Wireless communication device, communication control method, and program
The wireless communication device adjusts RADIUS re-authentication intervals based on failure thresholds to stabilize network communication and security, addressing the challenges of frequent failures and security compromise.
Patent Information
- Application Number
- JP2021203459
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-12-15
- Publication Date
- 2025-10-07
- Estimated Expiration
- 2041-12-15
AI Technical Summary
Frequent RADIUS re-authentication failures lead to network communication problems, while extending the re-authentication interval compromises network security, and users lack knowledge to set appropriate intervals.
A wireless communication device adjusts the RADIUS re-authentication interval based on the number of failures and a threshold value for each connected terminal, extending the interval when failures exceed a threshold and shortening it when failures are low.
This approach stabilizes network communication and maintains security by dynamically adjusting the re-authentication interval, simplifying user settings without requiring environmental knowledge.
Smart Images

Figure 0007750077000001 
Figure 0007750077000002 
Figure 0007750077000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a wireless communication device, a communication control method, and a program. [Background technology]
[0002] Conventionally, there have been communication systems that require authentication for connection of communication terminals to a network. In such communication systems, in order to manage authentication information of the communication terminals, the communication terminals are periodically authenticated by an authentication server connected to a network device such as an access point. For example, the network device is authenticated according to IEEE (Institute of Electrical and Electronics Engineers) 802.1X. As an authentication method, RADIUS (Remote Authentication Dial-in User Service) authentication is applied. A RADIUS server is used as the server for RADIUS authentication. Patent Document 1 discloses a method for preventing quality degradation by monitoring communication conditions and initiating RADIUS re-authentication processing only when the communication conditions are good while a real-time application is running. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-197462 Summary of the Invention [Problem to be solved by the invention]
[0004] On the other hand, if the periodic RADIUS re-authentication fails, the communication terminal's network communication will be disconnected. Frequent RADIUS re-authentication failures may lead to network communication problems. On the other hand, if the RADIUS re-authentication interval is extended, it becomes difficult to maintain a network security environment. For this reason, it is expected that users will change the RADIUS re-authentication interval themselves. However, users do not have sufficient knowledge of the conditions under which they should change the RADIUS re-authentication interval.
[0005] One of the objects of the present invention is to easily set an appropriate RADIUS re-authentication interval. [Means for solving the problem]
[0006] According to one embodiment of the present invention, there is provided a wireless communication device having a control unit that changes the RADIUS re-authentication interval used by a RADIUS server based on the number of RADIUS re-authentication failures in each of multiple communication terminals connected to the wireless communication device and a first threshold value.
[0007] Furthermore, according to one embodiment of the present invention, a communication control method is provided in which a wireless communication device changes the RADIUS re-authentication interval used by a RADIUS server based on the number of RADIUS re-authentication failures and a first threshold value in each of a plurality of communication terminals connected to the wireless communication device.
[0008] Furthermore, according to one embodiment of the present invention, a program is provided that causes a computer to change the RADIUS re-authentication interval used by the RADIUS server based on the number of RADIUS re-authentication failures and a first threshold value in each of multiple communication terminals connected to a wireless communication device. [Effects of the Invention]
[0009] According to the present invention, the RADIUS re-authentication interval can be easily set. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a diagram illustrating a configuration of a communication system according to a first embodiment of the present invention. [Figure 2] 4 is a flowchart illustrating a communication control process in the first embodiment of the present invention. [Figure 3] 4 is a flowchart illustrating an initialization process according to the first embodiment of the present invention. [Figure 4] FIG. 4 is a diagram illustrating a RADIUS re-authentication interval setting process according to the first embodiment of the present invention. [Figure 5] FIG. 4 is a diagram illustrating a data table of RADIUS re-authentication results in the first embodiment of the present invention. [Figure 6] FIG. 4 is a diagram illustrating a data table of the number of RADIUS re-authentication failures in the first embodiment of the present invention. [Figure 7] FIG. 4 is a diagram illustrating a data table of the number of RADIUS re-authentication failures in the first embodiment of the present invention. [Figure 8] 10 is a flowchart illustrating a RADIUS re-authentication interval change process according to the first embodiment of the present invention. [Figure 9] 10 is a flowchart illustrating a RADIUS re-authentication interval change process according to the second embodiment of the present invention. [Figure 10] 13 is a flowchart illustrating a RADIUS re-authentication interval change process according to the third embodiment of the present invention. [Figure 11] FIG. 13 is a diagram illustrating a RADIUS re-authentication interval setting process according to the fourth embodiment of the present invention. [Figure 12] FIG. 10 is a diagram illustrating the configuration of a communication system according to a fifth embodiment of the present invention. [Figure 13] 13 is a flowchart illustrating an initialization process according to a sixth embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0011] A communication system according to one embodiment of the present invention will be described in detail below with reference to the drawings. The embodiment described below is merely an example of an embodiment of the present invention, and the present invention should not be construed as being limited to these embodiments. In the drawings referred to in this embodiment, identical parts or parts having similar functions are designated by the same or similar reference symbols (reference symbols consisting of a number followed by A, B, etc.), and repeated explanations of such parts may be omitted.
