Method, device and equipment for realizing Portal authentication and storage medium
By combining a unified strategy at the main access point with local processing at the access point in the MESH network, the authentication status of the entire network is consistent, which solves the problem of low Portal authentication accuracy and improves authentication accuracy and user experience.
Patent Information
- Application Number
- CN202511786498.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-01
- Publication Date
- 2026-02-06
AI Technical Summary
In existing MESH networks, Portal authentication has low accuracy, centralized solutions have excessively long paths and high latency, and distributed solutions have inconsistent state synchronization, leading to authentication failures and false interceptions.
The main access point (MAP) issues a unified Portal authentication policy, and the access point (AP) locally processes terminal access and traffic interception. Combined with multicast/broadcast synchronization, unicast retransmission, batch synchronization of new nodes, and serial number verification, it achieves real-time consistency of authentication status across the entire network.
It improves the accuracy of Portal authentication, avoids issues such as excessively long paths and delays, resolves secondary authentication and false interception caused by state confusion, and optimizes user experience and network deployment.
Smart Images

Figure CN121486818A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, device, and storage medium for implementing Portal authentication. Background Technology
[0002] With the rapid development of wireless communication technology, MESH networking, with its self-organizing, self-healing, and flexible expansion characteristics, has been widely deployed in public places requiring large-area wireless coverage, such as shopping malls, airports, campuses, and large corporate parks. In these scenarios, network operators typically need to authenticate and authorize accessing end users. Portal authentication, as a mature technology, can redirect web page requests from unauthenticated users to specific authentication pages, thereby verifying user identity and controlling network access permissions.
[0003] In existing technologies, there are two main typical schemes for implementing Portal authentication in a MESH network environment. The first is a centralized authentication scheme, in which the Portal authentication function is deployed only on the main access point (MAP) of the network, and all traffic from unauthenticated users must be redirected through the MAP. The second is a distributed authentication scheme, in which the Portal authentication function is enabled on each access point (AP) in the network, and each AP independently handles the authentication process of its associated terminals.
[0004] However, existing technologies have low accuracy in achieving Portal authentication in MESH networks. Summary of the Invention
[0005] This application provides a method, apparatus, device, and storage medium for implementing Portal authentication, which can improve the accuracy of Portal authentication in a MESH network.
[0006] To achieve the above objectives, this application adopts the following technical solution: Firstly, this application provides a method for implementing Portal authentication, including: Obtain the Portal authentication policy issued by the main access point MAP, wherein the Portal authentication policy includes the Portal server address and the redirect URL; When a terminal connects to the target access point (AP) and the terminal is in an unauthenticated state, the request initiated by the unauthenticated terminal is intercepted according to the Portal authentication policy, and the request is redirected to the Portal authentication page through the redirect URL. The receiving terminal submits authentication information through the Portal authentication page and forwards the authentication information to the authentication server corresponding to the Portal server address; Receive the authentication success notification returned by the authentication server; In response to the authentication success notification, the authentication success status information of the terminal is synchronized to the MAP; Receive authentication status records synchronized by MAP based on the global status, and update the locally stored authentication status records. When a terminal that is in an authenticated state according to the locally stored authentication status record accesses the target AP, the terminal is directly allowed to access the network based on its authenticated state.
[0007] Optionally, synchronizing the authentication success status information of the terminal to the MAP includes: The authentication success status information is synchronized to the MAP via multicast or broadcast.
[0008] Optionally, the method further includes: When the MAP does not receive confirmation of the successful authentication status of the synchronization from the target AP, it receives the unicast synchronization message from the MAP.
[0009] Optionally, the method further includes: Receive the MAP authentication status clear command; In response to the clearing command, the authentication status record of the specified terminal stored locally is updated to unauthenticated status.
[0010] Optionally, the authentication status record carries a sequence number; receiving the authentication status record synchronized by the MAP according to the global status and updating the locally stored authentication status record includes: When the sequence number received from the authentication status record synchronized by the MAP based on the global status is greater than the corresponding sequence number stored locally by the target AP, the authentication status record stored locally is updated based on the received authentication status record.
[0011] Optionally, the method further includes: If the target AP is newly launched, it receives a batch synchronization message sent by the MAP, which contains the authentication status records of all authenticated terminals; Update the authentication status record in the local storage according to the batch synchronization message.
