Network access method, device, equipment and program product
By simulating the authentication server's response to authentication requests through network control equipment and generating temporary authentication entries, the problem of manual access for new users when the authentication server is abnormal is solved, thus achieving automation and continuity of network access.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XINHUASAN INFORMATION TECH CO LTD
- Filing Date
- 2026-01-30
- Publication Date
- 2026-05-05
AI Technical Summary
When the authentication server malfunctions, existing technology requires manually connecting new users to the network access device, resulting in a large workload and affecting the continuity of network access.
After the authentication server malfunctions, the network control device controls the network access device to continue providing wireless access services for the original SSID, simulates the authentication server's response to authentication request messages, generates temporary authentication entries, and allows the terminal to go online and access the network until the authentication server returns to normal.
This feature enables new users to automatically connect to the network in the event of an authentication server malfunction, avoiding manual operation, ensuring the continuity and security of network access, and improving the user experience.
Smart Images

Figure CN121984751A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a network access method, apparatus, device, and program product. Background Technology
[0002] In networking applications, when an authentication server, such as a Remote Authentication Dial-In User Service (RADIUS) server, malfunctions or becomes unreachable, it's necessary to manually connect a new user to the network access device upon their arrival. This involves manually selecting an access point (i.e., the access service identifier provided by the network control device or master / slave gateway) for the new user within a wireless network architecture. The same situation arises in Fiber to the Room (FTTR) scenarios where a manual connection to the network access device is required when the authentication server malfunctions. Summary of the Invention
[0003] This application provides a network access method, apparatus, device, and program product to avoid problems such as large workload caused by manually connecting new users to the network access device after the authentication server malfunctions.
[0004] This application provides a network access method, which is applied to a network control device, and the method includes: If an anomaly is detected in the authentication server, then: Control the connected network access devices to continue providing wireless access services according to the original access service identifier (SSID) so that the authenticated online terminals remain online; Receive authentication request messages for terminal authentication forwarded by network access devices; the authentication request message is generated based on the login information entered by the newly added terminal when it needs to access the network; or, it is generated based on the login information of the terminal that has been authenticated and disconnected after the authentication server malfunctions and needs to reconnect. It prohibits sending access request messages corresponding to authentication request messages to the authentication server; it simulates the authentication server returning response messages corresponding to authentication request messages to the terminal, so that the terminal can go online and access the network.
[0005] Optionally, controlling the connected network access devices to continue providing wireless access services according to the original Access Service Identifier (SSID) includes: Send a notification to the connected network access device to instruct it to continue providing wireless access service according to the original Access Service Identifier (SSID); or, Sending SSID switching notifications to connected network access devices is prohibited. SSID switching notifications are used to instruct network access devices to switch their original access service identifier (SSID) to provide wireless access services through the switched SSID.
[0006] Optionally, the response message returned to the terminal corresponding to the authentication request message includes: Based on the login information carried in the authentication request message, the simulated authentication server sends an authentication success message to the terminal in response to the authentication request message; or, Record the username carried in the authentication request message, and simulate the authentication server to generate a key and send it to the terminal, so that the terminal can use the key to encrypt the password corresponding to the username to obtain ciphertext and send it to the network control device; The system receives ciphertext sent by the terminal, decrypts the ciphertext using a key, and simulates an authentication server sending an authentication success message to the terminal.
[0007] Optionally, the response message returned by the simulated authentication server to the terminal corresponding to the authentication request message further includes: A temporary authentication entry corresponding to the terminal is generated, and the authentication information in the temporary authentication entry is sent to the network access device. The authentication information is used by the network access device to authenticate the terminal.
[0008] Optionally, the response message returned by the simulated authentication server to the terminal corresponding to the authentication request message further includes: A temporary authentication entry corresponding to the terminal is generated, and the authentication information in the temporary authentication entry is sent to the network access device. The authentication information is used by the network access device to authenticate the terminal.
[0009] Optionally, the method further includes: After the authentication server recovers from the anomaly, the online target terminals that came online after the authentication server anomaly and have registered with the authentication server are identified. For each online target terminal, negotiate with the authentication server whether to allow the online target terminal to continue online; if yes, allow the online target terminal to continue network access; otherwise, control the online target terminal to go offline.
