Login verification method, system, device, equipment, product and medium

CN122845146APending Publication Date: 2026-09-29BEIJING HUAWEI DIGITAL TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510376683.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

但是,目前的登录验证是比较麻烦的,在对内部网络访问的时候需要进行一次用户输入,在对外部网络访问的时候需要进行一次用户输入,影响用户的使用体验

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845146A_ABST
    Figure CN122845146A_ABST
Patent Text Reader

Abstract

The application provides a login verification method, system, device, equipment, product and medium. The method comprises the following steps: a client sends a first external access request to a first forwarding device; the first forwarding device sends the first external access request to a second forwarding device, and the IP address of the second forwarding device is the IP address of a local area network; the second forwarding device sends a public network login request to a server based on the first external access request, and the public network login request comprises a specified username, and the specified username is the first IP address of the client; the server sends a public network login consent response or a public network login failure response to the second forwarding device according to the first IP address of the client; and the second forwarding device sends the first external access request to a next-hop device based on the public network login consent response, or prohibits sending the first external access request to the next-hop device based on the public network login failure response. The above method can reduce the operation of the user and improve the access efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data communication, and in particular to a login authentication method, system, device, equipment, product, and medium. Background Technology

[0002] Login verification (or authentication) refers to the process of confirming a user's identity when attempting to access a network, ensuring that only authorized users can access the network. By requiring users to provide a username and password, login verification ensures that only users with the correct credentials can access sensitive information or system resources, preventing malicious users or hackers from gaining access. However, current login verification methods are somewhat cumbersome, requiring user input once for accessing the internal network and again for accessing the external network, impacting the user experience. Summary of the Invention

[0003] This application provides a login verification method, system, device, equipment, product, and medium that can reduce user operations and improve access efficiency.

[0004] Firstly, a login verification method is provided, including:

[0005] The client sends a first external access request to the first forwarding device, wherein the source network protocol IP address of the first external access request is the client's first network protocol IP address, the destination IP address of the first external access request is an IP address that does not belong to the local area network, and both the client's IP address and the first forwarding device's IP address belong to the local area network.

[0006] The first forwarding device sends the first external access request to the second forwarding device, wherein the IP address of the second forwarding device is the IP address of the local area network;

[0007] The second forwarding device sends an external network login request to the server based on the first external access request, wherein the external network login request includes a specified username, and the specified username is the client's first network protocol IP address;

[0008] The server sends an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address.

[0009] The second forwarding device sends the first external access request to the next-hop device based on the external network login agreement response, or prevents the first external access request from being sent to the next-hop device based on the external network login failure response.

[0010] In the above solution, after receiving the second login request, the server can directly check if it has an IP address that matches the IP address recorded in the second username. If such an IP address exists, the client can be allowed to log in. Compared to existing technologies that require the server to send a second login response to the client, and the client to run the login interface again and re-enter login information, this solution reduces user operations and improves access efficiency.

[0011] In some possible designs, before the second forwarding device sends an external network login request to the server based on the first external access request, the method further includes:

[0012] The first forwarding device sends an intranet login request to the server, wherein the intranet login request includes inputting a username, inputting a password, and the first IP address;

[0013] If the server verifies the entered username and password, it stores the first IP address in the server and sends an intranet login consent response to the first forwarding device.

[0014] In the above scheme, the first IP address is stored in the server when logging into the intranet. This eliminates the need for users to re-enter login information on the login page when logging into the external network, reducing user operations and improving access efficiency.

[0015] In some possible designs, the client can access devices on the local area network after the server sends the intranet login consent response.

[0016] In some possible designs, the client cannot access devices outside the local area network when the server sends the external login consent response.

[0017] In some possible designs, the server sends an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address, including:

[0018] The server searches for the first IP address in the server based on the client's first network protocol IP address. If the first IP address is found, the server sends an external network login consent response to the second forwarding device. If the first IP address is not found, the server sends an external network login failure response to the second forwarding device.

[0019] In some possible designs, the IP address of the next-hop device does not belong to the IP address of the local area network.

[0020] In some possible designs, the external network login request also includes a specified password, which is pre-set in the second forwarding device. The server sends an external network login consent response or an external network login failure response to the second forwarding device based on the client's first IP address, including:

[0021] The server sends an external network login consent response or an external network login failure response to the second forwarding device based on the client's first IP address and specified password.