[0012] Optionally, the authentication success status information includes the terminal's MAC address, authentication status identifier, and validity period.
[0013] Secondly, this application provides an apparatus for implementing Portal authentication, comprising: The acquisition module is used to acquire the Portal authentication policy issued by the main access point MAP. The Portal authentication policy includes the Portal server address and the redirect URL. The processing module is configured to, when a terminal accesses the target access point (AP) and the terminal is in an unauthenticated state, intercept requests initiated by the unauthenticated terminal according to the Portal authentication policy, and redirect the requests to the Portal authentication page via a redirect URL; receive authentication information submitted by the terminal through the Portal authentication page, and forward the authentication information to the authentication server corresponding to the Portal server address; receive authentication success notification returned by the authentication server; in response to the authentication success notification, synchronize the terminal's authentication success status information to the MAP; and receive authentication status records synchronized by the MAP according to the global status, and update the locally stored authentication status records. The authentication module is used to directly allow a terminal to access the network based on its authenticated status when it connects to the target AP, according to the locally stored authentication status record.
[0014] Thirdly, this application provides a computing device, including a memory and a processor; The memory stores one or more computer programs, the one or more computer programs including instructions; when the instructions are executed by the processor, the computing device performs the method as described in any one of the first aspects.
[0015] Fourthly, this application provides a computer-readable storage medium for storing a computer program for performing the method as described in any one of the first aspects.
[0016] As can be seen from the above technical solution, this application has at least the following beneficial effects: In this application, on the one hand, the target access point (AP) performs local interception and accurate redirection of HTTP / HTTPS requests initiated by unauthenticated terminals based on the unified Portal authentication policy issued by the main access point (MAP). This eliminates the need for traffic to bypass the MAP, thereby avoiding the problems of excessively long paths, high latency, and lost redirection messages in centralized solutions. This significantly reduces the probability of authentication failure and ensures the stability of the authentication process.
[0017] On the other hand, after successful terminal authentication, the target access point (AP) synchronizes the successful authentication status information to the MAP via multicast or broadcast. This, combined with the MAP's unicast retransmission mechanism for unicast transmission when no confirmation response is received, the batch synchronization mechanism for newly deployed target APs, and the status verification rules based on sequence numbers, ensures real-time consistency of authentication status records across all access point APs in the network. This design completely solves the problems of secondary authentication and authentication failure caused by asynchronous node states in distributed solutions, and effectively avoids the accidental interception of authenticated user traffic or unauthorized access by unauthenticated users due to state inconsistencies, thus improving authentication accuracy.
[0018] Meanwhile, when an authenticated terminal roams to any access point (AP), it can directly obtain network access permissions based on the locally synchronized authentication status, achieving seamless roaming and further optimizing the user experience. The globally unified policy control and flexible state synchronization mechanism can fully match the self-organizing and flexible expansion characteristics of Mesh networking, effectively improving network deployment.
[0019] It should be understood that the descriptions of technical features, technical solutions, beneficial effects, or similar language in this application do not imply that all features and advantages can be achieved in any single embodiment. Rather, it is understood that the description of a feature or beneficial effect means that a specific technical feature, technical solution, or beneficial effect is included in at least one embodiment. Therefore, the descriptions of technical features, technical solutions, or beneficial effects in this specification do not necessarily refer to the same embodiment. Furthermore, the technical features, technical solutions, and beneficial effects described in this embodiment can be combined in any suitable manner. Those skilled in the art will understand that embodiments can be implemented without one or more specific technical features, technical solutions, or beneficial effects of a particular embodiment. In other embodiments, additional technical features and beneficial effects may be identified in specific embodiments that do not embody all embodiments. Attached Figure Description
[0020] Figure 1 A flowchart illustrating a method for implementing Portal authentication provided in this application embodiment; Figure 2 A schematic diagram of a device for implementing Portal authentication provided in an embodiment of this application; Figure 3 This is a schematic diagram of a computing device provided in an embodiment of this application. Detailed Implementation
[0021] The terms "first," "second," and "third," etc., used in this application specification and accompanying drawings are used to distinguish different objects, not to limit a specific order.
[0022] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.
