Client-free authentication method and system based on network card firmware

By completing identity information encryption authentication and network address generation at the network card firmware layer, the problem of deployment complexity and low security caused by network access authentication relying on client software in the existing technology is solved, realizing automatic authentication access without client and improving security.

CN122027367APending Publication Date: 2026-05-12SUZHOU HONGCUNXINJIE TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUZHOU HONGCUNXINJIE TECH CO LTD
Filing Date
2026-04-14
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing technologies rely on client software for network access authentication, which leads to complex deployment and low security, making it difficult to guarantee the security of identity information and the reliability of access control.

Method used

By implementing identity information encryption authentication and network address generation at the network card firmware layer, a temporary network address is obtained using the network card firmware, the target identity information is obtained and encrypted, an authentication request is sent to the authentication server, and a formal network address is generated based on the authentication result, thus achieving automatic authentication access without the need for client software.

Benefits of technology

It enables network access without client software, simplifies the deployment process, and improves the security and reliability of network access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122027367A_ABST
    Figure CN122027367A_ABST
Patent Text Reader

Abstract

The invention discloses a client-free authentication method and system based on network card firmware, and relates to the technical field of information transmission, and the method comprises the steps: obtaining a temporary network address through firmware after a network card is powered on; obtaining target identity information of a target user; encrypting the target identity information to obtain a target authentication request, and sending the target authentication request to an authentication server; judging whether the target identity information passes verification or not based on the authentication server, if yes, generating target authentication success information, obtaining a target identity identifier of the target user, sending the target identity identifier to an address generation server, calling a preset address generation strategy, and generating a formal network address in combination with the target identity identifier; and the target user completes the access of the client device to the target network based on the formal network address. The technical problems that in the prior art, authentication depends on client software, deployment is complex, and safety is low are solved, and the technical effects that automatic authentication access can be achieved without a client, and safety is improved are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information transmission technology, and more specifically to a client-free authentication method and system based on network card firmware. Background Technology

[0002] In network access authentication, authentication software typically needs to be pre-installed on the client device. The operating system layer initiates authentication requests and interacts with the authentication server to complete network access control. However, this method relies on terminal environment configuration, making installation and maintenance cumbersome. It also suffers from poor compatibility across different operating systems or terminal types, increasing deployment and maintenance costs. Furthermore, since the authentication process is primarily software-based, it is vulnerable to tampering, bypassing, or malicious attacks, making it difficult to guarantee the security of identity information and the reliability of access control. Summary of the Invention

[0003] This application provides a client-free authentication method and system based on network card firmware, which addresses the technical problems of existing technologies that rely on client software for authentication, are complex to deploy, and have low security.

[0004] In view of the above problems, this application provides a client-free authentication method and system based on network card firmware.

[0005] The first aspect of this application provides a client-free authentication method based on network card firmware, the method comprising: After the network card is powered on, a temporary network address is obtained through the firmware; the target user's target identity information is obtained, wherein the target identity information refers to the identity information submitted by the target user when accessing the target network through a client device with the network card installed; the target identity information is encrypted through the firmware to obtain a target authentication request, and the target authentication request is sent to the authentication server; based on the authentication server, it is determined whether the target identity information has been verified successfully, and if the verification is successful, a target authentication success message is generated; based on the target authentication success message, the target user's target identity identifier is obtained, and the target identity identifier is sent to the address generation server; the address generation server retrieves a preset address generation strategy and generates a formal network address in combination with the target identity identifier; the target user completes the client device's access to the target network based on the formal network address.

