Authentication System and Authentication Server

The authentication system dynamically selects authentication methods based on RADIUS attribute information to address the challenge of flexibly setting authentication strength, thereby enhancing security and reducing operational costs for communication terminals with random MAC addresses.

JP7692442B2Active Publication Date: 2025-06-13HC NETWORKS CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2023015405
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-02-03
Publication Date
2025-06-13
Estimated Expiration
2043-02-03

AI Technical Summary

Technical Problem

Existing authentication systems based on the IEEE802.1X standard face challenges in flexibly setting authentication strength, particularly when dealing with communication terminals with random versus non-random MAC addresses, which affects security and operational costs.

Method used

An authentication system that includes an authentication server and device, which selects an appropriate authentication method from a plurality of methods based on RADIUS attribute information, such as the MAC address type, to dynamically adjust authentication strength.

Benefits of technology

This approach allows for flexible setting of authentication strength, enhancing security for communication terminals with random MAC addresses while minimizing operational costs and maintaining convenience and versatility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007692442000001
    Figure 0007692442000001
  • Figure 0007692442000002
    Figure 0007692442000002
  • Figure 0007692442000003
    Figure 0007692442000003
Patent Text Reader

Abstract

To provide an authentication server and an authentication system capable of flexibly setting an authentication intensity.SOLUTION: A communication terminal 13 operates as a supplicant based on IEEE802.1X standard. An authentication server 10 authenticates the communication terminal 13 on the basis of IEEE802.1X standard. An authentication device 12 operates as an authenticator based on IEEE802.1X standard, communicates an EAPOL frame with the communication terminal 13, and communicates a RADIUS packet with the authentication server 10. The authentication server 10 selects one authentication method from among a plurality of authentication methods on the basis of RADIUS attribute information included in the RADIUS packet obtained from the authentication device 12, and proposes usage of the selected authentication method to the communication terminal 13.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication system and an authentication server.

Background Art

[0002] Patent Document 1 discloses a relay device capable of determining whether to connect even to a communication terminal with a randomized MAC address. When the MAC address included in the connection request from the communication terminal does not correspond to the registered MAC address, the relay device executes a connection process for temporary connection determination to obtain the host name from the communication terminal. Then, the relay device permits the connection when the obtained host name corresponds to the registered host name.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In an authentication system including a wired LAN or a wireless LAN, authentication based on the IEEE802.1X standard is widely used. In the IEEE802.1X standard, authentication is performed using the EAP (Extensible Authentication Protocol) and RADIUS (Remote Authentication Dial In User Service) standards. EAP defines procedures for using various authentication methods. The RADIUS standard defines procedures for performing authentication using a RADIUS server for an authentication request from a RADIUS client.

[0005] In such an authentication system, the authentication strength can be changed depending on the authentication method used. For example, when using an authentication method with low authentication strength, since it is not necessary to implement advanced functions on the communication terminal, which is the device to be authenticated, the security level may be insufficient. On the other hand, from the viewpoints of operation cost, convenience, or versatility, it is beneficial. On the contrary, when using an authentication method with high authentication strength, since it is necessary to implement advanced functions on the communication terminal, the security level can be sufficient, but it is disadvantageous from the viewpoints of operation cost, convenience, or versatility. Therefore, in consideration of such a balance, a mechanism that can flexibly set the authentication strength is desired.

[0006] As a specific example, assume an authentication system in which communication terminal A having a random MAC address and communication terminal B having a non-random MAC address coexist as described in Patent Document 1. In communication terminal A having a random MAC address, unlike communication terminal B having a non-random MAC address, it may be difficult to track the behavior of the communication terminal from the communication log including the MAC address. For this reason, it is desirable to apply an authentication method with higher authentication strength to communication terminal A than to communication terminal B. However, if everything is unified to an authentication method with high authentication strength, for example, a situation where the convenience when using communication terminal B is impaired or a situation where the existing communication terminal B cannot support the authentication method may occur.

