An authentication redirection processing method and device, a computer device and a storage medium

CN122845656APending Publication Date: 2026-09-29HANGZHOU DPTECH TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610815557.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-05
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0004]有鉴于此,本申请提供一种认证重定向处理方法、装置、计算机设备及存储介质,用以解决透明模式下无法进行认证重定向的问题

Benefits of technology

[0023]本申请实施例所提供的认证重定向处理方法、装置、计算机设备及存储介质,通过在透明模式网络设备中为需要进行认证重定向处理的目标报文建立关联记录,并在原始入接口不具有IP地址的情况下,利用预先配置的辅助接口将目标报文送入协议栈进行认证处理,再基于所述关联记录对回复报文的源地址、源端口、出接口及二层封装进行还原,能够在透明转发入接口不配置IP地址的场景下实现认证重定向处理,并使回复报文沿原始路径返回客户端,从而提高透明模式网络设备中认证处理的可实施性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845656A_ABST
    Figure CN122845656A_ABST
Patent Text Reader

Abstract

The application provides an authentication redirection processing method and device, computer equipment and a storage medium. The application establishes an association record for a target message requiring authentication redirection processing in a transparent mode network device, and in the case that the original incoming interface does not have an IP address, the target message is sent into a protocol stack for authentication processing by using a pre-configured auxiliary interface, and then the source address, source port, outgoing interface and two-layer encapsulation of a reply message are restored based on the association record. The authentication redirection processing can be implemented in the case that the transparent forwarding incoming interface is not configured with an IP address, and the reply message is returned to the client along the original path, thereby improving the implementability of the authentication processing in the transparent mode network device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and more specifically, to an authentication redirection processing method, apparatus, computer device, and storage medium. Background Technology

[0002] With the increasing demands for network access control, authentication redirection technology has been widely applied in user access management scenarios. In this technology, after receiving a target packet from a client, network devices typically determine whether the client has been authenticated based on the authentication policy. For packets that have failed authentication but meet the redirection conditions, they are redirected to the authentication processing flow to either return an authentication page to the client or establish an authentication connection, thus allowing access only after the client completes authentication.

[0003] However, in transparent mode, network devices are typically deployed using transparent forwarding, and their transparent forwarding ingress interfaces for receiving client target packets are generally not configured with IP addresses. Thus, when related technologies still rely on the IP address corresponding to the original ingress interface to send the target packet to the device's protocol stack for authentication, problems may arise where the target packet cannot be effectively sent, and the reply packet may not return correctly along the original path, thereby affecting the implementation of authentication redirection processing. Summary of the Invention

[0004] In view of this, this application provides an authentication redirection processing method, apparatus, computer device, and storage medium to solve the problem that authentication redirection cannot be performed in transparent mode.

[0005] Specifically, this application is implemented through the following technical solution: Firstly, this application provides an authentication redirection processing method applied to a transparent mode network device, the method comprising: Receive the target message sent by the client, and determine whether the target message is an unauthenticated message that needs to be processed for authentication redirection based on the authentication policy; If the target packet is an unauthenticated packet that requires authentication redirection, an association record corresponding to the target packet is established. The association record is used to record at least the original destination IP address, original destination port, original ingress interface, and original Layer 2 header information of the target packet. The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet. If the original ingress interface does not have an IP address, a pre-configured auxiliary interface is obtained, wherein the auxiliary interface is a Layer 3 interface with an IP address; The destination IP address and destination port of the target packet are modified to the interface IP address and preset authentication service port of the auxiliary interface, and the receiving interface information of the target packet is pointed to the auxiliary interface, so that the target packet is sent into the protocol stack of the transparent mode network device for authentication processing. Upon receiving a reply message for the target message, the source IP address and source port of the reply message are restored to the original destination IP address and original destination port of the target message according to the association record; Based on the associated record, the outgoing interface of the reply message is set to the original incoming interface, and the reply message is encapsulated and restored using the original Layer 2 header information. The restored reply message is sent through the original ingress interface.

[0006] In some embodiments, determining whether the target packet is an unauthenticated packet requiring authentication redirection based on the authentication policy includes: If the client corresponding to the target message is not authenticated and the destination port of the target message is within the redirection port range, the target message is determined to be an unauthenticated message that needs to be processed for authentication redirection.

[0007] In some embodiments, establishing an association record corresponding to the target message includes: Index information is generated based on the original source IP address and original source port of the target message, and the associated record is established based on the index information.

[0008] In some embodiments, the original Layer 2 header information includes at least one of the following: source MAC address, destination MAC address, and VLAN identifier.

[0009] In some embodiments, the auxiliary interface is a pre-configured logical Layer 3 interface.

[0010] In some embodiments, after pointing the receiving interface information of the target message to the auxiliary interface, the method further includes: The target message is sent to the packet receiving queue of the processing unit where the authentication processing service is located.

[0011] In some embodiments, the authentication process includes at least one of the following: generating an authentication page, establishing a Transport Layer Security (TLS) connection.

[0012] In some embodiments, the reply message is encapsulated and restored based on the original Layer 2 header information, including at least one of the following: the source MAC address of the exchange; the destination MAC address of the exchange; and the restored VLAN tag.

[0013] Secondly, this application also provides an authentication redirection processing apparatus for a transparent mode network device, the apparatus comprising: The receiving module is used to receive the target message sent by the client and determine whether the target message is an unauthenticated message that needs to be processed for authentication redirection based on the authentication policy. The recording module is used to establish an association record corresponding to the target packet when the target packet is an unauthenticated packet that needs to be authenticated and redirected. The association record is used to record at least the original destination IP address, original destination port, original ingress interface and original Layer 2 header information of the target packet. The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet. The acquisition module is used to acquire a pre-configured auxiliary interface when the original ingress interface does not have an IP address, wherein the auxiliary interface is a Layer 3 interface with an IP address; The modification module is used to modify the destination IP address and destination port of the target packet to the interface IP address and preset authentication service port of the auxiliary interface, and to point the receiving interface information of the target packet to the auxiliary interface, so that the target packet is sent into the protocol stack of the transparent mode network device for authentication processing. The recovery module is used to, upon receiving a reply message for the target message, restore the source IP address and source port of the reply message to the original destination IP address and original destination port of the target message according to the association record. The setting module is used to set the outgoing interface of the reply message to the original incoming interface according to the associated record, and to perform layer 2 encapsulation and restoration of the reply message according to the original layer 2 header information. The sending module is used to send the restored reply message through the original input interface.

