Scenic spot network management system
Through the collaborative architecture of the central user management platform and access gateway, the problem of duplicate authentication in public wireless networks at multiple scenic spots within the scenic area has been solved, achieving cross-scenic spot authentication-free and unified management, thus improving access experience and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- YANTAI XINRONG NETWORK TECHNOLOGY CO LTD
- Filing Date
- 2026-02-03
- Publication Date
- 2026-04-28
AI Technical Summary
In the public wireless networks at multiple attractions within the scenic area, tourists need to authenticate repeatedly, resulting in a discontinuous access experience. Furthermore, the lack of unified user lifecycle management and security policies makes it difficult to conduct centralized audits and handle security incidents.
A collaborative architecture is introduced between a central user management platform and distributed access gateways to achieve unified identity authentication, roaming token issuance, and policy management. Roaming tokens are generated and quickly verified locally on the access gateway to achieve cross-scenic spot authentication without duplication. Centralized auditing and revocation linkage are achieved through log feedback.
It enables cross-scenic spot authentication without duplicate authentication, improves access convenience and security, reduces on-site consultation and complaint risks, and enhances centralized management capabilities and security controllability of operation and maintenance.
Smart Images

Figure CN121940753A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of scenic area management technology, and more specifically, to a scenic area network management system. Background Technology
[0002] Public Wi-Fi networks in tourist destinations are typically built and maintained separately by multiple attractions, with inconsistent hotspot names, passwords, authentication methods, and management policies. Tourists moving between attractions frequently need to repeatedly request passwords or open authentication pages to log in, resulting in a discontinuous access experience and creating pressure on service desks and increasing the risk of complaints during peak periods. Furthermore, the dispersed deployment of routers or gateways at each attraction lacks a unified user lifecycle management and security policy enforcement mechanism. Operators struggle to centrally audit and control user behavior across attractions, and find it difficult to uniformly collect and analyze authentication, roaming, and access logs for big data analysis to support capacity assessment, anomaly identification, and service quality governance. This results in a long and inconsistent security incident handling chain.
[0003] Among existing hotspot interconnection technologies, IEEE 802.11u proposes the goal of achieving interoperability with external networks through network discovery and selection, and external network information transmission, providing a protocol foundation for hotspot interconnection. The publicly available document, *Cisco Wireless LAN Passpoint Configuration Manual*, discloses a wireless access configuration scheme based on Passpoint (Hotspot 2.0) authentication, such as... Figure 2 As shown, Passpoint (Hotspot 2.0) is used to support terminals in automatically discovering and authenticating access to hotspots, improving the convenience of public Wi-Fi connections. In the authentication and authorization system, RADIUS is used for centralized AAA management, and OAuth 2.0 and its Bearer Token usage provide a general framework for token-based resource access control.
[0004] However, directly applying these capabilities to scenic area network scenarios faces implementation obstacles. For example, the authentication methods of heterogeneous gateways across multiple scenic spots are inconsistent, hindering the continuity of "non-repeating authentication" across scenic spots. Furthermore, the lack of policy version consistency for scenic area operations, token revocation linkage, and a unified audit loop makes centralized management difficult. Therefore, a centralized user management system for scenic area network routes is needed to ensure security and maintainability while enabling unified and convenient access across scenic spots. Summary of the Invention
[0005] To overcome the aforementioned deficiencies of the prior art, this invention provides a scenic area network management system. This system achieves user data sharing and policy unification through a central user management platform. Upon receiving authentication records from the unified identity authentication module, it calls the associated records in the user data management module to generate and bind roaming tokens corresponding to tourist terminals, thereby unifying tourist identities. Based on roaming range management constraints, it restricts the set of scenic spots where roaming tokens can be used, enabling tourists to undergo cross-scenic spot authentication without duplicate authentication. Finally, it achieves rapid local verification and policy execution through the access gateways of each scenic spot, thus solving the problems mentioned in the background art.
[0006] To achieve the above objectives, the present invention provides the following technical solution: A scenic area network management system includes a central user management platform and access gateways deployed at multiple scenic spots. The central user management platform is used for unified identity authentication, user data management, roaming token issuance, key management, policy management, and token revocation and renewal. The access gateways are used to acquire and quickly verify roaming tokens locally when tourists access multiple scenic spots, and send authentication and roaming events back to the central user management platform to achieve centralized auditing and revocation linkage.
