Access management method, device and equipment for network convergence access, medium and program product
By integrating access gateways and dynamic policy engines, the problem of independent management of 5G and WLAN networks has been solved, enabling rapid authentication and service continuity, and improving user experience and network switching efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHENGDU SKSPRUCE TECH
- Filing Date
- 2026-01-23
- Publication Date
- 2026-04-21
AI Technical Summary
5G and WLAN networks operate independently in terms of authentication, address allocation, and access control, making it difficult for users to switch efficiently and affecting user experience. Furthermore, existing solutions lack a unified approach to managing converged network access.
By deploying a converged access gateway, unified management of 5G and WLAN networks can be achieved. An authentication information caching mechanism and a dynamic policy engine are adopted to achieve fast authentication and access control, ensuring unified management of user identity and IP address and business continuity.
It improves network switching efficiency, reduces authentication latency, ensures business continuity and user experience, and achieves policy uniformity and flexibility across different networks.
Smart Images

Figure CN121908269A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network management technology, and more specifically, to an access management method, apparatus, device, medium, and program product for converged network access. Background Technology
[0002] With the widespread application of 5G private networks in vertical industries, enterprise users are increasingly demanding the convergence of multiple access networks. On the one hand, 5G networks, with their high bandwidth, low latency, and wide connectivity, have become the preferred bearer network for critical businesses such as industrial control and remote operation and maintenance. On the other hand, WLAN, with its advantages of flexible deployment and low cost, still occupies an important position in indoor scenarios such as offices, warehouses, and exhibition halls.
[0003] Currently, 5G and WLAN networks operate independently in terms of authentication, address allocation, and access control. The lack of a unified approach to managing converged network access prevents users from efficiently switching between 5G and WLAN network scenarios, impacting user experience. Summary of the Invention
[0004] The purpose of this application is to provide a network converged access management method, apparatus, device, medium, and program product to improve the switching efficiency of 5G and WLAN network access and enhance user experience.
[0005] In a first aspect, embodiments of this application provide an access management method for network converged access, applied to a converged access gateway, comprising: In response to the EAP authentication request from the user equipment, if it is determined that the user equipment is currently performing its first authentication, EAP access authentication is performed on the user equipment based on the pre-stored user information; If the user equipment is determined to have successfully passed EAP access authentication, authentication cache information corresponding to the user equipment is generated and stored. Assign IP addresses to the user equipment; Access control is performed on the user equipment based on the IP address.
[0006] In this embodiment, a converged access gateway is used to manage different access networks in a unified manner, and an authentication information caching mechanism is used to achieve fast authentication when switching between different networks, thereby effectively improving network switching efficiency.
[0007] In some embodiments, the response to the EAP authentication request from the user equipment further includes: If it is determined that the user equipment is not currently undergoing its first authentication, the authentication cache information corresponding to the user equipment is retrieved from the local machine. The user equipment is authenticated for EAP access based on the authentication cache information.
[0008] In this embodiment of the application, fast authentication is achieved by directly using authentication cache information during network switching, thereby effectively improving the efficiency of network switching.
[0009] In some embodiments, allocating an IP address to the user equipment includes: If it is determined that a cached IP address corresponding to the user equipment exists locally, the cached IP address shall be used as the IP address assigned to the user equipment this time. If it is determined that there is no cached IP address corresponding to the user equipment locally, an IP address is assigned to the user equipment.
[0010] In this embodiment of the application, by caching IP addresses, the original IP addresses can be reused after network switching, avoiding service interruption and thus ensuring service continuity.
[0011] In some embodiments, the EAP access authentication of the user equipment based on pre-stored user information includes: If it is determined that user information corresponding to the user equipment is pre-stored locally, EAP access authentication is performed on the user equipment based on the pre-stored user information. If it is determined that no user information corresponding to the user equipment exists locally, the user information is retrieved from the unified data management system based on the unique identifier of the user equipment, and the EAP access authentication is performed on the user equipment based on the retrieved user information.
[0012] In this embodiment, user information is pre-stored or retrieved in real time to achieve fast authentication for EAP access, further improving the flexibility of access authentication.
[0013] In some embodiments, determining that the user equipment is currently undergoing its first authentication includes: Obtain the unique identifier of the user equipment; If a query of the local machine determines that there is no authentication cache information corresponding to the unique identifier, it is determined that the user equipment is currently performing its first authentication. If a query confirms the existence of authentication cache information corresponding to the unique identifier in the local database, it is determined that the user equipment is currently undergoing a non-first-time authentication.
[0014] In this embodiment of the application, the unique identifier of the user equipment is obtained to determine whether it is the first authentication, and corresponding authentication strategies are adopted according to different situations, which further improves the flexibility of network access authentication.