[0014] In some embodiments, the receiving module is used to: If the client corresponding to the target message is not authenticated and the destination port of the target message is within the redirection port range, the target message is determined to be an unauthenticated message that needs to be processed for authentication redirection.

[0015] In some embodiments, the recording module is used for: Index information is generated based on the original source IP address and original source port of the target message, and the associated record is established based on the index information.

[0016] In some embodiments, the original Layer 2 header information includes at least one of the following: source MAC address, destination MAC address, and VLAN identifier.

[0017] In some embodiments, the auxiliary interface is a pre-configured logical Layer 3 interface.

[0018] In some embodiments, the apparatus further includes a queue module for sending the target packet into the packet receiving queue of the processing unit where the authentication processing service is located after the receiving interface information of the target packet points to the auxiliary interface.

[0019] In some embodiments, the authentication process includes at least one of the following: generating an authentication page, establishing a Transport Layer Security (TLS) connection.

[0020] In some embodiments, the setting module is specifically used for at least one of the following: switching source MAC addresses; switching destination MAC addresses; and restoring VLAN tags.

[0021] Thirdly, this application also provides a computer device including a processor and a memory, the memory storing machine-readable instructions executable by the processor, the processor executing the machine-readable instructions stored in the memory, the machine-readable instructions being executed by the processor performing the steps of the first aspect above, or any possible implementation of the first aspect.

[0022] Fourthly, this application also provides a computer-readable storage medium storing a computer program that, when run, performs the steps of the first aspect or any possible implementation thereof.

[0023] The authentication redirection processing method, apparatus, computer device, and storage medium provided in this application establish an association record for the target packet requiring authentication redirection processing in a transparent mode network device. When the original ingress interface does not have an IP address, the target packet is sent to the protocol stack for authentication processing using a pre-configured auxiliary interface. Then, based on the association record, the source address, source port, outgress interface, and Layer 2 encapsulation of the response packet are restored. This enables authentication redirection processing in scenarios where the transparent forwarding ingress interface is not configured with an IP address, and allows the response packet to return to the client along the original path, thereby improving the feasibility of authentication processing in transparent mode network devices. Attached Figure Description

[0024] Figure 1 This is a flowchart illustrating an authentication redirection processing method according to an exemplary embodiment of this application; Figure 2 This is a flowchart illustrating another authentication redirection processing method according to an exemplary embodiment of this application; Figure 3 This is a schematic diagram of an authentication redirection processing apparatus shown in an exemplary embodiment of this application; Figure 4 This is a schematic diagram of a computer device illustrated in an exemplary embodiment of this application. Detailed Implementation

[0025] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0026] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0027] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0028] Research has revealed that in transparent mode, network devices are typically deployed using transparent forwarding, and their transparent forwarding ingress interfaces for receiving client target packets are generally not configured with IP addresses. Thus, when related technologies still rely on the IP address corresponding to the original ingress interface to send the target packet to the device's protocol stack for authentication, problems may arise where the target packet cannot be effectively sent, and the reply packet may fail to return correctly along the original path, thereby affecting the implementation of authentication redirection processing.

[0029] In view of this, embodiments of this application provide an authentication redirection processing method, apparatus, computer device, and storage medium to solve the problem that authentication redirection cannot be performed in transparent mode.

[0030] To facilitate understanding of this embodiment, the application scenarios of the authentication redirection processing method disclosed in this application embodiment will first be introduced. The execution subject of the authentication redirection processing method provided in this application embodiment can be a computer device. In some possible implementations, the authentication redirection processing method can be implemented by a processor calling computer-readable instructions stored in memory. The computer device can be a network device in transparent mode in the network, and this application does not limit this.

[0031] See Figure 1 The diagram shown is a flowchart of an authentication redirection processing method provided in an exemplary embodiment of this application. The method includes steps S101 to S107, wherein: S101. Receive the target message sent by the client, and determine whether the target message is an unauthenticated message that needs to be processed for authentication redirection based on the authentication policy.

[0032] The client described in this application can be a terminal device accessing a local area network, such as a personal computer, mobile terminal, tablet terminal, or other network access device capable of initiating authentication interactions via a webpage. The transparent mode network device described in this application can be a security device, access control device, or other network device with message processing capabilities deployed in the network link using transparent forwarding. This transparent mode network device can detect, identify, and process messages sent by the client in the network without altering the existing network topology or original network addressing relationships.

[0033] In some implementations, the authentication redirection process described in this application can be applied to portal authentication scenarios. Portal authentication is an access control method that guides the client to input authentication information through an authentication page and grants network access permissions upon successful authentication. Accordingly, when a client attempts to access network resources without successful authentication, the transparent mode network device can identify the target packets sent by the client and introduce target packets that meet the conditions into the authentication redirection process, so as to subsequently return the authentication page to the client or establish a secure connection related to authentication interaction, thereby enabling the client to complete authentication.

[0034] When a client accesses the network and attempts to access network resources, the client can send a target message to the target server. The target message can be a service access message initiated by the client, such as a Hypertext Transfer Protocol (HTTP) message or Hypertext Transfer Security Protocol (HTTP) message generated when accessing a webpage, or other message types that require access control before authentication. This application does not limit this.

[0035] Upon receiving the target packet, the transparent mode network device can first obtain packet characteristic information related to the target packet. This packet characteristic information may include at least one of the following: source IP address, destination IP address, source port, destination port, protocol information, ingress interface information, and Layer 2 header information. Subsequently, the transparent mode network device can match the packet characteristic information with a pre-configured authentication policy to determine whether the client corresponding to the target packet requires authentication control.

[0036] The authentication policy can be used to characterize the authentication processing method to be adopted for messages from different sources, destinations, or service types. For example, the authentication policy may include at least a portion of the following: source address range, destination address range, port range, interface range, protocol type, user state conditions, and authentication actions. When a target message meets the matching conditions defined by the authentication policy, it can be considered a message within the scope of authentication control; otherwise, the target message can be treated as a message that does not require authentication redirection processing and forwarded or otherwise processed.

[0037] In some implementations, transparent mode network devices can further determine the target packet based on the client's current authentication status. Specifically, authentication status information for the client can be maintained in advance, such as authenticated, unauthenticated, or in the process of authentication. When it is detected that the client corresponding to the target packet has not been authenticated, and the target packet meets the preset redirection conditions in the authentication policy, the target packet can be determined as an unauthenticated packet requiring authentication redirection. Conversely, if the client has been authenticated, or the target packet does not meet the redirection conditions, the target packet is not determined as an unauthenticated packet requiring authentication redirection.