[0007] The present invention has been made in view of such circumstances, and one of its objects is to provide an authentication server and an authentication system capable of flexibly setting the authentication strength.

[0008] The above and other objects and novel features of the present invention will become apparent from the description of this specification and the accompanying drawings.

Means for Solving the Problems

[0009] Briefly explaining the outline of a typical embodiment among the inventions disclosed in the present application, it is as follows.

[0010] An authentication system according to an embodiment includes a communication terminal, an authentication server, and an authentication device. The communication terminal operates as a supplicant based on the IEEE802.1X standard. The authentication server authenticates the communication terminal based on the IEEE802.1X standard. The authentication device operates as an authenticator based on the IEEE802.1X standard, communicates EAPOL frames with the communication terminal, and communicates RADIUS packets with the authentication server. The authentication server selects one authentication method from a plurality of authentication methods based on the RADIUS attribute information included in the RADIUS packet from the authentication device, and proposes to the communication terminal the use of the selected authentication method.

Advantages of the Invention

[0011] Among the inventions disclosed in the present application, the effects obtained by typical embodiments will be briefly described. The authentication strength can be flexibly set.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2A

Figure 2B

Figure 3

Figure 4A

Figure 4B

Figure 5

Embodiments for Carrying Out the Invention

[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In all the drawings for explaining the embodiments, the same members are generally denoted by the same reference numerals, and repeated explanations thereof are omitted.

[0014] <Outline of the Authentication System> FIG. 1 is a schematic diagram showing a configuration example and a main operation example of an authentication system according to an embodiment. The authentication system shown in FIG. 1 includes an authentication server 10, authentication devices 12a and 12b, and communication terminals 13a and 13b. The authentication devices 12a and 12b and the authentication server 10 are connected via a layer 3 (L3) network 11. Also, the authentication devices 12a and 12b and the communication terminals 13a and 13b are connected via a layer 2 (L2) network. In the specification, the communication terminals 13a and 13b are collectively referred to as the communication terminal 13, and the authentication devices 12a and 12b are collectively referred to as the authentication device 12.

[0015] The communication terminal 13 operates as a supplicant based on the IEEE802.1X standard. Specifically, the communication terminal 13 has, for example, a processor and a memory, and operates as a supplicant by executing a program for the supplicant stored in the memory by the processor. In this example, the communication terminal 13a is a personal computer (PC) or the like, and the communication terminal 13b is a mobile device such as a smartphone or a tablet PC. The communication terminal 13a is used by the user 14a, and the communication terminal 13b is used by the user 14b.

[0016] The authentication server 10 is a RADIUS server, and based on the IEEE802.1X standard, authenticates the communication terminal 13 via the authentication device 12. The authentication device 12 operates as an authenticator based on the IEEE802.1X standard and is also a RADIUS client. The authentication devices 12a and 12b communicate EAPOL (EAP Over LAN) frames with the communication terminals 13a and 13b respectively. Also, the authentication devices 12a and 12b communicate RADIUS packets with the authentication server 10.

[0017] Here, for example, the authentication device 12a is an authentication switch that relays MAC (Medium Access Control) frames by wire, and the authentication device 12b is a wireless access point that relays MAC frames wirelessly. In particular, communication terminals 13 used in wireless communication networks such as public wireless LANs may have a random MAC address from the perspective of protecting user privacy. Therefore, in this example, the communication terminal 13b has a random MAC address, and the communication terminal 13a has a non-random MAC address.

[0018] Unlike a non-random MAC address, in a random MAC address, (the 42nd and 41st bits) in the 48-bit MAC address are fixed to (1, 0). That is, a random MAC address, using hexadecimal notation and with "X" as the don't care value, is either "X2:XX:XX:XX:XX:XX", "X6:XX:XX:XX:XX:XX", "XA:XX:XX:XX:XX:XX", or "XE:XX:XX:XX:XX:XX".