[0012] First Embodiment [1-1. Overall configuration of the communication system] FIG. 1 is a diagram illustrating the configuration of a communication system 1. The communication system 1 includes an access point 3, a communication terminal 5, and a router 9. The communication system 1 in this embodiment is realized by the access point 3 that relays wireless communication. The access point 3 is capable of executing processing equivalent to a RADIUS authentication function. The access point 3 can easily set a RADIUS re-authentication interval according to the user's usage environment and perform wireless communication using the method described below. The access point in this embodiment will be described below.
[0013] [1-2. Access point configuration] The access point 3 is a device that provides a wireless LAN (Local Area Network) environment for multiple communication terminals 5, and is a device that acts as a relay for connecting the communication terminals 5 to a WAN (Wide Area Network) such as the Internet via a router 9. The access point 3 is also called a wireless communication device. Note that, although two communication terminals 5 (communication terminal 5a and communication terminal 5b) are shown in FIG. 1, this is not limiting. The communication system 1 may include only one communication terminal, or may include three or more communication terminals.
[0014] The access point 3 includes a communication module Ma10, a control unit 50, a storage unit 70, an operation unit 80, and a communication module Mz90. These components are connected to one another by a bus.
[0015] The communication module Ma10 performs wireless communication (in this example, wireless communication Csa and Csb) with the communication terminal 5 using a channel set by the control unit 50 among channels in the 5 GHz band. The channel set in the communication module Ma10 is selected from channels included in types W52, W53, and W56 in the IEEE802.11 standard. Note that the communication module Ma10 is not limited to a channel in the 5 GHz band, and may use a channel in the 2.4 GHz band.
[0016] In this example, the communication module Mz90 functions as a communication unit for communicating with the router 9 and communicating with other devices via the router 9. This communication may be wireless, for example, using the 2.4 GHz band or 5 GHz, or may be wired.
[0017] The storage unit 70 stores information such as a control program executed by the control unit 50 and various tables. The storage unit 70 stores, for example, a data table including date and time information (described later) and the RADIUS re-authentication result at that date and time. The operation unit 80 includes operators such as a power button and a setting button, accepts user operations on the operators, and outputs a signal corresponding to the operation to the control unit 50.
[0018] The control unit 50 includes a processing circuit such as a CPU and a memory. The control unit 50 executes a control program stored in the storage unit 70 using the CPU to realize various functions in the access point 3. The realized functions include a communication control function. This communication control function makes it possible to execute the processing described below (hereinafter referred to as communication control processing).
[0019] In this embodiment, the control unit 50 of the access point 3 has communication control functions as a RADIUS server and a RADIUS client. The RADIUS server function is a function that determines whether to authenticate (permit or deny) connection of the connected communication terminal 5 to the network. The RADIUS client function is a function that requests RADIUS authentication from the RADIUS server in response to a connection request from the communication terminal 5. If the RADIUS authentication by the RADIUS server is successful, the communication terminal 5 can communicate with other communication terminals 5 provided within the network and with servers connected to the network. On the other hand, if the RADIUS authentication by the RADIUS server fails, the communication terminal 5 cannot communicate with other communication terminals 5 provided within the network and with servers connected to the network.