[0022] Secondly, a login verification system is provided, including:

[0023] The client is used to send a first external access request to the first forwarding device, wherein the source network protocol IP address of the first external access request is the first network protocol IP address of the client, the destination IP address of the first external access request is an IP address that does not belong to the local area network, and both the IP address of the client and the IP address of the first forwarding device belong to the local area network.

[0024] The first forwarding device is used to send the first external access request to the second forwarding device, wherein the IP address of the second forwarding device is the IP address of the local area network;

[0025] The second forwarding device is used to send an external network login request to the server based on the first external access request, wherein the external network login request includes a specified username, and the specified username is the client's first network protocol IP address;

[0026] The server is used to send an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address;

[0027] The second forwarding device is used to send the first external access request to the next-hop device based on the external network login agreement response, or to prevent the first external access request from being sent to the next-hop device based on the external network login failure response.

[0028] In some possible designs, the first forwarding device is used to send an intranet login request to the server, wherein the intranet login request includes inputting a username, inputting a password, and the first IP address;

[0029] The server is used to store the first IP address in the server and send an intranet login consent response to the first forwarding device if the input username and password are verified.

[0030] In some possible designs, the client can access devices on the local area network after the server sends the intranet login consent response.

[0031] In some possible designs, the client cannot access devices outside the local area network when the server sends the external login consent response.

[0032] In some possible designs, the server is used to look up the first IP address in the server based on the client's first network protocol IP address. If the first IP address is found, the server sends an external network login consent response to the second forwarding device. If the first IP address is not found, the server sends an external network login failure response to the second forwarding device.

[0033] In some possible designs, the IP address of the next-hop device does not belong to the IP address of the local area network.

[0034] In some possible designs, the server is used to send an external network login consent response or an external network login failure response to the second forwarding device based on the client's first IP address and a specified password.

[0035] Thirdly, a login verification method is provided, including:

[0036] The server receives an external network login request sent by the second forwarding device, wherein the external network login request includes a specified username, and the specified username is the client's first network protocol IP address;

[0037] The server sends an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address.

[0038] Fourthly, a login verification device is provided, comprising:

[0039] The receiving module is used to receive an external network login request sent by the second forwarding device, wherein the external network login request includes a specified username, and the specified username is the first network protocol IP address of the client;

[0040] The sending module is used to send an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address.

[0041] Fifthly, a server is provided, the server including a processor and a memory;

[0042] The processor is used to execute instructions stored in the memory to cause the server to perform the operational steps of the method described in the third aspect.

[0043] In a sixth aspect, a computer program product containing instructions is provided, which, when executed by a server, cause the server to perform the operational steps described in the third aspect.

[0044] In a seventh aspect, a computer-readable storage medium is provided, including program instructions that, when executed by a server, perform the operational steps of the method described in the third aspect. Attached Figure Description

[0045] Figure 1 This is a schematic diagram of the structure of a network system provided in this application;

[0046] Figure 2 This is a flowchart illustrating an access verification method provided in this application;

[0047] Figure 3 This is a schematic diagram of the structure of a login verification device provided in an embodiment of this application;

[0048] Figure 4 A schematic diagram of the structure of a server provided in an exemplary embodiment of this application is shown. Detailed Implementation

[0049] See Figure 1 , Figure 1 This is a schematic diagram of the structure of a network system provided in this application. For example... Figure 1 As shown, the network system of this application includes: a client 110, a first forwarding device 120, a second forwarding device 130, and a server 140.

[0050] Client 110 can be any of the following: smartphone, tablet, laptop, desktop computer, smartwatch, smart speaker, helmet, etc. The client can include a first internet protocol (IP) address and a first media access control (MAC) address. The number of first IP addresses and the number of first MAC addresses can be one or more. For convenience, the following explanation will use only one first IP address and one first MAC address. The first IP address can be an IPv4 address or an IPv6 address. The first IP address can be a fixed IP address or a variable IP address. Taking a campus network scenario as an example, the first IP address could be the IP address used by a teacher (therefore, it can be a fixed IP address); or it could be the IP address used by a student (therefore, it can be a variable IP address).

