a mouse, keyboard, touchscreen device, or sensor device, etc.
[0113] In some embodiments, the memory 2003 stores program code 2010 for executing the solution of this application, and the processor 2001 can execute the program code 2010 stored in the memory 2003. That is, the network device 2000 can implement the network authentication method provided in the method embodiment through the processor 2001 and the program code 2010 in the memory 2003. The program code 2010 may include one or more software modules. Optionally, the processor 2001 itself may also store program code or instructions for executing the solution of this application.
[0114] In a specific embodiment, the network device 2000 of this application embodiment can correspond to the dialing device in the above-described method embodiments. The processor 2001 in the network device 2000 reads the instructions in the memory 2003, causing... Figure 6 The network device 2000 shown can perform all or part of the operations performed by the dial-up device.
[0115] Network device 2000 can also correspond to the above. Figure 5 The network authentication device shown in the diagram implements each functional module of the network device 2000 using software. In other words, the functional modules of the network authentication device are generated by the processor 2001 of the network device 2000 reading the program code 2010 stored in the memory 2003.
[0116] in, Figure 2Each step of the network authentication method shown is completed through integrated logic circuits in the hardware or software instructions in the processor of the network device 2000. The steps of the method disclosed in the embodiments of this application can be directly implemented by the hardware processor, or by a combination of hardware and software modules in the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. Since this storage medium is located in memory, the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method; to avoid repetition, these will not be described in detail here.
[0117] See Figure 7 , Figure 7 This invention provides a schematic diagram of the structure of a network device 2100 according to another exemplary embodiment of the present application. Figure 7 The network device 2100 shown is used to perform the above. Figure 2 The network authentication method shown involves all or part of the operations. The network device 2100 is, for example, a switch, a router, etc., and can be implemented using a general bus architecture.
[0118] like Figure 7 As shown, the network device 2100 includes a main control board 2110 and an interface board 2130.
[0119] The main control board, also known as the main processing unit (MPU) or route processor card, is used to control and manage the various components in the network device 2100, including routing calculation, device management, device maintenance, and protocol processing functions. The main control board 2110 includes a central processing unit 2111 and a memory 2112.
[0120] Interface board 2130 is also called a line processing unit (LPU), linecard, or service board. Interface board 2130 provides various service interfaces and implements packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces, POS (Packet over SONET / SDH) interfaces, etc., with Ethernet interfaces including, for example, Flexible Ethernet Clients (FlexE Clients). Interface board 2130 includes: a central processing unit 2131, a network processor 2132, a forwarding table entry memory 2134, and a physical interface card (PIC) 2133.
[0121] The central processing unit 2131 on the interface board 2130 is used to control and manage the interface board 2130 and communicate with the central processing unit 2111 on the main control board 2110.
[0122] Network processor 2132 is used to implement packet forwarding processing. Network processor 2132 can be in the form of a forwarding chip. The forwarding chip can be a network processor (NP). In some embodiments, the forwarding chip can be implemented using an application-specific integrated circuit (ASIC) or a field-programmable gate array (FPGA). Specifically, network processor 2132 forwards received packets based on the forwarding table stored in forwarding table entry memory 2134. If the destination address of the packet is the address of network device 2100, the packet is sent to the CPU (such as central processing unit 2131) for processing; if the destination address of the packet is not the address of network device 2100, the next hop and outgoing interface corresponding to the destination address are looked up in the forwarding table according to the destination address, and the packet is forwarded to the outgoing interface corresponding to the destination address. Uplink packet processing may include: packet ingress interface processing, forwarding table lookup; downlink packet processing may include: forwarding table lookup, etc. In some embodiments, the central processing unit can also perform the functions of the forwarding chip, such as implementing software forwarding based on a general-purpose CPU, thus eliminating the need for a forwarding chip on the interface board.