[0007] As a further embodiment of the present invention, the central user management platform includes a unified identity authentication module, a user data management module, a roaming token issuance module, a key management module, a policy management module, and a token revocation and renewal module; the access gateway includes an access control module, a token acquisition module, a local fast verification module, a policy execution module, and a log feedback module.
[0008] As a further aspect of this invention, the central user management platform is used for unified identity authentication, user data management, roaming token issuance, key management, policy management, and token revocation and renewal, including the following specific contents: When a tourist terminal first accesses the public wireless network at any scenic spot, the access gateway first places the tourist terminal's access session in a pending authentication state, and triggers the authentication process after detecting the tourist terminal's internet access request: The access gateway obtains basic information for authentication from the tourist terminal and generates an authentication request message. Subsequently, the access gateway forwards the authentication request to the unified identity authentication module of the central user management platform through the control signaling channel. The unified identity authentication module performs identity verification according to a preset authentication method. After the identity verification is successful, a corresponding user identifier is generated, and an authentication record containing the user identifier, terminal identifier, authentication time, access scenic spot identifier, and authentication result is formed. The central user management platform further writes the authentication record into the user data management module to form an associated record.
[0009] The roaming token issuance module receives the authentication record output by the unified identity authentication module, and reads the record item associated with the authentication record using the user identifier as the search key. It extracts the terminal identifier from the record item, performs a digest calculation on the terminal identifier, and generates a terminal identifier digest. The roaming token issuance module combines the authentication record and the terminal identifier digest into binding base data, constructs the payload field of the roaming token, performs a signature calculation on the payload field to generate a signature field, and combines the signature field and the payload field to form the roaming token. The roaming token issuance module writes the authentication record and the terminal identifier digest into the user data management module as a roaming token binding record, and establishes an association index between the binding record and the record item associated with the authentication record, thereby achieving the binding between the visitor terminal corresponding to the authentication record and the roaming token instance issued this time.
[0010] The generation of the signature field, which combines the signature field and the payload field to form a roaming token, includes: after the payload field is fixed, the roaming token issuing module first encodes the payload field to ensure that the same set of fields generates a consistent byte sequence when implemented in different software and hardware environments; then, it performs a digest operation on the byte sequence to generate a message digest value; and performs a digital signature operation on the message digest value to obtain a signature result as the signature field. The roaming token is organized and parsed in the order of "header field—payload field—signature field," and the logical structure of the roaming token is determined to consist of "header field, payload field, and signature field" in sequence. The roaming token issuing module performs standardized serialization encoding on the header field and payload field respectively, and concatenates the encoded header field, encoded payload field, and signature field into a continuous data string in sequence. The concatenated data string is then subjected to consistent character encoding to obtain a complete roaming token.
[0011] The central user management platform manages the roaming range to control the applicable attractions for the roaming token: After the initial authentication based on the roaming token is successful, the central user management platform generates a corresponding set of authorized attractions based on the tourist's selected route, scenic area group, and ticketing product permissions, and writes the set of authorized attractions into the roaming range field of the roaming token in the form of an attraction identifier list and a route identifier mapping; When each attraction access gateway performs local fast verification, in addition to verifying the signature and validity period, it reads the roaming range field in the roaming token and matches it with the currently accessed attraction identifier. If the match is successful, access is granted and repeated authentication is waived; if the match fails, access based on the roaming token is rejected and the process is initiated again.
[0012] The process of generating a set of authorized attractions based on the tourist's selected route, scenic area group, and ticketing product permissions includes: After initial authentication, the central user management platform reads the order or benefit information associated with the user's identifier, determines the tourist's selected route identifier, scenic area group identifier, and ticketing product identifier, and searches for three types of mapping relationships in the configuration data maintained on the central user management platform side: the mapping relationship between the route identifier and the set of attraction identifiers, the mapping relationship between the scenic area group identifier and the set of attraction identifiers, and the mapping relationship between the ticketing product identifier and the set of attraction identifiers; the central user management platform synthesizes the above three types of mapping relationships according to preset set operation rules. The synthesis includes at least a union to cover all attractions within the route, an intersection to limit attractions to those only authorized by ticketing, and a difference to remove temporarily closed or restricted attractions, thus obtaining the set of authorized attractions.
