Wireless network disaster recovery method and device, wireless access point, wireless controller and storage medium

By working together with the wireless access point and controller, a disaster recovery status notification is generated, downgraded authentication and rate limiting policies are configured, and a wireless network with the same name is created. This solves the access and roaming problems of the wireless network when the authentication server is abnormal, and achieves seamless access and secure use of the wireless network.

CN121568148APending Publication Date: 2026-02-24SHENZHEN SUNDRAY NETWORK SCI TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511561868.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-29
Publication Date
2026-02-24

AI Technical Summary

Technical Problem

Existing wireless network disaster recovery solutions rely on multiple authentication servers, resulting in wasted resources and an inability to resolve issues related to new terminal access and roaming handover for existing terminals when the core router malfunctions.

Method used

Wireless access points and wireless controllers monitor the access status of the authentication server. When the authentication server is inaccessible, they generate a disaster recovery status notification, configure downgraded authentication methods and rate limiting policies, create a wireless network with the same name, and enable terminals to complete authentication and restrict permissions locally, thus achieving access without interaction with the authentication server.

Benefits of technology

In situations where the authentication server is inaccessible, ensure the normal use and security of the wireless network, avoid resource waste, and achieve seamless roaming and terminal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121568148A_ABST
    Figure CN121568148A_ABST
Patent Text Reader

Abstract

The invention discloses a wireless network disaster recovery method and device, a wireless access point, a wireless controller and a storage medium, and relates to the technical field of wireless networks. The method is applied to a wireless access point, the wireless access point is in communication connection with a wireless controller, and the method comprises the steps that if a disaster recovery state notification sent by the wireless controller is received, configuration information for a wireless network is acquired from the wireless controller, the disaster recovery state notification is generated when the wireless controller monitors that an authentication server cannot access, and the configuration information is sent to the wireless controller; and according to the configuration information, controlling the terminal to access the wireless network in a manner of not interacting with the authentication server. According to the method and the device, the terminal can be controlled to access the wireless network in a mode of not interacting with the authentication server even if the authentication server cannot access, so that the normal use of the wireless network is ensured on the premise of not influencing the safety of the wireless network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless network technology, and more specifically, to a wireless network disaster recovery method, apparatus, wireless access point, wireless controller, and storage medium. Background Technology

[0002] With the rapid development of mobile internet, wireless networks have become the mainstream way to access the internet. More and more public places, such as shopping malls, supermarkets, scenic spots, schools, hospitals, and parks, provide wireless network coverage, and the number of users connecting to wireless networks is constantly increasing. This has made the security and smooth wireless experience of wireless networks increasingly important.

[0003] To ensure network security, the mainstream authentication method currently used in the industry is 802.1x authentication, which requires communication with an authentication server. Current disaster recovery solutions on the market are mainly based on the authentication server side, using redundant server deployment to improve system reliability. However, this approach, requiring the deployment of multiple authentication servers, not only wastes resources but also fails to address the issues of new terminals being unable to access the network and existing terminals being unable to roam and switch over when a core router malfunctions and all authentication servers become inaccessible. Summary of the Invention

[0004] In view of the above problems, this application proposes a wireless network disaster recovery method, apparatus, wireless access point, wireless controller, and storage medium to solve the above problems.

[0005] In a first aspect, embodiments of this application provide a wireless network disaster recovery method applied to a wireless access point, wherein the wireless access point is communicatively connected to a wireless controller, the method comprising: if a disaster recovery status notification is received from the wireless controller, obtaining configuration information for the wireless network from the wireless controller, wherein the disaster recovery status notification is generated by the wireless controller when it detects that an authentication server is inaccessible; and according to the configuration information, a control terminal accesses the wireless network without interacting with the authentication server.

[0006] Furthermore, the step of controlling the terminal to access the wireless network without interacting with the authentication server according to the configuration information includes: creating a wireless network with the same name as the wireless network as a new wireless network; setting an authentication method for the new wireless network according to the configuration information, and restricting the internet access permissions of the new wireless network according to the configuration information; and connecting the terminal to the new wireless network based on the authentication method, wherein the terminal does not interact with the authentication server under the authentication method.

[0007] Furthermore, the authentication method includes a first authentication method or a second authentication method, wherein the first authentication method includes one or more of OPEN and WPA-PSK, and the second authentication method includes one or more of PEAP-GTC and EAP-TTL-GTC.

[0008] Further, the step of connecting the terminal to the newly added wireless network based on the authentication method includes: if a request to access the newly added wireless network initiated by the terminal is received, then determining whether the terminal meets specified conditions, wherein the specified conditions include having accessed the wireless network before and retaining the most recent authentication method; if the terminal does not meet the specified conditions, then connecting the terminal to the newly added wireless network based on the first authentication method; or if the terminal meets the specified conditions, then connecting the terminal to the newly added wireless network based on the second authentication method.

[0009] Further, the step of connecting the terminal to the newly added wireless network based on the second authentication method includes: receiving a token recognized by the GTC protocol sent by the terminal, wherein the token is obtained by the terminal through MSC HAV2 cryptographic encapsulation used when it last accessed the wireless network; parsing the core information of the terminal from the token and reporting the core information to the wireless controller to instruct the wireless controller to perform a legality verification of the terminal based on the core information; and if the wireless controller sends back information indicating that the verification has passed, then the terminal is connected to the newly added wireless network.

[0010] Furthermore, the method also includes: hiding the wireless network.

[0011] Furthermore, the step of controlling the terminal to access the wireless network without interacting with the authentication server according to the configuration information includes: if a roaming association request initiated by the terminal is received, then a new key is calculated by calling a core element stored locally for calculating the terminal's key, wherein the core element is collected and synchronously obtained by the terminal after the terminal completes the authentication process of the authentication server through the original wireless access point to which the terminal is connected; key negotiation is performed with the terminal using the new key, and the terminal is connected to the wireless network after the key negotiation is completed.

[0012] Furthermore, before calculating a new key by calling the locally stored core element used to calculate the key of the terminal if a roaming association request initiated by the terminal is received, the method further includes: receiving the core element distributed by the wireless controller based on a specified protocol, wherein the core element is collected by the original wireless access point and reported to the wireless controller after the terminal completes the authentication process of the authentication server.

[0013] Secondly, embodiments of this application provide a wireless network disaster recovery method applied to a wireless controller, wherein the wireless controller is communicatively connected to a wireless access point. The method includes: displaying a disaster recovery configuration interface; if a configuration operation is detected acting on the disaster recovery configuration interface, generating configuration information for the wireless network based on the configuration operation; if an authentication server is found to be inaccessible, generating a disaster recovery status notification and sending the disaster recovery status notification and the configuration information to the wireless access point.