[0020] The control program may be provided in a state stored in a computer-readable recording medium such as a magnetic recording medium, an optical recording medium, a magneto-optical recording medium, or a semiconductor memory, as long as it is executable by a computer. In this case, the access point 3 may be provided with a device for reading the recording medium. The control program may also be downloaded via a communication module. Next, the communication control process (communication control method) will be described.
[0021] [1-3. Communication control processing] The communication control process is started when the power is turned on at the access point 3. The communication control process may also be started in response to a request from the user to start the communication control process (start setting). FIG. 2 is a flowchart illustrating the communication control process in the first embodiment of the present invention. In this embodiment, the communication control process includes an initialization process S100 and a RADIUS re-authentication interval setting process S200. The initialization process S100 is a process for setting various conditions required for RADIUS re-authentication at the access point 3. The RADIUS re-authentication interval setting process S200 is a process for setting the RADIUS re-authentication interval depending on the result of RADIUS re-authentication for a predetermined period. When the communication control process is started, the control unit 50 first executes the initialization process S100.
[0022] [1-3-1. Initialization process] FIG. 3 is a flowchart showing the initialization process. As shown in FIG. 3, when the initialization process S100 starts, the control unit 50 performs a RADIUS re-authentication initial setting process for the communication module Ma10 (step S101). In the RADIUS re-authentication initial setting process, a time interval for performing RADIUS re-authentication (also referred to as a RADIUS re-authentication interval) is set as an initial condition. The set RADIUS re-authentication interval may be a predetermined re-authentication interval, may be the re-authentication interval set the previous time the power was turned off, or may be determined based on past history. The RADIUS re-authentication interval is stored in the storage unit 70. In this example, the control unit 50 sets the RADIUS re-authentication interval to "1 hour."
[0023] Next, the control unit 50 sets a period (also referred to as a first period) for RADIUS re-authentication to determine whether to change the RADIUS re-authentication interval (S103). The first period may be determined in advance, may be the condition set the last time the power was turned off, or may be determined based on past history. The set first period is stored in the storage unit 70. In this example, the control unit 50 sets the first period to "8 hours."
[0024] Next, the control unit 50 sets a threshold value (also referred to as a first threshold value) of the number of RADIUS re-authentication failures that determines whether to change the RADIUS re-authentication interval (S105). In this example, the first threshold value is set to "4 times" in accordance with the first period of "8 hours."
[0025] When the process of setting the first threshold (S105) is completed, the control unit 50 starts the process of setting the RADIUS re-authentication interval S200 to be used based on the number of currently connected communication terminals.
[0026] [1-3-2. RADIUS re-authentication interval setting process] In the RADIUS re-authentication interval setting process S200, first, the control unit 50 waits until a predetermined period (first period) has elapsed (S201; No). When the first period has elapsed (S201; Yes), the control unit 50 acquires the RADIUS re-authentication result (also referred to as a RADIUS re-authentication failure log) for the first period (S203). FIG. 5 shows a RADIUS re-authentication result data table 100 indicating the RADIUS re-authentication result in the communication terminal 5a. The RADIUS re-authentication result data table 100 includes date and time information 101 and a RADIUS authentication result 103 corresponding to the date and time information. In this example, the preset period is set to "8 hours," and RADIUS authentication is performed every hour. The acquired RADIUS re-authentication result is stored in the storage unit 70.
[0027] Next, the control unit 50 acquires the number of RADIUS re-authentication failures based on the acquired RADIUS re-authentication result (S205). The number of RADIUS re-authentication failures is the total number of times that RADIUS re-authentications performed at the above-mentioned RADIUS re-authentication intervals during the first period have failed. FIGS. 6 and 7 show a RADIUS re-authentication failure count data table 110. The RADIUS re-authentication failure count data table 110 includes a communication terminal name 111 and a RADIUS re-authentication failure count 113. As shown in FIG. 6, in the first case, the number of RADIUS re-authentication failures for the communication terminal 5a is "2 times," and the number of RADIUS re-authentication failures for the communication terminal 5b is "1 time." As shown in FIG. 7, in the second case, the number of RADIUS re-authentication failures for the communication terminal 5a is "0 times," and the number of RADIUS re-authentication failures for the communication terminal 5b is "5 times."
