Communication control system, communication method and program

The communication system automates RADIUS client configuration by transmitting identification and private keys between network devices, simplifying the setup process and improving efficiency.

JP7786154B2Active Publication Date: 2025-12-16YAMAHA CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021190422
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-11-24
Publication Date
2025-12-16
Estimated Expiration
2041-11-24

AI Technical Summary

Technical Problem

Configuring a RADIUS client requires manual input of configuration information, which is cumbersome and inefficient.

Method used

A communication system where a first network device functions as a RADIUS server and automatically transmits identification information and a private key to a second network device, enabling the second device to operate as a RADIUS client without manual input.

Benefits of technology

Facilitates easy configuration of RADIUS clients by automating the setup process, reducing user intervention and enhancing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007786154000001
    Figure 0007786154000001
  • Figure 0007786154000002
    Figure 0007786154000002
  • Figure 0007786154000003
    Figure 0007786154000003
Patent Text Reader

Abstract

To provide a communication control system for easily setting a RADIUS client and provide a method.SOLUTION: A communication control system 1 contains: an access point 10 that includes a function as a RADIUS server for determining whether or not a network communication of a terminal is identified or a first RADIUS client corresponded to the RADIUS server, and stores identification information and a secret key for identifying the RADIUS server; and a layer 2(L2) switch 20 directly connected in a network segment similar to the access point. The access point 10 contains a transmission part that transmits the stored identification information and the secret key to the L2 switch in a first time period. The layer L2 switch contains: a reception part that receives the identification information and the secret key transmitted from the access point; and a setting part that performs a setting so that the L2 switch is operated as a second RADIUS client corresponded to the RADIUS server on the basis of the received identification information and the secret key.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a network device, a communication control system, a communication control method, and a program. [Background technology]

[0002] Conventionally, there are communication systems that require authentication for connection of communication terminals to a network. In such communication systems, in order to manage authentication information of communication terminals, the communication terminals are authenticated by an authentication server connected to a network device such as an access point. For example, the network device is authenticated according to IEEE (Institute of Electrical and Electronics Engineers) 802.1X. As an authentication method, RADIUS (Remote Authentication Dial-in User Service) authentication is applied. A RADIUS server is used as the server for RADIUS authentication. Patent Document 1 discloses a method for authenticating communication terminals using a RADIUS server. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-139650 Summary of the Invention [Problem to be solved by the invention]

[0004] When authentication is performed using a RADIUS server, a RADIUS client corresponding to the RADIUS server is configured. The communication terminal performs authentication by the RADIUS server via the RADIUS client. However, configuring the RADIUS client requires the user to input configuration information. Therefore, whenever a RADIUS client needs to be configured, the user must input the configuration information, which is extremely cumbersome.

[0005] In view of the above problem, one object of the present invention is to make it possible to easily set up a RADIUS client. [Means for solving the problem]

[0006] According to one embodiment of the present invention, there is provided a communication system including a first network device having the function of a RADIUS server that determines whether to authenticate a terminal's network communication, or a first RADIUS client corresponding to the RADIUS server, and storing identification information and a private key for identifying the RADIUS server, and a second network device directly connected to the first network device in the same network segment, wherein the first network device includes a transmitting unit that transmits the stored identification information and private key to the second network device at a first time period, and the second network device includes a first receiving unit that receives the identification information and private key transmitted from the first network device, and a first setting unit that configures the second network device to operate as a second RADIUS client corresponding to the RADIUS server based on the received identification information and private key. [Effects of the Invention]

[0007] According to the present invention, a RADIUS client can be easily configured. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a schematic diagram showing the overall configuration of a communication control system according to an embodiment of the present invention; [Figure 2] 1 is a block diagram showing a hardware configuration of an access point according to an embodiment of the present invention. [Figure 3] 1 is a block diagram showing a hardware configuration of an L2 switch according to an embodiment of the present invention; [Figure 4] 1 is a functional block diagram of a communication control system according to an embodiment of the present invention. [Figure 5] FIG. 2 is a diagram illustrating an example of a data set held by a first access point according to an embodiment of the present invention. [Figure 6] FIG. 10 is a diagram illustrating an example of a data set held by a second access point according to an embodiment of the present invention. [Figure 7] FIG. 10 is a diagram illustrating an example of a data set held by an L2 switch according to an embodiment of the present invention. [Figure 8] FIG. 2 is a flowchart showing an example of a flow of processing executed in the communication control system according to one embodiment of the present invention. [Figure 9] FIG. 2 is a flowchart showing an example of a flow of processing executed in the communication control system according to one embodiment of the present invention. [Figure 10] 1 is a block diagram showing the overall configuration of a communication control system according to an embodiment of the present invention; [Figure 11] 1 is a functional block diagram of a communication control system according to an embodiment of the present invention. [Figure 12] FIG. 10 is a diagram illustrating an example of a data set held by an L2 switch according to an embodiment of the present invention. [Figure 13] FIG. 2 is a flowchart showing an example of a flow of processing executed in the communication control system according to one embodiment of the present invention. [Figure 14] FIG. 2 is a flowchart showing an example of a flow of processing executed in the communication control system according to one embodiment of the present invention. [Figure 15] FIG. 2 is a flowchart showing an example of a flow of processing executed in the communication control system according to one embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings and the like. However, the present invention can be embodied in many different forms, and should not be construed as being limited to the following exemplary embodiments. The drawings may be represented diagrammatically for clarity, but these are merely examples and do not limit the interpretation of the present invention. Furthermore, the letters "first" and "second" attached to each element are convenient labels used to distinguish between elements and have no further meaning unless otherwise specified. In the drawings referred to in this embodiment, identical or similar symbols (e.g., a symbol simply consisting of the numeral XXX followed by A, B, 1, 2, etc.) are used to designate identical or similarly functional parts, and repeated explanations may be omitted. Furthermore, some components may be omitted from the drawings. Furthermore, if a person of ordinary skill in the art to which the present invention pertains would recognize such features, no special explanation will be provided.