[0038] In some implementations, the redirection condition may further include that the destination port of the target packet is within a preset redirection port range. The redirection port range can be set according to actual business needs, and may include service ports used for web access or secure access. By limiting the destination port, authentication redirection processing can be more targeted towards access requests requiring authentication interaction, avoiding unnecessary processing of other business packets that are not suitable for redirection.

[0039] Thus, by executing S101, after receiving client packets, the transparent mode network device can first identify the unauthenticated packets that need to enter the authentication redirection process, thereby providing a processing basis for establishing association records, sending packets to the protocol stack for authentication processing through auxiliary interfaces, and restoring the path and encapsulation of reply packets.

[0040] S102. If the target packet is an unauthenticated packet that requires authentication redirection processing, an association record corresponding to the target packet is established. The association record is used to record at least the original destination IP address, original destination port, original ingress interface, and original Layer 2 header information of the target packet. The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet.

[0041] Understandably, in S101, when the transparent mode network device determines that the target packet sent by the client is an unauthenticated packet requiring authentication redirection, in order to ensure that the reply packet generated after the subsequent authentication process can be correctly returned to the client, the device can pre-establish an association record corresponding to the target packet. This association record can be used to store the original access information and original forwarding path information of the target packet before entering the authentication redirection process, thereby providing a basis for subsequent address recovery and forwarding path recovery of the reply packet.

[0042] In some implementations, the association record can be understood as session association information established for the target packet. Since the destination IP address, destination port, and receiving interface information of the target packet can be rewritten during subsequent authentication redirection processing to allow the target packet to be sent to the protocol stack of the transparent mode network device for authentication, if the original key information of the target packet is not saved before rewriting, it may be impossible to determine the source address, interface, and Layer 2 encapsulation format of the authentication reply packet when the device generates the authentication reply packet. Therefore, this application establishes the association record before the target packet enters the subsequent processing flow.

[0043] The original destination IP address can be the IP address of the target server that the client intends to access when initiating network access, and the original destination port can be the service port corresponding to the client's access request. For example, in a portal authentication scenario, when a client attempts to access web resources in an unauthenticated state, it can send an access request message to an external server. In this case, the address and port of the external server constitute the original destination IP address and original destination port of the target message. After subsequent authentication processing is completed and an authentication page needs to be returned to the client or an authentication interaction connection needs to be established, the transparent mode network device can restore the source address and source port of the reply message based on the recorded original destination IP address and original destination port, so that the communication peer perceived by the client side is still its original access target.

[0044] The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet. In other words, the original ingress interface can be the interface through which the target packet initially enters the transparent mode network device. This interface mainly performs the function of transparent forwarding of packets in transparent mode and is not used as a Layer 3 gateway interface. In some embodiments, the transparent forwarding ingress interface can be a bridge-side interface, a bridge group member interface, or other packet receiving interface used for transparent forwarding; this application does not limit this. The purpose of recording the original ingress interface is that after the subsequent authentication reply packet is generated, the reply packet can be redirected to the original ingress interface so that the reply packet returns to the client along the path corresponding to when the target packet entered.

[0045] The original Layer 2 header information can be link-layer related information carried by the target packet when it enters a transparent mode network device. In some embodiments, the original Layer 2 header information may include at least one of the following: source Media Access Control (MAC) address, destination MAC address, Virtual Local Area Network (VLAN) identifier, and VLAN tag; this application does not limit this. The purpose of recording the original Layer 2 header information is that when an authentication reply packet needs to be sent back to the client later, the reply packet can be reconstructed using the original Layer 2 header information to ensure that the reply packet conforms to the forwarding requirements of the original Layer 2 network environment. For example, the data link layer frame header corresponding to the reply packet can be reconstructed based on the recorded source and destination MAC addresses, or the VLAN identifier or tag corresponding to the reply packet can be restored based on the recorded VLAN related information.

[0046] In some implementations, when establishing the association record, index information for retrieving the association record can be further generated based on other characteristic information of the target packet. For example, index information can be generated based on the original source IP address and original source port of the target packet, and the association record can be established based on the index information. In this way, when the device subsequently receives a response packet related to authentication processing, it can quickly locate the corresponding association record based on the relevant fields in the response packet to perform subsequent address recovery, interface recovery, and Layer 2 encapsulation restoration operations.

[0047] It should be noted that this application does not limit the specific storage format of the associated records. The associated records can exist as table entries, session records, cache units, or other data organization formats that can save and retrieve relevant information. As long as it can record the original destination IP address, original destination port, original ingress interface, and original Layer 2 header information of the target packet, and can be used by the device in the subsequent reply packet processing stage, it is applicable to this application.

[0048] Thus, by executing S102, this application can pre-save the original access target information and original forwarding path information corresponding to the target packet before the target packet is redirected into the authentication processing flow. This allows the transparent mode network device to not only restore the source address and source port of the subsequent authentication reply packet, but also restore the outgoing interface and Layer 2 encapsulation information of the reply packet, ensuring that the authentication reply packet can be returned to the client according to the original communication relationship and forwarding path corresponding to the target packet. In this way, even if the transparent forwarding inbound interface of the transparent mode network device does not have an IP address, it can still provide the information basis for subsequent authentication redirection processing and reply packet return.

[0049] S103. If the original input interface does not have an IP address, obtain a pre-configured auxiliary interface, wherein the auxiliary interface is a Layer 3 interface with an IP address.

[0050] Understandably, in transparent mode, transparent network devices are typically deployed in network links using transparent forwarding. Their transparent forwarding inbound interfaces are primarily used for Layer 2 packet forwarding and do not perform Layer 3 gateway functions. Correspondingly, these transparent forwarding inbound interfaces are usually not configured with IP addresses. Thus, when authentication redirection processing is required on a received target packet, and it is desired to further send the target packet into the device's internal protocol stack for authentication, if the interface address corresponding to the original inbound interface is still relied upon as the local receiving address, the target packet will lack a valid local Layer 3 receiving identifier because the original inbound interface itself does not have an IP address, making it difficult to be properly introduced into the protocol stack processing flow.

[0051] Therefore, in this application, when it is determined that the original ingress interface does not have an IP address, a pre-configured auxiliary interface can be obtained as the interface basis for subsequent authentication redirection processing. The auxiliary interface can be a Layer 3 interface with an IP address pre-configured in the transparent mode network device. In other words, the auxiliary interface is not the original transparent forwarding ingress interface for receiving target packets, but rather an interface pre-configured by the device specifically for providing Layer 3 access capabilities for authentication redirection processing in transparent mode. By introducing the auxiliary interface, a usable Layer 3 interface can be provided for target packets that need to enter the protocol stack processing flow without changing the original transparent forwarding deployment method of the transparent mode network device.