[0014] Thirdly, this application provides a wireless network disaster recovery device applied to a wireless access point. The wireless access point is communicatively connected to a wireless controller. The device includes: a configuration information acquisition module, configured to acquire configuration information for the wireless network from the wireless controller if a disaster recovery status notification is received from the wireless controller, wherein the disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible; and a wireless network access module, configured to control a terminal to access the wireless network without interacting with the authentication server, based on the configuration information.

[0015] Fourthly, this application provides a wireless network disaster recovery device applied to a wireless controller, the wireless controller being communicatively connected to a wireless access point. The device includes: a configuration interface display module for displaying a disaster recovery configuration interface; a configuration information generation module for generating configuration information for the wireless network based on a configuration operation detected on the disaster recovery configuration interface; and a configuration information sending module for generating a disaster recovery status notification and sending the disaster recovery status notification and the configuration information to the wireless access point if an authentication server is detected to be inaccessible.

[0016] Fifthly, embodiments of this application provide a wireless access point, including a memory and a processor, wherein the memory is coupled to the processor, the memory stores instructions, and when the instructions are executed by the processor, the processor performs the above-described method.

[0017] In a sixth aspect, embodiments of this application provide a wireless controller, including a memory and a processor, wherein the memory is coupled to the processor, the memory stores instructions, and when the instructions are executed by the processor, the processor performs the above-described method.

[0018] In a seventh aspect, embodiments of this application provide a computer-readable storage medium storing program code, which can be invoked by a processor to execute the above-described method.

[0019] The wireless network disaster recovery method, apparatus, wireless access point, wireless controller, and storage medium provided in this application embodiment allow the wireless access point to obtain configuration information for the wireless network from the wireless controller if it receives a disaster recovery status notification sent by the wireless controller. The disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible. Based on the configuration information, the control terminal accesses the wireless network without interacting with the authentication server. Thus, even when the authentication server is inaccessible, the terminal can still access the wireless network without interacting with the authentication server, thereby ensuring the normal use of the wireless network without affecting its security. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 A network topology diagram is shown that can be used in the wireless network disaster recovery method provided in the embodiments of this application; Figure 2 A flowchart illustrating a wireless network disaster recovery method provided in an embodiment of this application is shown; Figure 3 A flowchart illustrating a wireless network disaster recovery method provided in an embodiment of this application is shown; Figure 4 A flowchart illustrating a wireless network disaster recovery method provided in an embodiment of this application is shown; Figure 5 A flowchart illustrating a wireless network disaster recovery method provided in an embodiment of this application is shown; Figure 6 This paper shows a block diagram of a wireless network disaster recovery device according to an embodiment of the present application; Figure 7 This paper shows a block diagram of a wireless network disaster recovery device according to an embodiment of the present application; Figure 8 A block diagram of a wireless access point for implementing a wireless network disaster recovery method according to an embodiment of this application is shown; Figure 9 A block diagram of a wireless controller for implementing a wireless network disaster recovery method according to an embodiment of this application is shown; Figure 10 A storage unit for storing or carrying program code implementing the wireless network disaster recovery method according to an embodiment of the present application is shown. Detailed Implementation

[0022] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0023] One approach to improving system reliability by deploying multiple authentication servers not only wastes resources but also fails to address the issues of new terminals being unable to access the network and existing terminals being unable to roam and switch over when the core router malfunctions and all authentication servers become inaccessible. To address these problems, the inventors, through extensive research, have developed and proposed the wireless network disaster recovery method, apparatus, wireless access point, wireless controller, and storage medium provided in this application. This method allows terminals to access the wireless network even when authentication servers are inaccessible, enabling them to do so without interacting with the authentication servers, thus ensuring normal wireless network operation without compromising security. The specific wireless network disaster recovery method is described in detail in subsequent embodiments. Optionally, the wireless network disaster recovery method provided in this embodiment can be used to improve the disaster recovery capabilities of 802.1x wireless networks.

[0024] The following will explain the technical terms that can be used in the wireless network disaster recovery method provided in the embodiments of this application.

[0025] Wireless AP: Short for Wireless Access Point, its full English name is Access Point, its function is to establish a connection between wired and wireless networks.

[0026] 802.1x authentication: This is a port-based access control standard primarily used to solve the access authentication problem for wireless LAN users. Wireless roaming refers to the process where a wireless terminal moves to the boundary area between the coverage areas of two access points (APs), associates with the new AP and disconnects from the original AP, and maintains an uninterrupted network connection during this process.

[0027] PMK caching, defined by the 802.11i protocol, is an effective authentication technique used between a single access point (AP) and a terminal. It works by allowing a terminal to roam from an AP to another AP and then back to the same AP without requiring a full authentication process. Instead, it performs a four-way handshake to exchange a shared key, as defined in 802.11i.

[0028] OKC: Opportunistic Key Caching, also known as PKC (Proactive Key Caching), is a technology similar to PMKcaching, but it allows all APs in a wireless network to share a single PMK for the same wireless client, so that the terminal does not need to go through the full 802.1X authentication process even when roaming between different APs.

[0029] 802.11r: Roaming Standard. The FT (Fast BSS Transition) function defined in the 802.11r protocol is used to reduce the time delay of the client during roaming, thereby reducing the probability of connection interruption and improving the quality of roaming services.

[0030] Please see Figure 1 , Figure 1 A network topology diagram is shown that can be used in the wireless network disaster recovery method provided in the embodiments of this application, such as Figure 1 As shown, it includes a wireless controller 100 and a wireless access point 200.

[0031] in, Figure 1 The three servers with key icons at the top represent the server-side devices responsible for 802.1x authentication, i.e., the authentication servers. A cross indicates that the authentication server is inaccessible due to network failure (such as a core router malfunction). Wireless Controller 100 refers to the device in the topology diagram used to centrally manage the wireless access points (wireless APs) 200 below, serving as the control hub of the wireless network. Wireless Access Points 200 refer to the three devices with antennas below, responsible for transmitting wireless signals to cover different areas (Area1, Area2, Area3), providing wireless access capabilities for terminals. The laptop on the left represents a new terminal, accessing the wireless network through the wireless access point in Area1. When the authentication server is unavailable, the wireless network can ensure access through degradation and rate limiting mechanisms, while restricting permissions to balance security and availability. When an older terminal in Area1 roams to Area2, it relies on a key synchronization mechanism. The original wireless access point synchronizes key elements with the target wireless access point, and the terminal and the target wireless access point negotiate a new key to complete the roaming, without relying on an inaccessible authentication server, achieving seamless switching.