[0051] The first forwarding device 120 can be any of a router, a Layer 2 switch, a Layer 3 switch, a wireless access point, a modem, etc. In a specific embodiment, the first forwarding device 120 can be the device "closest" to the client. Here, "closest" does not refer to physical distance, but rather to the routing path with the fewest hops. For example, the next hop of the first forwarding device 120 can be the client. Of course, the first forwarding device 120 may not be the device "closest" to the client; for example, the next hop after the next hop of the first forwarding device 120 is the client. The first forwarding device 120 is used to implement access control of the client 110 to the internal network. An internal network (usually called an intranet or local area network) refers to a private network established within an organization, institution, or specific scope for communication and resource sharing between internal devices. It is isolated from the public Internet, providing higher security and controllability. For example, an internal network can be a corporate intranet, a home intranet, or a campus intranet, etc. The size of the internal network can be configured as needed. For example, it can include a few to dozens of devices, dozens to hundreds of devices, hundreds to thousands of devices, or thousands to tens of thousands of devices.

[0052] The second forwarding device 130 can be any of a router, a Layer 2 switch, a Layer 3 switch, a wireless access point, a modem, etc. In a specific embodiment, the second forwarding device 130 can be the device "closest" to the external network. Here, "closest" does not refer to physical distance, but rather to the routing path with the fewest hops. For example, the next hop of the second forwarding device 130 can be an external network. Of course, the first forwarding device 120 may not be the device "closest" to the external network. For example, the next hop after the next hop of the second forwarding device 130 is the external network. The second forwarding device 130 is used to implement access control of the client 110 to the external network. An external network refers to the network environment located outside the boundary of a specific internal network or system. Therefore, the external network covers a wide range of areas, including but not limited to the Internet, the private networks of other enterprises or organizations, and public networks. For example, when an organization (such as a school) has its own internal LAN, the LANs of other organizations, the networks of Internet service providers (ISPs), and the global Internet all belong to the organization's external network.

[0053] Server 140 can be a bare metal server (BMS), a virtual machine, a container, or an edge computing device. A BMS refers to a general-purpose physical server, such as an ARM or x86 server; a virtual machine refers to a complete computer system simulated by software, possessing full hardware system functionality and running in a completely isolated environment. Any task that can be performed on a physical computer can also be performed in a virtual machine. When creating a virtual machine on a computing device, a portion of the physical machine's hard drive and memory capacity is used as the virtual machine's hard drive and memory capacity. Each virtual machine has its own independent basic input / output system (BIOS), hard drive, and operating system, and can be operated like a physical machine. A container is a portable software unit that combines an application and all its dependencies into a single software package. This package is not limited by the underlying host operating system, eliminating the need to build complex environments and simplifying the application development and deployment process. Edge computing devices are hardware devices located close to the data source or data user.

[0054] It is understood that the above system configuration is only an example. In practical applications, the system may include more devices. For example, a core switch may be included between the first forwarding device 120 and the second forwarding device 130, etc. No specific limitation is made here.

[0055] The following section details how client 110 passes server 140's authentication, thereby enabling client 110 to access the internal network.

[0056] Client 110 sends a first login request to first forwarding device 120, and correspondingly, first forwarding device 120 receives the first login request sent by client 110.

[0057] The first forwarding device 120 sends a first login request to the server 140, and the server 140 receives the first login request sent by the first forwarding device 120. Here, although both the request sent by the client 110 to the first forwarding device 120 and the request sent by the first forwarding device 120 to the server 140 are referred to as the first login request, the two first login requests may carry exactly the same information or carry partially the same information, and no specific limitation is made here.

[0058] Server 140 sends a first login response to first forwarding device 120, and correspondingly, first forwarding device 120 receives the first login response sent by server 140.

[0059] The first forwarding device 120 sends a first login response to the client 110, and the client 110 receives the first login response sent by the first forwarding device 120. Here, although both the login response sent by the server 140 to the first forwarding device 120 and the login response sent by the first forwarding device 120 to the client 110 are referred to as the first login response, the two first login responses may carry exactly the same information or carry partially the same information, and no specific limitation is made here.

[0060] After receiving the first login response, client 110 displays a login interface, prompting the user to enter a first username and a first password. The first username is the user's unique identifier and is a string composed of one or more of the following: letters, numbers, and symbols. The first password can be a string composed of one or more of the following: letters, numbers, and symbols; it can be a pattern drawn on a specific graphical interface; or it can be the user's biometric features, such as fingerprints, facial recognition, iris scanning, or voice recognition. Here, both the first username and the first password can be set by the user; for example, the first username could be "Zhang San" and the first password could be "20220105". After receiving the username and password entered by the user, the client generates a first login message. This first login message includes the first username, the first password, the first IP address, and the first MAC address.

