Authentication method and apparatus and related device
By implementing the MAC authentication function in the wireless controller and storing the portal-free authentication list, the problem of large load and delay in the authentication server in the existing MAC priority portal authentication is solved, and a more efficient authentication process and wider sensorless access coverage are achieved.
Patent Information
- Application Number
- PCT/CN2024/127658
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2024-10-28
- Publication Date
- 2025-05-08
AI Technical Summary
The existing MAC-first portal authentication has problems such as large load, large delay, and limited application scenarios of authentication servers.
By implementing the MAC authentication function in the wireless controller, the portal-free authentication list is stored, which reduces dependence on the authentication server, reduces authentication delay and improves authentication efficiency.
It reduces the access burden of the authentication server, reduces the delay in MAC authentication, improves the authentication efficiency, and realizes sensorless access for terminal devices to roam between different APs managed by wireless controllers.
Smart Images

Figure CN2024127658_08052025_PF_FP_ABST
Abstract
Description
Authentication method, device and related equipment
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on October 31, 2023, with application number 202311439876.1 and application name “Authentication methods, devices and related equipment”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to an authentication method, apparatus, and related equipment. Background Art
[0003] Portal authentication is also commonly referred to as web authentication, and the portal authentication website is often referred to as a portal page. When users go online, they must authenticate on the portal page. If authentication fails, they can only access specific network resources. Only after successful authentication can they access other network resources. This simple, convenient, and mature technology, requiring no additional client software installation, allows authentication directly on the web page. It is widely used in networks such as carriers, fast food chains, hotels, and schools.
[0004] In order to avoid the user frequently performing portal authentication when the terminal device reconnects to the wireless network after being disconnected, media access control (MAC)-prioritized portal authentication can be used to enable the terminal device to access the network without portal authentication within the validity period. MAC-prioritized portal authentication means that after the user successfully performs portal authentication, he disconnects from the network and reconnects within a certain period of time, and can directly access the network through MAC authentication without entering the username and password to re-authenticate the portal. Specifically, when the client user authenticates for the first time, the access device will send the client's MAC address to the authentication server for authentication, but because the authentication server does not find the MAC address information, the authentication fails, triggering the client user to perform portal authentication. After the authentication is successful, the authentication server will automatically save the client's MAC address. When the client tries to access the network again due to unstable wireless signal or leaving the wireless signal coverage area, the access device will send the client's MAC address to the RADIUS server for authentication.
[0005] Current MAC-based portal authentication suffers from high server load and latency. Furthermore, it requires the server to cache MAC addresses, making it inflexible to deploy and limiting its application scenarios.
[0006] Summary of the Invention
[0007] The present application provides an authentication method, apparatus and related equipment to solve the problems of heavy authentication server load, long authentication delay and limited application scenarios in the current MAC-priority portal authentication.
[0008] In the first aspect, the present application provides an authentication method. The first wireless controller receives a request message from an access point (AP), the request message being used to request association of a target terminal device with the AP, and the request message including the MAC address of the terminal. The first wireless controller determines whether the MAC address of the target terminal device is in a portal-free authentication list stored by the first wireless controller, the portal-free authentication list including the MAC addresses of terminal devices that have passed portal authentication. That is, the MAC addresses in the portal-free authentication list are MAC addresses of terminal devices that do not require portal authentication. When the MAC address of the target terminal device is included in the portal-free authentication list, the first wireless controller determines that the target terminal device has passed authentication. The MAC authentication of the terminal device is implemented by the wireless controller, that is, the MAC authentication function is deployed on the wireless controller, which is more flexible in deployment and can reduce the access burden of the authentication server. Since MAC authentication in this embodiment does not require the terminal device to interact with the authentication server, it can also reduce the MAC authentication delay and improve authentication efficiency.