[0013] As a further aspect of the present invention, the access gateway is used to acquire and quickly verify the roaming token locally when tourists access the site across attractions, and to send the authentication and roaming events back to the central platform to achieve centralized auditing and revocation linkage, including the following specific content: when a tourist terminal switches from an attraction that has completed the initial authentication to another attraction and accesses the wireless network of the attraction, the token acquisition module of the access gateway acquires the roaming token in the access session in which the terminal initiates the Internet access request.
[0014] After obtaining the roaming token, the access gateway submits the roaming token to the local fast verification module, which performs multiple verifications on the token without triggering a duplicate authentication page. When all verifications pass, the local fast verification module outputs a release command to the access control module, which then switches the terminal session from the pending authentication state to the authenticated and released state, thereby enabling convenient access across attractions without duplicate authentication. The log feedback module records key events in a structured manner using a unified audit field set and sends them back to the central user management platform. These key events include at least the initial authentication event, cross-attraction roaming event, release result, and revocation processing result.
[0015] The technical effects and advantages of this invention's scenic area network management system are as follows: By introducing a collaborative architecture of "central user management platform + distributed access gateway" among multiple scenic spots in a scenic area, this invention simultaneously improves the cross-scenic spot access experience for tourists and the security and maintenance capabilities of the operation side. On the one hand, when a tourist accesses any scenic spot for the first time, the central platform completes unified identity authentication and generates a roaming token bound to the tourist's terminal based on the authentication record, thereby unifying the management of "tourist identity" and "terminal access credentials." Simultaneously, the platform manages the applicable scenic spot set of the roaming token through "roaming range management," enabling the access gateway to determine whether to allow access or transfer to re-authentication based on the roaming range matching the current scenic spot identifier during local verification. This mechanism achieves controllable roaming "without repeated authentication only within the authorized scenic spot set," solving the problem of repeated authentication across scenic spots caused by multiple hotspot fragmentation. To address the issue of discontinuous experience, each attraction's access gateway uses token acquisition and local rapid verification to complete token integrity, validity, and terminal binding consistency checks without triggering duplicate authentication pages, and then allows access. Simultaneously, it utilizes the "policy version number - policy template" mechanism of policy management to enforce access duration, bandwidth, concurrency, blacklists, and access control, triggering updates when versions are inconsistent to avoid policy drift causing inconsistencies in experience and security. Furthermore, the system provides token revocation and renewal capabilities to support continuous access during security governance and route traversal. The log feedback module returns the initial authentication, roaming, access, and revocation results according to a unified audit field set, creating a cross-attraction audit link on the platform. This provides a basis for operation and maintenance analysis, complaint tracing, and security handling, significantly reducing the risk of on-site consultations and complaints and improving centralized operation and maintenance and security controllability. Attached Figure Description
[0016] Figure 1 This is a schematic diagram of the structure of a scenic area network management system according to the present invention.
[0017] Figure 2 This diagram illustrates the use of Passpoint for home network connectivity using existing technology.
[0018] Figure 3 This is a schematic diagram comparing the efficiency of the cancellation list and the cancellation incremental distribution in this invention.
[0019] In the diagram: Passpoint Terminal, a terminal device supporting Passpoint / Hotspot 2.0; ANQP Exchange, the query exchange process of the access network query protocol; 802.1x (EAP-SIM), 802.1X / EAP access authentication between the terminal and the access network; Passpoint AP, a wireless access point that supports 802.11u / HS2.0 capability announcements and responds to ANQP queries through Wi-Fi Alliance Passpoint authentication; Passpoint WLC, a wireless LAN controller; RADIUS (EAP-SIM), the interaction between the WLC and the AAA side via RADIUS forwarding / bearing EAP-SIM authentication-related interactions; AAA Server, the AAA server; MAP Gateway, the mobile network MAP; AuC / HLR from MSP, the authentication center / home location register from the mobile service provider. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] Example 1
[0022] like Figure 1 As shown, the present invention discloses a scenic area network management system, which includes a central user management platform and access gateways deployed at multiple scenic spots. The central user management platform is used for unified identity authentication, user data management, roaming token issuance, key management, policy management, and token revocation and renewal. The central user management platform includes a unified identity authentication module, a user data management module, a roaming token issuance module, a key management module, a policy management module, and a token revocation and renewal module. The access gateway is used to acquire and quickly verify roaming tokens locally when tourists access multiple scenic spots, and to send authentication and roaming events back to the central user management platform to achieve centralized auditing and revocation linkage. The access gateway includes an access control module, a token acquisition module, a local quick verification module, a policy execution module, and a log transmission module.