[0006] A second aspect of this application provides a client-free authentication system based on network interface card firmware, the system comprising: The address acquisition module is used to acquire a temporary network address through the firmware after the network card is powered on; the identity information acquisition module is used to acquire the target user's target identity information, wherein the target identity information refers to the identity information submitted by the target user when accessing the target network through a client device with the network card installed; the encryption module is used to encrypt the target identity information through the firmware to obtain a target authentication request, and send the target authentication request to the authentication server; the verification module is used to determine whether the target identity information has been verified successfully based on the authentication server, and if the verification is successful, generate target authentication success information; the identifier sending module is used to acquire the target user's target identity identifier based on the target authentication success information, and send the target identity identifier to the address generation server; the network address generation module is used for the address generation server to retrieve a preset address generation strategy and generate a formal network address in combination with the target identity identifier; the access module is used for the target user to complete the client device's access to the target network based on the formal network address.

[0007] One or more technical solutions provided in this application have at least the following technical effects or advantages: When the network card is powered on, this application obtains a temporary network address through the firmware; obtains the target user's target identity information, wherein the target identity information refers to the identity information submitted by the target user when accessing the target network through a client device with the network card installed; encrypts the target identity information through the firmware to obtain a target authentication request, and sends the target authentication request to the authentication server; the authentication server determines whether the target identity information has been verified successfully, and if so, generates target authentication success information; obtains the target user's target identity identifier based on the target authentication success information, and sends the target identity identifier to the address generation server; the address generation server retrieves a preset address generation strategy and generates a formal network address based on the target identity identifier; the target user completes the client device's access to the target network based on the formal network address. This invention solves the technical problems of existing technologies that rely on client software for authentication, are complex to deploy, and have low security. By completing identity information encryption authentication and network address generation based on identity identifiers at the network card firmware layer, it achieves the technical effect of automatic authentication access without a client and improves security. Attached Figure Description

[0008] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0009] Figure 1 A schematic diagram of the client-free authentication method based on network card firmware provided in this application embodiment; Figure 2 This is a schematic diagram of the architecture of a client-free authentication system based on network card firmware provided in an embodiment of this application.

[0010] Explanation of reference numerals in the attached diagram: Address acquisition module 11, Identity information acquisition module 12, Encryption module 13, Verification module 14, Identifier sending module 15, Network address generation module 16, Access module 17. Detailed Implementation

[0011] This application provides a client-free authentication method and system based on network interface card (NIC) firmware. It addresses the technical problems of existing technologies that rely on client software for authentication, which are complex to deploy and have low security. By completing identity information encryption authentication and network address generation based on identity identifiers at the NIC firmware layer, it achieves the technical effect of automatic authentication access without a client and improves security.

[0012] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0013] It should be noted that any variation of the terms "comprising" and "having" is intended to cover non-exclusive inclusion, for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to such processes, methods, products, or devices.

[0014] Example 1, as Figure 1As shown, this application provides a client-free authentication method based on network interface card (NIC) firmware. This client-free authentication method is applied to a client-free authentication system based on NIC firmware, and the NIC firmware-based client-free authentication system is communicatively connected to a target network. The target network includes a NIC, an authentication server, and an address generation server. The NIC has built-in firmware. The client-free authentication method based on NIC firmware includes: Step S100: After the network card is powered on, a temporary network address is obtained through the firmware.

[0015] In this embodiment, when the network card is powered on, its built-in firmware is triggered to execute a network address initialization and acquisition process. The firmware is a control program pre-burned into the network card, used to complete network communication control without relying on the operating system. The acquisition process is implemented based on the Dynamic Host Configuration Protocol (DHCP). The firmware sends temporary address discovery and request messages to the address allocation node in the target network by calling a preset DHCP processing mechanism, and completes protocol interaction through link-layer broadcast. This allows the address allocation node to identify the device based on the network card's Media Access Control (MAC) address and return an address allocation response message. The firmware then parses the address allocation response message, extracts and obtains the temporary network address. This temporary network address is a transitional network address used to establish a basic communication connection before identity authentication is completed. It supports the initial network connectivity between the network card and the authentication server and address generation server, thereby providing a network layer communication identifier for subsequent identity authentication data interaction.

[0016] Step S200: Obtain the target user's target identity information, wherein the target identity information refers to the identity information submitted by the target user when accessing the target network through a client device with the network card installed.