[0010] Optionally, negotiating with the authentication server whether to allow the online target terminal to remain online includes: The login information of the online target terminal is sent to the authentication server for authentication. If authentication is successful, the online target terminal is allowed to continue online; otherwise, it is prohibited from continuing online. The system sends the username from the login information of the target online terminal to the authentication server, receives the key returned by the authentication server, encrypts the password of the corresponding username using the key to obtain ciphertext, and sends it to the authentication server so that the authentication server can authenticate the password based on the ciphertext. If the authentication is successful, the target online terminal is allowed to continue online; otherwise, the target online terminal is prohibited from continuing online.
[0011] Optionally, when allowing the online target terminal to continue online, the method further includes: modifying the temporary authentication entry corresponding to the online target terminal into a formal authentication entry; When prohibiting the target online terminal from continuing to be online, the method further includes: deleting the temporary table entry corresponding to the target online terminal.
[0012] This application provides a network access device, which is applied to a network control device, and the device includes: If an anomaly is detected in the authentication server, then: The control module is configured to control the connected network access devices to continue providing wireless access services according to the original access service identifier (SSID), so that the authenticated online terminals remain online; The receiving module is configured to receive authentication request messages for terminal authentication forwarded by the network access device; the authentication request message is generated based on the login information entered by the newly added terminal when it needs to access the network; or, it is generated based on the login information of the terminal that has been authenticated and disconnected after the authentication server malfunctions and needs to reconnect. The return module is configured to prevent the sending of access request messages corresponding to the authentication request messages to the authentication server; it simulates the authentication server returning response messages corresponding to the authentication request messages to the terminal, so that the terminal can go online and access the network.
[0013] This application provides a computer program product, including a computer program that, when executed by a processor, implements the network access method described above.
[0014] This application provides a server, including: a processor and a machine-readable storage medium, the machine-readable storage medium storing machine-executable instructions that can be executed by the processor; wherein, the processor is used to execute the machine-executable instructions to implement the above-described network access method.
[0015] This application provides a machine-readable storage medium storing machine-executable instructions that can be executed by a processor; wherein the processor executes the machine-executable instructions to implement the network access method described above.
[0016] As can be seen from the above technical solution, in this embodiment, after the authentication server malfunctions, the network control device controls the network access device to continue providing network access services with the original SSID, so that the authenticated online terminals remain online. When a terminal, such as a terminal that drops out after the authentication server malfunctions, or a new terminal connects to the network access device, the control device can replace the authentication server to authenticate the terminal, ensuring that the terminal can access the network normally even when the authentication server is malfunctioning. This achieves automatic access to the network access device for new users after the authentication server malfunctions, avoiding problems such as large workload caused by manually connecting new users to the network access device after the authentication server malfunctions. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating a network access method provided in some embodiments of this application; Figure 2 This is a schematic diagram of the network access process provided in some embodiments of this application; Figure 3 This is a schematic diagram of the structure of a network access device provided in some embodiments of this application; Figure 4 These are hardware structure diagrams of electronic devices provided in some embodiments of this application. Detailed Implementation
[0018] The network access method of this application will be described below with reference to specific embodiments. See also Figure 1 The diagram shown is a flowchart of a network access method in an embodiment of this application. The method may include: After detecting an anomaly in the authentication server, perform the following steps: Step 101: Control the connected network access devices to continue providing wireless access services according to the original access service identifier (SSID) so that the authenticated online terminals remain online.
[0019] Before the authentication server malfunctions, the network access device will broadcast the SSID currently used for network access in the network, such as SSID100, so that terminals can connect to the network access device through the SSID to obtain network services. In this embodiment, the network access device can be a network access point in a wireless network architecture or a master gateway or slave gateway in an FTTR architecture.
[0020] Here, an authentication server malfunction could be due to a fault in the authentication server itself, the authentication server being currently silent, or the authentication server being unreachable. In this embodiment, after an authentication server malfunctions, the network control device will no longer instruct the network access device to hide the original Access Service Identifier (SSID) to ensure that the previously authenticated online terminals remain online.