[0015] In some embodiments, allocating an IP address to the user equipment includes: If it is determined that the user information contains a pre-allocated static IP address, an IP address is allocated to the user equipment based on the static IP address; If it is determined that the user information does not contain a pre-assigned static IP address, an IP address is assigned to the user equipment according to a preset dynamic allocation strategy.
[0016] In this embodiment of the application, the flexibility of IP address allocation is further improved by using static IP addresses or dynamically allocated IP addresses from user information.
[0017] In some embodiments, the access control of the user equipment based on the IP address includes: Based on the IP address, obtain the preset user permissions and cached network context information corresponding to the user equipment; According to the preset dynamic policy template, an access control policy is generated based on the preset user permissions and the cached network context information; Access control is performed on the user equipment based on the access control policy.
[0018] In this embodiment of the application, access control policies are generated based on dynamic policy templates and related information, thereby achieving policy uniformity across different networks.
[0019] In some embodiments, the network converged access access management method further includes: Collect real-time context information corresponding to the user equipment; The access control policy is dynamically adjusted based on the real-time context information. Access control for the user equipment is performed based on dynamically adjusted access control policies.
[0020] In this embodiment of the application, by dynamically collecting context information and dynamically updating access control policies, the reliability and flexibility of access control are further improved.
[0021] Secondly, embodiments of this application provide an access management device for network converged access, applied to a converged access gateway, comprising: The device authentication module is used to respond to the EAP authentication request of the user device, and when it is determined that the user device is currently authenticating for the first time, it performs EAP access authentication on the user device based on the pre-stored user information. The information caching module is used to generate and store authentication cache information corresponding to the user equipment when it is determined that the user equipment has successfully passed EAP access authentication; The address allocation module is used to allocate IP addresses to the user equipment; The access control module is used to perform access control on the user equipment based on the IP address.
[0022] Thirdly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement the method described in any embodiment of the first aspect.
[0023] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement the method described in any embodiment of the first aspect.
[0024] Fifthly, embodiments of this application provide a computer program product, the computer program product including a computer program, wherein when the computer program is executed by a processor, it can implement the method described in any embodiment of the first aspect. Attached Figure Description
[0025] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0026] Figure 1 A flowchart illustrating an access management method for network converged access provided in an embodiment of this application; Figure 2 This is a system architecture diagram of network converged access provided in the embodiments of this application; Figure 3 This is a schematic diagram of the interaction process for network converged access provided in an embodiment of this application; Figure 4 A schematic diagram of the structure of an access management device for network converged access provided in an embodiment of this application; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0027] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0028] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0029] It should be noted that current 5G and WLAN networks operate independently in terms of authentication, address allocation, and access control, resulting in fragmented user experiences, complex security management, and difficulties in unifying policies.
[0030] In existing technologies, 3GPP standards (such as TS 23.501) propose a solution for WLAN access to the 5G core network through N3IWF (Non-3GPP InterWorking Function). However, this solution mainly relies on IPSec tunnels for secure transmission, and authentication still needs to be completed through AAA (Authentication, Authorization, Accounting) servers, failing to achieve deep integration with 5G AKA (Authentication and Key Agreement) authentication. Furthermore, traditional WLAN networks typically use RADIUS servers for authentication, making it difficult to link user identity information (such as IMSI) with UDM (Unified Data Management) data in the 5G core network, thus preventing the system from implementing policy control based on unified user identities.
[0031] Furthermore, when users switch between 5G and WLAN, the IP address of the user device changes with the network access (e.g., 5G uses a static IP while WLAN uses dynamic allocation via DHCP), making upper-layer application sessions highly susceptible to interruption. Simultaneously, the two independent authentication processes not only increase authentication latency but also burden the UDM and AAA servers. Moreover, existing solutions lack awareness of user context (such as location, time, and device type), and access control policies are mostly statically configured, making it difficult to meet the requirements of a zero-trust security architecture.
[0032] In summary, the existing technology mainly has the following problems: 1. Redundancy and duplication of authentication process: Although both 5G and WLAN can use EAP authentication, the two networks initiate authentication independently, failing to achieve single point authentication and multi-access sharing (i.e., one authentication, multiple networks available).
[0033] 2. Insufficient sharing of user context: There is a lack of real-time synchronization of context information (such as session status, location, QoS requirements, etc.) between the 5G-side SMF / UDM (Session Management Function / Unified Data Management) and the WLAN-side converged gateway.
[0034] 3. Fragmented IP address allocation strategy: Switching from 5G to WLAN may result in different IP addresses being allocated, leading to application layer session interruptions or inconsistent strategies.