[0017] In this embodiment, after obtaining a temporary network address through the firmware and establishing a preliminary communication connection between the network card and the target network, the target identity information acquisition process begins. The target user is the user accessing the target network through a client device equipped with a network card. The target identity information refers to the identity information submitted by the target user when accessing the target network through the client device, used to characterize the target user's identity and as the basis for subsequent authentication processing. Specifically, the firmware triggers the identity information acquisition process based on the established communication connection. Through data interaction between the network card and the client device, the client device enters an identity information submission state. The target user completes the input and submission of identity information on the client device, or the firmware retrieves pre-stored identity information from the client device, thus forming raw identity data. Subsequently, the firmware receives the raw identity data, organizes it, and determines the target user's target identity information.

[0018] Furthermore, in the method provided in the application embodiment, the network card has a built-in security element, obtains the target user's target identity information, and then further includes: The target identity information is encrypted at the hardware level using the security element.

[0019] In this embodiment, after the firmware acquires the target user's identity information, it enters a security element-based encryption process. The network interface card (NIC) has a built-in security element, a hardware unit integrated within the NIC, used for key storage and encryption operations to achieve data protection at the hardware level. Specifically, the firmware sends the target identity information to the security element through a preset hardware data interaction interface. The security element then performs encryption operations on the target identity information based on its internally stored encryption algorithm and key, thereby obtaining encrypted identity data. Hardware-level encryption means that the encryption process is completed within the security element; the target identity information undergoes encryption conversion within the security element and is output in ciphertext form.

[0020] Furthermore, the method provided in the application embodiments also includes: The authentication server and the security element perform two-way digital certificate verification.

[0021] In this embodiment of the application, after the security element completes the hardware-level encryption of the target identity information, the authentication server and the security element perform two-way digital certificate verification. The two-way digital certificate verification refers to the authentication server and the security element verifying each other's digital certificates during the establishment of a communication connection to confirm the authenticity and legality of the identities of the two communicating parties. The digital certificate is an electronic credential containing the subject's identity information, public key information, and the signature of the certificate issuing authority. Specifically, the secure element sends its pre-installed client digital certificate and signature data generated based on the private key to the authentication server. Upon receiving the client digital certificate, the authentication server verifies the signature based on the pre-set root certificate and trusted certificate chain to confirm that the digital certificate was issued by a trusted certificate authority. It also verifies the certificate's validity period and status, and uses the public key in the client digital certificate to verify the signature data, confirming that the secure element holds the corresponding private key. After verification, the authentication server returns the server digital certificate and signature data generated based on the server's private key to the secure element. Upon receiving the server digital certificate, the secure element verifies the signature based on the internally stored root certificate, checks the certificate's validity period and status, and uses the public key in the server digital certificate to verify the signature data, confirming that the authentication server holds the corresponding private key. Once both parties have completed certificate signature verification, certificate status verification, and signature data verification, a trusted communication relationship is established between the authentication server and the secure element, thus completing two-way digital certificate verification.

[0022] Step S300: Encrypt the target identity information using the firmware to obtain a target authentication request, and send the target authentication request to the authentication server.

[0023] In this embodiment, after the hardware-level encryption of the target identity information is completed and the two-way digital certificate verification between the authentication server and the security element is successful, the firmware built into the network card will generate and send the authentication request. The firmware retrieves the target identity information that has been hardware-level encrypted by the security element, and performs message encapsulation processing on the encrypted target identity information in combination with the preset authentication request data format specification. It adds verification fields such as request identifier, timestamp, and network card media access control address, and generates a target authentication request after completing the data structure integration. The target authentication request is a request message that contains the encrypted target identity information and conforms to the target network authentication interaction protocol, and is used to initiate identity authentication to the authentication server.