[0023] When a tourist terminal first accesses the public wireless network at any attraction, the access gateway first places the tourist terminal's access session in a pending authentication state. Upon detecting an internet access request initiated by the tourist terminal, it triggers the authentication process: the access gateway obtains basic authentication information from the tourist terminal and generates an authentication request message. The basic information includes at least the access gateway identifier, the attraction identifier, the access point identifier, the terminal identifier, and a timestamp. The terminal identifier can be one of the terminal's MAC address, 802.1X identifier, or an identifier digest calculated from the terminal's fingerprint. Subsequently, the access gateway forwards the authentication request to the unified identity authentication module of the central user management platform through the control signaling channel. The unified identity authentication module performs identity verification according to a preset authentication method, which can be at least one of SMS verification code verification, third-party account authorization login, or ticket order information verification. After successful identity verification, a corresponding user identifier is generated, forming an authentication record containing the user identifier, terminal identifier, authentication time, attraction identifier, and authentication result. The central user management platform further writes the authentication record into the user data management module to form an associated record.
[0024] The roaming token issuance module receives the authentication record output by the unified identity authentication module and performs format and validity checks on the authentication record. The checks include at least determining whether the authentication record is empty, whether it conforms to the preset length and character set rules, and whether it is in an issueable state. After the checks pass, the authentication record is written into the issuance context as the primary index key for this token issuance.
[0025] The roaming token issuance module uses the user identifier as the retrieval key to read the record item associated with the authentication record from the user data management module (the record item refers to a user authentication association record stored in the user data management module with the user identifier as the index, whose content includes at least the terminal identifier, authentication time, access attraction identifier, and authentication result fields, etc.). It then extracts the terminal identifier and its generation source information, as well as the authentication time field corresponding to the record item, from the record item to confirm that the terminal identifier is a valid terminal identifier formed during the initial authentication. Subsequently, the roaming token issuance module performs a digest calculation on the terminal identifier according to a preset digest rule to generate a terminal identifier digest. The digest rule can be to normalize the terminal MAC address or 802.1X identifier before calculating the hash digest, thereby obtaining a terminal identifier digest of fixed length that is easy to compare. Finally, the roaming token issuance module combines and encapsulates the authentication record and the terminal identifier digest into binding base data and writes the binding base data into the current issuance context.
[0026] After forming the binding baseline data, the roaming token issuance module constructs the payload fields of the roaming token using field mapping and structured serialization. Specifically, it includes: first, writing the authentication record and terminal identifier digest into the corresponding fields one by one according to the preset payload field template, and then encoding the set of fields into a structured data string in a fixed order.
[0027] After the payload field is fixed, the roaming token issuance module performs signature calculation on the payload field, generates a signature field, and combines the signature field with the payload field to form a complete roaming token.
[0028] The roaming token issuance module performs signature calculations on the payload field to generate a signature field, and combines the signature field with the payload field to form a complete roaming token. This includes: after the payload field is fixed, the roaming token issuance module first normalizes and encodes the payload field according to preset serialization rules to ensure that the same set of fields produces a consistent byte sequence when implemented in different software and hardware environments; then, it performs a digest operation on the byte sequence to generate a message digest value, and calls a preset signature key to perform a digital signature operation on the message digest value to obtain a signature result as the signature field. After generating the signature field, a predefined token encapsulation specification stipulates that the roaming token is organized and parsed in the order of "header field - payload field - signature field". This determines that the logical structure of the roaming token consists of "header field, payload field, and signature field" in sequence. The header field identifies the signature algorithm used, the token version number, and the key identifier. The payload field is a fixed set of data including user identifier, terminal identifier digest, validity period start and end time, roaming range, policy version number, and random number. The signature field is the signature result calculated from the payload field. The roaming token issuance module performs standardized serialization encoding on the header field and payload field respectively, and concatenates the encoded header field, encoded payload field, and signature field into a continuous data string in sequence. Finally, the concatenated data string undergoes consistent character encoding for stable transmission during network transmission and terminal storage, resulting in a complete roaming token that can be parsed by the access gateway.