[0035] 4. Lack of dynamic policy linkage: Access control policies are based solely on static IP addresses and are not dynamically adjusted in conjunction with context such as user identity, device fingerprints, time, and location.
[0036] To address the problems existing in the prior art, the purpose of this application is to provide a technical solution that enables deep integration of 5G and WLAN networks at the levels of user identity, authentication process, IP address allocation, and access control policies, so as to solve problems such as authentication redundancy, IP inconsistency, ambiguous security boundaries, and rigid policies in the prior art.
[0037] This application embodiment deploys a converged access gateway to unify the management of user authentication for both 5G and WLAN networks, enabling unified access management for both 5G and WLAN users. After a user accesses the 5G private network and completes the registration and authentication process through the AMF (Authentication Management Function), they can use the 5G network DN-AAA (Data Network-AAA, a mechanism in the 5G core network used for secondary authentication and authorization of PDU sessions) feature to perform secondary authentication for private network access when establishing a PDU (Protocol Data Unit) session.
[0038] For example, the network structure of a converged network system is as follows: Figure 2 As shown, when a 5G private network user activates a SIM card or private network, they sign up for the private network through the UDM. The private network signing data may include the DNN (Data Network Name), the user's signed-up static IP address (optional, determined by the operator), and DN-AAA authentication information (whether DN-AAA is used, the DN-AAA address, and whether an IP address is allocated from DN-AAA). The signed-up user information (the aforementioned private network signing data) can be synchronized to the converged access gateway via SMF (Session Management function). Additionally, different users' intranet access permissions can be pre-configured on the converged access gateway.
[0039] like Figure 1 As shown in the figure, this application provides an access management method for network converged access, applied to a converged access gateway, which may include the following steps: S1. In response to the EAP authentication request from the user equipment, if it is determined that the user equipment is currently undergoing its first authentication, perform EAP access authentication on the user equipment based on the pre-stored user information.
[0040] In some embodiments, step S1, in response to the EAP authentication request from the user equipment, further includes: If it is determined that the user device is not currently undergoing its first authentication, retrieve the authentication cache information corresponding to the user device from the local machine. EAP access authentication is performed on user equipment based on authentication cache information.
[0041] It should be noted that user equipment can access the intranet via 5G or WLAN networks.
[0042] When a user equipment initiates an EAP authentication request, such as initiating EAP-AKA', it is first determined whether the user equipment is authenticating for the first time. If so, EAP access authentication is performed on the user equipment based on the pre-stored user information. If the user equipment is not authenticating for the first time, such as when switching from 5G access to WLAN access, EAP access authentication can be performed on the user equipment through the locally cached authentication cache information.
[0043] S2. If it is determined that the user equipment has successfully passed EAP access authentication, generate and store the authentication cache information corresponding to the user equipment.
[0044] It should be noted that when EAP access authentication is successfully completed, the integrated access gateway can cache the relevant data generated during the authentication process (such as user context information and authentication key information) to form authentication cache information, so that user equipment can achieve fast authentication when switching network access in the future.
[0045] S3. Assign IP addresses to user equipment.
[0046] In some embodiments, step S3 may include: If it is determined that the user information contains a pre-assigned static IP address, an IP address is assigned to the user equipment based on the static IP address; If it is determined that the user information does not contain a pre-assigned static IP address, an IP address is assigned to the user equipment according to the preset dynamic allocation strategy.
[0047] It should be noted that after EAP authentication is passed, an IP address needs to be assigned to the user equipment. This IP address can be statically planned and assigned (consistent with the user equipment's contracted static IP address in UDM). If the user information does not have a static IP address, it can be dynamically assigned through the address pool managed by the converged gateway.
[0048] S4. Access control for user equipment based on IP address.
[0049] Finally, the user equipment forwards its access traffic to the converged access gateway via the IP address and then accesses the intranet / private network. The converged access gateway controls the access traffic of the user equipment based on the assigned IP address.
[0050] Based on this, a unified management of different access networks is achieved through a converged access gateway, and a fast authentication is realized when switching between different networks through an authentication information caching mechanism, thereby effectively improving network switching efficiency.
[0051] It should be noted that user equipment can initially access the intranet via the 5G network, and then switch to accessing the intranet via the WLAN network as needed. Similarly, user equipment can also initially access the intranet via the WLAN network, and then switch to accessing the intranet via the 5G network as needed.
[0052] For example, the process of a user equipment accessing a private intranet via a 5G network is as follows: Step 1: The UE (User Equipment) accesses the network through 5G NR (5G New Radio, 5G New Access Standard), and initiates the PDU session creation process after completing the 5G registration and authentication process.