[0019] In such an authentication system, assume a case where the communication terminal 13a is authenticated. Generally speaking, first, the communication terminal 13a transmits authentication information to the authentication device 12a using an EAPOL frame (step S101a). In response to this, the authentication device 12a transmits a RADIUS packet containing various RADIUS attribute information to the authentication server 10 (step S102a). The RADIUS attribute information may include, in addition to the authentication information contained in the EAPOL frame, the authentication information added by the authentication device 12a.

[0020] Subsequently, the authentication server 10 selects one authentication method from a plurality of pre-provided authentication methods based on the RADIUS attribute information contained in the RADIUS packet from the authentication device 12a (step S103). Then, the authentication server 10 proposes the use of the selected authentication method to the communication terminal 13a via the authentication device 12a. Specifically, the authentication server 10 transmits a RADIUS packet for proposing the use of the selected authentication method to the authentication device 12a (step S104a). In response to this, the authentication device 12a converts the RADIUS packet into an EAPOL frame and transmits it to the communication terminal 13a (step S105a).

[0021] When authenticating the communication terminal 13b, similar to the case of the communication terminal 13a, the processes of steps S101b, S102b, S103, S104b, and S105b corresponding to the processes of steps S101a, S102a, S103, S104a, and S105a are respectively performed. However, in steps S101a and S105a, wired communication is performed, while in steps S101b and S105b, wireless communication is performed.

[0022] By using such a method, it becomes possible to flexibly set the authentication strength based on various information obtained from the RADIUS attribute information. As a specific example, the authentication device 12 can define the MAC address of the communication terminal 13 included in the EAPOL frame from the communication terminal 13 as the calling station ID which is one of the RADIUS attribute information. Then, the authentication device 12 can send the RADIUS packet including the calling station ID to the authentication server 10 (steps S102a, S102b).

[0023] In this case, the authentication server 10 can determine whether the MAC address of the communication terminal 13 is a non-random MAC address or a random MAC address based on the value of the calling station ID, specifically, the values of the (42nd bit, 41st bit) described above. Then, when the MAC address of the communication terminal 13 is a random MAC address, the authentication server 10 can select an authentication method with a higher authentication strength than when it is a non-random MAC address (step S103).

[0024] In the communication terminal 13b having a random MAC address, different from the communication terminal 13a having a non-random MAC address, it may be difficult to track the behavior of the communication terminal 13b from the communication log including the MAC address. For this reason, it is desirable to apply an authentication method with a higher authentication strength to the communication terminal 13b than to the communication terminal 13a. By using the authentication system shown in FIG. 1, it becomes possible to satisfy such a requirement.

[0025] As a plurality of authentication methods provided in advance in the authentication server 10, for example, PEAP (Protected EAP), EAP-TLS (EAP-Transport Level Security), EAP-MD5 (EAP-Message Digest 5), EAP-TTLS (EAP-Tunneled TLS), etc. can be mentioned. PEAP and EAP-TTLS are authentication methods using the server certificate in the authentication server 10 and the user ID and user password in the communication terminal 13. EAP-TLS is an authentication method using the server certificate in the authentication server 10 and the client certificate in the communication terminal 13. EAP-MD5 is an authentication method using the user ID and user password in the communication terminal 13 without using a server certificate.

[0026] The authentication strength is the highest for EAP-TLS that uses server certificates and client certificates, and the lowest for EAP-MD5 that uses neither server certificates nor client certificates. However, when using EAP-TLS, in particular, it is necessary to pre-incorporate a client certificate in the communication terminal 13, which may be disadvantageous in terms of operation cost, convenience, or versatility. Also, PEAP is, for example, natively supported by communication terminals 13 equipped with an OS such as Windows (registered trademark). Therefore, PEAP is an authentication method with an excellent balance between operation cost, convenience, or versatility and authentication strength.

[0027] Assuming that such authentication methods are provided, when the MAC address of the communication terminal 13 is a random MAC address, that is, when authenticating the communication terminal 13b, it is desirable for the authentication server 10 to select EAP-TLS as the authentication method. On the other hand, when the MAC address of the communication terminal 13 is a non-random MAC address, that is, when authenticating the communication terminal 13a, it is desirable for the authentication server 10 to select PEAP as the authentication method.