[0029] After completing the character encoding of the header field, payload field and signature field and suppressing them, in order to quantify the impact of the roaming range field in the payload field on the overall length of the roaming token as the size of the authorized attractions set changes, the length of each field of the token and the length after character encoding under different numbers of authorized attractions were statistically analyzed, and the results are shown in Table 1.
[0030] Table 1. Statistics on roaming token length under different roaming ranges.
[0031] Table 1 shows the trend of roaming token length changing with the size of the "roaming range field (authorized attraction set encoding)" when the payload field is fixed with a set of fields such as "user identifier, terminal identifier digest, validity period start and end time, roaming range, policy version number and random number" and then concatenated according to "header field - payload field - signature field" before character encoding and encapsulation. The statistical caliber is to keep the header field structure such as signature algorithm identifier / token version number / key identifier fixed, keep the signature field length fixed, and only change the number of attraction identifiers included in the roaming range, thus proving that "controllable roaming range written into the payload field" will not lead to uncontrollable token length.
[0032] The roaming token issuance module writes the authentication record and terminal identifier summary into the user data management module as a roaming token binding record, and establishes an association index between the binding record and the record item associated with the authentication record to realize the binding between the tourist terminal corresponding to the authentication record and the roaming token instance issued this time. After the binding record is successfully written, it is determined that the roaming token issuance is completed, and the complete roaming token is output as the usable roaming credential of the tourist terminal corresponding to the authentication record.
[0033] The central user management platform manages the roaming token's applicable attraction set through "roaming range management." After initial authentication based on the roaming token, the platform generates a corresponding authorized attraction set based on the tourist's selected route, affiliated scenic area group, and ticketing product permissions. This authorized attraction set is then written into the roaming range field of the roaming token in the form of an attraction identifier list and a route identifier mapping (the roaming range field refers to the data item in the roaming token's payload field, used to record the authorized attraction set determined by the central user management platform). During local rapid verification, each attraction access gateway, in addition to verifying the signature and validity period, further reads the roaming range field in the roaming token and matches it with the currently accessed attraction identifier. If the match is successful, access is granted directly without repeated authentication; if the match fails, access based on the roaming token is rejected, and the process is initiated for re-authentication. This achieves controllable roaming "without repeated authentication only within the authorized attraction set."
[0034] The process of generating a set of authorized attractions based on the tourist's selected route, scenic area group, and ticketing product permissions includes: After initial authentication, the central user management platform reads the order or benefit information associated with the user's identifier to determine the tourist's selected route identifier, scenic area group identifier, and ticketing product identifier. It then searches the configuration data maintained on the platform side for three types of mapping relationships: "Route Identifier → Attraction Identifier Set," "Scenic Area Group Identifier → Attraction Identifier Set," and "Ticketing Product Identifier → Attraction Identifier Set." The central user management platform synthesizes these three mapping relationships according to preset set operation rules. This synthesis includes at least a union to cover all attractions within the route, an intersection to limit attractions to those only authorized by ticketing, and a difference to remove temporarily closed or restricted attractions, thus obtaining the final set of authorized attractions. Finally, the central user management platform solidifies the set of authorized attractions into a roaming range code and writes it into a roaming token, enabling the access gateway to perform range matching and achieve controlled roaming.
[0035] The key management module is responsible for the unified management and distribution of keys or verification parameters used for roaming token signature verification. After the access gateway completes registration, the key management module distributes the verification keys or verification parameters used for signature verification to each access gateway through the established control signaling channel between the platform and the access gateway. Each distribution includes a key identifier and effective time information, enabling the access gateway to establish an index cache of the key identifier and the corresponding verification key locally. When the access gateway receives a roaming token carried by a visitor terminal, its local fast verification module selects a matching verification key based on the key identifier carried in the token header and performs signature verification on the token payload field and signature field to determine whether the token was issued by the authorized platform and has not been tampered with. The entire process does not require accessing the central user management platform each time. At the same time, the key management module performs key rotation according to a preset rotation cycle. During rotation, it distributes the parallel effective window and expiration time of the old and new keys to the access gateway to ensure that the issued tokens can still be verified locally during the transition period, balancing continuous access and long-term operational security.