[0028] Next, the control unit 50 performs a process to change the RADIUS re-authentication interval (S207). FIG. 8 is an example of a flowchart showing the process to change the RADIUS re-authentication interval. As shown in FIG. 8, the control unit 50 determines whether the acquired number of RADIUS re-authentication failures is equal to or greater than a threshold (S2071). In this example, the control unit 50 makes the determination using the maximum value among the acquired numbers of RADIUS re-authentication failures.
[0029] For example, in the first case shown in Fig. 6, the maximum number of RADIUS re-authentication failures is "2 times." In this case, the control unit 50 determines that the number of RADIUS re-authentication failures is less than the threshold value of "4 times" (S2071; No). The control unit 50 maintains the RADIUS re-authentication interval (S2073). Therefore, the RADIUS re-authentication interval is maintained at "1 hour."
[0030] On the other hand, in the second case shown in Fig. 7, the maximum value of the number of RADIUS re-authentication failures is "5 times." In this case, the control unit 50 determines that the number of RADIUS re-authentication failures is greater than the threshold value of "4 times" (S2071; Yes). The control unit 50 changes the RADIUS re-authentication interval to extend it (S2075). Specifically, the RADIUS re-authentication interval is changed from "1 hour" to "12 hours." The control unit 50 repeats the communication module number change process S200 while the power is on.
[0031] The above communication control process ends when the power is turned off or when the access point 3 is switched to another communication control process.
[0032] As described above, in this embodiment, when the number of RADIUS re-authentication failures is low, stable network communication is achieved and a network security environment is maintained. Furthermore, when the number of RADIUS re-authentication failures is high, the occurrence of network communication problems can be reduced by increasing the RADIUS re-authentication interval. Therefore, by using this embodiment, the user does not need to understand the wireless environment in which they are using, and can easily set an appropriate RADIUS re-authentication interval to perform wireless communication.
[0033] Second Embodiment In this embodiment, a process for setting a RADIUS re-authentication interval that is different from that in the first embodiment will be described. Specifically, an example in which warning information is notified to a communication terminal after a process for changing the RADIUS re-authentication interval will be described. Note that a description of parts common to the first embodiment will be omitted as appropriate.
[0034] [2-1. Change in the number of communication modules] FIG. 9 is an example of a flowchart illustrating the RADIUS re-authentication interval change process S207A. As shown in FIG. 9, when the control unit 50 determines that the number of RADIUS re-authentication failures is equal to or greater than the threshold (S2071; Yes), the control unit 50 changes the RADIUS re-authentication interval so as to extend it (S2075). At this time, the control unit 50 notifies the network administrator of warning information indicating that the number of RADIUS re-authentication failures has exceeded the threshold (S2077). For example, in the second case, warning information indicating that the number of RADIUS re-authentication failures in the communication terminal 5b is equal to or greater than the first threshold is notified to the access point 3. At this time, the warning information may be displayed on a Web GUI (Graphical User Interface) of the access point, may be flashing a light, may be sent by email from the access point, or may be notified to an external management server or the like. The warning information may be displayed on a display unit of the communication terminal 5b, may be displayed as audio information, or may be notified by flashing a light of the communication terminal 5b. The warning information notified to the communication terminal 5b may also be sent to the communication terminal 5a. This makes it clear which communication terminal is experiencing the abnormality, making it easy to set an appropriate RADIUS re-authentication interval and creating a stable network environment.
[0035] <Third embodiment> In this embodiment, a communication system different from that of the first embodiment will be described. Specifically, an example will be described in which the RADIUS re-authentication interval is shortened when the number of RADIUS re-authentication failures in a predetermined period (first period) is less than a second threshold that is lower than a first threshold, and this state continues for a period (also referred to as a second period) longer than the first period. Note that descriptions of parts common to the first embodiment will be omitted as appropriate.