[0024] Subsequently, relying on the established temporary network address communication link and the trusted encrypted communication channel verified by two-way digital certificates, the firmware sends the encapsulated target authentication request to the authentication server through link layer data transmission in accordance with the network transmission specifications of Transmission Control Protocol / Internet Protocol, thereby realizing the secure and complete transmission of authentication request data from the network card to the authentication server.

[0025] Step S400: Based on the authentication server, determine whether the target identity information has been verified. If the verification is successful, generate target authentication success information.

[0026] In this embodiment of the application, after the authentication server receives the target authentication request sent by the network card firmware, it first calls its own pre-set decryption algorithm and matching decryption key that match the encryption algorithm of the security element, performs decryption operation on the target identity information in the target authentication request that is in an encrypted state, completes the parsing of the ciphertext target identity information, and restores the original data of the target identity information.

[0027] After decrypting and restoring the target identity information, the authentication server retrieves its pre-stored database of legitimate user identity information. It then performs a full-field, item-by-item comparison and verification of the restored target identity information against the corresponding user identity information registered in the database. This includes consistency checks on key fields such as the user's core identity identifier, account information, and permission association information. Based on the comparison results, the server determines whether the target identity information is legitimately registered within the target network, thus completing the overall verification of the target identity information. If, after the full-field, item-by-item comparison and verification, the restored target identity information is completely consistent with the identity information registered in the authentication server's legitimate user identity information database, the authentication server determines that the target identity information has been verified successfully. Subsequently, according to the authentication result data format pre-set by the target network, it generates a successful authentication message containing a user identity verification pass identifier, a verification completion timestamp, and the target user's basic identity association information.

[0028] Step S500: Obtain the target user's target identity identifier based on the target authentication success information, and send the target identity identifier to the address generation server.

[0029] In this embodiment of the application, after the authentication server generates the target authentication success information, the authentication server parses the target authentication success information. The target authentication success information is data containing the authentication pass result and user association information. The authentication server splits the target authentication success information into fields according to a preset data structure and extracts the identity identifier field corresponding to the target user to obtain the target identity identifier. The target identity identifier is data used to uniquely identify the target user's identity.

[0030] After obtaining the target identity identifier, the authentication server organizes and processes the target identity identifier according to a preset data format to ensure that the target identity identifier meets the data format requirements for network transmission. After completing the data organization of the target identity identifier, the authentication server sends the target identity identifier to the address generation server through the network communication interface according to the network transmission protocol. The address generation server then receives the target identity identifier and uses it in the subsequent formal network address generation process, thus completing the process of sending the target identity identifier to the address generation server.

[0031] Step S600: The address generation server retrieves a preset address generation strategy and generates a formal network address by combining it with the target identity identifier.

[0032] In this embodiment of the application, after the address generation server receives the target identity identifier, the address generation server parses the target identity identifier, where the target identity identifier is data used to uniquely identify the target user's identity. The address generation server performs field recognition on the target identity identifier according to preset data parsing rules, and extracts the identity association content used for address generation to determine the identity category, address allocation range or permission attribute corresponding to the target user, thereby providing an identity basis for subsequent formal network address generation.

[0033] After parsing the target identity, the address generation server retrieves a preset address generation strategy. This preset strategy is a set of address generation rules pre-stored in the address generation server, which specifies the formal network address generation method corresponding to different target identities. Specifically, the address generation server performs a matching query in the pre-stored strategy table based on the identity association content corresponding to the target identity to determine the address range, address allocation rules, and identity mapping rules corresponding to the target identity, thereby obtaining a preset address generation strategy suitable for the current target user.

[0034] After determining the preset address generation strategy, the address generation server generates a formal network address by combining the target identity identifier. In this process, the address generation server determines the address range, host bits, and associated identifier content of the formal network address according to the preset address generation strategy, and maps the identity association information to the generation process of the formal network address based on the target identity identifier, thereby obtaining a formal network address corresponding to the target user's identity. The formal network address is the network address used by the target user to complete the target network access.