[0036] In this embodiment, the policy management module of the central user management platform centrally manages access policies using a "policy version number - policy template" approach: the central user management platform assigns a unique policy version number to each executable access policy and stores the corresponding policy template using this policy version number as an index key. The policy template includes at least the upper limit of access duration, the upper limit of uplink bandwidth, the upper limit of downlink bandwidth, the upper limit of concurrent connections, blacklist rules, and access control rules. The blacklist rules describe the set of user identifiers, terminal identifiers, or token identifiers that are prohibited from accessing the network, while the access control rules describe the scope of accessible network resources or access restrictions. When a tourist terminal completes local fast verification and is allowed access at a scenic spot's access gateway using a roaming token, the policy execution module on the access gateway side reads the policy version number from the token payload field and locates the matching policy template in the local policy cache. The terminal implements resource control and access control for its sessions. Specifically, it time-tracks access duration and triggers disconnection or re-authentication when the limit is reached, limits uplink and downlink bandwidth, and imposes threshold constraints on the number of concurrent connections, rejecting new connections when the limit is exceeded. It also blocks or allows access based on blacklist rules and access control rules. To prevent policy drift due to differences in operation and maintenance configurations among different attractions, when the access gateway finds that the local policy version number is inconsistent with the policy version number in the token, the access gateway uses this version difference as a trigger condition to request a policy template with the corresponding policy version number from the central user management platform. After receiving the template, it verifies the integrity and version consistency. If the verification passes, the local policy cache is updated and access is allowed according to the new template. If the verification fails, it enters a restricted mode to execute a stricter basic policy or trigger re-authentication, thereby ensuring policy consistency across attractions and avoiding inconsistencies in experience and security.
[0037] To meet security governance and compliance requirements, this embodiment sets up a token revocation and renewal module on the central user management platform side. When the central user management platform detects that a revocation condition has been triggered, the token revocation and renewal module generates revocation information and synchronizes it to the access gateways of each attraction. The revocation information is distributed in the form of a revocation list or a revocation increment. The revocation list provides a set of currently expired token identifiers or user identifiers, while the revocation increment adds or updates revocation records to the existing revocation list to improve distribution efficiency. Figure 3As shown, by comparing the changes in the amount of data distributed under different numbers of revocation record entries on the two line graphs ("revocation list" and "revocation increment"), it can be seen that when the size of the revocation record increases, the distribution overhead of the complete revocation list increases approximately linearly with the number of entries, and the data volume grows faster; while the revocation increment only carries newly added or changed revocation records, and its overall data volume is significantly lower than that of the revocation list and grows more slowly. This shows that the "revocation increment" mechanism can effectively reduce the control plane distribution load and improve the efficiency of revocation information synchronization in large-scale revocation scenarios, and is more conducive to the access gateway to obtain the revocation status in a timely manner for local comparison and processing. During the local fast verification phase, each access gateway verifies not only the token signature, validity period, and consistency with the terminal binding, but also matches revocation information. Specifically, it compares the token identifier or user identifier in the current token payload with the locally cached revocation list. If a revocation is found, access is denied and the revocation result is recorded. Furthermore, online sessions are disconnected for immediate blocking if necessary. On the other hand, when a roaming token is about to expire and the user is still in a serviceable state, the platform's revocation and renewal module generates a renewal token and updates the validity period start and end times. Simultaneously, the policy version number can be updated according to the current policy governance needs, binding the renewal token to the new version policy template. This extends the available access time during the tour without requiring tourists to re-authenticate, while maintaining policy consistency and controllable upgrades across attractions. The revocation conditions refer to a set of judgment conditions triggered when the central user management platform determines, based on unified audit logs, policy rules, and security risk control criteria, that a roaming token or its corresponding terminal no longer meets the security or compliance requirements for continued access without duplicate authentication. Specifically, these conditions may include: abnormally high frequency of cross-scenic spot roaming by the same user identifier or the same terminal identifier within a set time window (reflecting possible token sharing, script-based connection manipulation, or abnormal behavior); abnormal binding relationships where the same user identifier corresponds to multiple terminal identifiers or the same terminal identifier corresponds to multiple user identifiers within a short period of time (reflecting account lending or identity forgery risks); abnormal events such as access failure, signature failure, and anti-replay hits reported by the access gateway reaching a threshold (reflecting that the token may have been tampered with or replayed); hitting blacklist rules or access control rules (such as being complained about, restricted by regulatory requirements, or identified as an attack source); and changes in operational-side permissions such as ticketing product permissions becoming invalid or temporary control of lines or scenic spots leading to changes in roaming range. When any of the revocation conditions is met, the platform generates revocation information and sends it to each access gateway to prevent the token from being used for cross-scenic spot access without duplicate authentication.