[0036] 10 is an example of a flowchart illustrating the RADIUS re-authentication interval change process S207B. As shown in FIG. 10, when the control unit 50 determines that the number of RADIUS re-authentication failures is equal to or greater than the first threshold (four times) (S2071; Yes), the control unit 50 changes the RADIUS re-authentication interval so as to extend it (S2075). When the control unit 50 determines that the number of RADIUS re-authentication failures is less than the first threshold (four times) (S2071; No), the control unit 50 may further determine whether the number of RADIUS re-authentication failures has remained below a second threshold, which is lower than the first threshold, for a certain period (second period) longer than the first period (S2072). For example, if the first period is "8 hours (one day)" and the RADIUS re-authentication interval is "one hour," the second threshold for the number of RADIUS re-authentication failures may be set to "one time" and the second period may be set to "one week." When the above condition is not met (S2072; No), the RADIUS re-authentication interval is maintained (S2073). If the above condition is met (S2072; Yes), the control unit 50 may change the RADIUS re-authentication interval to shorten it to "30 minutes" (S2074).
[0037] By using this embodiment, the RADIUS re-authentication interval can be controlled according to the network environment. In this example, the conditions for shortening the RADIUS re-authentication interval are stricter than those for extending it. This reduces the occurrence of network connection problems. Furthermore, if RADIUS re-authentication has been consistently successful over the long term, the RADIUS re-authentication interval is shortened. This allows an appropriate RADIUS re-authentication interval to be easily set, and also enhances the network security environment.
[0038] <Fourth embodiment> In this embodiment, an example will be described in which the RADIUS re-authentication interval setting process S200C is performed based on time information.
[0039] 11 is an example of a flowchart showing S200C. In the RADIUS re-authentication interval change process S200C, the control unit 50 acquires the number of times that RADIUS re-authentication has failed in each communication terminal within a predetermined period (S205), and then acquires date and time information (S206). The timing of acquiring the date and time information is not particularly limited. The date and time information may be acquired from within the access point 3 or from another device. The control unit 50 determines whether the acquired date and time information is a predetermined date and time (S208). If the acquired date and time information is not the predetermined time (S208; No), the control unit 50 performs a RADIUS re-authentication interval change process (S207). The RADIUS re-authentication interval change process S207 is as described in the first embodiment of the present invention.
[0040] On the other hand, if the acquired date and time information is a predetermined date and time (S208; Yes), the control unit 50 sets a specific RADIUS re-authentication interval (S209). The specific RADIUS re-authentication interval may be set based on the number of connected communication terminals and the date and time information. Specifically, the RADIUS re-authentication interval may be set to "1 hour" on Saturdays and Sundays when wireless network communication is low.
[0041] When this embodiment is used, a predetermined RADIUS re-authentication interval is set at a predetermined date and time, making it easy to set an appropriate RADIUS re-authentication interval.
[0042] Fifth Embodiment In this embodiment, a configuration of a communication system different from that of the first embodiment will be described. Specifically, an example in which the communication system includes a different access point will be described. Note that descriptions of parts common to the first embodiment will be omitted as appropriate.
[0043] FIG. 12 is a configuration diagram of a communication system 1D. As shown in FIG. 12, the communication system 1D includes an access point 4 in addition to an access point 3, a communication terminal 5, and a router 9. The access point 4 includes a communication module Mb20. The communication module Mb20 may have a configuration similar to that of the communication module Ma10 of the access point 3. The access points 3 and 4 are arranged in the same network segment. As shown in FIG. 12, the access points 3 and 4 may be connected directly or via the router 9. In this embodiment, the communication terminal 5 communicates wirelessly with the access point 4. In this case, the access point 4 may function as a RADIUS client, and the access point 3 may function as a RADIUS server. A control unit 50 of the access point 3 may perform communication control processing using various information stored in the access points 3 and 4.
[0044] Sixth Embodiment In this embodiment, a process for setting a threshold value (first threshold value) for the number of RADIUS re-authentication failures, which is different from that in the first embodiment, will be described. Specifically, an example will be described in which the number of connected communication terminals is acquired and the first threshold value is set.
[0045] FIG. 13 is a flowchart showing the initialization process S100E. As shown in FIG. 13, in this embodiment, after setting the RADIUS re-authentication period (S103), the control unit 50 may obtain the number of connected communication terminals (S104). At this time, the control unit 50 may set a threshold (first threshold) for the number of RADIUS re-authentication failures based on the number of connected communication terminals (S105). For example, if the number of connected communication terminals is large, the first threshold may be set low. This makes it possible to prevent frequent network disconnections due to RADIUS re-authentication failures and easily set an appropriate RADIUS re-authentication interval.