[0123] The physical interface card 2133 is used to implement physical layer interfacing functions. Raw traffic enters the interface board 2130 through this card, and processed packets are sent out from the physical interface card 2133. The physical interface card 2133, also called a daughter card, can be installed on the interface board 2130. It is responsible for converting photoelectric signals into packets, performing validity checks on the packets, and forwarding them to the network processor 2132 for processing. In some embodiments, the central processing unit 2131 can also perform the functions of the network processor 2132, such as implementing software forwarding based on a general-purpose CPU, thus eliminating the need for the network processor 2132 in the physical interface card 2133.
[0124] Optionally, network device 2100 includes multiple interface boards. For example, network device 2100 also includes interface board 2140, which includes: a central processing unit 2141, a network processor 2142, a forwarding table entry memory 2144, and a physical interface card 2143. The functions and implementation methods of each component in interface board 2140 are the same as or similar to those in interface board 2130, and will not be described in detail here.
[0125] Optionally, network device 2100 also includes a switching fabric board 2120. The switching fabric board 2120 can also be referred to as a switch fabric unit (SFU). When network device 2100 has multiple interface boards, the switching fabric board 2120 is used to complete data exchange between the interface boards. For example, interface boards 2130 and 2140 can communicate through the switching fabric board 2120.
[0126] The main control board 2110 and the interface boards are coupled. For example, the main control board 2110, interface boards 2130 and 2140, and the switching network board 2120 communicate with each other via a system bus connected to the system backplane. In one possible implementation, an inter-process communication (IPC) channel is established between the main control board 2110 and interface boards 2130 and 2140, and communication between the main control board 2110 and interface boards 2130 and 2140 is achieved through the IPC channel.
[0127] Logically, network device 2100 includes a control plane and a forwarding plane. The control plane includes a main control board 2110 and a central processing unit 2111, while the forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 2134, a physical interface card 2133, and a network processor 2132. The control plane performs functions such as router operation, generating forwarding tables, processing signaling and protocol messages, and configuring and maintaining the status of network devices. The control plane distributes the generated forwarding tables to the forwarding plane. In the forwarding plane, the network processor 2132 forwards messages received by the physical interface card 2133 based on the forwarding tables distributed by the control plane. The forwarding tables distributed by the control plane can be stored in the forwarding table entry memory 2134. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same network device.
[0128] It's worth noting that a network device may have one or more main control boards, including a primary and a backup main control board. It may also have one or more interface boards; the more powerful the network device's data processing capabilities, the more interface boards it provides. Each interface board may also have one or more physical interface cards. A switching board may or may not exist; multiple boards can share the load and provide redundancy. In a centralized forwarding architecture, the network device may not need a switching board, as the interface boards handle the entire system's business data processing. In a distributed forwarding architecture, the network device can have at least one switching board, which enables data exchange between multiple interface boards, providing high-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of a distributed architecture network device are greater than those of a centralized architecture network device. Alternatively, the network device can also be a single board, without a switching board. The functions of the interface board and the main control board are integrated on this one board. In this case, the central processing unit (CPU) on the interface board and the CPU on the main control board can be combined into a single CPU to perform the combined functions. This type of network device has lower data exchange and processing capabilities (e.g., low-end switches or routers). The specific architecture adopted depends on the specific network deployment scenario, and no restrictions are imposed here.
[0129] In a specific embodiment, network device 2100 corresponds to the above. Figure 5 The network authentication device shown. In some embodiments, Figure 5 The transceiver module 501 in the network authentication device shown is equivalent to the physical interface card 2133 in the network device 2100, and the processing module 502 is equivalent to the central processing unit 2111 or network processor 2132 in the network device 2100.
[0130] Figure 8 This is a schematic diagram of a server structure provided in an embodiment of this application. The server 800 can vary significantly due to different configurations or performance. It may include one or more processors 801 and one or more memories 802. The one or more memories 802 store at least one computer program, which is loaded and executed by the one or more processors 801 to enable the server to implement the network authentication methods provided in the above-described method embodiments. Of course, the server 800 may also have wired or wireless network interfaces, a keyboard, and input / output interfaces for input and output. The server 800 may also include other components for implementing device functions, which will not be elaborated upon here.