[0010] First Embodiment A communication control system according to a first embodiment of the present invention will be described in detail with reference to the drawings.

[0011] (1-1. Configuration of communication control system) 1 is a block diagram showing the configuration of a communication control system 1. As shown in FIG. 1, the communication control system 1 includes access points 10 (a first access point 10-1 and a second access point 10-2), an L2 switch 20 (a first L2 switch 20-1 and a second L2 switch 20-2), and a communication terminal 30.

[0012] The communication control system 1 configures a network 40 under the control of a router 45. The network 40 is, for example, an intranet, which is an example of a closed network. The intranet is, for example, a local area network (LAN). Therefore, the first access point 10-1, the second access point 10-2, the first L2 switch 20-1, the second L2 switch 20-2, and the communication terminal 30 can be said to exist in the same network segment. In FIG. 1, the first access point 10-1 and the second access point 10-2 are connected by wire via the first L2 switch 20-1, the second L2 switch 20-2, and the router 45. The first access point 10-1 and the first L2 switch 20-1 are directly connected by wire. Similarly, the second access point 10-2 and the second L2 switch 20-2 are directly connected by wire. The communication terminal 30-1 is connected wirelessly to the second access point 10-2. The communication terminals 30-2 and 30-3 are connected to the first L2 switch 20-1 or the second L2 switch 20-2 via wires.

[0013] (1-1-1. Access Point 10) In the communication control system 1, the access points 10 (first access point 10-1, second access point 10-2) are network devices (also referred to as first network devices) connected to the L2 switch 20 and the communication terminal 30 via a network 40 by wired or wireless communication. The access points 10 have a function of relaying between the communication terminal 30 and the L2 switch 20 (or a router 45). In this embodiment, the first access point 10-1 (also referred to as a controller access point) of the access points 10 also functions as a RADIUS server. The RADIUS server determines whether to authenticate network communication of the connected communication terminal 30. The second access point 10-2 (also referred to as a member access point) can also function as a RADIUS client corresponding to the RADIUS server, as will be described later. In this embodiment, when the first access point 10-1 and the second access point 10-2 are not distinguished from each other, they will be described as the access point 10.

[0014] 2 is a diagram showing the hardware configuration of the access point 10. As shown in Fig. 2, the access point 10 has a control device 11, a storage device 13, and a communication unit 15. The control device 11, the storage device 13, and the communication unit 15 are connected via a wiring bus 17.

[0015] The control device 11 includes a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other processing circuit, as well as a memory including a read only memory (ROM) and a random access memory (RAM). The control device 11 controls the functions of each unit using a communication control program stored in the memory.

[0016] In addition to semiconductor memories such as SSDs (Solid State Drives), magnetic recording media (magnetic tapes, magnetic disks, etc.), optical recording media, magneto-optical recording media, and storage elements that are storage media may be used for the storage device 13. The storage device 13 functions as a database that stores various information used in the communication control program.

[0017] The communication unit 15 is an interface for connecting to external devices (L2 switch 20, communication terminal 30) via a wired or wireless connection under the control of the control device 11 to transmit and receive information. In this embodiment, the communication unit 15 is connected to another access point 10 via a wired connection via the L2 switch 20 and router 45. The communication unit 15 communicates with the L2 switch 20 via a wired connection. At this time, the communication unit 15 uses a connector to which a cable or the like is connected. The communication unit 15 communicates with the communication terminal 30 wirelessly. At this time, the communication unit 15 uses a communication module capable of communication using, for example, a wireless LAN, Bluetooth (registered trademark), or the like.