[0021] Step 102: Receive the authentication request message for terminal authentication forwarded by the network access device; the authentication request message is generated based on the login information entered by the newly added terminal when it needs to access the network; or, it is generated based on the login information of the terminal that has been authenticated and disconnected after the authentication server malfunctions and needs to reconnect.
[0022] When a terminal disconnects due to an authentication server malfunction, or when a newly added terminal accesses the wireless network, it can send an authentication request message to the network access device. For example, for a newly added terminal, an authentication request message can be generated based on the login information entered by the user in the authentication window when accessing the network. For a disconnected terminal, an authentication request message can be generated based on the terminal's login information stored in the network access device.
[0023] Step 103: Prevent the sending of access request messages corresponding to the authentication request messages to the authentication server; return the response message corresponding to the authentication request message to the terminal that initiated the authentication request message, so that the terminal that initiated the authentication request message can go online and access the network.
[0024] When the authentication server is functioning normally, the network control device can encapsulate the login information and its own identifier carried in the received authentication request message into a RADIUS access request message (ACCESS-Accept) and send the access request message to the remote RADIUS server. If the authentication server malfunctions, the network control device will no longer forward terminal authentication messages to the authentication server. In some embodiments, the network control device can be prohibited from sending authentication request messages to the RADIUS authentication server to reduce computational resource overhead and prevent access request message transmission failures from affecting the normal operation of the network control device.
[0025] The response message is a success message for the authentication request message. Upon receiving the authentication request message, the network control device no longer waits for instructions from the RADIUS authentication server but directly sends an authentication success message to the terminal. Simultaneously, the network control device can generate a temporary authentication entry corresponding to the terminal based on the login information carried in the authentication request. The login information may include the user's identity identifier (e.g., username), a password matching the user's identity identifier, or the terminal's login certificate. For example, if the authentication method is CHAP or PAP, the login information may include the username and a password matching the username. If the authentication method is EAP, the login information may only include the username.
[0026] Network control devices can generate temporary authentication entries based on obtained username information, password, and corresponding network access permissions. These temporary authentication entries serve as the terminal's identity authentication, and may include the terminal's network access information, network access permissions, and address. Terminals can access wireless network services based on these temporary authentication entries. The network control device can send information related to the temporary authentication entries to the network access device, facilitating the retrieval of the corresponding temporary authentication entry from the network control device when a terminal accesses the wireless network. Network access permissions indicate the scope of content a user accessing the wireless network through a given terminal can view or the services they can use. After accessing the network via the wireless escape service, users can only view content within their authorized scope to enhance security and prevent data leakage.
[0027] During a RADIUS authentication server outage, the network control device can record each terminal accessing the wireless network via the wireless escape service, along with the username and password for each terminal. Upon detecting that the RADIUS authentication server has recovered, the network control device can retrieve full user information with network access permissions via the Lightweight Directory Access Protocol (Light LDAP sync protocol). Subsequently, based on this full user information, terminals with network access permissions are identified from newly added terminals and those that have lost connection. The usernames corresponding to these terminals are included in the full user information. This process effectively filters out users without network access permissions.
[0028] For each terminal with network access, the network control device generates a RADIUS access request message based on the terminal's stored username and password. This message is then sent to the authentication server. The authentication server parses the access request message to obtain the terminal's username and password and verifies them against its stored user information. If verification passes, the server sends an authentication success message to the network control device. If verification fails, the server sends an authentication failure message to the network control device.
[0029] After receiving an access response message from the authentication server in response to an access request message, the network control device will, if the access response message indicates that the login information has failed authentication, disconnect the terminal from the wireless network, disconnect the terminal, and delete the terminal's temporary authentication entry. If the access response message indicates that the login information has passed authentication, maintain the terminal's connection to the wireless network and convert the terminal's temporary authentication entry into a formal authentication entry.
[0030] The network access method provided in this application will be described below with reference to specific embodiments.
[0031] Example 1: Wireless Escape in Case of Authentication Server Failure In a wireless communication environment, if the network control device detects that the RADIUS authentication server is unavailable or unreachable, it will activate the wireless escape service. This service will continue to provide wireless access based on the original Access Service Identifier (SSID) to keep authenticated online terminals online. For terminals that disconnect after the wireless escape service is activated, or for newly connected terminals, network access will be provided via the wireless escape service.