[0061] Client 110 sends a first login message to first forwarding device 120, and correspondingly, first forwarding device 120 receives the first login message sent by client 110.

[0062] The first forwarding device 120 sends a first login message to the server 140, and correspondingly, the server 140 receives the first login message sent by the first forwarding device 120. Here, although both the message sent by the client 110 to the first forwarding device 120 and the message sent by the first forwarding device 120 to the server 140 are called the first login message, the two first login messages may carry exactly the same information or carry partially the same information, and no specific limitation is made here.

[0063] After receiving the first login message, server 140 associates and stores the first username, first password, first IP address, and first MAC address. Server 140 authenticates the username and password. If authentication is successful, a first login consent response is generated and sent to the first forwarding device 120; if authentication fails, a first login failure response is generated and sent to the first forwarding device 120. The following explanation uses the generation of the first login consent response as an example. Optionally, in addition to authenticating the username and password, the server can also verify at least one of the first IP address and the first MAC address. For example, by verifying the first IP address, access permissions can be restricted to a specific network or IP range. For instance, an internal enterprise server may only allow access from IP addresses within the enterprise's local area network, preventing unauthorized external users from directly accessing the server from the public network and reducing the risk of network attacks. By verifying the first MAC address, IP spoofing attacks can be prevented. Since the MAC address is the client's physical address, it is unique within the local area network and relatively difficult to forge, while the IP address is relatively easy to forge. Therefore, verifying the first MAC address can effectively reduce the possibility of being impersonated.

[0064] The first forwarding device 120 sends a first login consent response to the client 110, and correspondingly, the client 110 receives the first login consent response sent by the first forwarding device 120. Here, although both the consent response sent by the server 140 to the first forwarding device 120 and the consent response sent by the first forwarding device 120 to the client 110 are referred to as the first login consent response, the two first login consent responses may carry exactly the same information or partially the same information; no specific limitation is made here. After receiving the first login consent response, the client can access the internal network, but is not allowed to access the external network.

[0065] See Figure 2 , Figure 2 This is a flowchart illustrating an access verification method provided in this application. Figure 2 As shown, the access verification method of this application includes:

[0066] S101: The client sends a first external access request to the first forwarding device. Accordingly, the first forwarding device receives the first external access request sent by the client.

[0067] When a client needs to access an external network, it sends a first external access request to the first forwarding device. The source IP address in the first external access request is the client's IP address, and the destination IP address is not part of the internal network segment. Optionally, the first external access request may also include one or more of the following: source port number, destination port number, protocol header information, and request data. The source port number is a randomly assigned port number by the client, used to identify the client's application, allowing the client to communicate with multiple servers simultaneously through different ports and correctly receive response data from the servers. The destination port number specifies the application port on the target server to be accessed. Different network services use different port numbers so that the server can correctly forward received data packets to the appropriate service process. For example, the Hypertext Transfer Protocol (HTTP) uses port 80 by default, Hypertext Transfer Protocol Secure (HTTPS) uses port 443, and the File Transfer Protocol (FTP) uses ports 20 and 21, etc. The information contained in the protocol header varies depending on the network protocol used. Taking the common TCP / IP protocol as an example, the TCP header contains one or more of the following: sequence number, acknowledgment number, flags (such as synchronize sequence numbers (SSN), acknowledgment character (ACK), finish flag (FIN), etc.), window size, etc.; the IP header contains one or more of the following: version, header length, type of service, total length, identifier, flags, fragment offset, time to live, protocol, etc.

[0068] S102: The first forwarding device sends a first external access request to the second forwarding device. Accordingly, the second forwarding device receives the first external access request sent by the first forwarding device.

[0069] S103: The second forwarding device generates a second login request.

[0070] After receiving the first external access request, the second forwarding device generates a second login request. The second login request includes a second username, a second password, a second IP address, and attributes. The second username can be the source IP address from the first external access request, i.e., the IP address of client 110. The second password can be a preset password, which can be a string composed of one or more of letters, numbers, and symbols. The second password may or may not be user-set. The second IP address can be the source IP address from the first external access request, i.e., the IP address of client 110. The attributes can be a preset first value, for example, 1, 0, or other values; no specific limitation is made here.