[0131] This application also provides a network authentication system, which includes: a dial-up device, an intranet authentication server, and an extranet gateway. For example, the dial-up device is... Figure 6The network device shown is 2000 or Figure 7 The network device 2100 shown has an internal network authentication server. Figure 8 The server shown has an external network gateway of [gateway information missing]. Figure 6 The network device shown is 2000 or Figure 7 The network device 2100 shown above. The network authentication methods performed by the proxy device, the intranet authentication server, and the extranet gateway can be found in the above description. Figure 2 The relevant descriptions of the embodiments shown will not be repeated here.
[0132] This application also provides a communication device, which includes a transceiver, a memory, and a processor. The transceiver, the memory, and the processor communicate with each other via an internal connection path. The memory stores instructions, and the processor executes the instructions stored in the memory to control the transceiver to receive and transmit signals. When the processor executes the instructions stored in the memory, it causes the processor to perform the methods required by the call-on device.
[0133] It should be understood that the aforementioned processor can be a CPU, or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. General-purpose processors can be microprocessors or any conventional processor. It is worth noting that the processor can be a processor supporting Advanced Reduced Instruction Set Computing (RISC) machines (ARM) architecture.
[0134] Furthermore, in an alternative embodiment, the memory described above may include read-only memory and random access memory, and provide instructions and data to the processor. The memory may also include non-volatile random access memory. For example, the memory may also store device type information.
[0135] The memory can be volatile or non-volatile, or may include both. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which serves as an external cache. Many forms of RAM are available by way of example, but not limitation. Examples include static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0136] This application also provides a computer-readable storage medium storing at least one instruction, which is loaded and executed by a processor to enable the computer to implement any of the network authentication methods described above.
[0137] This application also provides a computer program (product) that, when executed by a computer, causes the processor or computer to perform the corresponding steps and / or processes in the above method embodiments.
[0138] This application also provides a chip, including a processor, for calling and executing instructions stored in a memory, causing a communication device with the chip installed to perform any of the network authentication methods described above.
[0139] This application embodiment also provides another chip, including: an input interface, an output interface, a processor, and a memory. The input interface, output interface, processor, and memory are connected through an internal connection path. The processor is used to execute code in the memory. When the code is executed, the processor is used to execute any of the network authentication methods mentioned above.
[0140] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to this application are generated, in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk), etc.
[0141] Those skilled in the art will recognize that the method steps and modules described in conjunction with the embodiments disclosed herein can be implemented in software, hardware, firmware, or any combination thereof. To clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0142] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.
[0143] When implemented using software, it can be implemented wholly or partially as a computer program product. This computer program product includes one or more computer program instructions. As an example, the methods of this application embodiment can be described in the context of machine-executable instructions, such as program modules that execute on a device on a real or virtual processor of the target. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., which perform specific tasks or implement specific abstract data structures. In various embodiments, the functionality of program modules can be combined or divided among the described program modules. The machine-executable instructions for the program modules can execute within a local or distributed device. In a distributed device, the program modules can reside on both local and remote storage media.
[0144] Computer program code used to implement the methods of the embodiments of this application may be written in one or more programming languages. This computer program code may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, such that when executed by the computer or other programmable data processing apparatus, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a computer, partially on a computer, as a standalone software package, partially on a computer and partially on a remote computer, or entirely on a remote computer or server.
[0145] In the context of the embodiments of this application, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, etc.
[0146] Examples of signals may include electrical, optical, radio, sound, or other forms of propagation signals, such as carrier waves, infrared signals, etc.
[0147] A machine-readable medium can be any tangible medium that contains or stores programs for or relating to an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. More detailed examples of machine-readable storage media include electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0148] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be found in the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0149] In the embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the couplings or direct couplings or communication connections shown or discussed may be indirect couplings or communication connections through some interfaces, devices, or modules, or they may be electrical, mechanical, or other forms of connection.
[0150] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of the embodiments of this application, depending on actual needs.
[0151] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.