[0035] Furthermore, in the method provided in the application embodiment, the address generation server retrieves a preset address generation strategy, combines it with the target identity identifier to generate a formal network address, and then further includes: The network interface card (NIC) is used to acquire incoming and outgoing network data packets; based on the real-time encryption and decryption processing of the network data packets, a secure authentication channel is established, wherein the secure authentication channel refers to a secure encrypted authentication channel from the NIC to the target network.

[0036] In this embodiment, after the address generation server generates a formal network address and completes network access, the network interface card (NIC) acquires data entering and leaving the target network through its data transceiver interface. Specifically, in the data sending direction, the NIC encapsulates data from the client device into network data packets and sends them to the target network through the network interface. Simultaneously, in the data receiving direction, the NIC receives data from the target network and parses it into corresponding data content, thereby acquiring data packets entering and leaving the network.

[0037] After acquiring network data packets, the network card calls the preset encryption and decryption algorithm and combines it with the preset key to perform real-time encryption and decryption processing on the network data packets. For network data packets sent, the data fields are encrypted after encapsulation before being sent. For network data packets received, the data fields are decrypted and the data field content is restored after reception, so that the network data packets are always in an encrypted protection state during transmission.

[0038] During the continuous encryption and decryption of network data packets, the network card establishes a stable data communication relationship with the target network through the data transmission link based on the formal network address. By performing consistent encryption and decryption on each network data packet, a secure authentication channel is formed between the network card and the target network. The secure authentication channel refers to the secure encrypted authentication channel from the network card to the target network, which is used to ensure the confidentiality and integrity of data transmission.

[0039] Furthermore, in the method provided in the application embodiments, before the target user completes the client device's access to the target network based on the formal network address, it further includes: Obtain the unique hardware identifier of the client device; bind the unique hardware identifier to the official network address and send it back to the target user.

[0040] In this embodiment, after the formal network address is generated, the unique hardware identifier of the client device is first obtained. This unique hardware identifier is identification information used to uniquely represent the hardware identity of the client device. Specifically, the network interface card (NIC) reads the underlying hardware identifier information of the client device and extracts hardware identifier data that uniquely corresponds to the client device to obtain the unique hardware identifier. After obtaining the unique hardware identifier, it is bound to the formal network address. That is, a one-to-one correspondence between the unique hardware identifier and the formal network address is established in a preset binding relationship table, making the formal network address uniquely associated with the client device. After the binding is completed, feedback information containing the correspondence between the unique hardware identifier and the formal network address is generated and sent to the target user so that the target user knows the formal network address corresponding to the client device and its binding result.

[0041] Furthermore, the method provided in the application embodiments also includes: The authentication server has an embedded security audit server, which is used to record the target identity information, the unique hardware identifier, the official network address, the establishment and termination time of the network connection, and the key operation behavior of the target user, forming a traceable audit log.

[0042] In this embodiment, the authentication server embeds a security audit server. When the authentication server processes the target authentication request and network access process, the security audit server acquires and records relevant data. Specifically, the security audit server obtains the target identity information, unique hardware identifier, and formal network address from the authentication process by calling the data acquisition interface inside the authentication server. The target identity information is the identity data submitted by the target user, the unique hardware identifier is the hardware identifier data of the client device, and the formal network address is the network address assigned to the client device. By collecting the above data, the relationship between the user identity and the network address is recorded.

[0043] After obtaining the target's identity information, unique hardware identifier, and official network address, the security audit server monitors the network connection status and records the establishment and termination times of the network connection based on network connection events. Specifically, the security audit server records the connection establishment time when it detects that a client device is accessing the target network, and records the connection termination time when it detects that a client device is disconnecting from the network, thereby achieving the recording of the network connection lifecycle.

[0044] After completing the network connection status recording, the security audit server collects the target user's key operational behaviors during the network access process. By obtaining network access records or operation records, it records the target user's access to network resources, execution of operation commands, and other behaviors, thereby obtaining the target user's key operational behavior data.