[0038] Furthermore, when a tourist terminal switches from a scenic spot that has completed its initial authentication to another scenic spot and accesses the scenic spot's wireless network, the token acquisition module of the access gateway obtains a roaming token in the access session in which the terminal initiates an internet access request. The acquisition method can be to read the token from the data carried by the terminal, extract it from the token returned from the terminal's local cache, or match the corresponding token from the session cache already established on the access gateway side.
[0039] After obtaining the roaming token, the access gateway submits the roaming token to the local fast verification module. The local fast verification module performs multiple verifications on the token without triggering a duplicate authentication page: Integrity verification: Based on a preset verification key, the token signature field is verified to confirm that the token has not been tampered with and was issued by the authorized platform; Validity verification: The start and end times of the validity period in the token payload are read and compared with the access gateway's trusted time to determine if the token is within an available period; Binding consistency verification: The terminal identifier or terminal identifier digest obtained from the current access session is compared with the terminal identifier digest in the token payload to confirm that the token is indeed bound to the current visitor's terminal. When all verifications pass, the local fast verification module outputs a release command to the access control module. The access control module then switches the terminal session from a pending authentication state to an authenticated and released state, thereby achieving convenient access across attractions without duplicate authentication.
[0040] The log feedback module records key events in a structured manner using a unified audit field set and sends them back to the central user management platform. These key events include at least initial authentication events, cross-scenic spot roaming events, access results, and revocation results. The unified audit field set includes at least the user identifier, terminal identifier or its summary, access scenic spot identifier, access gateway identifier, token identifier, event type, policy version number, timestamp, and revocation result identifier. When an event occurs, the log feedback module writes these fields into a log record of the same format and uploads it through the control signaling channel. After receiving the logs, the central user management platform aggregates and associates them according to the unified fields, linking authentication, roaming, access, and revocation records of the same user identifier or the same token identifier across different scenic spots into a cross-scenic spot audit link. This provides a basis for the operations and maintenance side to locate access anomalies, analyze policy execution effects, handle temporal evidence in tourist complaints, and conduct security actions and tracing when risk or revocation conditions are met.
[0041] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0042] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A scenic area network management system, characterized in that, It includes a central user management platform and access gateways deployed at multiple attractions; the central user management platform is used for unified identity authentication, management of user data, roaming token issuance, key management, policy management, and token revocation and renewal; the access gateway is used to obtain and quickly verify the roaming token locally when tourists access across attractions, and to send the authentication and roaming events back to the central user management platform to achieve centralized auditing and revocation linkage. The roaming token issuance module built into the central user management platform receives the authentication record output by the unified identity authentication module, and reads the record item associated with the authentication record using the user identifier as the search key. It extracts the terminal identifier from the record item, performs a digest calculation on the terminal identifier, and generates a terminal identifier digest. The roaming token issuance module combines the authentication record and the terminal identifier digest into binding base data, constructs the payload field of the roaming token, performs a signature calculation on the payload field to generate a signature field, and combines the signature field and the payload field to form the roaming token. The roaming token issuance module writes the authentication record and the terminal identifier digest into the user data management module as a roaming token binding record, and establishes an association index between the binding record and the record item associated with the authentication record, thereby achieving the binding between the visitor terminal corresponding to the authentication record and the roaming token instance issued this time.
2. The scenic area network management system according to claim 1, characterized in that... The generation of the signature field, which combines the signature field and the payload field to form a roaming token, includes: after the payload field is fixed, the roaming token issuing module first encodes the payload field to ensure that the same set of fields generates a consistent byte sequence when implemented in different software and hardware environments; then, it performs a digest operation on the byte sequence to generate a message digest value; and performs a digital signature operation on the message digest value to obtain a signature result as the signature field; the roaming token is organized and parsed in the order of "header field - payload field - signature field", and the logical structure of the roaming token is determined to be composed of "header field, payload field, and signature field" in sequence; the roaming token issuing module performs normalized serialization encoding on the header field and the payload field respectively, and concatenates the encoded header field, the encoded payload field, and the signature field in sequence into a continuous data string; and performs consistent character encoding on the concatenated data string to obtain a complete roaming token.