[0052] In some implementations, the auxiliary interface may be a logical Layer 3 interface. For example, the auxiliary interface may be a logical interface, a virtual interface, or other Layer 3 interface that can be recognized and received by the device protocol stack, which is pre-created and configured by the user. This application does not limit the specific implementation of the auxiliary interface; as long as the interface has an IP address that can be recognized by the protocol stack and can be used to undertake the message reception requirements corresponding to subsequent authentication processing, it is applicable to this application.

[0053] In some implementations, "obtaining a pre-configured auxiliary interface" may include: querying the auxiliary interface corresponding to the current authentication redirection process from the interface configuration information pre-saved by the transparent mode network device; or selecting a target auxiliary interface matching the current processing scenario from a preset list of auxiliary interfaces. For example, different auxiliary interfaces can be configured for different authentication services, different security zones, or different authentication policies. When performing authentication redirection processing, the auxiliary interface used is determined based on the processing scenario to which the target packet belongs. This application does not limit this.

[0054] It should be noted that the auxiliary interface primarily serves to provide a Layer 3 receiving foundation for subsequent authentication redirection processing, without altering the original access location or original return path of the target packet. The target packet initially enters the transparent mode network device via the original ingress interface, and subsequent authentication reply packets can still be sent back to the client from the original ingress interface based on the aforementioned association record. In other words, the auxiliary interface mainly addresses the issue that the original ingress interface in transparent mode lacks an IP address and cannot handle protocol stack processing, while the original ingress interface and its corresponding original Layer 2 header information primarily ensure that the authentication reply packet returns along the correct path. Both play different roles in the processing, jointly supporting the implementation of authentication redirection processing in transparent mode.

[0055] Thus, by executing S103, this application can provide a Layer 3 interface with an IP address in advance for sending the target packet into the protocol stack for authentication processing when the original ingress interface of the transparent mode network device does not have an IP address, thereby avoiding the problem that the target packet cannot enter the authentication process due to the lack of an interface address on the transparent forwarding ingress interface.

[0056] S104. Modify the destination IP address and destination port of the target packet to the interface IP address and preset authentication service port of the auxiliary interface, and point the receiving interface information of the target packet to the auxiliary interface, so that the target packet is sent into the protocol stack of the transparent mode network device for authentication processing.

[0057] Understandably, after obtaining the auxiliary interface with an IP address via S103, in order to enable the target packet to be recognized by the protocol stack inside the transparent mode network device as a packet destined for the local authentication process, a redirection and rewriting process can be performed on the target packet. This redirection and rewriting process may include modifying the destination IP address and destination port of the target packet, and adjusting the receiving interface information of the target packet, thereby converting the target packet originally destined for an external target server into a packet destined for the internal authentication processing path of the transparent mode network device.

[0058] Specifically, modifying the destination IP address of the target packet to the interface IP address of the auxiliary interface allows the target packet to point to a local interface within the transparent mode network device that can be recognized by the protocol stack in a Layer 3 addressing sense. Since the auxiliary interface has an IP address, after rewriting the destination IP address of the target packet to the interface IP address of the auxiliary interface, the device protocol stack can recognize the target packet as a locally received packet, rather than continuing to treat it as a normal transparent forwarding service packet. Furthermore, modifying the destination port of the target packet to a preset authentication service port allows the target packet to be submitted to the corresponding authentication processing service after being received by the protocol stack. The preset authentication service port can be a listening port pre-assigned for authentication page generation service, authentication interaction service, or secure connection establishment service; this application does not limit this.

[0059] In some implementations, the preset authentication service port can be set according to the specific type of authentication processing. For example, in some scenarios, the preset authentication service port may correspond to the service process used to generate and return the authentication page; in other scenarios, the preset authentication service port may correspond to the service process used to establish a Transport Layer Security (TLS) protocol connection. Accordingly, when the target packet is rewritten and sent to the protocol stack, the protocol stack can distribute the target packet to the corresponding authentication processing module or user-space service process based on the rewritten destination port to perform subsequent authentication processing.

[0060] In addition to rewriting the destination IP address and destination port, this application also points the receiving interface information of the target packet to the auxiliary interface. It is understood that in some implementations, the packet processing path within the device is related not only to the destination address information in the packet header but also to which interface the packet is identified as entering the device from. Therefore, if only the destination IP address and destination port of the packet are modified, and the target packet still retains the receiving interface information corresponding to the original transparent forwarding interface, the device's internal processing flow may still treat the target packet as originating from a transparent forwarding interface without an IP address, thus affecting its correct entry into the protocol stack for processing. Based on this, this application further points the receiving interface information of the target packet to the auxiliary interface, establishing a correspondence between the target packet and the auxiliary interface during the device's internal processing, thereby further improving the reliability of the target packet being correctly introduced into the protocol stack.

[0061] In some implementations, after rewriting the destination IP address, destination port, and receiving interface information of the target packet, the packet delivery mechanism provided by the driver layer or forwarding layer can be invoked to send the target packet to the receiving queue of the processing unit where the authentication processing service is located. Subsequently, the corresponding processing unit can retrieve the target packet from the receiving queue and hand it over to the protocol stack for connection establishment, packet parsing, and service distribution. For example, the protocol stack can identify that the packet belongs to the local receiving packet based on the rewritten destination IP address, and then deliver it to the corresponding authentication processing service based on the rewritten destination port to generate an authentication page, establish an authentication interaction connection, or perform other authentication-related processing.

[0062] It should be noted that the rewriting of the target packet in S104 is mainly to enable the target packet to enter the authentication process within the transparent mode network device, and does not mean that the original access target information corresponding to the target packet is permanently replaced. On the contrary, as described in S102, this application has already saved the original destination IP address, original destination port, original ingress interface, and original Layer 2 header information of the target packet through an association record before performing the rewriting. Therefore, when generating a reply packet for the target packet, the transparent mode network device can still restore the source address, source port, outgress interface, and Layer 2 encapsulation of the reply packet based on the association record, so that the communication relationship perceived by the client side still corresponds to the original access target.

[0063] Thus, by executing S104, this application can redirect the target message originally sent to the external target server to the internal auxiliary interface and authentication processing service of the device when the original ingress interface of the transparent mode network device does not have an IP address. By adjusting the receiving interface information, the target message can be correctly received and processed by the protocol stack of the transparent mode network device, thereby providing a processing basis for subsequent authentication page return, authentication interaction establishment and reply message restoration.