[0018] (1-1-2. L2 switch 20) The Layer 2 (L2) switches 20 (first L2 switch 20-1, second L2 switch 20-2) are network devices (also referred to as second network devices) that relay terminals via the network 40. In this embodiment, when the first L2 switch 20-1 and the second L2 switch 20-2 are not distinguished from each other, they will be described as the L2 switches 20.

[0019] Fig. 3 is a block diagram showing an example of the hardware configuration of the L2 switch 20. As shown in Fig. 3, the L2 switch 20 has a control device 21, a storage device 23, and a communication unit 25. The control device 21, the storage device 23, and the communication unit 25 are connected via a wiring bus 27.

[0020] The control device 21 controls each part of the L2 switch 20 using a communication control program. The storage device 23 functions as a database that stores various information related to the communication control program. The communication unit 25 is an interface that connects to external devices (access point 10, communication terminal 30, and router 45) under the control of the control device 21 and transmits and receives information. The control device 21 and the storage device 23 can be the same devices as the access point 10. The communication unit 25 uses a connector to which a cable or the like is connected.

[0021] (1-1-3. Communication terminal 30) The communication terminal 30 is a computer device that requests authentication by a RADIUS server. If authenticated by the RADIUS server, the communication terminal 30 can communicate with other communication terminals 30 provided within the network 40 and with servers or communication terminals connected to a network 50 (e.g., the Internet) provided outside the network 40. If not authenticated by the RADIUS server, the communication terminal 30 cannot communicate with other communication terminals 30 provided within the network 40 or with servers or communication terminals connected to the network 50, even if the communication terminal 30 is connected to the access point 10 or the L2 switch 20. A personal computer is used as the communication terminal 30. Note that the communication terminal 30 is not limited to a personal computer and may be a mobile phone (feature phone), a smartphone, a tablet terminal, or an IoT (Internet of Things) device (a device equipped with a power supply mechanism, communication function, and information storage mechanism), and the like, as long as it can communicate with each device via a network.

[0022] In this embodiment, the first access point 10-1 functions as a RADIUS server and the second access point 10-2 functions as a RADIUS client, but the present invention is not limited to this. The first access point 10-1 may have a function as a RADIUS client in addition to a function as a RADIUS server. In this case, the first access point 10-1 can have a function as an access point, a function as a RADIUS server, and a function as a RADIUS client. As a result, when the communication terminal 30 is connected to the first access point 10-1, network authentication of the communication terminal can be performed without connecting to another network device having a RADIUS client function.

[0023] (1-2. Functional block diagram of the communication control system) 4 is a block diagram showing an example of the functional configuration of the communication control system 1. Each function described below is realized by hardware, software, or a combination of hardware and software.

[0024] In FIG. 4, first access point 10-1 includes storage unit 103, transmission unit 107, and transmission unit 109.

[0025] The storage unit 103 stores RADIUS server information. FIG. 5 shows an example of a data set of the stored RADIUS server information 1030. As shown in FIG. 5, the RADIUS server information 1030 includes identification information 1030a of the RADIUS server (first access point 10-1) and a secret key 1030b shared in the network 40. In this example, an IP address is used as the identification number 1030a. A password is used as the secret key 1030b. The storage unit 103 may also store identification information of the client network in addition to the identification information of the RADIUS server.

[0026] The transmitter 107 transmits the stored RADIUS server information to the second access point 10-2 via the L2 switch 20 and the router 45 by wire.

[0027] The transmitter 109 (also referred to as a first transmitter) transmits the stored RADIUS server information to the first L2 switch 20-1 via a wired connection. At this time, the first access point 10-1 and the first L2 switch 20-1 are directly connected. Therefore, the transmitter 109 can transmit the RADIUS server information to the first L2 switch 20-1 at a fixed time period (also referred to as a first time period). For example, the RADIUS server information may be stored in an LLDP (Link Layer Discovery Protocol) frame and transmitted.

[0028] 4, the second access point 10-2 includes a receiving unit 111, a storage unit 113, a setting unit 115, and a transmitting unit 117.

[0029] The receiving unit 111 (also referred to as a second receiving unit) receives the RADIUS server information transmitted from the first access point 10-1. The storage unit 113 stores the received RADIUS server information. FIG. 6 is an example of a data set of information 1130 stored in the second access point 10-2. As shown in FIG. 6, the stored information 1130 includes identification information 1130a and a secret key 1130b. At this time, the RADIUS server information (the identification information of the first access point 10-1 and the secret key common to the network 40) is stored in the second access point 10-2.

[0030] The setting unit 115 (also referred to as a second setting unit) sets the second access point 10-2 to operate as a RADIUS client based on the RADIUS server information.