[0028] <Details of the authentication system> FIG. 2A is a schematic diagram showing an example of the format configuration of an EAPOL frame used in the communication between the authentication device 12 and the communication terminal 13 in the authentication system shown in FIG. 1. The EAPOL frame 20 shown in FIG. 2A is also a MAC frame based on the EAPOL protocol. The EAPOL frame 20 includes areas for a destination MAC address 30, a source MAC address 31, and an EAP message 32. The EAP message 32 includes areas for a packet type 33 and a packet body 34. The packet body 34 includes an EAP packet 21. The EAP packet 21 includes areas for a code 35, a type 36, and data 37.

[0029] In the packet type 33, functions to be carried by the packet, such as an EAP packet, EAP start, or EAP end, are set. When an EAP packet is set by the packet type 33, the content of an instruction or notification, such as an EAP request, EAP response, EAP success, or EAP failure, is set by the code 35 in the EAP packet 21. Further, the content of a notification such as "Identity" or "NAK" and the type of an authentication method such as EAP-TLS or PEAP are set by the type 36. In the area of the data 37, respective data corresponding to the set content of the code 35 or the type 36 are stored. Note that EAP success represents successful authentication, and EAP failure represents failed authentication.

[0030] FIG. 2B is a schematic diagram showing an example of the format configuration of a RADIUS packet used in the communication between the authentication device 12 and the authentication server 10 in the authentication system shown in FIG. 1. As shown in FIG. 2B, the RADIUS packet 26 is stored in the area of UDP data 42 in a UDP (User Datagram Protocol) packet 25. The UDP packet 25 includes areas for a source port 40 and a destination port 41 in addition to the area of the UDP data 42. Prescribed values representing RADIUS are stored in the areas of the source port 40 and the destination port 41.

[0031] The RADIUS packet 26 includes areas for a code 43, an authentication code 44, and attributes 45. In the code 43, the content of an instruction or notification is set, such as a RADIUS access request, a RADIUS access grant, a RADIUS access rejection, a RADIUS access challenge, and the like. The area of the authentication code 44 is used to prevent forgery of data. The attributes 45 include areas for an arbitrary number n of RADIUS attribute information 46[1] to 46[n]. In the specification, the n pieces of RADIUS attribute information 46[1] to 46[n] are collectively referred to as RADIUS attribute information 46. Each RADIUS attribute information 46 is represented in a TLV format consisting of a type (T), a length (L), and an attribute value (V).

[0032] The RADIUS attribute information 46 may include various authentication information, for example, represented by a user ID, a user password, a NAS-IP address, a calling station ID, a cold station ID, and the like. The NAS-IP address is defined as the IP address of the authentication device 12. The calling station ID is defined as the MAC address of the communication terminal 13 as described above. The cold station ID is defined as the MAC address of the authentication device 12 and, in addition, the SSID (Service Set Identifier) used by the communication terminal 13.

[0033] Also, the RADIUS attribute information 46 can include the information of the EAP message 32 shown in FIG. 2A. Thereby, the authentication device 12 can receive the EAPOL frame 20 from the communication terminal 13, store the EAP message 32 included therein in the RADIUS packet 26, and transmit it to the authentication server 10. Similarly, the authentication device 12 can receive the RADIUS packet 26 from the authentication server 10, store the RADIUS attribute information 46 representing the EAP message 32 included therein in the EAPOL frame 20, and transmit it to the communication terminal 13.

[0034] Figure 3 is a sequence diagram showing an operation example when authenticating a communication terminal 13a having a non-random MAC address in the authentication system shown in FIG. 1. In FIG. 3, the communication terminal 13a notifies the authentication device 12a of the start of EAP (step S201). The authentication device 12a notified of the start of EAP transmits an EAP request for requesting a user ID, which is one of the authentication information, to the communication terminal 13a (step S202). In response to this, the communication terminal 13a transmits an EAP response including the user ID to the authentication device 12a (step S203).