[0064] In some implementations, after modifying the destination IP address and destination port of the target packet to the interface IP address and preset authentication service port of the auxiliary interface, and pointing the receiving interface information of the target packet to the auxiliary interface, the target packet can be sent to the packet receiving queue corresponding to the CPU where the authentication processing service is located. After receiving the target packet, the CPU can send the target packet as a local received packet into the local TCP / IP protocol stack for processing.

[0065] In some implementations, the CPU can first identify the message type of the target message based on its processing stage in the TCP / IP protocol stack. For example, it can determine whether the current message belongs to a handshake message corresponding to the TCP connection establishment phase or a business message carrying authentication interaction content after the connection is established. This application does not limit this.

[0066] When the target message is a handshake message, the protocol stack can perform the corresponding connection establishment process based on the target message and construct a handshake message return packet.

[0067] When the target message is a service message, the protocol stack can send the target message to the corresponding user-space processing process according to the rewritten destination port. The user-space processing process can receive and process the target message and generate corresponding application layer response content, such as authentication page content, redirection response content, or other authentication interaction content.

[0068] S105. Upon receiving a reply message for the target message, the source IP address and source port of the reply message are restored to the original destination IP address and original destination port of the target message according to the association record.

[0069] It is understood that after the target packet is sent to the protocol stack of the transparent mode network device for authentication processing via S104, the protocol stack or the corresponding authentication processing service can generate a reply packet for the target packet. The reply packet can be a packet used to return an authentication page to the client, or a packet used to establish an authentication interaction connection, return the authentication processing result, or perform other authentication interactions. This application does not limit this. Since the destination IP address and destination port of the target packet have been rewritten to the interface IP address and preset authentication service port of the auxiliary interface before entering the authentication processing flow, the source IP address and source port of the reply packet directly generated by the protocol stack or authentication processing service usually correspond to the auxiliary interface and the preset authentication service port, rather than the original target server address and port that the client intended to access. If this reply packet is directly returned to the client, the communication peer perceived by the client will change, which may affect the normal implementation of the authentication redirection process.

[0070] Based on this, in this application, when the transparent mode network device receives a reply message for the target message, it can restore the source IP address and source port of the reply message according to the association record established in S102. Specifically, the source IP address of the reply message can be restored to the original destination IP address of the target message, and the source port of the reply message can be restored to the original destination port of the target message. That is, the reply message is made to reappear from the target server that the client originally wanted to access in the network layer and transport layer sender identifier, rather than from the auxiliary interface and authentication processing service inside the transparent mode network device.

[0071] In some implementations, the transparent mode network device can first locate the associated record corresponding to the target packet based on the correspondence between the reply packet and the target packet, then read the stored original destination IP address and original destination port from the associated record, and restore the reply packet accordingly. The aforementioned correspondence can be determined using pre-established index information. For example, in some implementations, the transparent mode network device can find the corresponding associated record based on the destination IP address, destination port, and other session identifier information in the reply packet, thereby obtaining the required original destination IP address and original destination port. This application does not limit this, as long as it can locate the corresponding associated record and restore the source address and source port of the reply packet.

[0072] In Portal authentication scenarios, clients typically trigger authentication redirection when attempting to access a network resource while unauthenticated. At this point, the client initially believes it is establishing a communication relationship with the target server. If the authentication service, when returning to the authentication page or establishing an authentication connection, directly sends a reply message to the client using the auxiliary interface address and authentication service port as the source address and port, the client will perceive the communication peer as the processing address within the transparent mode network device. This is detrimental to maintaining communication continuity in authentication redirection scenarios. By performing this step, the reply message maintains consistency with the client's original access target at the address and port level, ensuring the client still interprets the reply message as a response message corresponding to the original access target, thus improving the consistency and transparency of the authentication redirection process.

[0073] It should be noted that the recovery of the source IP address and source port of the reply packet in this step mainly targets the recovery of the sender information of the reply packet at the Layer 3 and transport layers, and does not replace the subsequent recovery processing of the reply packet forwarding path and Layer 2 encapsulation. In other words, after completing the recovery of the source IP address and source port, the transparent mode network device can further recover the outgoing interface and link layer encapsulation of the reply packet based on the original ingress interface and original Layer 2 header information stored in the association record, so that the reply packet not only matches the original access target at the address level, but also can return to the client along the correct path.

[0074] Thus, by executing S105, this application can restore the source IP address and source port of the reply message to the original destination IP address and original destination port of the target message after completing the authentication process inside the transparent mode network device. This ensures that the sender of the reply message perceived by the client side still corresponds to the original access target, providing support for implementing authentication redirection processing with continuous communication semantics in transparent mode.

[0075] S106. Based on the associated record, set the outgoing interface of the reply message to the original incoming interface, and perform Layer 2 encapsulation and restoration on the reply message according to the original Layer 2 header information.

[0076] It is understandable that after the source IP address and source port of the reply message are restored through S105, although the reply message already corresponds to the original access target of the target message in the sender identifier at the network layer and transport layer, if it is still sent directly according to the default packet sending path and default link layer encapsulation method when the CPU generates the reply message, the reply message may still fail to return along the client's original access path, or its link layer format may not match the original Layer 2 network environment, thus affecting the correct reception of the reply message by the client. Based on this, this application further restores the outgoing interface and Layer 2 encapsulation of the reply message according to the associated record.

[0077] The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet. Since the target packet initially enters the transparent mode network device via this original ingress interface, setting the outgress interface of the reply packet to the original ingress interface after the reply packet is generated allows the reply packet to return to the interface path corresponding to when the target packet entered. In other words, this application does not continue to send the reply packet generated on the CPU side via the auxiliary interface. Instead, it redirects the reply packet to the transparent forwarding ingress interface where the client initially accessed the transparent mode network device using the original ingress interface information stored in the association record, thus providing the reply packet with a path basis to be sent back to the client along the original direction.

[0078] In some implementations, setting the outgoing interface of the reply message as the original incoming interface may include: before the reply message enters the device's packet sending path, querying the associated record corresponding to the reply message, reading the recorded original incoming interface identifier, and writing the original incoming interface identifier into the packet sending control information corresponding to the reply message, so as to instruct the device to subsequently send the reply message through the original incoming interface. This application does not limit the specific implementation of the outgoing interface setting, as long as it enables the device to send the reply message according to the original incoming interface indicated by the associated record when sending packets.