[0032] The network control device can send a RADIUS Echo-Request message to the RADIUS server at fixed intervals (e.g., 3-6 seconds) to check if the RADIUS server is online. If no response message is received from the RADIUS server multiple times, the RADIUS server is determined to be unavailable. Furthermore, if the RADIUS server is detected to have repeatedly failed to respond to service messages (e.g., Access-Request messages) sent by the network control device, the RADIUS server is also determined to be unavailable. After enabling the wireless escape service, if an authentication request message is received, a response message can be generated based on the login information carried in the authentication request message, enabling the terminal that initiated the authentication request message to access the network.
[0033] 802.1x authentication methods include EAP, CHAP, and PAP. The login information carried in the authentication request message differs depending on the authentication method, and the process for generating the response message also varies.
[0034] For example, under CHAP or PAP authentication methods, the terminal uploads the username, password, etc., to the network control device via EAP messages. The network control device then repackages these into RADIUS messages and sends them to the authentication service for authentication. When the network control device detects that the RADIUS authentication server is unavailable or unreachable, it saves the received username, password, etc., locally and generates a temporary authentication entry. It then directly replies to the terminal with the EAP-Success field as a response message to the authentication request, enabling the terminal to successfully connect and access network resources.
[0035] In EAP authentication mode, when the network control device receives a connection request from a user terminal, it sends an EAP-Request / Identity message to the user terminal requesting the username. The user terminal then replies with an EAP-Response / Identity message to send its username information to the network control device. Therefore, in EAP authentication mode, the login information only includes the username.
[0036] After receiving the authentication request message, the network control device records the username information and generates an MD5 Challenge encryption key for the terminal, sending this key to the terminal. The encryption key can be randomly generated or generated based on the username information; no limitation is made here. The terminal can use this encryption key to encrypt the password matching the username information and generate an EAP-Response / MD5 Challenge message based on the encrypted password. Upon receiving the EAP-Response / MD5 Challenge message, the network control device parses the message using the encryption key to obtain and record the password matching the username information. Subsequently, the network control device generates a temporary authentication entry based on the username information, password, and network access permissions corresponding to the user.
[0037] The user terminal encrypts its own password using the MD5 Challenge to generate an EAP-Response / MD5 Challenge message, which is then sent to the network control device. The network control device parses the encrypted password using the MD5 Challenge, obtains the user's password, and records it. Subsequently, the network control device directly replies to the terminal with an EAP-Success message, while simultaneously generating a temporary authentication entry, allowing the terminal to connect online and access network resources normally.
[0038] Example 2: Re-authentication after the authentication server recovers After the authentication server recovers, the terminals that can access the network include the following two types: terminals that have been authenticated by the authentication server (i.e., terminals that were authenticated before the authentication server malfunctioned) and client terminals that have not been authenticated by the authentication server (i.e., terminals newly added after the authentication server malfunctioned and terminals that went offline after the authentication server malfunctioned). When the network control device detects that the authentication server has recovered, it disables the wireless escape service and re-authenticates the terminals that accessed the network during the authentication server malfunction period.
[0039] The authentication server can first use the LDAP sync protocol to collect all user information (i.e., the identity information of all users allowed to access the network). For each newly added or disconnected terminal, if the full user information includes the username information corresponding to the terminal, then the terminal is determined to have network access rights. If the full user information does not include the username information corresponding to the terminal, then the terminal's connection to the wireless network is disconnected.
[0040] For a terminal with network access, re-authentication can be performed using a RADIUS authentication server based on the recorded username and password. For example, if the authentication method is CHAP or PAP, the network control device can directly generate a RADIUS access request message based on the recorded username and password. This access request message is then sent to the RADIUS authentication server for verification. If an access response message ACCESS-Accept with a Success field is received from the authentication server, it indicates that the username and password are correct. The network control device can maintain the connection between the terminal and the wireless network and convert the terminal's corresponding temporary authentication entry into a formal authentication entry. For example, the temporary identifier in the temporary authentication entry can be deleted to obtain the formal authentication entry. This allows for switching between normal network connection and wireless escape without manual switching or login information input by the user. Furthermore, no further negotiation is required, ensuring that the connection between the terminal and the wireless network remains unaffected.