[0035] Subsequently, the authentication device 12a that has received the EAP response transmits a RADIUS access request including various RADIUS attribute information 46 to the authentication server 10 (step S204). At this time, the RADIUS attribute information 46 includes, in addition to the authentication information contained in the EAP message 32 in the EAP response, such as the user ID, also the calling station ID, etc. Specifically, the authentication device 12a determines the MAC address of the communication terminal 13a, for example, the source MAC address 31, included in the EAPOL frame 20 from the communication terminal 13a as the calling station ID. Then, the authentication device 12a transmits a RADIUS access request including the calling station ID, etc. to the authentication server 10.

[0036] Next, the authentication server 10 that has received the RADIUS access request determines whether the MAC address of the communication terminal 13a is a non-random MAC address or a random MAC address based on the value of the calling station ID (step S205). The determination result here is a non-random MAC address. Therefore, the authentication server 10 selects PEAP as the authentication method (step S205).

[0037] Subsequently, the authentication server 10 transmits a RADIUS access challenge for proposing the use of PEAP to the authentication device 12a (step S206). The authentication device 12a that has received the RADIUS access challenge transmits an EAP request for proposing the use of PEAP to the communication terminal 13a (step S207). In response, the communication terminal 13a transmits an EAP response for accepting the use of PEAP to the authentication device 12a (step S208).

[0038] Next, the authentication device 12a that has received the EAP response transmits a RADIUS access request for accepting the use of PEAP to the authentication server 10 (step S209). In response, the authentication server 10 transmits a RADIUS access challenge for notifying the start of PEAP authentication to the authentication device 12a (step S210). Then, the authentication device 12a that has received the RADIUS access challenge transmits an EAP request for notifying the start of PEAP authentication to the communication terminal 13a (step S211).

[0039] Thereafter, an authentication sequence defined by PEAP is executed among the communication terminal 13a, the authentication device 12a, and the authentication server 10 (step S212). Roughly speaking, a TLS session for performing encryption protection is constructed between the communication terminal 13a and the authentication server 10 through TLS negotiation using a server certificate. Then, the authentication server 10 determines whether the user ID and user password in the communication terminal 13a are authenticated or not using a challenge-response method within the TLS session.

[0040] As a result, when the authentication server 10 permits authentication, it notifies the authentication device 12a of a RADIUS access permission indicating authentication success, and when it rejects authentication, it notifies the authentication device 12a of a RADIUS access rejection indicating authentication failure. The authentication device 12a converts the RADIUS access permission or RADIUS access rejection into an EAP success and an EAP failure, respectively, and notifies the communication terminal 13a.

[0041] Figures 4A and 4B are sequence diagrams showing examples of operations when authenticating communication terminal 13b having a random MAC address in the authentication system shown in FIG. 1. FIG. 4A shows an example of an operation when a client certificate is incorporated in communication terminal 13b, and FIG. 4B shows an example of an operation when a client certificate is not incorporated in communication terminal 13b.

[0042] In FIG. 4A, first, similar to the case of FIG. 3, the processes of steps S201 to S204 are performed. That is, communication terminal 13b notifies authentication device 12b of the start of EAP, authentication device 12b transmits an EAP request to communication terminal 13b, and communication terminal 13b transmits an EAP response to authentication device 12b (steps S201 to S203). Then, authentication device 12b transmits a RADIUS access request to authentication server 10 (step S204).

[0043] Subsequently, authentication server 10 that has received the RADIUS access request determines, similar to the case of FIG. 3, whether the MAC address of communication terminal 13b is a non-random MAC address or a random MAC address based on the value of the calling station ID (step S305). The determination result here is a random MAC address, different from the case of FIG. 3. Therefore, authentication server 10 selects EAP-TLS as the authentication method (step S305).