[0079] In addition to restoring the outgoing interface, this application also performs Layer 2 encapsulation restoration on the reply message based on the original Layer 2 header information. It is understood that when a target message initially enters a transparent mode network device, its link-layer encapsulation typically carries Layer 2 header information corresponding to the current Layer 2 network environment, such as source MAC address, destination MAC address, VLAN identifier, and VLAN tag. This information reflects the Layer 2 communication relationship and the Layer 2 network environment to which the target message belongs when it enters the device. However, the reply message generated on the CPU side based on the auxiliary interface typically corresponds to the internal processing path in its initial Layer 2 encapsulation and does not naturally possess Layer 2 header information matching the client's original access scenario. Therefore, to ensure that the reply message conforms to the Layer 2 forwarding environment corresponding to the target message's entry when it is sent from the original incoming interface, this application further performs Layer 2 encapsulation restoration on the reply message based on the original Layer 2 header information stored in the association record.

[0080] In some implementations, the Layer 2 encapsulation restoration may include at least one of the following: restoring the destination MAC address of the reply packet, restoring the source MAC address of the reply packet, restoring the VLAN identifier corresponding to the reply packet, and restoring the VLAN tag corresponding to the reply packet. For example, in some scenarios, the Layer 2 header corresponding to the reply packet can be reconstructed based on the original Layer 2 header information of the target packet stored in the association record; for instance, the Layer 2 address information required when sending the reply packet can be determined based on the source MAC address and destination MAC address carried when the target packet enters the device, and the virtual LAN to which the reply packet belongs can be restored based on the original VLAN information. Furthermore, in some implementations, the Layer 2 address of the reply packet can be switched to correspond to the link layer communication relationship expected by the client when receiving the reply packet. This application does not limit this, as long as the reply packet meets the encapsulation requirements of the original Layer 2 network environment when sent from the original ingress interface.

[0081] In some implementations, the transparent mode network device can first query the associated records to obtain the original ingress interface and the original Layer 2 header information, and then perform outgress interface recovery and Layer 2 encapsulation recovery according to a preset recovery order. For example, the outgress interface of the reply packet can be set to the original ingress interface first, and then the Layer 2 header of the reply packet can be reconstructed based on the original Layer 2 header information; alternatively, the Layer 2 encapsulation of the reply packet can be constructed first based on the original Layer 2 header information, and then associated with the original ingress interface before being sent to the packet transmission path. This application does not limit the specific order of the two processes.

[0082] In Portal authentication scenarios, when a client initiates an access request that fails authentication, the subsequent authentication page responses, handshake packets, or other authentication interaction replies it receives must not only maintain consistency with the original access target at the IP address and port level, but also be able to return along the client's original access path at the link layer. By performing this step, the reply packet generated on the CPU side can regain the corresponding outgoing interface and Layer 2 encapsulation form when the target packet enters the transparent mode network device. This allows the reply packet to be correctly returned to the client in transparent mode, improving the integrity and transparency of the authentication redirection process.

[0083] Thus, by executing S106, this application can restore the packet sending interface and Layer 2 encapsulation of the reply message according to the associated record after the reply message is generated, so that the reply message matches the original Layer 2 path environment corresponding to the target message, thereby ensuring that the reply message can return to the client along the original ingress interface and adapt to the Layer 2 network forwarding requirements of the client.

[0084] S107. Send the restored reply message through the original input interface.

[0085] Understandably, after restoring the source IP address, source port, outgoing interface, and Layer 2 encapsulation of the reply message through S105 and S106 respectively, the reply message is ready to return to the client according to the original access relationship and original Layer 2 forwarding path of the target message. At this time, the transparent mode network device can send the restored reply message out through the original ingoing interface, so that the reply message returns to the client along the direction corresponding to when the target message entered.

[0086] The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet. Since the client initially sends the target packet into the transparent mode network device via the link corresponding to this original ingress interface, continuing to send the reply packet through the original ingress interface after the reply packet has recovered ensures that the reply packet maintains a correspondence with the target packet's entry path at the interface level. This facilitates the reply packet's return along the client's original access path in transparent mode, avoiding deviations from the original forwarding path caused by sending packets from auxiliary interfaces or other non-original interfaces.

[0087] In some implementations, after completing the recovery processing of the reply message, the transparent mode network device can invoke the driver layer packet sending interface, the forwarding layer packet sending interface, or other packet sending interfaces to send the restored reply message out from the original ingress interface. This application does not limit the specific software module or hardware interface form used, as long as it enables the sending of the reply message through the original ingress interface.

[0088] In some implementations, the "restored reply message" may include a message that has been processed as follows: its source IP address and source port have been restored to the original destination IP address and original destination port of the target message, its outgoing interface has been set to the original incoming interface, and its Layer 2 header has been reconstructed based on the original Layer 2 header information. Thus, when the restored reply message is sent via the original incoming interface, the message received by the client not only connects to the original access target at the network and transport layers, but also adapts to the client's network environment in terms of Layer 2 forwarding path and Layer 2 encapsulation form.

[0089] In Portal authentication scenarios, the authentication page response message, handshake return packet, or other authentication interaction reply generated on the CPU side, after completing the aforementioned recovery, is sent out through the original ingress interface. This allows the client side to perceive that such reply messages are returned along their original access path and maintain continuous communication semantics with their original access target. Thus, even if the transparent mode network device itself completes authentication processing using auxiliary interfaces and internal protocol stacks, the client side can still complete subsequent authentication interactions without being aware of changes in the device's internal processing details.

[0090] Thus, by executing S107, this application can send the recovered reply message from the original ingress interface corresponding to the target message, so that the reply message returns to the client along the original path, thereby realizing the complete authentication redirection reply process even when the transparent forwarding ingress interface of the transparent mode network device does not have an IP address.

[0091] The authentication redirection processing method provided in this application establishes an association record for the target packet that needs authentication redirection processing in a transparent mode network device. When the original ingress interface does not have an IP address, the target packet is sent to the protocol stack for authentication processing using a pre-configured auxiliary interface. Then, based on the association record, the source address, source port, outgress interface, and Layer 2 encapsulation of the reply packet are restored. This method can achieve authentication redirection processing in scenarios where the transparent forwarding ingress interface is not configured with an IP address, and allows the reply packet to return to the client along the original path, thereby improving the feasibility of authentication processing in transparent mode network devices.

[0092] See Figure 2 The diagram shown is a flowchart of another authentication redirection processing method provided in an exemplary embodiment of this application. In this method, after receiving a message, the device first determines whether an authentication page is required. If no authentication page is required, the message is either allowed to pass or dropped; if an authentication page is required, the device further queries the ingress interface IP configuration.

[0093] When the ingress interface IP configuration is successfully queried, the device can add the five-tuple information to the authentication list and modify the packet destination IP to the ingress interface IP. The authentication list in the diagram can be understood as a data record structure used to store packet-related information, such as the association record in the aforementioned implementation.