[0046] <Modification> While one embodiment of the present invention has been described above, those skilled in the art may conceive of various modifications and alterations within the scope of the concept of the present invention, and it is understood that these modifications and alterations also fall within the scope of the present invention. For example, even if a person skilled in the art appropriately adds, deletes, or modifies components of the above-described embodiments, or adds, omits, or modifies the conditions of steps, these modifications are also included within the scope of the present invention as long as they maintain the gist of the present invention.
[0047] In the first embodiment of the present invention, the maximum value of the acquired RADIUS re-authentication failure counts is used to perform the determination process, but the present invention is not limited to this. For example, the average or median value of the acquired RADIUS re-authentication failure counts may be used to perform the determination process.
[0048] Furthermore, in the first embodiment of the present invention, an example has been shown in which various types of information related to the communication control process are stored in the storage unit 70 of the access point 3, but the present invention is not limited to this. The various types of information may also be stored in a storage device of a communication device or server (a local server or a cloud server) different from the access point 3. Furthermore, the communication control process is not limited to being executed by the control unit 50 of the access point 3, but may also be executed by a control unit provided in another device such as a server.
[0049] In the first embodiment of the present invention, an example in which a set first threshold value is used is shown, but the present invention is not limited to this. For example, machine learning may be performed in advance using information related to RADIUS authentication as an input value, and the first threshold value may be output using the generated trained model. In this case, the first threshold value may be changed as appropriate.
[0050] In the first embodiment of the present invention, an example was shown in which the access point 3 has the function of a RADIUS server, but the present invention is not limited to this. For example, a communication device provided outside the access point 3 may have the function of a RADIUS server.
[0051] In the fourth embodiment of the present invention, an example is shown in which a specific RADIUS re-authentication interval is set based on specific date and time information that has been set in advance, but the present invention is not limited to this. For example, machine learning may be performed on transition data of RADIUS re-authentication failures, and a specific RADIUS re-authentication interval may be set for a specific date and time (day of the week or time period) based on the results of the machine learning.
[0052] In a wireless communication device of one embodiment of the present invention, the number of RADIUS re-authentication failures may be the total number of times the RADIUS re-authentication performed at each RADIUS re-authentication interval during a predetermined first period has failed.
[0053] In a wireless communication device of one embodiment of the present invention, the control unit may shorten the RADIUS re-authentication interval when the period during which the number of RADIUS re-authentication failures is equal to or less than a second threshold value that is lower than the first threshold value exceeds a second period that is longer than the first period.
[0054] In the wireless communication device according to one embodiment of the present invention, the control unit may set the first threshold value based on the number of communication terminals wirelessly connected to the wireless communication device.
[0055] In the wireless communication device according to one embodiment of the present invention, the control unit may acquire date and time information, and when the date and time information satisfies a predetermined condition, set the RADIUS re-authentication interval to a predetermined time interval.
[0056] In a wireless communication device of one embodiment of the present invention, the control unit may notify warning information indicating that the number of RADIUS re-authentication failures in at least one communication terminal among the plurality of communication terminals is greater than or equal to the first threshold.
[0057] In a wireless communication device of one embodiment of the present invention, the number of RADIUS re-authentication failures may be the total number of times the RADIUS re-authentication performed at each RADIUS re-authentication interval during a predetermined first period has failed.
[0058] In one embodiment of the communication control method, the RADIUS re-authentication interval may be shortened when the period during which the number of RADIUS re-authentication failures is equal to or less than a second threshold value that is lower than the first threshold value exceeds a second period that is longer than the first period.
[0059] In the communication control method according to one embodiment of the present invention, the first threshold may be set based on the number of communication terminals wirelessly connected to the wireless communication device.
[0060] In a communication control method according to one embodiment of the present invention, date and time information may be acquired, and when the date and time information satisfies a predetermined condition, the RADIUS re-authentication interval may be set to a predetermined time interval.