[0032] Please see Figure 2 , Figure 2A flowchart illustrating a wireless network disaster recovery method according to an embodiment of this application is shown. This method allows a terminal to access the wireless network even when the authentication server is inaccessible, enabling it to do so without interacting with the authentication server, thereby ensuring the normal operation of the wireless network without compromising its security. In a specific embodiment, this wireless network disaster recovery method is applied to a wireless network disaster recovery device 300 and a wireless controller 100 configured with the wireless network disaster recovery device 300. The following will focus on... Figure 2 The process shown is described in detail. The wireless network disaster recovery method may specifically include the following steps: Step S110: Display the disaster recovery configuration interface.

[0033] Optionally, both the wireless controller and the wireless access point can provide a disaster recovery configuration interface for users to enable or disable disaster recovery policies. Accordingly, users can enable or disable disaster recovery policies through the disaster recovery configuration interface provided by the wireless controller and / or the wireless access point. In this embodiment, the example of a user enabling or disabling a disaster recovery policy in the wireless controller is used. Of course, users can also enable or disable disaster recovery policies in the wireless access point; the operation method is the same as that of enabling or disabling disaster recovery policies in the wireless controller, and will not be repeated here.

[0034] In this embodiment, the wireless controller can display a disaster recovery configuration interface, allowing users to select whether to enable or disable a disaster recovery policy, and configure specific disaster recovery policies when the disaster recovery policy is enabled.

[0035] In some implementations, during the process of displaying the disaster recovery configuration interface, the wireless controller can provide a target switch in the disaster recovery configuration interface, whereby the target switch is used to control the enabling or disabling of the disaster recovery policy. Based on this, if a first operation is detected acting on the target switch, the disaster recovery policy can be enabled, and the user can be instructed to configure the specific disaster recovery policy; if a second operation is detected acting on the target switch, the disaster recovery policy can be disabled.

[0036] Step S120: If a configuration operation is detected on the disaster recovery configuration interface, configuration information for the wireless network is generated based on the configuration operation.

[0037] In this implementation, the wireless controller can detect configuration operations performed on the disaster recovery configuration interface while displaying the interface. If a configuration operation is detected, the controller can respond to the operation and generate configuration information for the wireless network based on it. If no configuration operation is detected, the controller can continue displaying the disaster recovery configuration interface until a configuration operation is detected, at which point it generates configuration information for the wireless network based on the operation.

[0038] In some implementations, the wireless controller may detect configuration operations performed on the disaster recovery configuration interface in real time, at preset time intervals, at preset time points, or according to other preset rules, etc., during the process of displaying the disaster recovery configuration interface. No further limitations are specified here.

[0039] In some implementations, configuration operations performed on the disaster recovery configuration interface may include one or a combination of click operations, press operations, and swipe operations performed on the disaster recovery configuration interface.

[0040] Optionally, the above configuration operation can be triggered by finger touch or by clicking with an external device (such as a mouse), and there is no limitation here.

[0041] In some implementations, the disaster recovery configuration interface can provide policies for enabling / disabling wireless network authentication method downgrades and rate limiting during disaster recovery. If enabled, the configuration method is as follows: ① Create a new wireless network with the same name, and select the downgraded authentication method. This example provides the following two methods: A. Select an authentication method such as OPEN / WPA-PSK for the wireless access authentication server; B. If the original authentication method of the wireless network is PEAP-MSCHAPV2 or EAP-TTLS-MSCHAPV2, select PEAP-GTC / EAP-TTL-GTC protocol as the authentication method, that is, use GTC protocol instead of MSCHAPV2 protocol in the protocol negotiation phase of Phase 2. It is understandable that in the above configuration method, creating a new network with the same name is to enable the terminal (especially the old terminal that has previously been connected to the original wireless network) to automatically recognize and attempt to connect, avoiding the user manually switching networks. The downgraded authentication method abandons the original 802.1x authentication that requires the participation of the authentication server and uses authentication logic that does not require the authentication server, ensuring normal network connection and use when the authentication server cannot be accessed.

[0042] OPEN refers to open authentication, an authentication method without encryption or key verification. Terminals can directly access the network without providing any identity information or keys, which is the simplest wireless access logic.

[0043] WPA-PSK refers to pre-shared key authentication, an encryption authentication method based on a pre-shared key. The terminal needs to enter a key pre-agreed with the wireless access point. The wireless access point verifies the key consistency locally. Once the verification is successful, the terminal can access the network without the need for an external authentication server.

[0044] PEAP-MSCHAPV2 refers to a combination of PEAP (Protected Extensible Authentication Protocol) and MSCHAPV2 (Microsoft Challenge Handshake Authentication Protocol Version 2). PEAP is responsible for establishing an encrypted tunnel, while MSCHAPV2 is responsible for verifying the user's identity (such as username and password) within the tunnel, requiring real-time interaction with the authentication server.

[0045] EAP-TTLS-MSCHAPV2 refers to a combination of EAP-TTLS (Tunneled Transport Layer Security) and MSCHAPV2. TTLS functions similarly to PEAP, both used to establish encrypted tunnels. Subsequent identity verification within the tunnel is also performed using the MSCHAPV2 protocol, making it essentially the same as PEAP-MSCHAPV2. The only slight differences lie in the underlying technical details of tunnel establishment (such as the handshake process and cipher suite support), ultimately relying on an authentication server for authentication.

[0046] PEAP-GTC refers to the use of the GTC (Generic Token Card) protocol to replace the original MSCHAPV2 in the second stage of authentication (identity verification within the tunnel) based on the PEAP framework, so that local verification can be completed without interaction with the authentication server.

[0047] EAP-TTLS-GTC refers to a protocol based on the TTLS framework that replaces MSCHAPV2 with the GTC protocol in the second stage of authentication. It is essentially the same as PEAP-GTC, except for the differences in the underlying protocol details of tunnel establishment. Both ultimately achieve serverless authentication.

[0048] ② After choosing to downgrade, you can use permission-related policies, including but not limited to restrictions on VLANs, roles, and traffic; It is understood that downgraded authentication (such as OPEN without encryption, WPA-PSK with simple passwords) reduces network security. Therefore, this embodiment sets up access restrictions to limit the network access range of controlled terminals, preventing unauthorized terminals from abusing network resources or attacking the internal network. Specific restrictions may include: VLAN restrictions: Assign terminals in the downgraded network to isolated VLANs, allowing them to access the external network, such as web pages and videos, but prohibiting them from accessing the corporate internal network, such as financial systems and databases; Role restrictions: Assign low-privilege roles to terminals in the downgraded network and prohibit the use of high-privilege functions, such as prohibiting access to intranet printers and access to shared files; Traffic limiting: Limit the bandwidth of a single device, such as limiting the speed to 1Mbps, to prevent individual devices from consuming too many resources and to ensure a basic network connection experience for other devices.