[0023] To ensure clarity and conciseness in the description of the following embodiments, a brief introduction to the related technologies is given first: Wireless mesh networking is a wireless network architecture with self-organizing, self-healing and flexible expansion characteristics. It achieves large-area wireless coverage by working together with a main access point (MAP) and multiple access points (APs), and is widely used in public places such as shopping malls, airports, and campuses.
[0024] Portal authentication is a technology used by network operators to authenticate end users and authorize services. Its purpose is to redirect web page requests from unauthenticated users to a specific authentication page, and grant network access after successful verification.
[0025] The main problem with existing technologies for implementing Portal authentication in Mesh networks is low authentication accuracy, a problem particularly pronounced in centralized authentication schemes. These schemes deploy Portal authentication functionality only on the main access point (MAP), requiring all traffic from unauthenticated terminals to be redirected through the MAP. However, the multi-hop transmission characteristic of Mesh networks leads to excessively long authentication traffic paths for remote terminals, resulting in high transmission latency and the potential for intermediate nodes to drop redirected packets due to unrecognized authentication status, directly causing authentication failure and reducing accuracy.
[0026] While distributed authentication schemes can avoid the problem of traffic bypassing the MAP (Access Point Map), they also have inherent drawbacks that lead to low authentication accuracy. This scheme deploys authentication functionality independently on each access point (AP), lacking an effective global state synchronization mechanism. After a terminal completes authentication at one AP, its authentication status cannot be synchronized to other APs in real time. This not only requires secondary authentication when the terminal roams, but also may lead to the accidental interception of authenticated user traffic or the unauthorized granting of permissions to unauthenticated users due to inconsistent node states, further exacerbating the low authentication accuracy problem.
[0027] In view of this, embodiments of this application provide a method for implementing Portal authentication, which can be performed by an access point (AP).
[0028] To address the low authentication accuracy issue present in both centralized and distributed portal authentication schemes in existing Mesh networks, this application addresses this problem by having the main access point distribute a unified portal authentication policy via MAP, ensuring consistent authentication rules across all access point APs. The access point APs handle terminal access, traffic interception, and redirection locally, avoiding the excessively long paths and latency issues of centralized schemes. Furthermore, a multi-state coordination mechanism is designed, including multicast / broadcast synchronization, unicast retransmission, batch synchronization of new nodes, and sequence number verification, to achieve real-time consistency of authentication status across the entire network. This resolves the state inconsistency problem in distributed schemes, ultimately improving authentication accuracy and user experience.
[0029] To address the low authentication accuracy issues present in both centralized and distributed portal authentication schemes in existing Mesh networks, this application adopts a approach of centralized MAP management, distributed AP execution, and multi-state collaboration. The MAP uniformly distributes portal authentication policies, ensuring consistency in authentication rules across all APs in the network. Terminal access, traffic interception, and redirection are handled locally by the APs, fundamentally avoiding the excessively long paths and high latency issues caused by traffic bypassing the MAP in centralized schemes. Simultaneously, an innovative multi-state collaboration mechanism is designed, including multicast / broadcast synchronization, unicast retransmission, batch synchronization of new nodes, and sequence number verification, to achieve real-time unification of authentication status across the entire network. This resolves the pain point of state inconsistencies in distributed schemes, ultimately improving authentication accuracy and user network experience.
[0030] To make the technical solution of this application clearer and easier to understand, a method for implementing Portal authentication provided by an embodiment of this application will be described below with reference to the accompanying drawings. Figure 1 As shown, this figure is a flowchart of a method for implementing Portal authentication provided in an embodiment of this application. The method includes: S201. The target access point (AP) obtains the Portal authentication policy issued by the primary access point (MAP). The Portal authentication policy includes the Portal server address and the redirect URL.
[0031] The target access point (AP) is the node in a mesh network that directly connects to terminal access and executes the authentication process. It is responsible for local processing of terminal access requests, traffic interception and redirection, and other operations.
[0032] The Master Access Point (MAP) is the control node of the Mesh network, responsible for overall management and control, including issuing unified authentication policies and synchronizing the authentication status of all terminals across the network.
[0033] The Portal authentication policy is a set of global authentication rules uniformly issued by MAP. It serves as the basis for each target AP to perform Portal authentication, ensuring that the authentication logic is consistent across the entire network.
[0034] The Portal server address is the network address of the server that receives terminal authentication information during Portal authentication. The target AP needs to forward the authentication information such as account and password submitted by the terminal to this address so that the server can complete the authentication.