[0009] In one possible implementation, the first wireless controller determining that the target terminal device has passed authentication includes: the first wireless controller sending an indication to the AP indicating that the target terminal device has passed authentication. Thus, when the AP receives a Hypertext Transfer Protocol (HTTP) request or Hypertext Transfer Protocol Secure (HTTPS) request message from the target terminal device, it can determine whether to pass the message based on the indication.
[0010] In one possible implementation, the first wireless controller includes a built-in portal server. The method further includes: upon receiving a Hypertext Transfer Protocol (HTTP) / Hypertext Transfer Protocol Secure (HTTPS) request message from a target terminal device, the first wireless controller sends an HTTP / HTTPS response message to the target terminal device, the HTTP / HTTPS response message including a portal authentication page. Thus, if the target terminal device fails authentication, captive portal authentication is implemented for the target terminal device, thereby improving network security.
[0011] In one possible implementation, the method further includes: if the user information of the target terminal device passes portal authentication, the first wireless controller adds the MAC address of the target terminal device to a portal-free authentication list, where the user information is collected through the portal authentication page. After the target terminal device passes portal authentication, the MAC address of the target terminal device is added to the portal-free authentication list. Thus, when the target terminal device reconnects to the wireless network, it can determine whether the terminal device still needs to undergo portal authentication based on the portal-free authentication list. If the MAC address of the target terminal device is still in the portal-free authentication list, the target terminal device does not need to undergo portal authentication, and the user does not need to enter user information on the portal authentication page, thus achieving seamless access.
[0012] In one possible implementation, the method further includes: when the target terminal device's MAC address has been included in the portal-free authentication list for a period exceeding a preset period, the first wireless controller deleting the target terminal device's MAC address from the portal-free authentication list. Setting an expiration period for the MAC addresses in the portal-free authentication list, and deleting the target terminal device's MAC address from the portal-free authentication list when the target terminal device's MAC address has been included in the portal-free authentication list (i.e., the period since the target terminal device last passed portal authentication) exceeds a preset period. Thus, when the target terminal device accesses again, if the target terminal device's MAC address is no longer in the portal-free authentication list, the target terminal device will need to undergo portal authentication, thereby improving network integrity.
[0013] In one possible implementation, after the first wireless controller determines that the target terminal device has passed portal authentication, the first wireless controller further includes: sending the MAC address of the target terminal device to the second wireless controller. Alternatively, the first wireless controller sends the MAC address of the target terminal device and the remaining portal cache time of the target terminal device to the second wireless controller. This allows the target terminal device to access the AP managed by the second wireless controller without portal authentication, thereby improving the coverage of portal-free authentication.
[0014] The remaining cache time is the remaining duration that the target terminal device's MAC address remains in the portal-free authentication list. The remaining cache time is variable and decreases over time. When the remaining cache time corresponding to the target terminal device's MAC address reaches 0 at a certain moment, the MAC address's function for portal-free authentication becomes invalid, and the first wireless controller deletes the target terminal device's MAC address from the portal-free authentication list. The remaining cache time can mask the effects of clock asynchrony between different wireless controllers, ensuring that different wireless controllers delete MAC addresses from their respective portal-free authentication lists at the most consistent times possible.
[0015] A second aspect provides a communication device. The communication device is applied to a wireless controller. The device includes a transceiver module and a processing module. The transceiver module is configured to receive a request message from an AP, the request message being used to request association of a target terminal device with the AP, the request message including the terminal's media access control (MAC) address. The processing module is configured to determine whether the MAC address of the target terminal device is included in a portal-free authentication list stored by a first wireless controller, the portal-free authentication list including the MAC addresses of terminal devices that have passed portal authentication. The processing module is configured to determine that the target terminal device has passed authentication when the MAC address of the target terminal device is included in the portal-free authentication list.
[0016] In a possible implementation, the transceiver module is further configured to send an indication that the target terminal device has passed authentication to the AP.