[0049] ③ Select the relevant access points, including but not limited to a single access point / access point group / access point area / all; In this context, it's understandable that selecting access points means the administrator specifies which wireless access points need to enable the "Create New Network with Same Name" and "Downgrade Authentication" functions based on the actual scenario, rather than enabling them uniformly on all wireless access points, thus avoiding unnecessary resource consumption. Specific selection dimensions may include: Single access point: Enabled only on one wireless access point in the faulty area; Access point groups: Enabled by function, such as conference room AP group, visitor area AP group, and priority access is given to high-traffic areas; Access point area: Enabled by physical area, such as the AP area of ​​Building 1, the AP area of ​​the underground parking garage, to adapt to regional fault scenarios; All access points: All wireless access points across the network will be enabled.

[0050] ④ Choose whether to hide the wireless network.

[0051] It's understandable that if the original 802.11x network isn't hidden, new terminals will scan for and initiate access requests to that network. However, because they cannot connect to the authentication server, they will ultimately be rejected due to authentication timeout or failure. This not only prevents new terminals from connecting to the network normally but also generates a large number of invalid authentication requests, consuming AP processing resources (such as protocol interaction threads and bandwidth) and even affecting the normal use of existing users. By hiding the original network, new terminals' attempts to access the original network, which requires authentication server support, are directly blocked, paving the way for subsequent guidance of new terminals to access disaster recovery networks that do not require authentication servers.

[0052] In some implementations, the disaster recovery configuration interface can provide the option to enable / disable key synchronization during disaster recovery. If enabled, the configuration method is as follows: ① Select the key synchronization method (including but not limited to synchronization with the wireless access point via WAC or synchronization between wireless access points, and the synchronization protocol used includes but is not limited to TCP / UDP protocols). One understandable pain point in disaster recovery scenarios is that when an already connected terminal loses connection to the authentication server, it may experience network outages when roaming to other wireless access points or reconnecting, as it cannot re-complete 802.1x authentication. The core purpose of key synchronization configuration is to pre-synchronize the terminal's key calculation information to the target wireless access point (such as a wireless access point the terminal might roam to) when the authentication server is functioning normally. This allows the target wireless access point to directly calculate the required key for the terminal when the authentication server becomes inaccessible, enabling the terminal to complete roaming or reconnection without interacting with the server, thus ensuring network continuity.

[0053] ② Select the relevant access points, including but not limited to a single access point / access point group / access point area / all.

[0054] Step S130: If the authentication server is found to be inaccessible, a disaster recovery status notification is generated, and the disaster recovery status notification and the configuration information are sent to the wireless access point.

[0055] Optionally, both the wireless controller and the wireless access point can support monitoring the access status of the authentication server. In this embodiment, monitoring the access status of the authentication server through the wireless controller is used as an example. Of course, the access status of the authentication server can also be monitored through the wireless access point, and the monitoring method is the same as that through the wireless controller, so it will not be described again here.

[0056] In this embodiment, the wireless controller can monitor the access status of the authentication server. If the authentication server is inaccessible, a disaster recovery status notification can be generated, and the notification status and the configuration generated for the wireless network can be sent to the wireless access point. This instructs the wireless access point to ensure normal user access without affecting the network security of the wireless user network by using degradation and rate limiting and key synchronization based on the configuration information.

[0057] In this embodiment, the wireless controller can monitor the access status of the authentication server in real time, at preset time intervals, at preset time points, or according to other preset rules, etc., without limitation.

[0058] In some implementations, the core of monitoring the access status of the task server is to confirm whether the authentication server can provide 802.1x authentication services normally. Specific monitoring dimensions may include: network connectivity: whether the IP address of the authentication server can be pinged, and whether the network link between the wireless controller / wireless access point and the authentication server is unobstructed; service availability: whether the 802.1x authentication port of the authentication server is listening normally and whether it can respond to the authentication request test packets sent by the wireless controller / wireless access point.

[0059] In some implementations, the wireless controller can send a disaster recovery status notification to all connected wireless access points via a preset management channel (such as TCP / UDP protocol). This notification includes information such as the activation of disaster recovery mode and the required disaster recovery policies (degradation & rate limiting / key synchronization). For example, the wireless controller can send a broadcast message to each wireless access point via UDP protocol to inform the authentication server of an anomaly and to immediately activate the wireless network with the same name.

[0060] One embodiment of this application provides a wireless network disaster recovery method in which the wireless controller displays a disaster recovery configuration interface. If a configuration operation is detected on the disaster recovery configuration interface, configuration information for the wireless network is generated based on the configuration operation. If the authentication server is found to be inaccessible, a disaster recovery status notification is generated, and the disaster recovery status notification and configuration information are sent to the wireless access point. Thus, even when the authentication server is inaccessible, the terminal can be controlled to access the wireless network without interacting with the authentication server, thereby ensuring the normal use of the wireless network without affecting the security of the wireless network.

[0061] Please see Figure 3 , Figure 3 A flowchart illustrating a wireless network disaster recovery method according to an embodiment of this application is shown. This method allows a terminal to access the wireless network even when the authentication server is inaccessible, enabling it to do so without interacting with the authentication server, thereby ensuring the normal operation of the wireless network without compromising its security. In a specific embodiment, this wireless network disaster recovery method is applied to a wireless network disaster recovery device 400 and a wireless access point 200 configured with the wireless network disaster recovery device 400. The following will focus on... Figure 3 The process shown is described in detail. The wireless network disaster recovery method may specifically include the following steps: Step S210: If a disaster recovery status notification is received from the wireless controller, then obtain the configuration information for the wireless network from the wireless controller, wherein the disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible.

[0062] In this embodiment, the wireless controller can be used to monitor the status information of the authentication server. When it detects that the authentication server is inaccessible, it will send a disaster recovery status notification and configuration information to the wireless access point. Correspondingly, if the wireless access point receives the disaster recovery status notification sent by the wireless controller, it can obtain the configuration information for the wireless network from the wireless controller. This configuration information can be generated by the user through configuration operations in the disaster recovery configuration interface.

[0063] Step S220: According to the configuration information, the control terminal accesses the wireless network without interacting with the authentication server.

[0064] In this embodiment, when the wireless access point obtains the configuration information, it can control the terminal to access the wireless network without interacting with the authentication server.