[0045] After obtaining the target's identity information, unique hardware identifier, official network address, network connection establishment and termination time, and key operational behaviors, the security audit server performs structured processing on the above data according to a preset log recording format, and writes the processed data into the audit log storage medium to form an audit log. The audit log is a data set used to record the target user's network behavior, thereby realizing the recording and tracing of the target user's network behavior.

[0046] Step S700: The target user completes the client device's access to the target network based on the official network address.

[0047] In this embodiment, after the address generation server generates a formal network address, the formal network address, as a network address used to identify the communication identity of the client device in the target network, is sent to the network card and configured, enabling the client device to have a network layer communication identifier in the target network. Subsequently, the network card sends a network communication request to the target network based on the formal network address, and establishes a communication connection between the client device and the target network through the sending and receiving of network data packets. After the communication connection is established, the target user accesses network resources in the target network through the client device based on the formal network address, thereby completing the target user's access to the target network based on the formal network address.

[0048] Furthermore, in the method provided in the application embodiments, after the target user completes the client device's access to the target network based on the formal network address, it further includes: When the network card detects that the target user has completed network access, it releases the temporary network address.

[0049] In this embodiment, after the target user completes the client device's access to the target network based on the official network address, the network interface card (NIC) detects the network access status. The NIC monitors the communication status of the official network address to determine whether the client device has established a stable network communication connection based on the official network address. When the NIC detects that the target user has completed network access, that is, the client device has established a communication connection with the target network based on the official network address and can normally send and receive network data packets, the NIC performs temporary network address release processing, clears the network configuration corresponding to the temporary network address, and stops network communication based on the temporary network address, so that the temporary network address no longer occupies network resources.

[0050] Furthermore, the method provided in the application embodiments also includes: The server obtains the first address request from the target user; based on the first address request and the unique hardware identifier, the address generation server determines the official network address and assigns the official network address to the client device; the firmware of the client device receives the official network address and completes access to the target network.

[0051] In this embodiment of the application, during the process of a target user initiating network access, the client device sends a first address request to the address generation server through the network card. The first address request is a network request message used to apply for a formal network address. The first address request is constructed according to a preset request message format and sent to the address generation server through a network transmission protocol.

[0052] After the address generation server receives the first address request, it parses the first address request, extracts the request parameter information, and retrieves the unique hardware identifier corresponding to the client device. The address generation server matches the request parameter information in the first address request with the unique hardware identifier and determines the formal network address based on the preset address allocation rules. The formal network address is the network address used by the client device to communicate in the target network.

[0053] After determining the official network address, the address generation server encapsulates the official network address according to a preset data transmission format and sends the official network address to the client device through the network communication interface. The client device's firmware receives the official network address and configures it, enabling the client device to have the network communication identifier corresponding to the official network address.

[0054] After the client device completes the configuration of the official network address, the client device sends network data packets to the target network and receives network data packets from the target network based on the official network address, thereby establishing a communication connection between the client device and the target network and completing the access to the target network.

[0055] Furthermore, the method provided in the application embodiments also includes: The information embedded in the formal network address includes at least one or more of the target user's target identity identifier, target login timestamp, or target permission level, which is used to achieve user tracing and access control of network traffic.

[0056] In this embodiment of the application, when generating a formal network address, the address generation server embeds corresponding associated information in a specified field of the formal network address. The information embedded in the formal network address includes at least one or more of the following: the target user's target identity identifier, the target login timestamp, or the target permission level. The target identity identifier is a feature information used to uniquely identify the target user's identity, the target login timestamp is the time information that records when the target user completes authentication and applies for a network address, and the target permission level is the level information used to distinguish the target user's access permissions in the target network.

[0057] The address generation server embeds one or more of the above information into the formal network address and forms an association, so that the formal network address carries user identity attributes and permission attributes. This enables user tracing and access control of network traffic when the formal network address is used for network communication. User tracing is used to associate network traffic with the corresponding target user, and access control is used to restrict and manage network access behavior based on the target permission level.