[0053] Step 2: The SMF obtains the user's subscription data (user information) from the UDM and initiates the EAP-AKA authentication process based on the DN-AAA information in the subscription data. The UE and the converged access gateway exchange EAP authentication messages through the SMF. Messages between the SMF and the converged access gateway can also be forwarded through the UPF (User Plane Function, a fundamental component of the 5G core network infrastructure system architecture defined by 3GPP). In this case, the SMF and UPF need to establish an N4 interface connection first. If the converged access gateway does not yet have user information or lacks relevant information, it can obtain the required user data from the UDM through the SMF.
[0054] Step 3: After the UE completes EAP authentication, it establishes a PDU session with the UPF and accesses the intranet using the IP address allocated from the converged access gateway (or a static IP address can be allocated to the UE during UDM subscription). The IP address remains unchanged throughout the UE session lifecycle. Even if the UE switches between 5G and WLAN, the converged access gateway reuses the original IP address to ensure service continuity.
[0055] Step 4: The converged access gateway controls the accessible resources based on the user's IP address according to the intranet access permission policy set by the park / enterprise.
[0056] For example, the process of a user accessing the intranet via a WLAN network is as follows: Step 1: Set the WLAN network authentication method to 802.1X and configure the authentication server as the converged access gateway. Also, set the server that obtains IP addresses as the converged access gateway.
[0057] Step 2: The UE selects to use EAP-AKA' authentication for access. The UE sends an access request message to the converged access gateway through the AP / AC (Access Point, AP is the access point of the wireless network, responsible for realizing the connection between the terminal device and the wireless network; Access Controller, AC is the controller of the wireless network, responsible for unified management and control of the AP). The access request message contains the EAP authentication message and carries the user's IMSI (international mobile group identity, i.e., the unique identifier of the user equipment) information.
[0058] Step 3: The converged access gateway generates an EAP response message based on the user data pre-synchronized from the UDM (or, if not, obtains the required user information from the UDM using the UE's IMSI information carried in the EAP message), thus completing the EAP message interaction and authentication process.
[0059] Step 4: After completing access authentication, the UE obtains an IP address from the converged access gateway. This IP address can be statically planned and allocated (consistent with the UE's subscribed static IP address in the UDM) or dynamically allocated (IP addresses are allocated by the address pool managed by the converged gateway).
[0060] Step 5: The UE uses the obtained IP address to forward traffic to the converged access gateway through the tunnel via AP / AC to access the intranet. The converged access gateway determines the corresponding permission rules (access control policies) based on the UE's IP address and implements access control for user traffic based on these rules.
[0061] It should be noted that, in addition to EAP-AKA authentication, EAP-TLS authentication can also be used. However, this authentication method requires the UE to sign up for the private network, connect to the activation server to install the TLS client certificate, and then access the network. The corresponding server certificate needs to be pre-installed on the converged access gateway.
[0062] like Figure 3 As shown, assuming a user first accesses the network via 5G and then switches to WLAN, the network switching process is as follows: 1. The UE initiates a WLAN access request, carrying IMSI information; 2. The converged access gateway queries the local session cache based on the IMSI information and finds that there is a valid session (session information corresponding to the same IMSI and not expired). 3. The converged access gateway skips interaction with the UDM and directly reuses the cached IP addresses and key materials; 4. If the current authentication method is EAP-AKA, the challenge process can be simplified or a new key can be derived using the session key; 5. The UE quickly obtains the same IP address as when accessing 5G; 6. The converged access gateway maintains the original access policy (IP remains unchanged), and services are uninterrupted.
[0063] Similarly, if a user switches from a WLAN network to a 5G network, the SMF can query the user context from the converged access gateway through the N4 interface to avoid duplicate authentication.
[0064] In some embodiments, assigning an IP address to a user equipment includes: If it is determined that a cached IP address corresponding to the user device exists locally, the cached IP address will be used as the IP address assigned to the user device this time. If it is determined that there is no cached IP address corresponding to the user device locally, an IP address is assigned to the user device.
[0065] It should be noted that when it is determined that the user equipment is not authenticating for the first time, that is, when this is a network switching authentication (such as switching from 5G network access to WLAN network access), since the IP address assigned to the user equipment during the first authentication can be cached locally, the previously cached IP address can be directly obtained (through the unique identifier of the user equipment) as the IP address for the user equipment to access this time, thereby ensuring that the upper layer services are not interrupted.
[0066] Accordingly, if no cached IP address corresponding to the user device is found locally, an IP address will be allocated according to a preset strategy (such as using the user's static IP or dynamically allocating based on the address pool).