[0035] The redirect URL, or Uniform Resource Locator, is the network address of the authentication page that is used to automatically redirect web page requests from unauthenticated terminals to the corresponding Portal authentication page (such as the account and password login page).
[0036] The target AP first obtains the globally unified Portal authentication policy from the main access point (MAP). This policy contains two key pieces of information: the Portal server address, which specifies the receiving terminal for authentication information, and the redirect URL, which specifies the authentication page address that unauthenticated terminals should be redirected to. Through this step, all target APs obtain a unified authentication execution basis, laying the foundation for accurately intercepting unauthenticated traffic, guiding the authentication process, and forwarding authentication information. This ensures consistent authentication rules across the network and avoids authentication anomalies caused by rule differences.
[0037] S202. When a terminal accesses the target access point (AP) and the terminal is in an unauthenticated state, the target access point (AP) intercepts the request initiated by the unauthenticated terminal according to the Portal authentication policy and redirects the request to the Portal authentication page through a redirect URL.
[0038] The Portal authentication page is a user interaction page generated based on the redirected URL. End users need to submit authentication information such as account and password on this page to complete the authentication process.
[0039] When a user's terminal device connects to the target access point (AP), the AP first determines the terminal's status. If the terminal has not yet completed Portal authentication (i.e., is in an unauthenticated state), then whenever the terminal initiates any HTTP / HTTPS request, the target AP will accurately intercept these requests according to the unified Portal authentication policy obtained from the primary access point (MAP). Simultaneously, using the preset redirect URL in the authentication policy, the intercepted HTTP / HTTPS requests will be automatically redirected to the corresponding Portal authentication page, forcing the terminal user to enter the authentication process.
[0040] Hypertext Transfer Protocol (HTTP) / Hypertext Transfer Security (HTTPS) requests are network access requests initiated by a terminal after it has connected to the network, and they are also the standard communication protocol for interaction between the terminal and the network server. HTTP is used for ordinary network data transmission, while HTTPS adds encryption mechanisms to HTTP and is suitable for data transmission involving privacy (such as login and payment). Common scenarios include opening web pages, refreshing app content, loading images / videos, sending chat messages, and downloading files.
[0041] The purpose of this step is to ensure that unauthenticated terminals cannot directly access network resources via HTTP / HTTPS protocols through status checks, HTTP / HTTPS request interception, and redirection logic. They must complete authentication through the authentication page before they can obtain permissions. This not only meets the requirements of Portal authentication but also avoids the delay or loss problems caused by traffic routing in centralized solutions by executing interception and redirection locally.
[0042] S203. The target access point (AP) receives the authentication information submitted by the terminal through the Portal authentication page and forwards the authentication information to the authentication server corresponding to the Portal server address.
[0043] Authentication information is the identity verification data submitted by the end user on the Portal authentication page, which typically includes information such as account, password, and verification code used to confirm the user's identity.
[0044] The authentication server is the backend server corresponding to the Portal server address. Its responsibility is to verify the legality of the authentication information submitted by the terminal, such as whether the account and password match, whether the user has the right to access the account, and return the authentication result.
[0045] After the end user completes and submits their identity information on the Portal authentication page, the target AP directly connected to the end user will first receive this authentication information. Subsequently, the target AP will find the Portal server address based on the Portal authentication policy previously obtained from the MAP, and accurately forward the received authentication information to the authentication server corresponding to that address, so that the server can complete the subsequent identity verification work.
[0046] This step is a crucial bridge connecting user-submitted information with backend verification. By forwarding the information locally through the target AP, the authentication information transmission is bypassed, ensuring the efficiency and stability of information transmission.
[0047] S204. The target access point (AP) receives a successful authentication notification from the authentication server.
[0048] A successful authentication notification is a confirmation message sent by the authentication server to the target AP after verifying the terminal's authentication information. It informs the terminal that its identity is legitimate and has passed verification, and its purpose is to trigger subsequent permission granting and status synchronization operations.
[0049] After receiving the terminal authentication information forwarded by the target access point (AP), the authentication server will verify the legality of the authentication information. If the verification passes, it confirms that the user's identity is valid and that they have network access rights. The server will then send a special authentication success notification to the target AP. As the node directly connected to the terminal, the target AP will receive this notification to confirm that the terminal has completed legal authentication, thus laying the foundation for subsequently opening network access rights and synchronizing the authentication status.