[0094] When querying the ingress interface IP configuration fails, the device further checks the auxiliary interface. If the auxiliary interface is not configured, it will either allow the packet to pass or drop the packet; if the auxiliary interface is configured, the device can add the 5-tuple information, Layer 2 header information, and ingress interface information to the authentication list, and modify the packet destination IP to the auxiliary interface IP and the packet ingress interface to the auxiliary interface.

[0095] Afterwards, the two processing branches can merge. The device continues to change the destination port of the packet to the Portal redirection service port and sends the packet to the CPU queue where the redirection service is located. Subsequently, the CPU side executes the CPU queue to receive the packet and sends the packet as a local packet to the TCP protocol stack.

[0096] In TCP protocol stack processing, the device further checks the TCP packet type. If it is a handshake packet, a handshake packet return packet is constructed, and the authentication list is queried to obtain the original destination IP, port, and ingress interface information of the packet. Then, the packet source IP and port are set to the original destination IP and port, and the Layer 2 protocol stack continues to process and send the packet according to the original packet. If it is a service packet, the device sends it to the user-space process according to the port, and the user-space process receives and constructs the user-space process return packet. Afterward, the device performs recovery processing on the return packet, including: setting the packet source IP and port to the original destination IP and port, setting the packet outgress interface to the original packet ingress interface, querying the authentication list to obtain the Layer 2 header information, reconstructing the Layer 2 header, and finally calling the driver interface to send the packet directly.

[0097] Through the above processing, this embodiment can send packets to the CPU side for authentication processing with the help of an auxiliary interface in transparent mode when the ingress interface does not have an IP address, and restore the source address, outgress interface and Layer 2 header information of the packet after generating the return packet, so that the return packet can return along the original path.

[0098] Corresponding to the embodiments of the authentication redirection processing method, this application also provides embodiments of the authentication redirection processing apparatus.

[0099] See Figure 3 The diagram shown is a schematic representation of an authentication redirection processing apparatus according to an exemplary embodiment of this application. The apparatus is used in a transparent mode network device and includes: The receiving module 310 is used to receive the target message sent by the client and determine whether the target message is an unauthenticated message that needs to be processed for authentication redirection based on the authentication policy. The recording module 320 is used to establish an association record corresponding to the target packet when the target packet is an unauthenticated packet that needs to be authenticated and redirected. The association record is used to record at least the original destination IP address, original destination port, original ingress interface and original Layer 2 header information of the target packet. The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet. The acquisition module 330 is used to acquire a pre-configured auxiliary interface when the original ingress interface does not have an IP address, wherein the auxiliary interface is a Layer 3 interface with an IP address; Modification module 340 is used to modify the destination IP address and destination port of the target packet to the interface IP address and preset authentication service port of the auxiliary interface, and to point the receiving interface information of the target packet to the auxiliary interface, so that the target packet is sent into the protocol stack of the transparent mode network device for authentication processing. The recovery module 350 is used to, upon receiving a reply message for the target message, restore the source IP address and source port of the reply message to the original destination IP address and original destination port of the target message according to the association record. The setting module 360 ​​is used to set the outgoing interface of the reply message to the original incoming interface according to the associated record, and to perform layer 2 encapsulation and restoration of the reply message according to the original layer 2 header information. The sending module 370 is used to send the restored reply message through the original input interface.

[0100] In some embodiments, the receiving module 310 is used to: If the client corresponding to the target message is not authenticated and the destination port of the target message is within the redirection port range, the target message is determined to be an unauthenticated message that needs to be processed for authentication redirection.

[0101] In some embodiments, the recording module 320 is used for: Index information is generated based on the original source IP address and original source port of the target message, and the associated record is established based on the index information.

[0102] In some embodiments, the original Layer 2 header information includes at least one of the following: source MAC address, destination MAC address, and VLAN identifier.

[0103] In some embodiments, the auxiliary interface is a pre-configured logical Layer 3 interface.

[0104] In some embodiments, the apparatus further includes a queue module 380, which is used to send the target message into the packet receiving queue of the processing unit where the authentication processing service is located after the receiving interface information of the target message points to the auxiliary interface.

[0105] In some embodiments, the authentication process includes at least one of the following: generating an authentication page, establishing a Transport Layer Security (TLS) connection.

[0106] In some embodiments, the setting module 360 ​​is specifically used for at least one of the following: switching source MAC address; switching destination MAC address; restoring VLAN tag.

[0107] The authentication redirection processing apparatus provided in this application establishes an association record for the target packet requiring authentication redirection processing in a transparent mode network device. When the original ingress interface does not have an IP address, it uses a pre-configured auxiliary interface to send the target packet into the protocol stack for authentication processing. Then, based on the association record, it restores the source address, source port, outgress interface, and Layer 2 encapsulation of the reply packet. This enables authentication redirection processing in scenarios where the transparent forwarding ingress interface is not configured with an IP address, and allows the reply packet to return to the client along the original path, thereby improving the feasibility of authentication processing in transparent mode network devices.

[0108] For a description of the processing flow of each module in the device and the interaction flow between each module, please refer to the relevant descriptions in the above method embodiments, which will not be repeated here.

[0109] This application also provides a computer device, such as... Figure 4 The diagram shown is a schematic representation of a computer device structure according to an exemplary embodiment of this application. The computer device includes: Processor 41 and memory 42; the memory 42 stores machine-readable instructions executable by the processor 41, and the processor 41 executes the machine-readable instructions stored in the memory 42. When the machine-readable instructions are executed by the processor 41, the processor 41 performs the following steps: Receive the target message sent by the client, and determine whether the target message is an unauthenticated message that needs to be processed for authentication redirection based on the authentication policy; If the target packet is an unauthenticated packet that requires authentication redirection, an association record corresponding to the target packet is established. The association record is used to record at least the original destination IP address, original destination port, original ingress interface, and original Layer 2 header information of the target packet. The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet. If the original ingress interface does not have an IP address, a pre-configured auxiliary interface is obtained, wherein the auxiliary interface is a Layer 3 interface with an IP address; The destination IP address and destination port of the target packet are modified to the interface IP address and preset authentication service port of the auxiliary interface, and the receiving interface information of the target packet is pointed to the auxiliary interface, so that the target packet is sent into the protocol stack of the transparent mode network device for authentication processing. Upon receiving a reply message for the target message, the source IP address and source port of the reply message are restored to the original destination IP address and original destination port of the target message according to the association record; Based on the associated record, the outgoing interface of the reply message is set to the original incoming interface, and the reply message is encapsulated and restored using the original Layer 2 header information. The restored reply message is sent through the original ingress interface.