[0067] Based on this, by caching IP addresses, the original IP addresses can be reused after network switching, avoiding interruption of upper-layer services, thus effectively ensuring business continuity and helping to improve user experience.
[0068] In some embodiments, EAP access authentication of user equipment is performed based on pre-stored user information, including: If it is determined that user information corresponding to the user equipment is pre-stored locally, EAP access authentication is performed on the user equipment based on the pre-stored user information. If it is determined that no user information corresponding to the user equipment exists locally, the user information is retrieved from the unified data management system based on the unique identifier of the user equipment, and the EAP access authentication is performed on the user equipment based on the retrieved user information.
[0069] It should be noted that during the EAP access authentication process for user equipment, it is necessary to obtain the corresponding user information for authentication. This user information is usually pre-stored in the converged access gateway when the user activates the private network, and can be obtained directly from the local machine.
[0070] Accordingly, if no user information corresponding to the user device is found locally, the IMSI (Unique Identifier for SIM Card) information carried in the EAP message initiated by the user device needs to be obtained from the UDM, and an EAP response message is generated based on the obtained user information to complete the EAP message interaction and authentication process.
[0071] Based on this, user information can be pre-stored or retrieved in real time to achieve rapid authentication for EAP access, further improving the flexibility of access authentication.
[0072] In some embodiments, determining that the user equipment is currently undergoing its first authentication includes: Obtain the unique identifier of the user device; If a query confirms that no authentication cache information corresponding to the unique identifier exists locally, it is determined that the user device is currently performing its first authentication. If a query confirms the existence of authentication cache information corresponding to the unique identifier on the local machine, it is determined that the user device is not currently undergoing its first authentication.
[0073] It should be noted that when receiving an EAP authentication request initiated by a user device, the system can query whether the corresponding authentication cache information is cached locally based on the unique device identifier it carries. If so, it means that the user device is not authenticating for the first time (i.e., network switching authentication), such as switching from 5G network access to WLAN network access; otherwise, it is determined to be authenticating for the first time.
[0074] It should be noted that different authentication methods and IP address allocation methods are required for first-time authentication and non-first-time authentication in order to improve authentication efficiency and maintain business continuity.
[0075] Based on this, the unique identifier of the user equipment is obtained to determine whether it is the first authentication, and corresponding authentication strategies are adopted according to different situations, which further improves the flexibility of network access authentication.
[0076] In some embodiments, access control of user equipment based on IP address includes: Based on the IP address, obtain the preset user permissions and cached network context information corresponding to the user device; Based on the preset dynamic policy template, an access control policy is generated using preset user permissions and cached network context information. Access control is implemented for user equipment based on access control policies.
[0077] It should be noted that during the access control process, the IP address can be obtained based on the user device's access traffic, and combined with the corresponding user permissions and cached network context information as input. A preset dynamic policy template is used to generate a dynamic access control policy, and access control is performed based on the currently generated access control policy.
[0078] Based on this, access control policies are generated according to dynamic policy templates and related information, thereby achieving policy uniformity across different networks.
[0079] In some embodiments, the access management method for converged network access further includes: Collect real-time context information corresponding to user devices; Access control policies are dynamically adjusted based on real-time context information. Access control for user equipment is based on dynamically adjusted access control policies.
[0080] Specifically, during the process of a user accessing resources on the intranet, contextual information of the user device (such as user location, access time, device fingerprint, network risk score, etc.) can be monitored and collected in real time. Based on this contextual information and the UDM subscription policy, a dynamically adjusted access control policy can be generated, and the user device can be accessed according to the dynamically adjusted access control policy.
[0081] Based on this, by dynamically collecting context information and dynamically updating access control policies, the reliability and flexibility of access control are further improved.
[0082] For example, the integrated access mesh provided in this application embodiment may include the following functional modules: 1. 5G signaling interaction: Interacting with SMF and UPF to exchange 5G information, mainly parsing and encapsulating 5G signaling messages. These messages are used to transmit authentication process messages and context and policy information.
[0083] 2. User information synchronization: Receive user ID card and contract data, as well as PCF rules, sent from UDM when opening / closing an account / changing business. Proactively query user data and PCF (Point Coordination Function) rules from UDM (via UPF & SMF).
[0084] 3. User authentication management: Implement EAP authentication server functions to authenticate users and cache user context information and authentication key information; provide multi-dimensional data for the dynamic policy engine module, and support a fast authentication process when users roam, reducing authentication time.
[0085] 4. WLAN authentication message interaction: Receive user 802.1x authentication messages sent from WLAN. Encapsulate the messages using Radius packets, parse the authentication, and encapsulate and reply with authentication interaction messages.