[0050] S205. In response to the authentication success notification, the target access point (AP) synchronizes the terminal's authentication success status information to the MAP.
[0051] Successful authentication status information includes the terminal's MAC address, authentication status identifier, and validity period, which is used to synchronize the authentication status of all terminals across the network.
[0052] The target access point (AP) synchronizes the successful authentication status information to the MAP via multicast or broadcast.
[0053] Multicast is a one-to-many network data transmission method where the target AP sends an authentication success status message to a specific group address. Only APs that have joined the group can receive the message, balancing transmission efficiency and targeting.
[0054] Broadcast is a one-to-all network data transmission method. The target AP sends an authentication success status message to all nodes in its network to ensure that the AP can reliably receive it. It is suitable for scenarios with a small number of network nodes.
[0055] After receiving a successful terminal authentication notification from the authentication server, the target AP will choose either multicast or broadcast to send the terminal's successful authentication status information to the MAP. Using these two transmission methods ensures rapid information delivery to the MAP (multicast prioritizes efficiency, while broadcast guarantees coverage) and adapts to the distributed architecture of Mesh networking. This provides efficient data transmission support for the MAP to subsequently synchronize the authentication status with other APs across the network, enabling seamless terminal roaming and avoiding information loss or delays that might occur with a single transmission method.
[0056] When the MAP does not receive confirmation of the successful authentication status information for synchronization from the target AP, the target access point AP receives the MAP's unicast synchronization message.
[0057] Unicast synchronization messages are status synchronization data messages sent by the MAP using a one-to-one transmission method. Only the specified target AP can receive them, and they are used to accurately retransmit information that has not been successfully synchronized.
[0058] After the target AP synchronizes the terminal's successful authentication status information to the MAP via multicast or broadcast, the MAP receives the information and needs to return a "received" response to the target AP. If the MAP does not receive the acknowledgment response (which may be due to network interference, packet loss, or other factors causing initial synchronization failure), it will automatically initiate a retransmission process: sending a unicast synchronization message to the target AP via unicast to retransmit the corresponding successful authentication status information.
[0059] This step, through a dual guarantee design of receiving confirmation mechanism and unicast retransmission, ensures that authentication status information is reliably synchronized to MAP, effectively avoiding the problem of inconsistent authentication status across the network caused by synchronization failure, and further improving authentication accuracy.
[0060] S206. The target access point (AP) receives the authentication status record synchronized by the MAP according to the global status and updates the locally stored authentication status record.
[0061] Global status refers to the latest authentication status set of all terminals in the Mesh network summarized by MAP. It covers complete information of all authenticated and unauthenticated terminals in the network and is the basis for MAP to synchronize status.
[0062] The authentication status record is a data carrier that carries terminal authentication-related information. It includes key information such as terminal MAC address, authentication status (authenticated / unauthenticated), serial number, and validity period. It is divided into two categories: a unified global record stored by the main access point MAP and a local management record stored by the target access point AP.
[0063] Local storage is the target AP's own storage module, used to retain terminal authentication status records synchronized from within its jurisdiction and the entire network, supporting fast querying and retrieval.
[0064] Specifically, the authentication status record carries a sequence number. When the sequence number in the authentication status record synchronized by the MAP based on the global status is greater than the corresponding sequence number stored locally by the target AP, the target access point AP updates the authentication status record stored locally based on the received authentication status record.
[0065] The sequence number is a unique, incrementing identifier assigned to each authentication status record. It is used to mark the update sequence of the record. The larger the sequence number, the newer the record. It is the core basis for determining whether the status needs to be updated.
[0066] The corresponding sequence number stored locally is the sequence number of the authentication status record previously stored by the target AP that corresponds to the same terminal in the received record, representing the current version of the local record.
[0067] Each authentication status record is accompanied by a unique sequence number, which increments when the record is updated. When the target AP receives the global authentication status record synchronized by the MAP, it compares the sequence number in the global record with the corresponding sequence number stored locally for the same terminal. Only when the sequence number of the global record is greater than the local sequence number (indicating that the global record is the updated version) will the target AP use this received global authentication status record to overwrite and update the old record stored locally.
[0068] This design avoids duplicate updates or reverse updates (overwriting new records with old ones), ensuring that local records are always in the latest and consistent state across the entire network, further guaranteeing the accuracy of authentication status synchronization.