[0041] If an access response message ACCESS-Accept with a Fail field is received from the authentication server, it indicates that the username and password are incorrect. The network control device can disconnect the terminal from the wireless network and delete the corresponding temporary authentication entry for the terminal.
[0042] In some embodiments, the network control device can encapsulate the different identity information of multiple terminals into a single RADIUS access request message to authenticate the different identity information. This reduces the number of communications and improves terminal authentication efficiency.
[0043] When the authentication method is EAP, the network control device first sends the username information to the authentication server via an Access-Request (Identity) message. The authentication server verifies the username, finds the corresponding password, encrypts the password using a randomly generated MD5 Challenge, and sends this MD5 Challenge to the terminal via a RADIUS Access-Challenge message. Upon receiving the MD5 Challenge, the terminal encrypts its password using the Challenge and sends the encrypted password to the network control device. The network control device encapsulates the encrypted password in a RADIUS Access-Request message and sends it to the authentication server. The RADIUS authentication server compares the received encrypted password with its locally encrypted password. If they match, the user is considered legitimate, and the server sends an authentication pass message (RADIUSAccess-Accept) to the network control device. Upon receiving the authentication pass message carrying the Success field, the network control device converts the terminal's temporary authentication entry into a formal authentication entry and maintains the terminal's online status. If the Access-Accept message carries a Fail field, the network control device disconnects the terminal from the wireless network and deletes the temporary authentication entry corresponding to the terminal.
[0044] The solution provided in this application can be applied to an AC+FIT AP wireless network architecture or an FTTR network architecture. For example, in an AC+FIT AP architecture, the network access device can be a network access point (AP), and the network control device can be an access controller (AC). Figure 2 This is a schematic diagram of a wireless network architecture provided in an embodiment of this application. Figure 2 As shown, the wireless network architecture includes terminal 210, AP220, AC230 and authentication server 240.
[0045] In such Figure 2 In the wireless network architecture shown, AP220 broadcasts the SSID. After searching for and identifying the SSID, terminal 210 (STA) sends a connection request to AP220. Upon receiving the connection request, AP220 negotiates with the user terminal to determine the encryption method and completes the basic link encryption handshake.
[0046] After negotiation, user terminal 210 establishes a "temporary wireless link" with AP220. At this time, the terminal can only transmit authentication-related messages and cannot access the intranet / Internet, remaining in an "unauthenticated and unauthorized state." If AP220 detects that the user terminal is in an "unauthenticated state," it forwards the terminal's authentication request message (including the terminal's MAC address and SSID information) to AC230 through the "CAPWAP control tunnel."
[0047] AC230 confirms that the SSID is bound to 802.1X authentication and sends a "request terminal to submit identity information" command to AP220. AP220 then transmits the command to the terminal. The user terminal displays an authentication window, where the user enters their username and password. The user terminal then sends the encrypted identity information to AC230 via the AP220 and CAPWAP tunnel.
[0048] AC230 determines the operating status of the authentication server by detecting the message. If the authentication server 240 is detected to be faulty or in a silent state, AC230 will no longer send authentication request messages to the authentication server 240. After receiving the login information sent by terminal 210 through AP220, AC230 saves the login information locally, generates an authentication response message based on the received identity information, and sends it to AP220 to allow terminal 210 to access the wireless network through AP220.
[0049] After the authentication server returns to normal, the AC uploads the stored login information to the authentication server 240, so that the authentication server 240 can authenticate each terminal and disconnect unauthenticated terminals.
[0050] Similarly, in the FTTR architecture, the network access device can be a master gateway or a slave gateway, and the network control device can be a controller, in order to implement the above network access scheme.
[0051] As can be seen, the solution provided in this application, on the one hand, enables the terminal to access the network through a temporary authentication entry after the authentication server malfunctions, thus achieving wireless escape. On the other hand, after detecting an malfunction of the authentication server, the network access device maintains its original wireless access service and access service identifier (SSID) to ensure that authenticated online terminals remain online. Therefore, wireless escape is achieved without switching Wi-Fi connections, preventing network disconnection for authenticated online terminals. Furthermore, during the wireless escape, username and password information are recorded so that authentication can be completed using the recorded information after the authentication server recovers, eliminating the need for the terminal to re-initiate authentication. This achieves a seamless switch between normal network service and escape service, improving the user experience.