[0031] The transmitter 117 (also referred to as a second transmitter) transmits the stored RADIUS server information to the second L2 switch 20-2. At this time, the second access point 10-2 and the second L2 switch 20-2 are directly connected. Therefore, the transmitter 117 can transmit the RADIUS server information at a fixed time period (first time period). For example, the RADIUS server information may be stored in an LLDP frame and transmitted.

[0032] 4, the first L2 switch 20-1 and the second L2 switch 20-2 include a receiving unit 201, a storage unit 203, and a setting unit 205. The first L2 switch 20-1 and the second L2 switch 20-2 have the same functional units, and therefore will be collectively described as the L2 switch 20.

[0033] The receiving unit 201 receives the RADIUS server information transmitted from the first access point 10-1 or the second access point 10-2.

[0034] The storage unit 203 stores the received RADIUS server information. Fig. 7 shows an example of a data set of information 2030 stored in the L2 switch 20. As shown in Fig. 7, the stored information 2030 includes identification information 2030a and a secret key 2030b. At this time, the L2 switch 20 stores the RADIUS server information (the identification information and secret key of the first access point 10-1).

[0035] The setting unit 205 sets the L2 switch 20 to operate as a RADIUS client (also called a second RADIUS client) based on the stored RADIUS server information.

[0036] (1-3. Communication control processing) Next, the communication control process based on the instructions of the communication control program will be described with reference to FIGS.

[0037] First, the first access point 10-1, which functions as a RADIUS server, stores RADIUS server information. As shown in Fig. 5, the RADIUS server information 1030 includes identification information (IP address) of the first access point 10-1 and a secret key (password) generated for a RADIUS client present on the same network 40. The first access point 10-1 generates transmission information for transmitting the RADIUS server information (S101).

[0038] The first access point 10-1 transmits the stored RADIUS server information to the second access point 10-2 (S103). At this time, the first access point 10-1 may transmit the RADIUS server information using a communication protocol that can be used with the second access point.

[0039] The second access point 10-2 receives the RADIUS server information transmitted from the first access point 10-1 (S105). The second access point 10-2 stores the received RADIUS server information in the storage device 13 (S107). At this time, as shown in Fig. 6, the second access point 10-2 stores the RADIUS server information (the identification information and secret key of the first access point 10-1).

[0040] At this time, the second access point 10-2 belongs to the same network segment as the first access point 10-1 functioning as the RADIUS server, and has a secret key generated for a RADIUS client existing on the same network 40. As a result, the setting unit 115 of the second access point 10-2 sets the second access point 10-2 to operate as a RADIUS client (first RADIUS client) (S109).

[0041] Next, the first access point 10-1 transmits the stored RADIUS server information to the first L2 switch 20-1 (S111). At this time, the first access point 10-1 and the first L2 switch 20-1 are directly connected. Therefore, the first access point 10-1 can transmit the RADIUS server information to the first L2 switch 20-1 at the first time interval. At this time, the RADIUS server information is stored in an LLDP frame and transmitted.

[0042] The first L2 switch 20-1 receives the RADIUS server information transmitted from the first access point 10-1 (S115).

[0043] The storage unit 203 of the first L2 switch 20-1 stores the received RADIUS server information (S117). As shown in Fig. 7, the first L2 switch 20-1 stores the RADIUS server information (identification information and secret key of the first access point).

[0044] At this time, the first L2 switch 20-1 belongs to the same network segment as the first access point 10-1 functioning as the RADIUS server and has a secret key generated for a RADIUS client that exists on the same network 40. As a result, the setting unit 205 sets the first L2 switch 20-1 to operate as a RADIUS client (also referred to as a second RADIUS client).

[0045] 9, the second access point 10-2 generates transmission information for transmitting the RADIUS server information (S112) and transmits the RADIUS server information to the second L2 switch 20-2 (S113). At this time, the second access point 10-2 and the second L2 switch 20-2 are directly connected. Therefore, the second access point 10-2 can transmit the RADIUS server information at the first time interval, just like the first access point 10-1. At this time, the RADIUS server information is stored in an LLDP frame and transmitted.

[0046] The second L2 switch 20-2 receives the RADIUS server information transmitted from the second access point 10-2 (S116).

[0047] The storage unit 203 of the second L2 switch 20-2 stores the received RADIUS server information (S118). The second L2 switch 20-2 stores the RADIUS server information (the identification information and secret key of the first access point).

[0048] At this time, the second L2 switch 20-2 belongs to the same network segment as the first access point 10-1 functioning as the RADIUS server and has a secret key generated for a RADIUS client that exists on the same network 40. As a result, the setting unit 205 of the second L2 switch 20-2 sets the second L2 switch 20-2 to operate as a RADIUS client (also referred to as a second RADIUS client).