[0071] Optionally, the second login request may also include one or more of the following: verification code, device type, operating system, network access method, application identifier, and login channel. The verification code can be a randomly generated string or number; the user needs to enter the correct verification code during login, and the second forwarding device will include it in the second login request and send it to the server. The device type helps the server provide appropriate services or perform compatibility processing based on different device types. The operating system includes the operating system name and version number, allowing the server to understand the client's operating environment for necessary optimization or security checks. The network access method helps the server adopt different security strategies or service optimization measures based on different network access methods. The application identifier helps the server identify which application is requesting login and thus provide corresponding services or permissions. The login channel indicates how the user logged in, such as through an official website, a third-party application platform, etc., which is helpful for the server to track login sources and analyze user behavior.

[0072] S104: The second forwarding device sends a second login request to the server. Correspondingly, the server receives the second login request sent by the second forwarding device.

[0073] S105: The server determines whether to allow the client to access the external network based on the second login request.

[0074] After receiving the second login request, the server reads the attribute value from the attributes. If the attribute value is determined to be the first value, the server searches for an IP address that matches the IP address recorded in the second username. If an IP address matching the second username is stored, the client is allowed to access the external network; otherwise, the client is not allowed to access the external network. In this embodiment, since the server has already associated and stored the first username, first password, first IP address, and first MAC address when the client sends the first login request, the server can find the IP address when searching for it based on the second username, thus allowing the client to access the external network.

[0075] S106: The server sends a second login consent response to the second forwarding device. Accordingly, the second forwarding device receives the second login consent response sent by the server.

[0076] The second login consent response includes a status code, which indicates that the client is allowed to access the external network. Optionally, the second login consent request may also include an access token, a refresh token, server time, etc. The access token is the credential used by the client to prove user identity and authorization in subsequent requests. Each time the client sends an authorization request to the server, it needs to include this access token in the request header. The server verifies the validity of the token to determine whether the requested operation is allowed. The refresh token is used to obtain a new access token after the original access token expires. When the access token expires, the client can use the refresh token to request a new access token from the server without requiring the user to re-enter their username and password to log in. The server time is the server's current time, which the second forwarding device can use to perform time-related operations, such as local time synchronization or determining session expiration time.

[0077] After receiving the second login agreement response from the server, the second forwarding device is permitted to send the first external access request to the next-hop device. The IP address of the next-hop device can be an IP address not belonging to the internal network.

[0078] The above example assumes that the client has already performed login verification with the server before accessing the external network, and the verification has been successful. The client can then access the internal network, and the server stores the first username, first password, first IP address, and first MAC address. If the client has not performed login verification with the server before accessing the external network, or if the verification fails, the server will not store the first username, first password, first IP address, and first MAC address. In this case, the server will not find the IP address that matches the IP address recorded in the second username. Therefore, the server generates a second login failure response and sends it to the second forwarding device, preventing the second forwarding device from sending the first external access request to the next device.

[0079] In the above solution, after receiving the second login request, the server can directly check if it has an IP address that matches the IP address recorded in the second username. If such an IP address exists, the client can be allowed to log in. Compared to existing technologies that require the server to send a second login response to the client, and the client to run the login interface again and re-enter login information, this solution reduces user operations and improves access efficiency.

[0080] Figure 3 This is a schematic diagram of the structure of a login verification device provided in an embodiment of this application. Figure 3 As shown, the login verification device includes:

[0081] The receiving module 210 is used to receive an external network login request sent by the second forwarding device, wherein the external network login request includes a specified username, and the specified username is the first network protocol IP address of the client;

[0082] The sending module 220 is used to send an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address.

[0083] Both the receiving module 210 and the transmitting module can be implemented in software or in hardware. For example, the implementation of the receiving module will be described below. Similarly, the implementation of the transmitting module can be referenced from that of the receiving module.

[0084] As an example of a software functional unit, a receiving module may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, or a container. Furthermore, the aforementioned computing instance may be one or more. For example, the receiving module may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed within the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed within the same availability zone (AZ) or in different AZs, each AZ comprising one or more geographically proximate data centers. Typically, a region may include multiple AZs.

[0085] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.

[0086] As an example of a hardware functional unit, the receiving module may include at least one computing device, such as a server. Alternatively, the receiving module may be implemented using a central processing unit (CPU), an application-specific integrated circuit (ASIC), or a programmable logic device (PLD). The aforementioned PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), a data processing unit (DPU), a neural network processing unit (NPU), a system-on-chip (SoC), an offload card, an accelerator card, or any combination thereof.