[0069] The method also includes authentication status clearing instructions: The target access point (AP) receives the authentication status clearing command from the MAP; in response to the clearing command, it updates the authentication status record of the specified terminal stored locally to an unauthenticated status.
[0070] The authentication status clearing command is a targeted control command issued by the MAP to notify the target AP to reset the authentication status of a specific terminal. It is usually triggered in scenarios such as the expiration of the terminal authentication validity period, user voluntary cancellation, or network management requirements.
[0071] In specific scenarios (such as terminal authentication expiration or user logout), MAP will send an authentication status clearing command to all target APs in the network. The command will clearly indicate the specified terminal whose status needs to be reset. After receiving the command, the target AP will immediately respond and perform the following operation: find the authentication status record of the specified terminal in the local storage and update it from "authenticated" to "unauthenticated".
[0072] This design enables unified management of the authentication status of all terminals across the network, avoiding security risks caused by retaining access permissions despite terminal authentication failure. At the same time, it ensures that terminals must re-authenticate before they can regain network access permissions, thus guaranteeing the security and compliance of network access.
[0073] The method also includes: if the target AP is newly launched, receiving a batch synchronization message sent by the MAP, the batch synchronization message containing the authentication status records of all authenticated terminals; and updating the locally stored authentication status records according to the batch synchronization message.
[0074] Newly added target APs refer to target access point APs that have just joined the Mesh network. Their local storage does not yet contain authentication status records of all terminals in the network. They can only provide services normally after synchronizing global information.
[0075] Batch synchronization messages are aggregated data messages sent by MAP to newly launched target APs, containing authentication status records of all authenticated terminals across the network, used to complete global status synchronization in one go.
[0076] When a target AP is a newly added node in a Mesh network, it cannot directly provide duplicate authentication services to roaming, already authenticated terminals because its local storage lacks authentication status records for all terminals in the network. In this case, the MAP will proactively send a batch synchronization message to the newly joined target AP. This message contains the complete authentication status records of all authenticated terminals in the current network. Upon receiving this batch synchronization message, the newly joined target AP will write all its authentication status records to its local storage, completing the initial update of its local records.
[0077] This design allows newly launched target APs to quickly adapt to the network's authentication status, ensuring that authenticated terminals can directly access the network when roaming to the node, avoiding secondary authentication, while also ensuring the consistency of the network's authentication status after the new node is connected, without affecting the overall user experience and network stability.
[0078] S207. When a terminal in the authenticated state recorded in the local storage accesses the target AP, the target access point AP directly allows the terminal to access the network based on the authenticated state.
[0079] Once a terminal has previously completed Portal authentication on any node within the Mesh network, and its "authenticated" status record has been synchronized to the target AP's local storage, if the terminal reconnects to the target AP (or roams to the AP), the target AP will immediately query the authentication status record in its local storage. Once it confirms that the terminal is in an "authenticated" state (and the authentication has not expired), it will directly allow the terminal to access the network without the terminal having to resubmit authentication information or complete the authentication process repeatedly.
[0080] The purpose of this step is to enable seamless roaming of terminals across the entire network, which reduces the time loss caused by the authentication process, optimizes the user experience, and meets the needs of Mesh networking for large-area coverage and flexible switching of access points by terminals.
[0081] Based on the above description, this application has the following beneficial effects: In this application, on the one hand, the target access point (AP) performs local interception and accurate redirection of HTTP / HTTPS requests initiated by unauthenticated terminals based on the unified Portal authentication policy issued by the main access point (MAP). This eliminates the need for traffic to bypass the MAP, fundamentally avoiding the problems of excessively long paths, high latency, and lost redirection messages in centralized solutions. This significantly reduces the probability of authentication failure and ensures the stability of the authentication process.
[0082] On the other hand, after successful terminal authentication, the target access point (AP) synchronizes the successful authentication status information to the MAP via multicast or broadcast. This, combined with the MAP's unicast retransmission mechanism for unicast transmission when no confirmation response is received, the batch synchronization mechanism for newly deployed target APs, and the status verification rules based on sequence numbers, ensures real-time consistency of authentication status records across all access point APs in the network. This design completely solves the problems of secondary authentication and authentication failure caused by asynchronous node states in distributed solutions, and effectively avoids the accidental interception of authenticated user traffic or unauthorized access by unauthenticated users due to state inconsistencies, thus improving authentication accuracy.