[0017] In one possible implementation, the wireless controller includes a built-in portal server. The transceiver module is further configured to, upon receiving a Hypertext Transfer Protocol (HTTP) / Hypertext Transfer Protocol Secure (HTTPS) request message from a target terminal device, send an HTTP / HTTPS response message to the target terminal device, where the HTTP / HTTPS response message includes a portal authentication page.
[0018] In a possible implementation, the processing module is configured to add the MAC address of the target terminal device to a portal authentication-free list when user information of the target terminal device passes portal authentication, and the user information is collected through the portal authentication page.
[0019] In a possible implementation, the processing module is configured to delete the MAC address of the target terminal device from the portal-free authentication list when the duration for which the MAC address of the target terminal device has been added to the portal-free authentication list exceeds a preset duration.
[0020] In a possible implementation, the transceiver module is further configured to send the MAC address of the target terminal device to the second wireless controller. Alternatively, the transceiver module is further configured to send the MAC address of the target terminal device and the remaining portal cache time of the target terminal device to the second wireless controller.
[0021] A third aspect provides a network device, comprising a processor and a memory, wherein the processor is coupled to the memory and configured to execute the authentication method of the first aspect or any possible implementation of the first aspect based on instructions stored in the memory.
[0022] A fourth aspect provides a computer-readable storage medium comprising instructions, which, when executed on a network device, causes the network device to execute the authentication method of the first aspect or any possible implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] FIG1 is a schematic diagram of the architecture of a WLAN system provided by the present application;
[0024] FIG2 is a network diagram of a portal authentication system provided by this application;
[0025] FIG3 is a flow chart of a portal authentication method provided by this application;
[0026] FIG4a is a schematic diagram of a network of an authentication system provided by the present application;
[0027] FIG4b is a network diagram of another authentication system provided by this application
[0028] FIG5 is a schematic diagram of an interactive process of an authentication method provided by this application;
[0029] FIG6 is a schematic diagram of the interaction flow of another authentication method provided by this application;
[0030] FIG7 is a schematic structural diagram of a communication device provided by the present application;
[0031] FIG8 is a schematic diagram of the structure of a network device provided by this application. DETAILED DESCRIPTION
[0032] This application provides an authentication method and related equipment to improve authentication efficiency.
[0033] The following describes the embodiments of the present application in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of the present application, rather than all the embodiments. Those skilled in the art will appreciate that with the development of technology and the emergence of new scenarios, the technical solutions provided in this application are also applicable to similar technical problems.
[0034] The terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. In the description of this application, unless otherwise specified, "plurality" means two or more.
[0035] The word “exemplary” is used exclusively herein to mean “serving as an example, example, or illustration.” Any embodiment described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments.
[0036] A wireless local area network (WLAN) is a wireless computer network that uses wireless channels instead of wired transmission media to connect two or more devices to form a local area network (LAN). In recent years, with the explosive growth of wireless terminal devices such as smartphones, laptops, tablets, and smart home appliances, WLAN has been widely used in homes, campuses, corporate offices, industrial manufacturing sites, hotels, tourist attractions, stadiums, and waiting rooms for trains and airports. WLAN access has become one of the primary ways to access the internet, allowing users to conveniently access the internet.
[0037] As shown in Figure 1, Figure 1 is a schematic diagram of the architecture of a WLAN system provided by this application. It should be understood that the number of APs, wireless controllers, and terminal devices in Figure 1 is for example only. A WLAN system includes one or more wireless access points (APs). An AP is an access device in a WLAN, used to provide wireless access services to terminal devices (also known as stations (STAs) in WLAN). Because the wireless signal coverage range of a single AP is limited, multiple APs need to be deployed to ensure large-scale wireless signal coverage in larger venues such as campuses, hotels, office buildings, parks, tourist attractions, stadiums, bus and airport terminals. Therefore, a WLAN system may also include one or more wireless controllers. In scenarios where multiple APs are networked, the APs can operate in thin AP mode, with the wireless controller providing unified management and control of these APs. Specifically, the wireless controller can control AP parameters such as operating frequency, power, channel allocation, and data transmission rate, and can also provide functions such as network access control to ensure network security. The wireless controller can configure multiple APs in batches, eliminating the need to configure each AP individually, thereby reducing WLAN management and maintenance costs.