[0061] In a communication control method according to one embodiment of the present invention, warning information indicating that the number of RADIUS re-authentication failures in at least one of the plurality of communication terminals is equal to or greater than the first threshold may be notified. [Explanation of symbols]
[0062] 1···Communication system, 3···Access point, 4···Access point, 5···Communication terminal, 9···Router, 50···Control unit, 70···Storage unit, 80···Operation unit, 100···RADIUS re-authentication result data table, 101···Date and time information, 103···RADIUS authentication result, 110···RADIUS re-authentication failure count data table, 111···Communication terminal name, 113···RADIUS re-authentication failure count
Claims
1. A wireless communication device, a control unit that changes a RADIUS re-authentication interval used by a RADIUS server based on a number of RADIUS re-authentication failures in each of a plurality of communication terminals connected to the wireless communication device and a first threshold value; The number of RADIUS re-authentication failures is the total number of times that the RADIUS re-authentication, which is performed at each RADIUS re-authentication interval during a predetermined first period, has failed; The control unit shortening the RADIUS re-authentication interval when a period during which the number of RADIUS re-authentication failures is equal to or less than a second threshold value that is lower than the first threshold value exceeds a second period that is longer than the first period; Wireless communication device.
2. A wireless communication device, a control unit that changes a RADIUS re-authentication interval used by a RADIUS server based on a number of RADIUS re-authentication failures in each of a plurality of communication terminals connected to the wireless communication device and a first threshold value; The control unit setting the first threshold value based on the number of communication terminals wirelessly connected to the wireless communication device; Wireless communication device.
3. The control unit acquires date and time information, When the date and time information satisfies a predetermined condition, the RADIUS re-authentication interval is set to a predetermined time interval.
3. The wireless communication device according to claim 1.
4. The control unit notifying warning information indicating that the number of RADIUS re-authentication failures in at least one communication terminal among the plurality of communication terminals is equal to or greater than the first threshold; 4. A wireless communication device according to claim 1.
5. A wireless communication device changing a RADIUS re-authentication interval used by a RADIUS server based on the number of RADIUS re-authentication failures and a first threshold value in each of a plurality of communication terminals connected to the wireless communication device; The number of RADIUS re-authentication failures is the total number of times that the RADIUS re-authentication, which is performed at each RADIUS re-authentication interval during a predetermined first period, has failed; shortening the RADIUS re-authentication interval when a period during which the number of RADIUS re-authentication failures is equal to or less than a second threshold value that is lower than the first threshold value exceeds a second period that is longer than the first period; Communication control method.
6. A wireless communication device, changing a RADIUS re-authentication interval used by a RADIUS server based on the number of RADIUS re-authentication failures and a first threshold value in each of a plurality of communication terminals connected to the wireless communication device; setting the first threshold value based on the number of communication terminals wirelessly connected to the wireless communication device; Communication control method.
7. Get the date and time information When the date and time information satisfies a predetermined condition, the RADIUS re-authentication interval is set to a predetermined time interval.
7. The communication control method according to claim 5 or 6.
8. transmitting warning information indicating that the number of RADIUS re-authentication failures in at least one communication terminal among the plurality of communication terminals is equal to or greater than the first threshold; The communication control method according to any one of claims 5 to 7.
9. On the computer, changing a RADIUS re-authentication interval used by the RADIUS server based on the number of RADIUS re-authentication failures and a first threshold value in each of a plurality of communication terminals connected to the wireless communication device; The number of RADIUS re-authentication failures is the total number of times that the RADIUS re-authentication, which is performed at each RADIUS re-authentication interval during a predetermined first period, has failed; shortening the RADIUS re-authentication interval when a period during which the number of RADIUS re-authentication failures is equal to or less than a second threshold value that is lower than the first threshold value exceeds a second period that is longer than the first period; program.
10. A computer comprising: changing a RADIUS re-authentication interval used by the RADIUS server based on the number of RADIUS re-authentication failures and a first threshold value in each of a plurality of communication terminals connected to the wireless communication device; setting the first threshold value based on the number of communication terminals wirelessly connected to the wireless communication device; program.
Citation Information
Patent Citations
Portable communication terminal and user authenticating method
JP2006197462A
Energy residual-quantity information system and its program
JP2008135920A
Authentication system for vehicle
JP2018107653A
System and method for authentication service
US20180351944A1