[0058] In summary, the embodiments of this application have at least the following technical effects: When the network card is powered on, this application obtains a temporary network address through the firmware; obtains the target user's target identity information, wherein the target identity information refers to the identity information submitted by the target user when accessing the target network through a client device with the network card installed; encrypts the target identity information through the firmware to obtain a target authentication request, and sends the target authentication request to the authentication server; the authentication server determines whether the target identity information has been verified successfully, and if so, generates target authentication success information; obtains the target user's target identity identifier based on the target authentication success information, and sends the target identity identifier to the address generation server; the address generation server retrieves a preset address generation strategy and generates a formal network address based on the target identity identifier; the target user completes the client device's access to the target network based on the formal network address. This invention solves the technical problems of existing technologies that rely on client software for authentication, are complex to deploy, and have low security. By completing identity information encryption authentication and network address generation based on identity identifiers at the network card firmware layer, it achieves the technical effect of automatic authentication access without a client and improves security.

[0059] Example 2 is based on the same inventive concept as the client-free authentication method based on network card firmware in the previous examples, such as... Figure 2 As shown, this application provides a client-free authentication system based on network card firmware. The system and method embodiments in this application are based on the same inventive concept. The system includes: Address acquisition module 11 is used to acquire a temporary network address through the firmware after the network card is powered on; identity information acquisition module 12 is used to acquire the target identity information of the target user, wherein the target identity information refers to the identity information submitted by the target user when accessing the target network through a client device with the network card installed; encryption module 13 is used to encrypt the target identity information through the firmware to obtain a target authentication request, and send the target authentication request to the authentication server; verification module 14 is used to determine whether the target identity information has been verified successfully based on the authentication server, and if the verification is successful, generate target authentication success information; identifier sending module 15 is used to acquire the target identity identifier of the target user based on the target authentication success information, and send the target identity identifier to the address generation server; network address generation module 16 is used for the address generation server to retrieve a preset address generation strategy and generate a formal network address in combination with the target identity identifier; access module 17 is used for the target user to complete the client device's access to the target network based on the formal network address.

[0060] Furthermore, the system is also used to implement the following functions: The network card has a built-in security element that obtains the target user's identity information, and then performs hardware-level encryption on the target identity information through the security element.

[0061] Furthermore, the system is also used to implement the following functions: The authentication server and the security element perform two-way digital certificate verification.

[0062] Furthermore, the system is also used to implement the following functions: Obtain the unique hardware identifier of the client device; bind the unique hardware identifier to the official network address and send it back to the target user.

[0063] Furthermore, the system is also used to implement the following functions: When the network card detects that the target user has completed network access, it releases the temporary network address.

[0064] Furthermore, the system is also used to implement the following functions: The server obtains the first address request from the target user; based on the first address request and the unique hardware identifier, the address generation server determines the official network address and assigns the official network address to the client device; the firmware of the client device receives the official network address and completes access to the target network.

[0065] Furthermore, the system is also used to implement the following functions: The information embedded in the formal network address includes at least one or more of the target user's target identity identifier, target login timestamp, or target permission level, which is used to achieve user tracing and access control of network traffic.

[0066] Furthermore, the system is also used to implement the following functions: The network interface card (NIC) is used to acquire incoming and outgoing network data packets; based on the real-time encryption and decryption processing of the network data packets, a secure authentication channel is established, wherein the secure authentication channel refers to a secure encrypted authentication channel from the NIC to the target network.

[0067] Furthermore, the system is also used to implement the following functions: The authentication server has an embedded security audit server, which is used to record the target identity information, the unique hardware identifier, the official network address, the establishment and termination time of the network connection, and the key operation behavior of the target user, forming a traceable audit log.

[0068] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.

[0069] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.