[0049] This completes the communication control process. In the same network segment, the first access point (controller access point) and the second access point (member access point) share the same secret key, so that RADIUS server information is automatically sent to the directly connected L2 switch in the same network segment, allowing the switch to be automatically configured as a RADIUS client. Therefore, by using this embodiment, a RADIUS client can be easily configured without the user having to input information.

[0050] Second Embodiment In this embodiment, a communication control system different from that in the first embodiment will be described in detail with reference to the drawings. Specifically, a communication control system having an L2 switch connected to another L2 switch will be described.

[0051] (2-1. Configuration of the communication control system) FIG. 10 is a block diagram showing the configuration of a communication control system 1A. As shown in FIG. 10, the communication control system 1A includes a first access point 10-1, a second access point 10-2, a first L2 switch 20-1, a second L2 switch 20-2, and a plurality of communication terminals 30, as well as a third L2 switch 20-3 (also referred to as a third network device). The third L2 switch 20-3 is directly connected to at least one of the first L2 switch 20-1 and the second L2 switch 20-2. In this example, the third L2 switch 20-3 is directly connected to the first L2 switch 20-1. The third L2 switch 20-3 has the same hardware configuration as the first L2 switch 20-1.

[0052] FIG. 11 is a block diagram showing an example of the functional configuration of the communication control system 1A. In FIG. 11, the first L2 switch 20-1 includes a transmitter 207 in addition to a receiver 201, a storage unit 203, and a setting unit 205. The transmitter 207 (also referred to as a third transmitter) transmits the RADIUS server information to the third L2 switch 20-3. At this time, the first L2 switch 20-1 and the third L2 switch 20-3 are directly connected. This allows the transmitter 207 to transmit the RADIUS server information at regular intervals. For example, the RADIUS server information may be stored in an LLDP (also referred to as a second LLDP) frame that is different from the LLDP (also referred to as a first LLDP) frame received by the first L2 switch 20-1 and transmitted.

[0053] The third L2 switch 20-3 includes a receiving unit 211, a storage unit 213, and a setting unit 215.

[0054] The receiving unit 211 receives the RADIUS server information transmitted from the first L2 switch 20-1.

[0055] The storage unit 213 stores the received RADIUS server information. Fig. 12 shows an example of a data set of information 2130 stored in the third L2 switch 20-3. As shown in Fig. 12, the stored information 2130 includes identification information 2130a and a secret key 2130b. At this time, the third L2 switch 20-3 stores the RADIUS server information (the identification information and secret key of the first access point 10-1).

[0056] The setting unit 215 sets the third L2 switch 20-3 as a RADIUS client based on a predetermined condition.

[0057] (2-2. Communication control processing) Next, a communication control process based on commands from a communication control program in the communication control system 1A will be described with reference to the drawings. The same processes as those in the first embodiment will be omitted as appropriate.

[0058] 13 shows a communication control process flow based on instructions from a communication control program in the communication control system 1A. When the first L2 switch 20-1 is set as a RADIUS client (S119), it generates transmission information for transmitting the stored RADIUS server information to the third L2 switch 20-3 (S121).

[0059] The first L2 switch 20-1 transmits the RADIUS server information to the third L2 switch 20-3 (S123). At this time, the first L2 switch 20-1 and the third L2 switch 20-3 are directly connected. Therefore, the RADIUS server information can be stored in a frame of a predetermined communication protocol (LLDP in this example) and transmitted. Note that the LLDP frame used at this time is not an LLDP frame (first LLDP) transmitted from the first access point, but an LLDP frame (second LLDP) transmitted spontaneously from the first L2 switch. This allows the first L2 switch 20-1 to transmit the RADIUS server information to the third L2 switch 20-3 via the second LLDP frame at regular time intervals (first time intervals).

[0060] The third L2 switch 20-3 receives the RADIUS server information sent from the first L2 switch 20-1 (S125).

[0061] The third L2 switch 20-3 stores the received RADIUS server information (S127). As shown in Fig. 12, the third L2 switch 20-3 stores the RADIUS server information (the identification information and secret key of the first access point).

[0062] At this time, the third L2 switch 20-3 belongs to the same network segment as the first access point 10-1 functioning as the RADIUS server, and has a secret key generated for a RADIUS client existing in the same network. As a result, the setting unit 215 of the third L2 switch 20-3 sets the third L2 switch 20-3 to operate as a new RADIUS client (third RADIUS client) (S129).

[0063] By using this embodiment, even an L2 switch that is not directly connected to a RADIUS server can be easily set as a RADIUS client.

[0064] <Third embodiment> In this embodiment, a communication control method in a communication control system 1B that is different from the communication control system 1 of the first embodiment will be described. Specifically, a communication control method when information from a RADIUS server is not received within a predetermined time will be described.

[0065] 14 is a flowchart of communication control processing based on instructions from a communication control program in the communication control system 1B. When the first L2 switch 20-1 is set as a RADIUS client (second RADIUS client) (S119), the first L2 switch 20-1 measures the elapsed time (S201).