[0083] Meanwhile, when an authenticated terminal roams to any access point (AP), it can directly obtain network access permissions based on the locally synchronized authentication status, achieving seamless roaming and further optimizing the user experience. The globally unified policy control and flexible state synchronization mechanism can fully match the self-organizing and flexible expansion characteristics of Mesh networking, effectively improving network deployment.
[0084] The above text combined Figure 1 The method for implementing Portal authentication provided in the embodiments of this application has been described in detail. The apparatus and device provided in the embodiments of this application will be described below with reference to the accompanying drawings.
[0085] like Figure 2 As shown in the figure, this is a schematic diagram of a device for implementing Portal authentication provided in an embodiment of this application. The device includes: The acquisition module 301 is used to acquire the Portal authentication policy issued by the main access point MAP, wherein the Portal authentication policy includes the Portal server address and the redirect URL; The processing module 302 is configured to, when a terminal accesses the target access point (AP) and the terminal is in an unauthenticated state, intercept requests initiated by the unauthenticated terminal according to the Portal authentication policy, and redirect the requests to the Portal authentication page via a redirect URL; receive authentication information submitted by the terminal through the Portal authentication page, and forward the authentication information to the authentication server corresponding to the Portal server address; receive an authentication success notification returned by the authentication server; in response to the authentication success notification, synchronize the terminal's authentication success status information to the MAP; and receive the authentication status records synchronized by the MAP according to the global status, and update the locally stored authentication status records. The authentication module 303 is used to directly allow a terminal to access the network based on its authentication status when a terminal in the locally stored authentication status record is in an authenticated state and accesses the target AP.
[0086] Optionally, the processing module 302 is used to synchronize the authentication success status information to the MAP via multicast or broadcast.
[0087] Optionally, the processing module 302 is used to receive the MAP's unicast synchronization message when the MAP does not receive confirmation of the target AP's successful authentication status information for synchronization.
[0088] Optionally, the processing module 302 is configured to receive an authentication status clearing instruction from the MAP; and in response to the clearing instruction, update the authentication status record of the specified terminal stored locally to an unauthenticated status.
[0089] Optionally, the processing module 302 is used to carry a sequence number in the authentication status record; the receiving MAP synchronizes the authentication status record according to the global status and updates the locally stored authentication status record, including: When the sequence number received from the authentication status record synchronized by the MAP based on the global status is greater than the corresponding sequence number stored locally by the target AP, the authentication status record stored locally is updated based on the received authentication status record.
[0090] Optionally, the processing module 302 is used to receive a batch synchronization message sent by the MAP when the target AP is newly online, the batch synchronization message containing the authentication status records of all authenticated terminals; Update the authentication status record in the local storage according to the batch synchronization message.
[0091] The apparatus for implementing Portal authentication according to the embodiments of this application can correspond to performing the method described in the embodiments of this application, and the other operations and / or functions of each module / unit of the apparatus for implementing Portal authentication are respectively for implementing Figure 1 For the sake of brevity, the corresponding processes of each method in the illustrated embodiments will not be described in detail here.
[0092] This application also provides a computing device. For example... Figure 3 As shown in the figure, this is a schematic diagram of a computing device provided in an embodiment of this application. The computing device 700 includes a bus 701, a processor 702, a communication interface 703, and a memory 704. The processor 702, the memory 704, and the communication interface 703 communicate with each other via the bus 701.
[0093] The 701 bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 3 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0094] The processor 702 can be any one or more of the following processors: central processing unit (CPU), graphics processing unit (GPU), microprocessor (MP), or digital signal processor (DSP).
[0095] The communication interface 703 is used for communication with external devices.
[0096] Memory 704 may include volatile memory, such as random access memory (RAM). Memory 704 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0097] The memory 704 stores executable code, which the processor 702 executes to perform the aforementioned method for implementing Portal authentication.
[0098] Specifically, in achieving Figure 2 In the case of the illustrated embodiment, and Figure 2 When the modules or units of the Portal authentication device described in the embodiments are implemented in software, the execution... Figure 2 The software or program code required for the functions of each module / unit can be partially or wholly stored in memory 704. Processor 702 executes the program code corresponding to each unit stored in memory 704 to execute the aforementioned method for implementing Portal authentication.