Claims

1. A client-free authentication method based on network card firmware, characterized in that, The client-free authentication method based on network interface card (NIC) firmware is applied to a client-free authentication system based on NIC firmware, and the client-free authentication system based on NIC firmware is communicatively connected to a target network. The target network includes a NIC, an authentication server, and an address generation server. The NIC has built-in firmware. The client-free authentication method based on NIC firmware includes: When the network card is powered on, a temporary network address is obtained through the firmware; Obtain the target user's target identity information, wherein the target identity information refers to the identity information submitted by the target user when accessing the target network through a client device with the network card installed; The firmware encrypts the target identity information to obtain a target authentication request, and then sends the target authentication request to the authentication server. The authentication server determines whether the target identity information has been successfully verified. If the verification is successful, a target authentication success message is generated. Based on the successful authentication information, the target user's target identity identifier is obtained, and the target identity identifier is sent to the address generation server; The address generation server retrieves a preset address generation strategy and combines it with the target identity identifier to generate a formal network address. The target user completes the client device's access to the target network based on the official network address.

2. The client-free authentication method based on network card firmware according to claim 1, characterized in that, The network card has a built-in security element that obtains the target user's identity information, and then performs hardware-level encryption on the target identity information through the security element.

3. The client-free authentication method based on network card firmware according to claim 2, characterized in that, The authentication server and the security element perform two-way digital certificate verification.

4. The client-free authentication method based on network card firmware according to claim 1, characterized in that, The target user completes the client device's access to the target network based on the official network address, prior to which the following steps are included: Obtain the unique hardware identifier of the client device; The unique hardware identifier is bound to the official network address and then sent back to the target user.

5. The client-free authentication method based on network card firmware according to claim 4, characterized in that, The target user completes the client device's access to the target network based on the formal network address, and then the following steps are taken: when the network card detects that the target user has completed network access, the temporary network address is released.

6. The client-free authentication method based on network card firmware according to claim 5, characterized in that, This also includes: Obtain the first address request of the target user; The address generation server determines the formal network address based on the first address request and the unique hardware identifier, and assigns the formal network address to the client device. The firmware of the client device receives the official network address and completes access to the target network.

7. The client-free authentication method based on network card firmware according to claim 1, characterized in that, The information embedded in the formal network address includes at least one or more of the target user's target identity identifier, target login timestamp, or target permission level, which is used to achieve user tracing and access control of network traffic.

8. The client-free authentication method based on network card firmware according to claim 1, characterized in that, The address generation server retrieves a preset address generation strategy, combines it with the target identity identifier to generate a formal network address, and then includes: The network interface card (NIC) is used to acquire incoming and outgoing network data packets. A secure authentication channel is established based on the real-time encryption and decryption processing of the network data packets. The secure authentication channel refers to a secure encrypted authentication channel from the network card to the target network.

9. The client-free authentication method based on network card firmware according to claim 4, characterized in that, The authentication server has an embedded security audit server, which is used to record the target identity information, the unique hardware identifier, the official network address, the establishment and termination time of the network connection, and the key operation behavior of the target user, forming a traceable audit log.

10. A client-free authentication system based on network card firmware, characterized in that, The system is used to execute the client-free authentication method based on network card firmware as described in any one of claims 1-9, and the system includes: The address acquisition module is used to obtain a temporary network address through the firmware after the network card is powered on. The identity information acquisition module is used to acquire the target identity information of the target user, wherein the target identity information refers to the identity information submitted by the target user when accessing the target network through a client device with the network card installed; An encryption module is used to encrypt the target identity information through the firmware to obtain a target authentication request, and send the target authentication request to the authentication server; The verification module is used to determine whether the target identity information has been verified successfully based on the authentication server. If the verification is successful, a target authentication success message is generated. The identifier sending module is used to obtain the target identity identifier of the target user based on the target authentication success information, and send the target identity identifier to the address generation server; The network address generation module is used by the address generation server to retrieve a preset address generation strategy and generate a formal network address in combination with the target identity identifier; An access module is used by the target user to complete the client device's access to the target network based on the official network address.