[0066] The first L2 switch 20-1 determines whether to acquire RADIUS server information again within a predetermined time (also referred to as a second time) (S203). The second time is longer than the first time period described in the first embodiment. If the RADIUS server information is acquired again within the predetermined time (S203; Yes), the process returns to S201 and loops.

[0067] If the RADIUS server information is not received again within a predetermined time (S203; No), the setting unit 205 of the first L2 switch 20-1 deletes the stored RADIUS server information (S205).

[0068] By using this embodiment, if RADIUS server information is not received within a predetermined time, the RADIUS server information that has already been received is automatically deleted. As a result, when a communication terminal is no longer connected to the RADIUS server, the RADIUS client does not need to perform unnecessary inquiry processing to a non-existent RADIUS server.

[0069] <Fourth embodiment> In this embodiment, a communication control method in a communication control system 1C that is different from the communication control system 1 of the first embodiment will be described. Specifically, a communication control method in which automatically set RADIUS server information is changed to a fixed setting and retained will be described.

[0070] 15 shows a communication control process flow based on instructions from a communication control program in the communication control system 1C. As shown in Fig. 15, when the first L2 switch 20-1 is set as a RADIUS client (S119), the first L2 switch 20-1 measures the elapsed time (S301).

[0071] The control unit of the first L2 switch 20-1 determines whether a request to register RADIUS server information as static setting information (hereinafter referred to as a "static setting request") based on a user input has been received within a predetermined time (a second time, also referred to as TTL (Time to Live)) (S302). The second time is longer than the first time described in the first embodiment. If a static setting request is received within the second time (S302; Yes), the first L2 switch 20-1 sets the stored RADIUS server information not to be deleted even after the second time has elapsed (S304).

[0072] If the fixed setting request is not received within the second time period (S302; No), the first L2 switch 20-1 determines whether the RADIUS server information has been received again within a predetermined time period (second time period) (S303). If the RADIUS server information has been received again within the second time period (S303; Yes), the process returns to S301 and loops. If the RADIUS server information has not been received again within the second time period (S303; No), the first L2 switch 20-1 deletes the RADIUS server information (S305).

[0073] By using this embodiment, it is possible to retain RADIUS server information even after a certain period of time has passed, and if RADIUS server information is not received within the certain period of time, it is possible to delete the RADIUS server information that has already been received. This eliminates the need for unnecessary authentication processing and also allows exceptional communication control processing to be performed.

[0074] (Variation) It should be noted that within the scope of the concept of the present invention, a person skilled in the art may conceive of various modifications and alterations, and it is understood that these modifications and alterations also fall within the scope of the present invention. For example, to the above-described embodiments, a person skilled in the art may appropriately add, delete, or modify components, or add, omit, or change conditions of steps, and these modifications are also included within the scope of the present invention as long as they maintain the gist of the present invention.

[0075] In the communication device of one embodiment of the present invention, the first network device may be an access point.

[0076] In the communication device of one embodiment of the present invention, the second network device may be an L2 (Layer 2) switch.

[0077] In a communication device of one embodiment of the present invention, the first network device may include a first access point functioning as the RADIUS server and a second access point functioning as the first RADIUS client, the second network device may include a first L2 switch and a second L2 switch, the first access point may include a first transmitter that transmits the stored identification information and the private key to the first L2 switch at the first time period, and the second access point may include a second receiver that receives the identification information and the private key transmitted from the first access point, a memory that stores the received identification information and the private key, a second setting unit that configures the first network device to operate as the first RADIUS client based on the stored identification information and the private key, and a second transmitter that transmits the stored identification information and the private key to the second L2 switch at the first time period.

[0078] In a communication device of one embodiment of the present invention, the second network device may further include a third transmission unit that transmits the stored identification information and the private key to a third network device directly connected in the same network segment at the first time period.

[0079] In the communication device according to one embodiment of the present invention, the identification information and the private key may be stored in an LLDP (Link Layer Discovery Protocol) frame and transmitted.

[0080] In a communication device of one embodiment of the present invention, if the first receiving unit does not receive the identification information and the private key for a second time period longer than the first time period, the first setting unit may delete the identification information and the private key stored in the second network device.

[0081] In a communication device of one embodiment of the present invention, when the first receiving unit receives a setting request for the identification information and the private key, the first setting unit may retain the stored identification information and the private key even after the second time has elapsed.

[0082] Furthermore, according to one embodiment of the present invention, there is provided a network device including: a receiving unit that receives identification information and a private key for identifying a RADIUS server, which are transmitted at a first time period from a RADIUS server or an access point that functions as a first RADIUS client corresponding to the RADIUS server; a memory unit that stores the received identification information and private key; and a setting unit that sets the network device to operate as a second RADIUS client based on the stored identification information and private key.