3. The scenic area network management system according to claim 2, characterized in that... The central user management platform manages the roaming range to control the applicable attractions for the roaming token: After the initial authentication based on the roaming token is successful, the central user management platform generates a corresponding set of authorized attractions based on the tourist's selected route, scenic area group, and ticketing product permissions, and writes the set of authorized attractions into the roaming range field of the roaming token in the form of an attraction identifier list and a route identifier mapping; When each attraction access gateway performs local fast verification, in addition to verifying the signature and validity period, it reads the roaming range field in the roaming token and matches it with the currently accessed attraction identifier. If the match is successful, access is granted and repeated authentication is waived; if the match is unsuccessful, access based on the roaming token is rejected and the process is initiated again.
4. The scenic area network management system according to claim 3, characterized in that, The process of generating a set of authorized attractions based on the tourist's selected route, scenic area group, and ticketing product permissions includes: After initial authentication, the central user management platform reads the order or benefit information associated with the user's identifier, determines the tourist's selected route identifier, scenic area group identifier, and ticketing product identifier, and searches for three types of mapping relationships in the configuration data maintained on the central user management platform side: the mapping relationship between the route identifier and the set of attraction identifiers, the mapping relationship between the scenic area group identifier and the set of attraction identifiers, and the mapping relationship between the ticketing product identifier and the set of attraction identifiers; the central user management platform synthesizes the above three types of mapping relationships according to preset set operation rules. The synthesis includes at least a union to cover all attractions within the route, an intersection to limit attractions to those only authorized by ticketing, and a difference to remove temporarily closed or restricted attractions, thus obtaining the set of authorized attractions.
5. The scenic area network management system according to claim 1, characterized in that... The central user management platform includes a unified identity authentication module, a user data management module, a roaming token issuance module, a key management module, a policy management module, and a token revocation and renewal module; the access gateway includes an access control module, a token acquisition module, a local fast verification module, a policy execution module, and a log feedback module.
6. The scenic area network management system according to claim 5, characterized in that... When a tourist terminal first accesses the network, the access gateway generates and forwards an authentication request message to the unified identity authentication module. The basic information carried in the authentication request message includes at least the access gateway identifier, the access attraction identifier, the access point identifier, the terminal identifier, and a timestamp. The unified identity authentication module performs identity verification according to a preset authentication method and generates the authentication record. The preset authentication method includes at least one of SMS verification code verification, third-party account authorization login, and ticket order information verification.
7. The scenic area network management system according to claim 6, characterized in that... The terminal identifier is one of the following: terminal MAC address, 802.1X identifier, or identifier digest calculated from terminal fingerprint.
8. The scenic area network management system according to claim 5, characterized in that... After the access gateway completes registration and access, the key management module sends a verification key or verification parameter along with a key identifier and effective time information to the access gateway through the control signaling channel between the platform and the access gateway. This enables the access gateway to establish an index cache of the key identifier and verification key. The key management module performs key rotation according to a preset rotation cycle and sends out a parallel effective window and expiration time for the new and old keys to ensure that the issued roaming tokens can be locally verified during the transition period.
9. The scenic area network management system according to claim 5, characterized in that... The policy management module centrally manages access policies using policy version numbers and policy templates. The policy template includes at least the upper limit of access duration, the upper limit of uplink bandwidth, the upper limit of downlink bandwidth, the upper limit of concurrent connections, blacklist rules, and access control rules. After allowing access, the policy execution module of the access gateway reads the policy version number in the payload field of the roaming token and locates the matching policy template in the local policy cache to implement timed disconnection or re-authentication, rate limiting control, concurrent threshold constraints, and blacklist blocking or access control. When the access gateway finds that the local policy version number is inconsistent with the policy version number in the roaming token, it requests the policy template with the corresponding policy version number from the central user management platform and updates the local policy cache after verifying the integrity and version consistency of the template.
10. The scenic area network management system according to claim 1, characterized in that... When the token revocation and renewal module detects a revocation condition, it generates revocation information and distributes it to each access gateway in the form of a revocation list or revocation increment. During the local fast verification phase, in addition to verifying the signature, validity period, terminal binding consistency and roaming range, the access gateway also compares the token identifier or user identifier in the roaming token payload with the locally cached revocation list. If a revocation is found, the gateway refuses to allow access, records the revocation processing result, and disconnects the online session to achieve immediate blocking.