[0065] In some implementations, when a wireless access point obtains configuration information, it can parse the configuration information. If the parsed configuration information indicates that a wireless network authentication method downgrade and rate limiting policy is enabled, the terminal can be controlled to access the wireless network using the wireless network authentication method downgrade and rate limiting policy. Specifically, the terminal does not interact with the authentication server when the wireless network authentication method downgrade and rate limiting policy is in effect.

[0066] In some implementations, when a wireless access point obtains configuration information, it can parse the configuration information. If the parsed configuration information indicates that key synchronization is enabled, it can control the terminal to access the wireless network using key synchronization. In key synchronization mode, the terminal does not interact with the authentication server.

[0067] One embodiment of this application provides a wireless network disaster recovery method. If a wireless access point receives a disaster recovery status notification sent by a wireless controller, it obtains configuration information for the wireless network from the wireless controller. The disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible. According to the configuration information, the control terminal accesses the wireless network without interacting with the authentication server. Thus, even when the authentication server is inaccessible, the control terminal can choose to access the wireless network without interacting with the authentication server, thereby ensuring the normal use of the wireless network without affecting its security.

[0068] Please see Figure 4 , Figure 4 A flowchart illustrating a wireless network disaster recovery method according to an embodiment of this application is shown. The following will focus on... Figure 4 The process shown is described in detail. The wireless network disaster recovery method may specifically include the following steps: Step S310: If a disaster recovery status notification is received from the wireless controller, then obtain the configuration information for the wireless network from the wireless controller, wherein the disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible.

[0069] For a detailed description of step S310, please refer to step S110, which will not be repeated here.

[0070] Step S320: Create a new wireless network with the same name as the wireless network.

[0071] Optionally, the configuration information may include enabling degradation and rate limiting.

[0072] In this embodiment, when the wireless access point obtains the configuration information for the wireless network from the wireless controller and determines the method of enabling degradation and rate limiting based on the configuration information, it can create a new wireless network with the same name as the wireless network.

[0073] In some implementations, a wireless access point can create a new wireless network with the same name as the original wireless network, while retaining the original wireless network, i.e., retaining the 802.1x authentication of the original wireless network. In this case, terminals that are already online are not affected and can be used normally, while new terminals will no longer be able to access the original wireless network.

[0074] In some implementations, a wireless access point can create a new wireless network with the same name as the original wireless network, while retaining the original wireless network and hiding it. In this case, the wireless access point stops actively broadcasting the SSID of the original wireless network, but does not interrupt the terminal sessions with established stable connections. Normally, the wireless access point periodically broadcasts its SSID. New terminals scan the surrounding SSID list to discover and select the target network to initiate an access request. After the hiding operation, the wireless access point no longer sends the SSID broadcast packet of the original wireless network. New terminals cannot discover the network through regular list scanning and therefore cannot actively initiate access. For users already online, their session links are stable. The wireless access point only stops broadcasting the SSID, without terminating the existing session, so the terminal can continue to send and receive data normally without any impact.

[0075] Step S330: Set the authentication method for the newly added wireless network according to the configuration information, and restrict the internet access permission of the newly added wireless network according to the configuration information.

[0076] In this embodiment, when the wireless access point obtains the configuration information for the wireless network from the wireless controller and determines to enable the degradation and rate limiting method based on the configuration information, it can set the authentication method for the newly added wireless network according to the configuration information and restrict the access permission of the newly added wireless network according to the configuration information.

[0077] Optionally, the authentication method configured in the configuration information for the newly added wireless network may include a first authentication method or a second authentication method. The first authentication method may include authentication methods that do not require access to an authentication server, such as OPEN / WPA-PSK, and the second authentication method may include authentication methods that do not require access to an authentication server, such as PEAP-GTC / EAP-TTL-GTC. The first authentication method is primarily for new terminals, i.e., terminals that have never accessed the wireless network before, or terminals that have accessed the wireless network but have not retained their most recent authentication method locally. The second authentication method is primarily for older terminals, i.e., terminals that have accessed the wireless network and have retained their most recent authentication method locally.

[0078] In some implementations, when the wireless access point obtains configuration information for the wireless network from the wireless controller and determines to enable the degradation and rate limiting method based on the configuration information, it can set the authentication method of the newly added wireless network to the first authentication method or the authentication method of the newly added wireless network to the second authentication method.

[0079] As one feasible approach, the wireless access point can obtain the original authentication method of the existing wireless network and determine whether the original authentication method is a preset authentication method. If it is determined that the original authentication method is a preset authentication method, the authentication method of the newly added wireless network can be set as the second authentication method; if it is determined that the original authentication method is not a preset authentication method, the authentication method of the newly added wireless network can be set as the first authentication method. Optionally, the preset authentication method may include PEAP-MSCHAPV2 or EAP-TTLS-MSCHAPV2.

[0080] In some implementations, when a wireless access point obtains configuration information for the wireless network from the wireless controller and determines whether to enable degradation and rate limiting based on the configuration information, it can restrict the internet access permissions of the newly added wireless network while maintaining the network permissions of the original wireless network. For example, restrictions can be placed on the VLAN, role, and traffic of the newly added wireless network.

[0081] Step S340: Connect the terminal to the newly added wireless network based on the authentication method, wherein the terminal does not interact with the authentication server under the authentication method.

[0082] In this embodiment, once the authentication method for the newly added wireless network is determined, the wireless access point can connect the terminal to the new wireless network based on that authentication method. Under this authentication method, the terminal does not interact with the authentication server; instead, authentication is completed locally at the wireless access point and / or the wireless controller. That is, the entire authentication process does not require the involvement of the authentication server, but its network permissions will be limited to maximize availability and security.

[0083] In some implementations, if the authentication method for the wireless network is the first authentication method (such as OPEN / WPA-PSK, which does not require access to the authentication server), then when a new terminal accesses the newly added wireless network, the authentication server will not be required, but its network permissions will be restricted to maximize availability and security.

[0084] In some implementations, if the authentication method for the wireless network is a second authentication method (such as PEAP-GTC / EAP-TTL-GTC, which does not require access to the authentication server), when an old terminal (which has previously accessed the original wireless network) reconnects, the terminal can report the previously retained MSCHAPV2 password as a token of the GTC protocol to the wireless access point. The wireless access point parses the token to obtain the terminal's core information (terminal MAC, key, etc.) and reports the terminal's core information to the wireless controller, instructing the wireless controller to perform a legitimacy verification on the terminal based on the core information. If the verification fails, the wireless access point returns an authentication failure result. If the verification succeeds, the wireless access point completes the normal authentication interaction process with the terminal, and the terminal goes online, but its network permissions will be restricted to maximize availability and security.