[0099] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to perform the above-described method for implementing Portal authentication.
[0100] This application also provides a computer program product comprising one or more computer instructions. When the computer instructions are loaded and executed on a computing device, all or part of the processes or functions described in this application are generated.
[0101] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means.
[0102] When the computer program product is executed by a computer, the computer executes any of the aforementioned methods for implementing Portal authentication. The computer program product can be a software installation package; when any of the aforementioned methods for implementing Portal authentication is required, the computer program product can be downloaded and executed on the computer.
[0103] The descriptions of the processes or structures corresponding to the above figures each have their own emphasis. For parts of a process or structure that are not described in detail, please refer to the relevant descriptions of other processes or structures.
[0104] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be covered within the scope of protection of this application.
Claims
1. A method for implementing Portal authentication, characterized in that, The method comprises: obtaining a Portal authentication policy issued by a master access point (MAP), wherein the Portal authentication policy comprises a Portal server address and a redirection URL; when a terminal accesses a target access point (AP) and the terminal is in an unauthenticated state, intercepting a request initiated by the terminal in the unauthenticated state according to the Portal authentication policy, and redirecting the request to a Portal authentication page through the redirection URL; receiving authentication information submitted by the terminal through the Portal authentication page, and forwarding the authentication information to an authentication server corresponding to the Portal server address; receiving an authentication success notification returned by the authentication server; in response to the authentication success notification, synchronizing authentication success state information of the terminal to the MAP; receiving authentication state records synchronized by the MAP according to global states, and updating locally stored authentication state records; when a terminal in an authenticated state in the locally stored authentication state records accesses the target AP, directly allowing the terminal to access a network according to the authenticated state.
2. The method of claim 1, wherein, The synchronization of the authentication success state information of the terminal to the MAP comprises: synchronizing the authentication success state information to the MAP through a multicast or broadcast mode.
3. The method of claim 1, wherein, The method further comprises: when the MAP does not receive a confirmation of the synchronized authentication success state information from the target AP, receiving a unicast synchronization message of the MAP.
4. The method of claim 1, wherein, The method further comprises: receiving an authentication state clearing instruction of the MAP; in response to the clearing instruction, updating authentication state records of a specified terminal in local storage to an unauthenticated state.
5. The method of claim 1, wherein, The authentication state records carry sequence numbers. The receiving of the authentication state records synchronized by the MAP according to the global states, and the updating of the locally stored authentication state records, comprise: when a sequence number in the authentication state records synchronized by the MAP according to the global states is greater than a corresponding sequence number stored locally by the target AP, updating the locally stored authentication state records according to the received authentication state records.
6. The method of claim 1, wherein, The method further comprises: if the target AP is newly online, receiving a batch synchronization message sent by the MAP, wherein the batch synchronization message comprises authentication state records of all authenticated terminals; according to the batch synchronization message, updating the locally stored authentication state records.
7. The method of claim 1, wherein, The authentication success state information comprises a MAC address of the terminal, an authentication state identifier, and a valid time length.
8. An apparatus for implementing a Portal authentication, the apparatus comprising: The apparatus comprises: an obtaining module configured to obtain a Portal authentication policy issued by a master access point (MAP), wherein the Portal authentication policy comprises a Portal server address and a redirection URL; The processing module is configured to, when a terminal accesses a target access point (AP) and the terminal is in an unauthenticated state, intercept a request initiated by the terminal in the unauthenticated state according to the Portal authentication strategy, and redirect the request to a Portal authentication page through a redirection URL; receive authentication information submitted by the terminal through the Portal authentication page, forward the authentication information to an authentication server corresponding to a Portal server address, receive an authentication success notification returned by the authentication server, and in response to the authentication success notification, synchronize authentication success state information of the terminal to a MAP; and receive authentication state records synchronized by the MAP according to a global state, and update locally stored authentication state records. The authentication module is configured to, when a terminal in an authenticated state in the locally stored authentication state records accesses a target AP, directly allow the terminal to access a network according to the authenticated state.
9. A computing device, comprising: comprise a memory and a processor; The memory stores one or more computer programs comprising instructions, which, when executed by the processor, cause the computing device to perform the method of any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium is configured to store a computer program for performing the method of any one of claims 1 to 7.