[0038] STAs and APs send and receive data over wireless channels, which are open, leading to certain security risks in WLANs. To ensure WLAN security and manage access user authorization and billing, WLANs can be configured with user access authentication. The device that manages user access authentication is called an authentication control point. The authentication control point in a WLAN can be an AP. When a WLAN includes a wireless controller, the authentication control point can also be a wireless controller. User access authentication is used to authenticate wireless access users in the WLAN. Users who fail user access authentication can only access designated network resources, while users who pass user access authentication can access other network resources, ensuring that WLAN security risks are controllable. User access authentication includes authentication methods such as 802.1x authentication, portal authentication, and media access control (MAC) authentication. In practice, you can select one authentication method to implement user access authentication based on business needs, or you can combine multiple authentication methods to implement user access authentication.
[0039] Portal authentication is also known as web authentication. Portal authentication websites are generally referred to as portal pages. When users access the Internet, they must authenticate on the portal page. If authentication fails, they can only access specific network resources. Only after successful authentication can they access other network resources. Users can authenticate through the portal authentication page displayed on the STA's browser, eliminating the need to install additional software on the STA. This simple and flexible authentication method is also customizable, allowing for example advertising push, corporate promotions, and informational notifications. Therefore, portal authentication is widely used in carrier WLANs, as well as WLANs in businesses, institutions, restaurants, hotels, and schools.
[0040] Portal authentication includes active portal authentication and captive portal authentication. Active portal authentication means that a user actively visits a known portal authentication website and enters user information such as username and password on the portal authentication page provided by the portal authentication website for authentication. Captive portal means that when a user attempts to access other unauthorized websites through a Hypertext Transfer Protocol (HTTP) request or a Hypertext Transfer Protocol Secure (HTTPS) request, they will be redirected to a portal page. If the portal page is an authentication page, the portal authentication process begins, that is, the user is forced to visit the portal authentication website for portal authentication.
[0041] As shown in Figure 2, Figure 2 is a network diagram of a portal authentication system provided by this application. The portal authentication system includes a client, an access device, a portal server, and an authentication server. Among them, the client is a host installed with a browser running the HTTP / HTTPS protocol, which is used to initiate HTTP / HTTPS requests. When the portal authentication system is deployed in a WLAN, the client is the STA in the WLAN. The portal server is used to receive client authentication requests and provide a portal authentication page for the client. The client is also used to send a portal authentication request based on the user information entered by the user on the portal authentication page. The authentication server is used to complete user identity authentication based on the user information, as well as user authorization and billing after the user authentication is passed. The access device is a general term for devices such as APs and wireless controllers in the WLAN. Before authentication, the access device is used to redirect HTTP / HTTPS requests from the client to the portal server. During the authentication process, the access device interacts with the portal server and the authentication server to complete user identity authentication, authorization and billing. After the authentication is passed, the access device allows the client to access network resources authorized by the authentication server.