[0085] In some implementations, if a request to access a new wireless network is received from a terminal, it is determined whether the terminal meets specified conditions, including having previously accessed a wireless network and retaining the most recent authentication method. If the terminal does not meet the specified conditions, it is connected to the new wireless network based on a first authentication method. If the terminal meets the specified conditions, it is connected to the new wireless network based on a second authentication method. The wireless access point can be configured with a first authentication method and a second authentication method. If a request to access a new wireless network is received from a terminal, and the terminal has previously accessed the original wireless network and retains the most recent authentication method, it can be connected to the new wireless network using authentication methods such as PEAP-GTC or EAP-TTL-GTC (this method is only provided by the original wireless network whose original authentication method is PEAP-MSCHAPV2 or EAP-TTLS-MSCHAPV2). If a request to access a new wireless network is received from a terminal, and the terminal has not previously accessed the original wireless network, or the terminal has previously accessed the original wireless network but did not retain the most recent authentication method, the terminal is considered a new terminal and can be connected to the new wireless network using authentication methods such as OPEN or WPA-PSK.

[0086] One embodiment of this application provides a wireless network disaster recovery method. If a wireless access point receives a disaster recovery status notification sent by a wireless controller, it obtains configuration information for the wireless network from the wireless controller. This disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible. A new wireless network with the same name as the existing wireless network is created. An authentication method for the new wireless network is set according to the configuration information, and internet access permissions for the new wireless network are restricted based on the configuration information. The terminal is then connected to the new wireless network based on this authentication method. Under this authentication method, the terminal does not interact with the authentication server. Compared to... Figure 3 The wireless network disaster recovery method shown in this embodiment can control the terminal to access the wireless network even when the authentication server is inaccessible, through downgrade and rate limiting authentication, thereby ensuring the normal use of the wireless network without affecting the wireless network security.

[0087] Please see Figure 5 , Figure 5 A flowchart illustrating a wireless network disaster recovery method according to an embodiment of this application is shown. The following will focus on... Figure 5 The process shown is described in detail. The wireless network disaster recovery method may specifically include the following steps: Step S410: If a disaster recovery status notification is received from the wireless controller, then obtain the configuration information for the wireless network from the wireless controller, wherein the disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible.

[0088] For a detailed description of step S410, please refer to step S110, which will not be repeated here.

[0089] Step S420: If a roaming association request initiated by the terminal is received, the core element used to calculate the key of the terminal in local storage is called to calculate a new key. The core element is collected and synchronously obtained by the terminal after the terminal completes the authentication process of the authentication server through the original wireless access point to which the terminal is connected.

[0090] Optionally, the configuration information may include how to enable key synchronization.

[0091] In some implementations, the current wireless access point (the wireless access point to which the terminal roams) can receive core elements distributed by the wireless controller based on a specified protocol. These core elements can be collected by the original wireless access point (the wireless access point to which the terminal connected before roaming) and reported to the wireless controller after the terminal completes the authentication process on the authentication server.

[0092] Under normal conditions (access is allowed) of the authentication server, the terminal, the original wireless access point, the wireless controller, and the authentication server can conduct a normal authentication process. After the terminal is successfully authenticated, the original wireless access point reports the core elements of the terminal (terminal MAC, key generated during the authentication process (such as PMK), whether it supports 802.11r / OKC / PMKcache, etc.) to the wireless controller. The wireless controller can periodically distribute the core elements to the relevant access points (wireless access points that have enabled this function) through protocols including but not limited to TCP / UDP / HTTP. Accordingly, the current wireless access point (the wireless access point to which the terminal roams) can receive the core elements distributed by the wireless controller based on the specified protocol.

[0093] In this embodiment, when the current wireless access point obtains configuration information for the wireless network from the wireless controller and determines to enable the key synchronization method based on the configuration information, if it receives a roaming association request initiated by the terminal, it calls the core element stored locally for calculating the terminal's key to calculate a new key. The core element is collected and synchronized by the original wireless access point to which the terminal is connected after the terminal completes the authentication process of the authentication server. The new key is used to negotiate the key with the terminal, and after the key negotiation is completed, the terminal is connected to the wireless network.

[0094] In some implementations, if an older terminal (including but not limited to terminals supporting protocols such as 802.11r / OKC / PMK cache) roams from the original wireless access point to the current wireless access point, since the current wireless access point has already received the core element distributed by the wireless controller based on the specified protocol, the current wireless access point itself can calculate a new key based on the core element. This allows the terminal and the current wireless access point to use the new key for key negotiation, eliminating the need to interact with the authentication server, and the terminal can ultimately roam successfully.

[0095] In some implementations, if an old terminal (which has previously accessed the wireless network) reconnects to the original wireless access point, the original wireless access point can calculate a new key based on the terminal's key since the original wireless access point contains the terminal's key. This allows the terminal and the original wireless access point to negotiate the key using the new key, eliminating the need to interact with the authentication server, and the terminal can eventually successfully go online.

[0096] Step S430: Perform key negotiation with the terminal using the new key, and connect the terminal to the wireless network after the key negotiation is completed.

[0097] The key negotiation process between the terminal and the new key essentially involves the terminal and the current wireless access point (WAIT) verifying the encryption algorithm and session key based on the newly generated key. This ensures that both parties use the same encryption rules for subsequent data transmission. The core of this process follows the four-way handshake defined in the 802.11i protocol: The WAIT sends a handshake request frame to the terminal, containing a random number (ANonce) generated by the WAIT and its own BSSID. Upon receiving this frame, the terminal calculates the new key based on its locally stored historical PMK, its own random number (SNonce), the WAIT's ANonce, and its own BSSID, and returns a handshake response frame to the WAIT, containing the SNonce and the new key's checksum. The WAIT uses its own calculated PTK to verify the checksum sent by the terminal. If the verification is successful, the WAIT sends a handshake confirmation frame to the terminal, containing the PTK's MIC. The terminal verifies the MIC sent by the WAIT and, after confirming the PTK consistency, returns a handshake completion frame, ending the negotiation and connecting the terminal to the wireless network.

[0098] One embodiment of this application provides a wireless network disaster recovery method. If a wireless access point receives a disaster recovery status notification sent by a wireless controller, it obtains configuration information for the wireless network from the wireless controller. The disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible. If a roaming association request initiated by a terminal is received, a new key is calculated using a core element stored locally for calculating the terminal's key. This core element is collected and synchronously obtained by the original wireless access point the terminal accesses after the terminal completes the authentication process with the authentication server. The new key is used to negotiate a key with the terminal, and after negotiation, the terminal is connected to the wireless network. Compared to... Figure 3 The wireless network disaster recovery method shown in this embodiment can control the terminal to access the wireless network even when the authentication server is inaccessible, thereby ensuring the normal use of the wireless network without affecting its security.