[0086] 5. User access control mainly manages user access permissions to the private network and allocates internal resources that users can access, in order to assist the dynamic policy engine in generating user-related control policies based on the configuration.
[0087] 6. IP Address Management: This function manages user IP addresses. If a static IP address is used, it needs to be specified when signing the 5G private network contract and synchronized with the user information. If a dynamic IP address is used, it will be obtained from the available address pool and assigned to the user.
[0088] 7. Policy Rules: Supports configuring and storing predefined dynamic policy templates (supports JSON / YAML format), generating corresponding network access rules (access control policies) based on user permissions, session, and network context information. Simultaneously, it converts 5G network configuration rules (such as QoS) into WLAN network rules and distributes them to the WLAN for execution, achieving rule linkage between 5G and WLAN networks and enabling QoS linkage of the access network.
[0089] 8. The dynamic policy engine collects real-time context information from the 5G core network, WLAN controller, and local session cache, and generates access control policies based on this information and matching policy rules. The decision results (access control policies) are then sent to the policy execution point (i.e., data forwarding) for execution.
[0090] 9. Data forwarding: Forward and control traffic entering the converged access gateway according to access control policies.
[0091] 10. Access log auditing: Record and store the access logs of all users accessing the intranet through the access gateway for easy auditing purposes.
[0092] For example, the dynamic strategy engine described above works as follows: 1. The dynamic policy engine collects the following real-time context information each time a user initiates an intranet access request (or a session is established):
[0093] It should be noted that all the above context information must be collected after successful user authentication and before traffic forwarding.
[0094] 2. Example of dynamic strategy rules.
[0095] Enterprise administrators configure conditional-action policies in the policy rule base, for example: yaml edit Example 1: - rule_id: "RULE_001" Description: "Access to the financial system is only permitted during working hours" condition: destination_ip: "10.20.5.0 / 24"# Financial system network segment time_range: "09:00-18:00" day_of_week: "Mon-Fri" action: "allow" Example 2: - rule_id: "RULE_002" Description: "Guest devices connected via WLAN are prohibited from accessing the production network." condition: network_type: "WLAN" device_type: "Guest-Device" destination_ip: "10.30.0.0 / 16"# Production network action: "deny" Example 3: - rule_id: "RULE_003" Description: "5G-connected industrial equipment can access the MES (Manufacturing Execution System) 24 / 7." condition: network_type: "5G" device_type: "Industrial-PLC" destination_ip: "10.40.10.50" action: "allow" It should be noted that the policy engine supports policy priority ordering and rule conflict resolution (e.g., deny takes precedence over allow).
[0096] 3. Strategy Decision-Making and Execution Process: When a UE attempts to access internal network resources, the access control process is as follows: 3.1 Traffic arrives at the converged access gateway (from UPF or WLAN tunnel); 3.2 The gateway extracts the source IP and uses the session cache to look up the corresponding IMSI and complete context; 3.3 The dynamic policy engine inputs the current access request (source IP, destination IP, port) and context into the policy rule base; 3.4 The engine matches all applicable rules and generates an allow / deny decision; 3.5 Decision results are sent to the data forwarding plane in real time (e.g., based on OpenFlow or Linux iptables); 3.1 If allowed, forward the traffic; if denied, discard it; and selectively log the traffic based on whether it is allowed or denied.
[0097] The process is completed in milliseconds and does not affect the user experience.
[0098] 4. Coordination with authentication and IP allocation: During the authentication phase, the policy engine is not activated; only the session context is established. After IP is assigned, the IMSI-IP binding relationship is written to the session cache and used as an index key for the policy engine; A policy evaluation is triggered with each access request to ensure that the policy takes effect dynamically with the context. When a session is updated (e.g., location changes): the context collector updates the cache, and the new strategy is automatically applied to subsequent accesses.
[0099] 5. Collaboration with the 5G core network: The dynamic policy engine works in collaboration with the PCF and / or SMF in the 5G core network. During the PDU session establishment process, the SMF transmits information such as user location, network slice identifier, or QoS context to the converged access gateway. The policy engine dynamically adjusts access control decisions based on the context. Alternatively, the converged access gateway, as an application function (AF), reports policy requirements to the PCF through the N5 interface, and the PCF generates PCC (Policy and Charging Control) rules and issues them to the SMF.