[0087] It should be noted that, in other embodiments, the receiving module can be used to execute any step of the login verification method executed by the server, and the sending module can be used to execute any step of the login verification method. The steps implemented by the receiving module and the sending module can be specified as needed. The login verification device can achieve all its functions by implementing different steps of the login verification method through the receiving module and the sending module respectively.

[0088] See Figure 4 , Figure 4 A schematic diagram of the structure of a server provided in an exemplary embodiment of this application is shown. This network device can be implemented using a general bus architecture.

[0089] The network device includes at least one processor 401, a communication bus 402, a memory 403, and at least one communication interface 404.

[0090] Processor 401 can be a general-purpose CPU, NP, microprocessor, or one or more integrated circuits for implementing the solutions of this application, such as application-specific integrated circuits (ASICs), programmable logic devices (PLDs), or combinations thereof. The aforementioned PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.

[0091] The communication bus 402 is used to transmit information between the aforementioned components. The communication bus 402 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, it is represented by only one thick line in the figure, but this does not indicate that there is only one bus or one type of bus.

[0092] The memory 403 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions; it may also be a random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions; it may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices; or any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. The memory 403 may exist independently and be connected to the processor 401 via a communication bus 402. The memory 403 may also be integrated with the processor 401.

[0093] Communication interface 404 uses any transceiver-like device for communicating with other devices or communication networks. Communication interface 404 includes a wired communication interface and may also include a wireless communication interface. The wired communication interface may be, for example, an Ethernet interface. The Ethernet interface may be an optical interface, an electrical interface, or a combination thereof. The wireless communication interface may be a wireless local area network (WLAN) interface, a cellular network communication interface, or a combination thereof.

[0094] In a specific implementation, as one example, the processor 401 may include one or more CPUs, such as Figure 4 CPU0 and CPU1 are shown in the diagram.

[0095] In a specific implementation, as one example, the server may include multiple processors, such as... Figure 4 The processors 401 and 405 are shown. Each of these processors can be a single-core processor or a multi-core processor. Here, "processor" can refer to one or more devices, circuits, and / or processing cores used to process data (such as computer program instructions).

[0096] In a specific implementation, as one example, the server may also include output devices and input devices. The output devices communicate with the processor 401 and can display information in various ways. For example, the output devices may be liquid crystal displays (LCDs), light-emitting diode (LED) displays, cathode ray tube (CRT) displays, or projectors. The input devices communicate with the processor 401 and can receive user input in various ways. For example, the input devices may be mice, keyboards, touchscreen devices, or sensing devices.

[0097] In some embodiments, memory 403 is used to store program code 410 of a server executing the scheme of this application, and processor 401 can execute the program code 410 stored in memory 403. That is, the server can implement the various steps of server execution provided in the method embodiment through processor 401 and program code 410 in memory 403.

[0098] The processor 401, communication interface 404, and other components in the server can implement the functions and / or various steps and methods of the server in the above method embodiments. For the sake of brevity, they will not be described in detail here.

[0099] The receiving module and transmitting module in the device can be equivalent to the communication interface 404 in the server.

[0100] This application provides a program product that, when run on a server, causes the server to execute the various steps of the server execution described in the above method embodiments.

[0101] Those skilled in the art will recognize that the method steps and units described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the steps and components of each embodiment have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0102] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be found in the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0103] In the several embodiments provided in this application, the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, or it may be an electrical, mechanical, or other form of connection.

[0104] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of this application, depending on actual needs.

[0105] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0106] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0107] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0108] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. This computer program product includes one or more computer program instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., digital video disc (DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0109] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0110] The above description is only an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A login verification method, characterized in that, include: The client sends a first external access request to the first forwarding device, wherein the source network protocol IP address of the first external access request is the client's first network protocol IP address, the destination IP address of the first external access request is an IP address that does not belong to the local area network, and both the client's IP address and the first forwarding device's IP address belong to the local area network. The first forwarding device sends the first external access request to the second forwarding device, wherein the IP address of the second forwarding device is the IP address of the local area network; The second forwarding device sends an external network login request to the server based on the first external access request, wherein the external network login request includes a specified username, and the specified username is the client's first network protocol IP address; The server sends an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address. The second forwarding device sends the first external access request to the next-hop device based on the external network login agreement response, or prevents the first external access request from being sent to the next-hop device based on the external network login failure response.