[0099] Please see Figure 6 , Figure 6 A block diagram of a wireless network disaster recovery device according to an embodiment of this application is shown. This wireless network disaster recovery device 300 is applied to the aforementioned wireless controller, which is communicatively connected to a wireless access point. The following will describe... Figure 6 The block diagram shown illustrates that the wireless network disaster recovery device 300 may include: a configuration interface display module 310, a configuration information generation module 320, and a configuration information sending module 330, wherein: The configuration interface display module 310 is used to display the disaster recovery configuration interface.

[0100] The configuration information generation module 320 is used to generate configuration information for the wireless network based on the configuration operation if a configuration operation is detected on the disaster recovery configuration interface.

[0101] The configuration information sending module 330 is used to generate a disaster recovery status notification if the authentication server is found to be inaccessible, and send the disaster recovery status notification and the configuration information to the wireless access point.

[0102] Please see Figure 7 , Figure 7 This illustration shows a module block diagram of a wireless network disaster recovery device according to an embodiment of the present application. The wireless network disaster recovery device 400 is applied to the aforementioned wireless access point, which is communicatively connected to a wireless controller. The following will describe its application in relation to... Figure 7 The block diagram shown illustrates that the wireless network disaster recovery device 400 may include: a configuration information acquisition module 410 and a wireless network access module 420, wherein: The configuration information acquisition module 410 is used to acquire configuration information for the wireless network from the wireless controller if it receives a disaster recovery status notification sent by the wireless controller, wherein the disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible.

[0103] The wireless network access module 420 is used to control the terminal to access the wireless network without interacting with the authentication server, based on the configuration information.

[0104] Furthermore, the wireless network access module 420 includes: a wireless network creation submodule, an authentication method setting submodule, and a first wireless network access submodule, wherein: The wireless network creation submodule is used to create a new wireless network with the same name as the wireless network mentioned above.

[0105] The authentication method setting submodule is used to set the authentication method for the newly added wireless network according to the configuration information, and to restrict the internet access permissions of the newly added wireless network according to the configuration information.

[0106] The first wireless network access submodule is used to connect the terminal to the newly added wireless network based on the authentication method, wherein the terminal does not interact with the authentication server under the authentication method.

[0107] Furthermore, the first wireless network access submodule includes: a specified condition judgment unit, a first wireless network access unit, and a second wireless network access unit, wherein: A specified condition judgment unit is used to determine whether the terminal meets specified conditions if a request to access the newly added wireless network is received from the terminal. The specified conditions include having accessed the wireless network before and retaining the most recent authentication method.

[0108] The first wireless network access unit is configured to connect the terminal to the newly added wireless network based on the first authentication method if the terminal does not meet the specified conditions.

[0109] The second wireless network access unit is configured to connect the terminal to the newly added wireless network based on the second authentication method if the terminal meets the specified conditions.

[0110] Furthermore, the second wireless network access unit includes: a token receiving subunit, a core information reporting subunit, and a wireless network access subunit, wherein: The token receiving subunit is used to receive a GTC protocol-approved token sent by the terminal, wherein the token is obtained by the terminal based on the MSCHAPV2 cryptographic encapsulation used when it last accessed the wireless network.

[0111] The core information reporting subunit is used to parse the core information of the terminal from the token and report the core information to the wireless controller to instruct the wireless controller to perform a legality verification of the terminal based on the core information.

[0112] The wireless network access subunit is configured to connect the terminal to the newly added wireless network if it receives information from the wireless controller indicating that the verification has passed.

[0113] Furthermore, the wireless network access module 420 further includes: a wireless network hiding submodule, wherein: A wireless network hiding submodule is used to hide the wireless network.

[0114] Furthermore, the wireless network access module 420 includes: a key receiving submodule and a second wireless network access submodule, wherein: The key receiving submodule is used to calculate a new key by calling the core element stored locally for calculating the key of the terminal if a roaming association request initiated by the terminal is received. The core element is collected and synchronously obtained by the terminal after the terminal completes the authentication process of the authentication server through the original wireless access point to which the terminal is connected.

[0115] The second wireless network access submodule is used to perform key negotiation with the terminal using the new key, and to connect the terminal to the wireless network after the key negotiation is completed.

[0116] Furthermore, the wireless network access module 420 also includes: a core element receiving submodule, wherein: The core element receiving submodule is used to receive the core element distributed by the wireless controller based on a specified protocol, wherein the core element is collected by the original wireless access point and reported to the wireless controller after the terminal completes the authentication process of the authentication server.

[0117] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the above-described device and module can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0118] In the several embodiments provided in this application, the coupling between modules can be electrical, mechanical, or other forms of coupling.

[0119] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0120] Please see Figure 8 This diagram illustrates a structural block diagram of a wireless access point 100 provided in an embodiment of this application. The wireless access point 100 in this application may include one or more of the following components: a processor 110, a memory 120, and one or more application programs, wherein the one or more application programs may be stored in the memory 120 and configured to be executed by one or more processors 110, and the one or more programs are configured to perform the methods described in the foregoing method embodiments.

[0121] The processor 110 may include one or more processing cores. The processor 110 connects to various parts within the wireless access point 100 via various interfaces and lines, and performs various functions and processes data of the wireless access point 100 by running or executing instructions, programs, code sets, or instruction sets stored in the memory 120, and by calling data stored in the memory 120. Optionally, the processor 110 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 110 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content to be displayed; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 110 and may be implemented separately using a communication chip.

[0122] The memory 120 may include random access memory (RAM) or read-only memory (ROM). The memory 120 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 120 may include a program storage area and a data storage area. The program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as touch functionality, sound playback functionality, image playback functionality, etc.), and instructions for implementing the various method embodiments described below. The data storage area may also store data created by the wireless access point 100 during use (such as phonebooks, audio and video data, chat log data, etc.).

[0123] Please see Figure 9 The diagram illustrates a structural block diagram of a wireless controller 200 provided in an embodiment of this application. The wireless controller 200 in this application may include one or more components: a processor 210, a memory 220, and one or more application programs. The one or more application programs may be stored in the memory 220 and configured to be executed by one or more processors 210. The one or more application programs are configured to perform the methods described in the foregoing method embodiments.

[0124] The processor 210 may include one or more processing cores. The processor 210 connects to various parts within the wireless controller 200 via various interfaces and lines, executing instructions, programs, code sets, or instruction sets stored in the memory 220, and calling data stored in the memory 220 to perform various functions and process data of the wireless controller 200. Optionally, the processor 210 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 210 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content to be displayed; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 210 and may be implemented separately using a communication chip.