[0052] Based on the same concept as the methods described above, this application proposes a network access device. See also... Figure 3 The diagram shown is a structural schematic of a network access device, which may include: The maintenance module 31 is configured to maintain the wireless access service provided by the connected network access device according to the original access service identifier (SSID) after detecting an anomaly in the authentication server, so as to keep the authenticated online terminals online.
[0053] The receiving module 32 is configured to receive an authentication request message for terminal authentication forwarded by the network access device; the authentication request message is generated based on the login information entered by the newly added terminal when it needs to access the network; or, it is generated based on the login information of the terminal that has been authenticated and has been disconnected after the authentication server malfunctions and needs to reconnect.
[0054] Return module 33 is configured to prohibit sending access request messages corresponding to the authentication request message to the authentication server; and to return response messages corresponding to the authentication request message to the terminal that initiated the authentication request message, so that the terminal that initiated the authentication request message can go online and access the network.
[0055] Optionally, the return module is also configured to generate a temporary authentication entry corresponding to the terminal that initiated the authentication request message based on the login information carried in the authentication request message; and send an authentication success message EAP-Success and information related to the temporary authentication entry to the terminal that initiated the authentication request message.
[0056] Optionally, the return module is also configured to record login information and generate temporary authentication entries based on the username, password, and network access permissions corresponding to the username.
[0057] Optionally, the login information includes username information; the return module is also configured to generate an encryption key MD5Challenge and send the encryption key to the terminal that initiated the authentication request message to obtain the password sent by the terminal that matches the username information; the password is encrypted using the encryption key; the username information and password are recorded, and a temporary authentication entry is generated based on the username information, password and network access permissions corresponding to the username information.
[0058] Optionally, the network access device also includes a permission determination module, which is configured to obtain full user information with network access permissions through the Lightweight Directory Access Protocol (LDP) and the LDAP sync protocol after detecting that the authentication server has recovered; based on the full user information, determine the terminals with network access permissions from newly added terminals and disconnected terminals; and include the usernames corresponding to the terminals with network access permissions in the full user information.
[0059] Optionally, the network access device also includes a re-authentication module, which is configured to generate an access request message for each terminal with network access rights based on the recorded username and password of the terminal, and send the access request message to the authentication server; receive an access response message from the authentication server in response to the access request message; and disconnect the terminal from the wireless network if the access response message indicates that the login information has not been authenticated.
[0060] Optionally, the network access device further includes an authentication entry update module, which is configured to maintain the connection between the terminal and the wireless network and generate a formal authentication entry based on the terminal's temporary authentication entry if the access response message indicates that the login information has passed authentication; and to delete the terminal's temporary authentication entry if the access response message indicates that the login information has failed authentication.
[0061] Based on the same concept as the above method, this application proposes an electronic device, see [link to previous application]. Figure 4 As shown, the electronic device includes a processor 41 and a machine-readable storage medium 42, the machine-readable storage medium 42 storing machine-executable instructions that can be executed by the processor 41; the processor 41 is used to execute the machine-executable instructions to implement the above-described network access method.
[0062] Based on the same concept as the above method, this application embodiment also provides a machine-readable storage medium storing a plurality of computer instructions, which, when executed by a processor, can implement the network access method disclosed in the above example of this application.
[0063] The aforementioned machine-readable storage medium can be any electronic, magnetic, optical, or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, machine-readable storage media can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or combinations thereof.
[0064] Based on the same application concept as the above method, this application embodiment also provides a computer program product, including a computer program, which implements the above network access method when executed by a processor.
[0065] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, embodiments of this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0066] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A network access method, characterized in that, This method is applied to network control devices, and the method includes: If an anomaly is detected in the authentication server, then: Control the connected network access devices to continue providing wireless access services according to the original access service identifier (SSID) so that the authenticated online terminals remain online; The system receives an authentication request message for terminal authentication forwarded by the network access device. The authentication request message is generated based on the login information entered by the newly added terminal when it needs to access the network; or, it is generated based on the login information of the terminal that has been authenticated and disconnected after the authentication server malfunctions, when it needs to reconnect. The system prohibits sending access request messages corresponding to the authentication request message to the authentication server; it simulates the authentication server returning a response message corresponding to the authentication request message to the terminal, so that the terminal can go online and access the network.