[0100] 7. Integration with WLAN: The dynamic policy engine acts as the authentication center for WLAN, and the converged access gateway acts as the WLAN traffic forwarding gateway. During the user's access to WLAN, the AC or AP needs to transmit real-time context information to the converged access gateway. At the same time, the dynamic policy engine obtains user data from the 5G core network for the policy engine to match policy rules and generate access permissions. If the user moves to a new AP, the AC can send a RADIUS Accounting-Update (session state update message) or CoA (Change of Authorization, an attribute in the RADIUS protocol used to dynamically adjust authorization information during the session) message, carrying the new AP location. The converged access gateway updates the session context and generates a new access control policy. Subsequent access will automatically apply the new access control policy (such as "external connections are prohibited after entering the equipment room area").
[0101] It should be noted that the embodiments of this application have the following characteristics: 1. Unified User Identity and Data Source: When all users activate 5G private network services, they complete the contract signing in UDM. The contract signing data includes information such as DNN and static IP (optional), and uses IMSI as a unique user identity identifier across 5G and WLAN networks, which is parsed and used by the converged access gateway during authentication.
[0102] 2. Single-point authentication and session continuity mechanism: After a user completes EAP-AKA' or EAP-TLS authentication for the first time on any network (5G or WLAN), the converged access gateway generates a unified authentication token (such as a session key derived from 5G AV) as authentication cache information and caches the user's session context (including IP, validity period, key materials, and QoS). When the user switches to another network (such as from 5G to WLAN), secondary authentication can be quickly completed through the IMSI carried by the user equipment, avoiding repeated UDM queries and significantly reducing authentication latency.
[0103] 3. IP Address Consistency Guarantee: Regardless of whether the user accesses via 5G or WLAN, the converged access gateway assigns the same IP address to the user based on the IMSI (which can be a static IP address subscribed to by the UDM or an IP address dynamically allocated from the unified address pool managed by the converged gateway). This IP address remains unchanged throughout the UE session lifecycle. Even if the UE switches between 5G and WLAN, the converged access gateway still reuses the original IP address to ensure service continuity and ensure that the application layer session is not interrupted during the switching process.
[0104] 4. Enhanced end-to-end secure tunnel: In WLAN access scenarios, a lightweight encrypted tunnel (such as DTLS or EAP-TLS over CAPWAP) is established between the UE and the converged access gateway to prevent edge devices such as AP / AC from stealing authentication information; at the same time, the converged access gateway can verify the device certificates of AP / AC to ensure the legitimacy of the access point and build a trusted edge.
[0105] 5. Dynamic Policy Engine: The converged access gateway integrates policy decisions, receives context information (including user location, access time, device fingerprint, network risk score, etc.) from the 5G core network (such as PCF) and WLAN controller in real time, and dynamically generates fine-grained access control lists (ACLs) in conjunction with UDM subscription policies. It also works in collaboration with SMF / UPF or AC / AP to achieve unified access policy control for heterogeneous networks.
[0106] 6. Hybrid Authentication Mode Support: The system supports dual-mode authentication of EAP-AKA (based on IMSI) and EAP-TLS (based on certificate). When using EAP-TLS, the converged access gateway can verify whether the UE certificate fingerprint is consistent with the certificate bound to the IMSI in the UDM, realizing a strong binding between 5G user identity and digital certificate, balancing high security and compatibility.
[0107] Please refer to Figure 4 , Figure 4 This paper illustrates a block diagram of an access management device for converged network access provided in some embodiments of this application. It should be understood that this access management device for converged network access is similar to the one described above. Figure 1 Corresponding to the method embodiments, it is able to execute the various steps involved in the above method embodiments. The specific functions of the access management device for network converged access can be found in the description above. To avoid repetition, detailed descriptions are appropriately omitted here.
[0108] Figure 4 The network converged access access management device includes at least one software function module that can be stored in a memory or embedded in the network converged access access management device in the form of software or firmware. This network converged access access management device is applied to a converged access gateway and includes: The device authentication module 410 is used to respond to the EAP authentication request of the user device and, if it is determined that the user device is currently undergoing its first authentication, perform EAP access authentication on the user device based on the pre-stored user information. The information caching module 420 is used to generate and store authentication cache information corresponding to the user equipment when it is determined that the user equipment has successfully passed EAP access authentication; Address allocation module 430 is used to allocate IP addresses to user equipment; Access control module 440 is used to perform access control on user equipment based on IP address.
[0109] It is understood that the above-described device embodiments correspond to the method embodiments of the present invention. The network converged access access management device provided by the embodiments of the present invention can implement the network converged access access management method provided by any one of the method embodiments of the present invention.
[0110] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the aforementioned method, and will not be elaborated further here.
[0111] like Figure 5 As shown, some embodiments of this application provide an electronic device 500, which includes: a memory 510, a processor 520, and a computer program stored in the memory 510 and executable on the processor 520. When the processor 520 reads the program from the memory 510 via a bus 530 and executes the program, it can implement any of the methods included in the above-described network converged access management method.