[0044] Thereafter, in steps S306 to S311, processes similar to the processes of steps S206 to S211 described in FIG. 3 are performed. However, in steps S306 and S307, the authentication method proposed by authentication server 10 is EAP-TLS, different from the case of FIG. 3. Also, a client certificate is incorporated in communication terminal 13b. Therefore, after communication terminal 13b is proposed to use EAP-TLS by authentication server 10, it accepts the proposal (steps S308 and S309). In response to this, authentication server 10 notifies communication terminal 13b of the start of EAP-TLS authentication (steps S310 and S311).

[0045] Thereafter, an authentication sequence defined by EAP-TLS is executed between the communication terminal 13b, the authentication device 12b, and the authentication server 10 (step S312). Generally, through TLS negotiation, the validity of the server certificate from the authentication server 10 is verified by the communication terminal 13b, and the validity of the client certificate from the communication terminal 13b is verified by the authentication server 10.

[0046] When these certificates are valid, the authentication server 10 notifies the authentication device 12b of a RADIUS access permission indicating authentication success, and when any of the certificates is invalid, the authentication server 10 notifies the authentication device 12b of a RADIUS access rejection indicating authentication failure. The authentication device 12b converts the RADIUS access permission or RADIUS access rejection into EAP success and EAP failure, respectively, and notifies the communication terminal 13b.

[0047] Also in FIG. 4B, the processes of steps S201 to S204 and S305 to S307 are performed in order as in the case of FIG. 4A. However, different from the case of FIG. 4A, a client certificate is not incorporated in the communication terminal 13b. For this reason, after the communication terminal 13b is proposed to use EAP-TLS (steps S306, S307), the communication terminal 13b rejects the proposal (step S408).

[0048] Specifically, for example, the communication terminal 13b transmits an EAP response for rejecting the use of EAP-TLS and proposing the use of PEAP to the authentication device 12b (step S408). The authentication device 12b converts the EAP response into a RADIUS access request and transmits it to the authentication server 10 (step S409). Here, when the authentication server 10 determines that the MAC address of the communication terminal 13b is a random MAC address, only the use of EAP-TLS is permitted and the use of other authentication methods is prohibited. For this reason, after proposing the use of EAP-TLS, when the proposal is rejected by the communication terminal 13b, the authentication server 10 determines authentication failure without changing to another authentication method, here PEAP.

[0049] As a result, the authentication server 10 notifies the authentication device 12b of a RADIUS access rejection indicating authentication failure (step S410). The authentication device 12b converts the RADIUS access rejection into an EAP failure and notifies the communication terminal 13b (step S411). Thereafter, the authentication device 12b blocks access from the communication terminal 13b to a predetermined network. This makes it possible to enhance the security for the communication terminal 13b having a random MAC address.

[0050] <Regarding the modification example> In FIGS. 3, 4A, and 4B, an example of selecting a proposed authentication method based on the calling station ID, which is one of the RADIUS attribute information 46, that is, the MAC address of the communication terminal 13, is shown. However, the RADIUS attribute information 46 used for selecting the authentication method is not limited to the calling station ID, and may be, for example, the NAS-IP address, the cold station ID, or the like.

[0051] These RADIUS attribute information 46 includes the IP address and MAC address of the authentication device 12, and the SSID used by the communication terminal 13b. Thereby, for example, when a plurality of authentication devices 12 are provided, it becomes possible to change the authentication method for each authentication device 12, and thus for each single or multiple communication terminals 13 for each authentication device 12, or to change the authentication method for each SSID.

[0052] In addition, the RADIUS attribute information 46 from the authentication device 12a may include, for example, an identifier of the physical port to which the communication terminal 13a is connected. In this case, it becomes possible to change the authentication method for each physical port, and thus for each communication terminal 13a for each physical port.

[0053] <Details of the authentication server> FIG. 5 is a functional block diagram showing a configuration example of the main part of the authentication server 10 in FIG. 1. The authentication server 10 shown in FIG. 5 includes an attribute information determination unit 50, an authentication method selection unit 51, an authentication method proposal unit 52, and an authentication sequence execution unit 53. Each of these units is realized, for example, by a processor executing a program stored in a memory. However, each of these units is not limited to program processing by a processor, and may be realized by hardware processing using an FPGA (Field Programmable Gate Array), an ASIC (Application Specific Integrated Circuit), etc., or may be realized by a combination of program processing and hardware processing.