[0083] In one embodiment of the present invention, the network device may further include a transmitting unit that transmits the stored identification information and private key to another network device directly connected in the same network segment at the first time period.

[0084] In a network device of one embodiment of the present invention, if the receiving unit does not receive the identification information and the private key within a second time period that is longer than the first time period, the setting unit may delete the identification information and the private key of the RADIUS server that are set in the network device.

[0085] Furthermore, according to one embodiment of the present invention, there is provided a network device having the function of a RADIUS server or a RADIUS client corresponding to the RADIUS server, the network device including: a memory unit that stores identification information and a private key for identifying the RADIUS server; and a transmitter unit that transmits the stored identification information and the private key to another network device directly connected in the same network segment at a first time period.

[0086] Furthermore, according to one embodiment of the present invention, a communication method is provided in which a first network device has the function of a RADIUS server that determines whether to authenticate a terminal's network communication, or a first RADIUS client corresponding to the RADIUS server, and stores identification information and a private key for identifying the RADIUS server, transmits the stored identification information and private key to a second network device directly connected to the same network segment at a first time period, and the second network device receives the identification information and private key transmitted from the first network device, and configures the second network device to operate as a second RADIUS client based on the received identification information and private key.

[0087] In the communication management method of one embodiment of the present invention, the first network device may be an access point.

[0088] In the communication management method of one embodiment of the present invention, the second network device may be an L2 (Layer 2) switch.

[0089] In a communication management method of one embodiment of the present invention, the first network device may include a first access point functioning as the RADIUS server and a second access point functioning as the first RADIUS client, the second network device may include a first L2 switch and a second L2 switch, the first access point may transmit the stored identification information and the private key to the first L2 switch at the first time period, the second access point may receive the identification information and the private key transmitted from the first access point, store the received identification information and the private key, configure the first network device to operate as the first RADIUS client based on the stored identification information and the private key, and transmit the stored identification information and the private key to the second L2 switch at the first time period.

[0090] In the communication management method according to one embodiment of the present invention, the stored identification information and private key may be transmitted at the first time interval to a third network device that is directly connected in the same network segment.

[0091] In the communication management method according to one embodiment of the present invention, the identification information and the private key may be stored in an LLDP (Link Layer Discovery Protocol) frame and transmitted.

[0092] In one embodiment of the communication management method, if the second network device does not receive the identification information and the private key within a second time period that is longer than the first time period, the second network device may delete the identification information and the private key stored in the second network device.

[0093] In a communication management method according to one embodiment of the present invention, when the second network device receives predetermined information, the stored identification information and private key may be retained even after the second time period has elapsed.

[0094] Furthermore, according to one embodiment of the present invention, there is provided a communication control program for causing a network device to receive identification information and a private key for identifying the RADIUS server, which are transmitted at a first time period from a RADIUS server or an access point having a function as a first RADIUS client corresponding to the RADIUS server, store the received identification information and private key, and configure the network device to operate as a second RADIUS client based on the stored identification information and private key.

[0095] The present invention can also be understood as a method invention (relay method, information processing method).

[0096] In the first embodiment of the present invention, an example was shown in which the RADIUS server information was stored in an LLDP frame and transmitted, but the present invention is not limited to this. The RADIUS server information may be stored in a frame of another communication protocol and transmitted as long as the communication protocol allows transmission at a fixed time interval.

[0097] In the first embodiment of the present invention, the RADIUS server information includes identification information (IP address) and a secret key, but the present invention is not limited to this. For example, the RADIUS server information may include information on the authentication UDP port number of the RADIUS server, information on the response waiting time for a request to the RADIUS server, information on the number of request retransmissions to the RADIUS server, etc.

[0098] In the first embodiment of the present invention, an example has been shown in which the first access point 10-1 functions as a RADIUS server and the second access point 10-2 functions as a RADIUS client, but the present invention is not limited to this. The access point 10 may control its functions as appropriate depending on the settings. For example, the second access point 10-2 may transmit information for switching settings to the first access point 10-1. This may allow the RADIUS server to be switched.