2. The method according to claim 1, characterized in that, The control-connected network access device continues to provide wireless access services according to the original Access Service Identifier (SSID), including: Send a notification to the connected network access device to instruct it to continue providing wireless access service according to the original Access Service Identifier (SSID); or, Sending SSID switching notifications to connected network access devices is prohibited. The SSID switching notification is used to instruct the network access devices to switch their original access service identifier (SSID) to provide wireless access services through the switched SSID.
3. The method according to claim 1, characterized in that, The response message returned to the terminal corresponding to the authentication request message includes: Based on the login information carried in the authentication request message, the simulated authentication server sends an authentication success message to the terminal in response to the authentication request message; or... The username carried in the authentication request message is recorded, and a key is generated by simulating an authentication server and sent to the terminal, so that the terminal can use the key to encrypt the password corresponding to the username to obtain ciphertext and send it to the network control device; The system receives the ciphertext sent by the terminal, decrypts the ciphertext using the key, and simulates an authentication server sending an authentication success message to the terminal.
4. The method according to claim 1, characterized in that, The simulated authentication server returning the response message corresponding to the authentication request message to the terminal further includes: A temporary authentication entry corresponding to the terminal is generated, and the authentication information in the temporary authentication entry is sent to the network access device. The authentication information is used by the network access device to authenticate the terminal.
5. The method according to claim 1, characterized in that, The simulated authentication server returning the response message corresponding to the authentication request message to the terminal further includes: A temporary authentication entry corresponding to the terminal is generated, and the authentication information in the temporary authentication entry is sent to the network access device. The authentication information is used by the network access device to authenticate the terminal.
6. The method according to claim 1, characterized in that, The method further includes: After the authentication server recovers from the anomaly, the online target terminal that went online after the authentication server went online and has registered with the authentication server is identified. For each online target terminal, negotiate with the authentication server whether to allow the online target terminal to continue online; if yes, allow the online target terminal to continue network access; otherwise, control the online target terminal to go offline.
7. The method according to claim 6, characterized in that, The step of negotiating with the authentication server whether to allow the online target terminal to remain online includes: The login information of the online target terminal is sent to the authentication server for authentication. If authentication is successful, the online target terminal is allowed to continue online; otherwise, the online target terminal is prohibited from continuing online. The username from the login information of the online target terminal is sent to the authentication server. The key returned by the authentication server is received. The password corresponding to the username is encrypted using the key to obtain ciphertext, which is then sent to the authentication server. The authentication server authenticates the password based on the ciphertext. If the authentication is successful, the online target terminal is allowed to continue online; otherwise, the online target terminal is prohibited from continuing online.
8. The method according to any one of claims 6 or 7, characterized in that, When allowing the online target terminal to remain online, the method further includes: modifying the temporary authentication entry corresponding to the online target terminal into a formal authentication entry; When prohibiting the online target terminal from continuing to be online, the method further includes: deleting the temporary table entry corresponding to the online target terminal.
9. A network access device, characterized in that, This device is used in network control equipment, and the device includes: If an anomaly is detected in the authentication server, then: The control module is configured to control the connected network access devices to continue providing wireless access services according to the original access service identifier (SSID), so that the authenticated online terminals remain online; The receiving module is configured to receive an authentication request message for terminal authentication forwarded by the network access device; the authentication request message is generated based on the login information entered by the newly added terminal when it needs to access the network; or, it is generated based on the login information of the terminal that has been authenticated and disconnected after the authentication server malfunctions when it needs to reconnect. The return module is configured to prohibit sending access request messages corresponding to the authentication request message to the authentication server; and to simulate the authentication server returning a response message corresponding to the authentication request message to the terminal, so that the terminal can go online and access the network.
10. An electronic device, characterized in that, include: A processor and a machine-readable storage medium, the machine-readable storage medium storing machine-executable instructions that can be executed by the processor; The processor is configured to execute machine-executable instructions to implement the method of any one of claims 1-7.