[0152] If the integrated module is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0153] In this application, the terms "first," "second," etc., are used to distinguish identical or similar items that have substantially the same function and purpose. It should be understood that there is no logical or temporal dependency between "first," "second," and "nth," nor does it limit the quantity or order of execution. It should also be understood that although the following description uses the terms "first," "second," etc., to describe various elements, these elements should not be limited by the terms. These terms are merely used to distinguish one element from another. For example, without departing from the scope of various examples, a first image can be referred to as a second image, and similarly, a second image can be referred to as a first image. Both the first image and the second image can be images, and in some cases, they can be separate and distinct images.
[0154] It should also be understood that, in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0155] In this application, the term "at least one" means one or more, and the term "multiple" means two or more. For example, multiple second messages refer to two or more second messages. The terms "system" and "network" are often used interchangeably in this document.
[0156] It should be understood that the terminology used in the description of the various examples herein is for the purpose of describing particular examples only and is not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms “a” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0157] It should also be understood that the term "and / or" as used herein refers to and covers any and all possible combinations of one or more of the associated listed items. The term "and / or" describes an association between related objects, indicating that three relationships can exist; for example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Additionally, the character " / " in this application generally indicates that the preceding and following related objects are in an "or" relationship.
[0158] It should also be understood that the term “comprising” (also referred to as “includes”, “including”, “comprises” and / or “comprising”) as used in this specification specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0159] It should also be understood that the terms “if” and “if” can be interpreted as meaning “when” or “upon”, or “in response to determination” or “in response to detection”. Similarly, depending on the context, the phrases “if determination…” or “if detection [the stated condition or event]” can be interpreted as meaning “when determination…”, or “in response to determination…”, or “when detection [the stated condition or event]” or “in response to detection [the stated condition or event]”.
[0160] It should be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.
[0161] It should also be understood that the phrases "an embodiment," "an embodiment," and "a possible implementation" used throughout the specification mean that a specific feature, structure, or characteristic related to an embodiment or implementation is included in at least one embodiment of this application. Therefore, the phrases "in an embodiment," "an embodiment," or "a possible implementation" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0162] The above description is only an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.
Claims
1. A network authentication method, characterized in that, The method includes: When the terminal is authenticated through the intranet, it receives the Internet Protocol (IPoE) dialing command based on Ethernet and the external network authentication information of the terminal sent by the intranet authentication server. Based on the IPoE dialing command and the external network authentication information, the terminal interacts with the external network gateway to achieve IPoE external network authentication. When the terminal is authenticated via the IPoE external network, it receives the external network address of the terminal sent by the external network gateway. The external network address is used by the terminal to access the external network.
2. The method according to claim 1, characterized in that, The step of interacting with the external network gateway based on the IPoE dialing command and the external network authentication information to achieve IPoE external network authentication for the terminal includes: Based on the IPoE dialing command, an IPoE dialing request is sent to the external network gateway; Receive the portal authentication address sent by the external network gateway based on the IPoE dial-up request; The portal authentication request is sent to the portal authentication server through the portal authentication address. The portal authentication request includes the external network authentication information of the terminal. The portal authentication request is used by the portal authentication server to interact with the external network gateway to realize the IPoE external network authentication of the terminal.
3. The method according to claim 2, characterized in that, Sending a portal authentication request to the portal authentication server via the portal authentication address includes: Parse the portal authentication address and add the terminal's external network authentication information to the obtained authentication page; The portal authentication request is generated based on the authentication page after adding the external network authentication information of the terminal, and then sent to the portal authentication server.
4. The method according to any one of claims 1-3, characterized in that, After receiving the external network address of the terminal sent by the external network gateway, the process further includes: Upon receiving external network access traffic sent by the terminal based on the internal network address, the internal network address is mapped to the external network address according to the first mapping relationship, and the external network access traffic is forwarded based on the external network address. The first mapping relationship includes the correspondence between internal network addresses and external network addresses. Upon receiving external network data traffic sent to the terminal based on the external network address, the external network address is mapped to the internal network address according to the first mapping relationship, and the external network data traffic is forwarded to the terminal based on the internal network address.