[0099] In the first embodiment of the present invention, the first access point functions as the RADIUS server, but the present invention is not limited to this. For example, the L2 switch 20 may function as the RADIUS server. [Explanation of symbols]

[0100] 1 communication control system, 10 access point, 11 control device, 13 storage device, 15 communication unit, 17 wiring bus, 20 L2 switch, 21 control device, 23 storage device, 25 communication unit, 27 wiring bus, 30 communication terminal, 40 network, 45 router, 50 network , 103···Memory unit, 107···Transmitter, 109···Transmitter, 111···Receiver, 113···Memory unit, 115···Setting unit, 117···Transmitter, 201···Receiver, 203···Memory unit, 205···Setting unit, 207···Transmitter, 211···Receiver, 213···Memory unit, 215···Setting unit, 1030···RADIUS server information

Claims

1. A first network device having a function as a RADIUS server that determines whether to authenticate a terminal's network communication, or a first RADIUS client corresponding to said RADIUS server, and storing identification information and a private key for identifying said RADIUS server; a second network device directly connected to the first network device in the same network segment; the first network device includes a transmitter configured to transmit the stored identification information and the stored private key to the second network device at a first time interval; The second network device a first receiving unit that receives the identification information and the private key transmitted from the first network device; a first setting unit that sets the second network device to operate as a second RADIUS client corresponding to the RADIUS server based on the received identification information and the private key; the first network device is an access point; the second network device is an L2 (Layer 2) switch, the first network device includes a first access point functioning as the RADIUS server and a second access point functioning as the first RADIUS client; the second network device includes a first L2 switch and a second L2 switch; the first access point includes a first transmitter that transmits the stored identification information and the stored private key to the first L2 switch at the first time period; The second access point a second receiving unit that receives the identification information and the private key transmitted from the first access point; a storage unit that stores the received identification information and the private key; a second setting unit that sets the first network device to operate as the first RADIUS client based on the stored identification information and the stored private key; a second transmitting unit that transmits the stored identification information and the private key to the second L2 switch at the first time period; Communication system.

2. the second network device further includes a third transmission unit that transmits the stored identification information and the private key to a third network device that is directly connected to the second network device in the same network segment at the first time interval; The communication system of claim 1 .

3. The identification information and the private key are stored in an LLDP (Link Layer Discovery Protocol) frame and transmitted.

3. A communication system according to claim 1 or 2.

4. the first receiving unit does not receive the identification information and the private key for a second time period that is longer than the first time period; the first setting unit deletes the identification information and the private key stored in the second network device. A communication system according to any one of claims 1 to 3.

5. When the first receiving unit receives a setting request for the identification information and the private key, the first setting unit holds the stored identification information and the private key even after the second time period has elapsed. The communication system according to claim 4.

6. A first network device has a function as a RADIUS server that determines whether to authenticate a network communication of a terminal, or a first RADIUS client corresponding to said RADIUS server, and stores identification information and a private key for identifying said RADIUS server, transmitting the stored identification information and the private key to a second network device directly connected in the same network segment at a first time period; The second network device receiving the identification information and the private key transmitted from the first network device; configuring the second network device to operate as a second RADIUS client based on the received identification information and private key; the first network device is an access point; the second network device is an L2 switch, the first network device includes a first access point functioning as the RADIUS server and a second access point functioning as the first RADIUS client; the second network device includes a first L2 switch and a second L2 switch; the first access point transmits the stored identification information and the secret key to the first L2 switch at the first time period; The second access point receiving the identification information and the private key transmitted from the first access point; storing the received identification information and the private key; configuring the first network device to operate as the first RADIUS client based on the stored identification information and the stored private key; transmitting the stored identification information and the secret key to the second L2 switch at the first time period; Communication method.

7. The second network device transmitting the stored identification information and the private key to a third network device directly connected in the same network segment at the first time period; The communication method according to claim 6.

8. The identification information and the secret key are transmitted in an LLDP frame.

8. The communication method according to claim 6 or 7.

9. The second network device if the identification information and the private key are not received for a second time period that is longer than the first time period; deleting the identification information and the private key stored in the second network device; A communication method according to any one of claims 6 to 8.

10. When the second network device receives the predetermined information, the second network device retains the stored identification information and the private key even after the second time period has elapsed. The communication method according to claim 9.

11. For network devices, receiving identification information and a secret key for identifying the RADIUS server, the identification information and secret key being transmitted at a first time period from the RADIUS server or an access point functioning as a first RADIUS client corresponding to the RADIUS server; storing the received identification information and the private key; and configuring the network device to operate as a second RADIUS client based on the stored identification information and private key, the access points include a first access point functioning as the RADIUS server and a second access point functioning as the first RADIUS client; the network device includes a first L2 switch and a second L2 switch; the first access point transmits the stored identification information and the secret key to the first L2 switch at the first time period; The second access point receiving the identification information and the private key transmitted from the first access point; storing the received identification information and the private key; configuring the access point to operate as the first RADIUS client based on the stored identification information and the secret key; transmitting the stored identification information and the secret key to the second L2 switch at the first time period; program.

Citation Information

Patent Citations

  • Wireless network node device and wireless trunk network constructing method

    JP2009153142A

  • Communication apparatus, method and program

    JP2010098597A

  • Communication system, communication device, communication method and computer program

    JP2012034142A

  • Authentication system, communication device and authentication data application method

    JP2017139650A

  • Method and system for mobile cryptocurrency wallet connectivity

    US20210056541A1