[0054] The attribute information determination unit 50 determines the content of the RADIUS attribute information 46 included in the RADIUS packet 26 from the authentication device 12 operating as an authenticator. The authentication method selection unit 51 selects one authentication method from a plurality of authentication methods based on the determination result by the attribute information determination unit 50. That is, the attribute information determination unit 50 and the authentication method selection unit 51 execute the processes of step S205 shown in FIG. 3 and step S305 shown in FIGS. 4A and 4B, for example.

[0055] The authentication method proposal unit 52 proposes the use of the authentication method selected by the authentication method selection unit 51 to the communication terminal 13 operating as a supplicant. In addition, after the authentication method proposal unit 52 proposes the use of the selected authentication method to the communication terminal 13, when the proposal is rejected by the communication terminal 13, the authentication method proposal unit 52 notifies the communication terminal 13 of authentication failure. However, at this time, the authentication method proposal unit 52 may determine whether to change to another authentication method according to the determination result by the attribute information determination unit 50 before notifying the authentication failure.

[0056] For example, as shown in FIG. 3, when the discrimination result in the attribute information discrimination unit 50 is a non-random MAC address and, in step S208, if the use of PEAP is rejected, the authentication method proposal unit 52 may change PEAP to another authentication method through negotiation with the communication terminal 13a. On the other hand, as shown in FIG. 4B, when the discrimination result in the attribute information discrimination unit 50 is a random MAC address and the use of EAP-TLS is rejected, the authentication method proposal unit 52 does not change to another authentication method and notifies the communication terminal 13b of the authentication failure.

[0057] Note that when the communication terminal 13 accepts the proposal of the use of the authentication method by the authentication method proposal unit 52, the authentication method proposal unit 52 determines the authentication method and notifies the communication terminal 13 to start authentication using the determined authentication method. That is, the authentication method proposal unit 52 executes the processes of steps S206 and S210 shown in FIG. 3, steps S306 and S310 shown in FIG. 4A, and steps S306 and S410 shown in FIG. 4B, for example.

[0058] The authentication sequence execution unit 53 receives the information on the determined authentication method from the authentication method proposal unit 52 and executes an authentication sequence based on the authentication method. That is, the authentication sequence execution unit 53 executes the processes of step S212 shown in FIG. 3 and step S312 shown in FIG. 4A, for example.

[0059] <Principal effects of the embodiment> As described above, in the method of the embodiment, the authentication server 10 selects one authentication method from a plurality of authentication methods based on the RADIUS attribute information 46. Thereby, an authentication server and an authentication system capable of flexibly setting the authentication strength can be realized. In particular, based on the RADIUS attribute information 46, it is determined whether the communication terminal 13 has a random MAC address, and by selecting an authentication method having a high authentication strength only when it has a random MAC address, it is possible to enhance security while suppressing an increase in operation costs and the like.

[0060] As described above, the invention made by the present inventor has been specifically described based on the embodiments. However, the present invention is not limited to the above embodiments, and various modifications can be made without departing from the gist thereof. For example, the above-described embodiments have been described in detail for easy understanding of the present invention, and are not necessarily limited to those having all the configurations described. Also, a part of the configuration of one embodiment can be replaced with the configuration of another embodiment, and the configuration of another embodiment can be added to the configuration of one embodiment. Further, for a part of the configuration of each embodiment, addition, deletion, or replacement with other configurations is possible.

[0061] For example, the above-described program can be stored in a non-temporary tangible computer-readable recording medium and then supplied to a computer. Examples of such a recording medium include magnetic recording media typified by a hard disk drive, etc., optical recording media typified by a DVD (Digital Versatile Disc), a Blu-ray Disc, etc., and semiconductor memories typified by a flash memory, etc.