5. The method according to claim 4, characterized in that, Before mapping the internal network address to the external network address according to the first mapping relationship, the method further includes: Receive the intranet address of the terminal sent by the intranet authentication server. The intranet address is the address assigned to the terminal by the intranet gateway when the terminal passes the intranet authentication. The first mapping relationship is obtained based on the terminal's internal network address and the terminal's external network address.
6. A network authentication method, characterized in that, The method includes: When the terminal is authenticated through the intranet, an IPoE dialing command based on Ethernet and the terminal's external network authentication information are sent to the proxy dialing device. The IPoE dialing command and the terminal's external network authentication information are used by the proxy dialing device to interact with the external network gateway to realize the terminal's IPoE external network authentication.
7. The method according to claim 6, characterized in that, Before sending the Ethernet-based Internet Protocol (IPoE) dialing command and the terminal's external network authentication information to the proxy dialing device, the method further includes: The external network authentication information of the terminal is obtained according to the second mapping relationship and the internal network authentication information of the terminal. The second mapping relationship includes the correspondence between the internal network authentication information and the external network authentication information.
8. The method according to claim 6 or 7, characterized in that, The method further includes: The internal network address of the terminal is sent to the dialing device. The internal network address of the terminal is used by the dialing device to obtain a first mapping relationship based on the external network address of the terminal. The first mapping relationship includes the correspondence between the internal network address and the external network address.
9. A network authentication method, characterized in that, The method includes: When the proxy dialing device receives the Internet Protocol (IPoE) dialing command based on Ethernet sent by the intranet authentication server and the external network authentication information of the terminal, it interacts with the proxy dialing device to realize the IPoE external network authentication of the terminal. When the terminal is authenticated via the IPoE external network, the external network address of the terminal is sent to the proxy dialing device. The external network address is used by the terminal to access the external network.
10. The method according to claim 9, characterized in that, The interaction with the proxy dialing device to achieve IPoE external network authentication for the terminal includes: Receive the IPoE dialing request sent by the proxy dialing device based on the IPoE dialing command; Based on the IPoE dialing request, a portal authentication address is sent to the proxy dialing device. The portal authentication address is used by the proxy dialing device to send a portal authentication request to the portal authentication server. The portal authentication request includes the external network authentication information of the terminal. The portal authentication request is used by the portal authentication server to interact with the external network gateway to realize the IPoE external network authentication of the terminal.
11. A network authentication device, characterized in that, The device includes: A transceiver module is used to perform the receiving and / or sending related operations in the method according to any one of claims 1-5; a processing module is used to perform other operations besides the receiving and / or sending related operations in the method according to any one of claims 1-5; or, A transceiver module is configured to perform the receiving and / or sending related operations as described in any one of claims 6-8; a processing module is configured to perform other operations besides the receiving and / or sending related operations as described in any one of claims 6-8; or, A transceiver module is used to perform the receiving and / or sending related operations in the method of any one of claims 9 or 10, and a processing module is used to perform other operations besides the receiving and / or sending related operations in the method of any one of claims 9 or 10.
12. A network device, characterized in that, The network device includes: a processor coupled to a memory, the memory storing at least one program instruction or code, the at least one program instruction or code being loaded and executed by the processor to enable the network device to implement the network authentication method according to any one of claims 1-5, or to enable the network device to implement the network authentication method according to any one of claims 6-8, or to enable the network device to implement the network authentication method according to any one of claims 9 or 10.
13. A network authentication system, characterized in that, The network authentication system includes a dial-up device, an intranet authentication server, and an extranet gateway; The dialing device is used to perform the method according to any one of claims 1-5, the intranet authentication server is used to perform the method according to any one of claims 6-8, and the extranet gateway is used to perform the method according to any one of claims 9 or 10.
14. A computer-readable storage medium, characterized in that, The computer storage medium stores at least one instruction, which is loaded and executed by a processor to enable the computer to implement the network authentication method as described in any one of claims 1-10.
15. A computer program product, characterized in that, The computer program product includes: computer program code, which is loaded and executed by a computer to enable the computer to implement the network authentication method according to any one of claims 1-10.