[0110] In some embodiments, determining whether the target packet is an unauthenticated packet requiring authentication redirection based on the authentication policy includes: If the client corresponding to the target message is not authenticated and the destination port of the target message is within the redirection port range, the target message is determined to be an unauthenticated message that needs to be processed for authentication redirection.

[0111] In some embodiments, establishing an association record corresponding to the target message includes: Index information is generated based on the original source IP address and original source port of the target message, and the associated record is established based on the index information.

[0112] In some embodiments, the original Layer 2 header information includes at least one of the following: source MAC address, destination MAC address, and VLAN identifier.

[0113] In some embodiments, the auxiliary interface is a pre-configured logical Layer 3 interface.

[0114] In some embodiments, after pointing the receiving interface information of the target message to the auxiliary interface, the processor 41 further executes: The target message is sent to the packet receiving queue of the processing unit where the authentication processing service is located.

[0115] In some embodiments, the authentication process includes at least one of the following: generating an authentication page, establishing a Transport Layer Security (TLS) connection.

[0116] In some embodiments, the reply message is encapsulated and restored based on the original Layer 2 header information, including at least one of the following: the source MAC address of the exchange; the destination MAC address of the exchange; and the restored VLAN tag.

[0117] The aforementioned memory 42 includes a main memory 421 and an external memory 422; the main memory 421, also known as internal memory, is used to temporarily store the computational data in the processor 41, as well as the data exchanged with external memory 422 such as a hard disk. The processor 41 exchanges data with the external memory 422 through the main memory 421.

[0118] The specific execution process of the above instructions can be referred to the steps of the authentication redirection processing method described in the embodiments of this application, and will not be repeated here.

[0119] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0120] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the authentication redirection processing method described in the above method embodiments. The storage medium can be a volatile or non-volatile computer-readable storage medium.

[0121] This application also provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the authentication redirection processing method provided in the various embodiments of this application.

[0122] The aforementioned computer program product can be implemented through hardware, software, or a combination thereof. In one optional embodiment, the computer program product is specifically embodied in a computer storage medium; in another optional embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.

[0123] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems and devices described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interfaces; the indirect coupling or communication connection of devices or units may be electrical, mechanical, or other forms.

[0124] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0125] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0126] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0127] Finally, it should be noted that the above-described embodiments are merely specific implementations of this application, used to illustrate the technical solutions of this application, and not to limit them. The scope of protection of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features, within the scope of the technology disclosed in this application. Such modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0128] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. An authentication redirection processing method, characterized in that, Applied to transparent mode network devices, the method includes: Receive the target message sent by the client, and determine whether the target message is an unauthenticated message that needs to be processed for authentication redirection based on the authentication policy; If the target packet is an unauthenticated packet that requires authentication redirection, an association record corresponding to the target packet is established. The association record is used to record at least the original destination IP address, original destination port, original ingress interface, and original Layer 2 header information of the target packet. The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet. If the original ingress interface does not have an IP address, a pre-configured auxiliary interface is obtained, wherein the auxiliary interface is a Layer 3 interface with an IP address; The destination IP address and destination port of the target packet are modified to the interface IP address and preset authentication service port of the auxiliary interface, and the receiving interface information of the target packet is pointed to the auxiliary interface, so that the target packet is sent into the protocol stack of the transparent mode network device for authentication processing. Upon receiving a reply message for the target message, the source IP address and source port of the reply message are restored to the original destination IP address and original destination port of the target message according to the association record; Based on the associated record, the outgoing interface of the reply message is set to the original incoming interface, and the reply message is encapsulated and restored using the original Layer 2 header information. The restored reply message is sent through the original ingress interface.

2. The authentication redirection processing method according to claim 1, characterized in that, Determining whether the target message is an unauthenticated message requiring authentication redirection based on the authentication policy includes: If the client corresponding to the target message is not authenticated and the destination port of the target message is within the redirection port range, the target message is determined to be an unauthenticated message that needs to be processed for authentication redirection.

3. The authentication redirection processing method according to claim 1, characterized in that, Establish an association record corresponding to the target message, including: Index information is generated based on the original source IP address and original source port of the target message, and the associated record is established based on the index information.

4. The authentication redirection processing method according to claim 1, characterized in that, The original Layer 2 header information includes at least one of the following: source MAC address, destination MAC address, and VLAN identifier.

5. The authentication redirection processing method according to claim 1, characterized in that, The auxiliary interface is a pre-configured logical layer 3 interface.

6. The authentication redirection processing method according to claim 1, characterized in that, After pointing the receiving interface information of the target message to the auxiliary interface, the method further includes: The target message is sent to the packet receiving queue of the processing unit where the authentication processing service is located.

7. The authentication redirection processing method according to claim 1, characterized in that, The authentication process includes at least one of the following: generating an authentication page, or establishing a Transport Layer Security (TLS) connection.

8. The authentication redirection processing method according to claim 1, characterized in that, The reply message is encapsulated and restored using the original Layer 2 header information, including at least one of the following: the MAC address of the exchange source; Switch destination MAC address; restore VLAN tag.

9. An authentication redirection processing device, characterized in that, For a transparent mode network device, the apparatus includes: The receiving module is used to receive the target message sent by the client and determine whether the target message is an unauthenticated message that needs to be processed for authentication redirection based on the authentication policy. The recording module is used to establish an association record corresponding to the target packet when the target packet is an unauthenticated packet that needs to be authenticated and redirected. The association record is used to record at least the original destination IP address, original destination port, original ingress interface and original Layer 2 header information of the target packet. The original ingress interface is the transparent forwarding ingress interface in the transparent mode network device that receives the target packet. The acquisition module is used to acquire a pre-configured auxiliary interface when the original ingress interface does not have an IP address, wherein the auxiliary interface is a Layer 3 interface with an IP address; The modification module is used to modify the destination IP address and destination port of the target packet to the interface IP address and preset authentication service port of the auxiliary interface, and to point the receiving interface information of the target packet to the auxiliary interface, so that the target packet is sent into the protocol stack of the transparent mode network device for authentication processing. The recovery module is used to, upon receiving a reply message for the target message, restore the source IP address and source port of the reply message to the original destination IP address and original destination port of the target message according to the association record. The setting module is used to set the outgoing interface of the reply message to the original incoming interface according to the associated record, and to perform layer 2 encapsulation and restoration of the reply message according to the original layer 2 header information. The sending module is used to send the restored reply message through the original input interface.

10. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method as described in any one of claims 1 to 8.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 8.