Explanation of Reference Numerals

[0062] 10: Authentication server, 12: Authentication device, 13: Communication terminal, 20: EAPOL frame, 26: RADIUS packet, 46: RADIUS attribute information, 50: Attribute information discrimination unit, 51: Authentication method selection unit, 52: Authentication method proposal unit

Claims

1. A communication terminal operating as a supplicant based on the IEEE 802.1X standard, An authentication server that authenticates the communication terminal based on the IEEE 802.1X standard, An authentication device that operates as an authenticator based on the IEEE 802.1X standard, communicates EAPOL (Extensible Authentication Protocol Over LAN) frames with the communication terminal, and communicates RADIUS (Remote Authentication Dial In User Service) packets with the authentication server, An authentication system comprising: The authentication server selects one authentication method from a plurality of authentication methods based on the RADIUS attribute information included in the RADIUS packet from the authentication device, and proposes the use of the selected authentication method to the communication terminal, The communication terminal has a non-random MAC address or a random MAC address as its MAC address, The authentication device determines the MAC address of the communication terminal included in the EAPOL frame from the communication terminal as the calling station ID which is one of the RADIUS attribute information, and transmits the RADIUS packet including the calling station ID to the authentication server, The authentication server determines whether the MAC address of the communication terminal is the non-random MAC address or the random MAC address based on the value of the calling station ID, and when it is the random MAC address, selects an authentication method with a higher authentication strength than when it is the non-random MAC address, Authentication system.

2. In the authentication system according to Claim 1, When the MAC address of the communication terminal is the random MAC address, the authentication server selects EAP-TLS (EAP-Transport Level Security), and when it is the non-random MAC address, selects PEAP (Protected EAP), Authentication system.

3. In the authentication system according to Claim 1, When the MAC address of the communication terminal is the random MAC address, after the authentication server proposes to the communication terminal to use the selected authentication method, if the proposal is rejected by the communication terminal, the authentication server notifies the communication terminal of authentication failure without changing to another authentication method. Authentication system.

4. An authentication server that authenticates a communication terminal operating as a supplicant via an authenticator based on the IEEE 802.1X standard, An attribute information discrimination unit that discriminates the content of RADIUS attribute information included in a RADIUS (Remote Authentication Dial In User Service) packet from the authenticator; An authentication method selection unit that selects one authentication method from a plurality of authentication methods based on the discrimination result by the attribute information discrimination unit; An authentication method proposal unit that proposes to the supplicant to use the authentication method selected by the authentication method selection unit; Comprising The communication terminal has a non-random MAC address or a random MAC address as the MAC address, The authenticator determines the MAC address of the communication terminal as a calling station ID which is one of the RADIUS attribute information, and transmits the RADIUS packet including the calling station ID to the authentication server. The attribute information discrimination unit discriminates whether the MAC address of the communication terminal is the non-random MAC address or the random MAC address based on the value of the calling station ID. When the MAC address of the communication terminal is the random MAC address, the authentication method selection unit selects an authentication method with a higher authentication strength than when the MAC address is the non-random MAC address. Authentication server.

5. In the authentication server according to claim 4, When the MAC address of the communication terminal is the random MAC address, the authentication method selection unit selects EAP-TLS (Extensible Authentication Protocol-Transport Level Security), and when the MAC address is the non-random MAC address, the authentication method selection unit selects PEAP (Protected EAP). Authentication server.

6. In the authentication server according to claim 4, When the MAC address of the communication terminal is the random MAC address, the authentication method proposal unit proposes to the communication terminal to use the selected authentication method, and when the proposal is rejected by the communication terminal, it notifies the communication terminal of authentication failure without changing to another authentication method. Authentication server.

Citation Information

Patent Citations

  • Recipient authentication method, inter-network connection device therefor and recipient authentication system

    JP2005011245A

  • Wireless communication system and terminal management method

    JP2011239152A

  • Communication system, information appliance, communication method and program

    JP2015019267A

  • Communication device, communication method, and program

    JP2017201774A

  • Terminal authentication management system and method thereof, and program thereof

    JP2020107078A