[0125] The memory 220 may include random access memory (RAM) or read-only memory (ROM). The memory 220 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 220 may include a program storage area and a data storage area. The program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as touch functionality, sound playback functionality, image playback functionality, etc.), and instructions for implementing the various method embodiments described below. The data storage area may also store data created by the wireless controller 200 during use (such as phonebook data, audio and video data, chat log data, etc.).

[0126] Please see Figure 10 This diagram illustrates a structural block diagram of a computer-readable storage medium provided in an embodiment of this application. The computer-readable medium 500 stores program code that can be called by a processor to execute the methods described in the above method embodiments.

[0127] The computer-readable storage medium 500 may be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. Optionally, the computer-readable storage medium 500 includes a non-transitory computer-readable storage medium. The computer-readable storage medium 500 has storage space for program code 510 that performs any of the method steps described above. This program code can be read from or written to one or more computer program products. The program code 510 may be compressed, for example, in a suitable form.

[0128] In summary, the wireless network disaster recovery method, apparatus, wireless access point, wireless controller, and storage medium provided in this application embodiment allow the wireless access point to obtain configuration information for the wireless network from the wireless controller if it receives a disaster recovery status notification sent by the wireless controller. The disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible. Based on the configuration information, the control terminal accesses the wireless network without interacting with the authentication server. Therefore, even when the authentication server is inaccessible, the terminal can still access the wireless network without interacting with it, ensuring the normal use of the wireless network without compromising its security.

[0129] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A wireless network disaster recovery method, characterized in that, Applied to a wireless access point, wherein the wireless access point is communicatively connected to a wireless controller, the method includes: If a disaster recovery status notification is received from the wireless controller, the configuration information for the wireless network is obtained from the wireless controller, wherein the disaster recovery status notification is generated by the wireless controller when it detects that the authentication server is inaccessible. Based on the configuration information, the control terminal accesses the wireless network without interacting with the authentication server.

2. The method according to claim 1, characterized in that, The step of controlling the terminal to access the wireless network without interacting with the authentication server, based on the configuration information, includes: Create a new wireless network with the same name as the wireless network described above; The authentication method for the newly added wireless network is set according to the configuration information, and the internet access permissions of the newly added wireless network are restricted according to the configuration information. The terminal is connected to the newly added wireless network based on the authentication method, wherein the terminal does not interact with the authentication server under the authentication method.

3. The method according to claim 2, characterized in that, The authentication method includes a first authentication method or a second authentication method, wherein the first authentication method includes one or more of OPEN and WPA-PSK, and the second authentication method includes one or more of PEAP-GTC and EAP-TTL-GTC.

4. The method according to claim 3, characterized in that, The step of connecting the terminal to the newly added wireless network based on the authentication method includes: If a request to access the newly added wireless network is received from the terminal, it is determined whether the terminal meets the specified conditions, wherein the specified conditions include having accessed the wireless network before and retaining the most recent authentication method; If the terminal does not meet the specified conditions, then the terminal will be connected to the newly added wireless network based on the first authentication method; or If the terminal meets the specified conditions, the terminal will be connected to the newly added wireless network based on the second authentication method.

5. The method according to claim 4, characterized in that, The step of connecting the terminal to the newly added wireless network based on the second authentication method includes: The terminal receives a GTC protocol-approved token, wherein the token is obtained by the terminal through encapsulation based on the MSC HAV2 cryptographic code used during the last access to the wireless network. The core information of the terminal is parsed from the token and reported to the wireless controller to instruct the wireless controller to perform a legality verification of the terminal based on the core information; If the terminal receives information from the wireless controller indicating that the verification has passed, it will be connected to the newly added wireless network.

6. The method according to any one of claims 2-5, characterized in that, The method further includes: Hide the wireless network.

7. The method according to claim 1, characterized in that, The step of controlling the terminal to access the wireless network without interacting with the authentication server, based on the configuration information, includes: If a roaming association request initiated by the terminal is received, the core element used to calculate the key of the terminal in local storage is called to calculate a new key. The core element is collected and synchronously obtained by the terminal after the terminal completes the authentication process of the authentication server through the original wireless access point to which the terminal is connected. The terminal is used to perform key negotiation using the new key, and the terminal is then connected to the wireless network after the key negotiation is completed.

8. The method according to claim 7, characterized in that, Before calculating a new key by calling the locally stored core element used to calculate the key for the terminal if a roaming association request is received from the terminal, the method further includes: The system receives the core element distributed by the wireless controller based on a specified protocol, wherein the core element is collected by the original wireless access point and reported to the wireless controller after the terminal completes the authentication process of the authentication server.

9. A wireless network disaster recovery method, characterized in that, Applied to a wireless controller that is communicatively connected to a wireless access point, the method includes: Display the disaster recovery configuration interface; If a configuration operation is detected on the disaster recovery configuration interface, configuration information for the wireless network is generated based on the configuration operation. If the authentication server is found to be inaccessible, a disaster recovery status notification is generated, and the disaster recovery status notification and the configuration information are sent to the wireless access point.

10. A wireless network disaster recovery device, characterized in that, The device is used in a wireless access point, which is communicatively connected to a wireless controller, and includes: The configuration information acquisition module is used to acquire configuration information for the wireless network from the wireless controller if it receives a disaster recovery status notification sent by the wireless controller, wherein the disaster recovery status notification is generated by the wireless controller when it detects that the authentication server cannot be accessed. The wireless network access module is used to control the terminal to access the wireless network without interacting with the authentication server, based on the configuration information.

11. A wireless network disaster recovery device, characterized in that, The device is applied to a wireless controller, which is communicatively connected to a wireless access point, and includes: The configuration interface display module is used to display the disaster recovery configuration interface; The configuration information generation module is used to generate configuration information for the wireless network based on the configuration operation if a configuration operation is detected on the disaster recovery configuration interface. The configuration information sending module is used to generate a disaster recovery status notification if the authentication server is found to be inaccessible, and send the disaster recovery status notification and the configuration information to the wireless access point.

12. A wireless access point, characterized in that, The method includes a memory and a processor, the memory being coupled to the processor, the memory storing instructions that, when executed by the processor, the processor performs the method as described in any one of claims 1-8.

13. A wireless controller, characterized in that, It includes a memory and a processor, the memory being coupled to the processor, the memory storing instructions, and when the instructions are executed by the processor, the processor performs the method as described in claim 9.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium contains program code that can be called by a processor to execute the method as described in any one of claims 1-8 or 9.