2. The method according to claim 1, characterized in that, Before the second forwarding device sends an external network login request to the server based on the first external access request, the method further includes: The first forwarding device sends an intranet login request to the server, wherein the intranet login request includes inputting a username, inputting a password, and the first IP address; If the server verifies the entered username and password, it stores the first IP address in the server and sends an intranet login consent response to the first forwarding device.

3. The method according to claim 2, characterized in that, When the server sends the intranet login consent response, the client can access devices in the local area network.

4. The method according to claim 3, characterized in that, The client cannot access devices outside the local area network when the server sends the external login consent response.

5. The method according to any one of claims 2 to 4, characterized in that, The server sends an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address, including: The server searches for the first IP address in the server based on the client's first network protocol IP address. If the first IP address is found, the server sends an external network login consent response to the second forwarding device. If the first IP address is not found, the server sends an external network login failure response to the second forwarding device.

6. The method according to any one of claims 1 to 5, characterized in that, The IP address of the next-hop device does not belong to the IP address of the local area network.

7. The method according to any one of claims 1 to 6, characterized in that, The external network login request also includes a specified password, which is pre-set in the second forwarding device. The server sends an external network login consent response or an external network login failure response to the second forwarding device based on the client's first IP address, including: The server sends an external network login consent response or an external network login failure response to the second forwarding device based on the client's first IP address and specified password.

8. A login verification system, characterized in that, include: The client is used to send a first external access request to the first forwarding device, wherein the source network protocol IP address of the first external access request is the first network protocol IP address of the client, the destination IP address of the first external access request is an IP address that does not belong to the local area network, and both the IP address of the client and the IP address of the first forwarding device belong to the local area network. The first forwarding device is used to send the first external access request to the second forwarding device, wherein the IP address of the second forwarding device is the IP address of the local area network; The second forwarding device is used to send an external network login request to the server based on the first external access request, wherein the external network login request includes a specified username, and the specified username is the client's first network protocol IP address; The server is used to send an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address; The second forwarding device is used to send the first external access request to the next-hop device based on the external network login agreement response, or to prevent the first external access request from being sent to the next-hop device based on the external network login failure response.

9. The system according to claim 8, characterized in that, The first forwarding device is used to send an intranet login request to the server, wherein the intranet login request includes inputting a username, inputting a password, and the first IP address; The server is used to store the first IP address in the server and send an intranet login consent response to the first forwarding device after the input username and password have been verified.

10. The system according to claim 8, characterized in that, When the server sends the intranet login consent response, the client can access devices in the local area network.

11. The system according to claim 10, characterized in that, The client cannot access devices outside the local area network when the server sends the external login consent response.

12. The system according to any one of claims 10 to 11, characterized in that, The server is configured to search for the first IP address in the server based on the client's first network protocol IP address. If the first IP address is found, the server sends an external network login consent response to the second forwarding device. If the first IP address is not found, the server sends an external network login failure response to the second forwarding device.

13. The system according to any one of claims 9 to 12, characterized in that, The IP address of the next-hop device does not belong to the IP address of the local area network.

14. The system according to any one of claims 9 to 13, characterized in that, The server is used to send an external network login consent response or an external network login failure response to the second forwarding device based on the client's first IP address and a specified password.

15. A login verification method, characterized in that, include: The server receives an external network login request sent by the second forwarding device, wherein the external network login request includes a specified username, and the specified username is the client's first network protocol IP address; The server sends an external network login agreement response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address.

16. A login verification device, characterized in that, include: The receiving module is used to receive an external network login request sent by the second forwarding device, wherein the external network login request includes a specified username, and the specified username is the first network protocol IP address of the client; The sending module is used to send an external network login consent response or an external network login failure response to the second forwarding device based on the client's first network protocol IP address.

17. A server, characterized in that, The server includes a processor and memory; The processor is used to execute instructions stored in the memory to cause the server to perform the operation steps of the method as described in claim 16.

18. A computer program product containing instructions, characterized in that, When the instruction is executed by the server, the server performs the operation steps of the method as described in claim 16.

19. A computer-readable storage medium, characterized in that, It includes program instructions, which, when executed by the server, cause the server to perform the operational steps of the method as described in claim 16.