[0112] Processor 520 can process digital signals and can include various computing architectures. For example, it can be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 520 can be a microprocessor.
[0113] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all of the functions of one or more modules described in the embodiments of this application. The processor 520 of this disclosure embodiment can be used to execute the instructions in the memory 510 to implement the methods shown above. The memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.
[0114] Some embodiments of this application also provide a computer-readable storage medium storing a computer program that, when executed by a processor, describes the method described in the method embodiments.
[0115] Some embodiments of this application also provide a computer program product that, when run on a computer, causes the computer to perform the methods described in the method embodiments.
[0116] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For apparatus embodiments, since they are basically similar to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0117] It should be understood, in the several embodiments provided in this application, that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0118] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0119] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0120] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0121] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0122] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
Claims
1. A method for access management in converged network access, characterized in that, Applied to converged access gateways, including: In response to the EAP authentication request from the user equipment, if it is determined that the user equipment is currently performing its first authentication, EAP access authentication is performed on the user equipment based on the pre-stored user information; If the user equipment is determined to have successfully passed EAP access authentication, authentication cache information corresponding to the user equipment is generated and stored. Assign IP addresses to the user equipment; Access control is performed on the user equipment based on the IP address.
2. The access management method for network converged access according to claim 1, characterized in that, The response to the EAP authentication request from the user equipment also includes: If it is determined that the user equipment is not currently undergoing its first authentication, the authentication cache information corresponding to the user equipment is retrieved from the local machine. The user equipment is authenticated for EAP access based on the authentication cache information.
3. The access management method for network converged access according to claim 1, characterized in that, The allocation of IP addresses to the user equipment includes: If it is determined that a cached IP address corresponding to the user equipment exists locally, the cached IP address shall be used as the IP address assigned to the user equipment this time. If it is determined that there is no cached IP address corresponding to the user equipment locally, an IP address is assigned to the user equipment.
4. The access management method for network converged access according to claim 1, characterized in that, The EAP access authentication of the user equipment based on pre-stored user information includes: If it is determined that user information corresponding to the user equipment is pre-stored locally, EAP access authentication is performed on the user equipment based on the pre-stored user information. If it is determined that no user information corresponding to the user equipment exists locally, the user information is retrieved from the unified data management system based on the unique identifier of the user equipment, and the EAP access authentication is performed on the user equipment based on the retrieved user information.
5. The access management method for network converged access according to claim 1, characterized in that, The determination that the user equipment is currently undergoing its first authentication includes: Obtain the unique identifier of the user equipment; If a query of the local machine determines that there is no authentication cache information corresponding to the unique identifier, it is determined that the user equipment is currently performing its first authentication. If a query confirms the existence of authentication cache information corresponding to the unique identifier in the local database, it is determined that the user equipment is currently undergoing a non-first-time authentication.
6. The access management method for network converged access according to claim 1, characterized in that, The allocation of IP addresses to the user equipment includes: If it is determined that the user information contains a pre-allocated static IP address, an IP address is allocated to the user equipment based on the static IP address; If it is determined that the user information does not contain a pre-assigned static IP address, an IP address is assigned to the user equipment according to a preset dynamic allocation strategy.
7. The access management method for network converged access according to claim 1, characterized in that, The access control of the user equipment based on the IP address includes: Based on the IP address, obtain the preset user permissions and cached network context information corresponding to the user equipment; According to the preset dynamic policy template, an access control policy is generated based on the preset user permissions and the cached network context information; Access control is performed on the user equipment based on the access control policy.
8. The network converged access access management method according to any one of claims 1 to 7, characterized in that, Also includes: Collect real-time context information corresponding to the user equipment; The access control policy is dynamically adjusted based on the real-time context information. Access control for the user equipment is performed based on dynamically adjusted access control policies.
9. An access management device for converged network access, characterized in that, Applied to converged access gateways, including: The device authentication module is used to respond to the EAP authentication request of the user device, and when it is determined that the user device is currently authenticating for the first time, it performs EAP access authentication on the user device based on the pre-stored user information. The information caching module is used to generate and store authentication cache information corresponding to the user equipment when it is determined that the user equipment has successfully passed EAP access authentication; The address allocation module is used to allocate IP addresses to the user equipment; The access control module is used to perform access control on the user equipment based on the IP address.
10. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, it can implement the network converged access management method according to any one of claims 1-8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, performs the network converged access management method as described in any one of claims 1-8.
12. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the network converged access management method according to any one of claims 1-8.