[0042] Specifically, as shown in Figure 3. Figure 3 is a flow chart of a portal authentication method provided by this application. Figure 3 shows the authentication process of mandatory portal authentication. The active portal authentication process does not have redirection-related steps, and the client actively sends an HTTP / HTTPS request message to the portal server. The AP and AC in Figure 3 are access devices. Before authentication, a pre-connection has been established between the client and the AP, that is, the client user has established a user online table entry on the AP before the authentication is successful, and has only partial network access rights. The specific process of portal authentication is that the client initiates an HTTP / HTTPS request. When the AP determines that the received message is an HTTP / HTTPS request message based on the message port number (for example, port 80 for HTTP request messages and port 443 for HTTPS request messages), it allows the message to pass if it is intended to access a portal server or authentication-free network resources. If the message is intended to access other addresses, the AP sends an HTTP / HTTPS redirect message to the client. The HTTP / HTTPS redirect message includes the portal server's uniform resource locator (URL) or IP address to redirect the client's HTTP / HTTPS request message to the portal server. The client initiates an HTTP / HTTPS request to the portal server based on the URL or IP address in the HTTP / HTTPS redirect message returned by the AP. The portal server returns the portal authentication page to the client. After the user enters user information such as username and password on the portal authentication page, the client initiates a portal authentication request to the portal server. The portal authentication request includes the user information entered on the portal authentication page. After receiving the portal authentication request, the portal server sends it to the wireless controller based on CHAP or PAP authentication. Based on the user information obtained from the portal authentication request, the wireless controller sends a 3A authentication request to the authentication server. The authentication server authenticates the user information, obtains a result indicating whether the authentication is successful, and sends the result to the wireless controller. If the result indicates that the user information is successful, the wireless controller grants the user network access rights, allowing the corresponding client to access other network resources, and sends the portal authentication success page to the client through the AP. If the result indicates that the user information is unauthenticated, the client is denied access to other network resources.
[0043] When a client repeatedly leaves and enters the AP's wireless signal coverage area due to movement, the portal authentication process is triggered each time the client reconnects to the AP. To reduce the frequency of portal authentication within a certain period of time, you can configure MAC-prioritized portal authentication for the WLAN. MAC-prioritized portal authentication prioritizes MAC authentication during user authentication. If MAC authentication fails, portal authentication is performed instead. Specifically, the MAC-prioritized portal authentication process is as follows: when a client authenticates for the first time, the wireless controller sends the client's MAC address to the authentication server for authentication (MAC authentication phase). However, because the authentication server cannot find the MAC address information, MAC authentication fails. In response to the client's MAC authentication failure, the wireless controller redirects the client's HTTP / HTTPS request to the portal server, triggering the client to perform portal authentication (portal authentication phase). After successful portal authentication, the authentication server saves the client's MAC address. If the client attempts to reconnect to the AP due to wireless signal instability or leaving the AP's wireless signal coverage area, causing the client to lose connection, the wireless controller sends the client's MAC address to the authentication server for authentication (MAC authentication phase). If the client's MAC address is still stored on the authentication server, the server verifies the MAC address and directly authorizes the user. Authorized users can access the network directly without having to re-enter the portal authentication system and enter their username and password. If the client's MAC address has expired on the authentication server, the server deletes the stored MAC address. If MAC address authentication fails, the wireless controller redirects the client's HTTP / HTTPS request to the portal server, triggering the client user to perform portal authentication.
[0044] MAC-based portal authentication requires frequent interaction between the wireless controller, the portal server, and the authentication server. This interaction between the access device and the external server (an independent entity outside the wireless controller) increases authentication time and traffic to the authentication server, placing a significant load on the authentication server. Reducing the latency and load of MAC-based portal authentication has become a pressing issue.
[0045] In order to solve the above problems, the present application provides the following embodiments.
[0046] As shown in Figures 4a and 4b, Figure 4a is a network diagram of an authentication system provided by the present application; Figure 4b is a network diagram of another authentication system provided by the present application. The authentication system is used to implement wireless access authentication in a WLAN scenario. In this embodiment, the authentication system includes a wireless controller and an AP. The wireless controller is used to perform security, control, and management functions, such as mobility management, identity authentication, and radio frequency resource management. The wireless controller can be a direct-connected network in the authentication system, as shown in Figure 4a. The wireless controller can also be a side-mounted network, as shown in Figure 4b. The AP is used to complete wireless radio frequency access functions and provide wireless access services to terminal devices, such as wireless signal transmission and detection response, data encryption and decryption, data transmission confirmation, etc.
[0047] The wireless controller can manage and control one or more APs. Optionally, when the wireless controller manages multiple APs, the authentication system may further include a switch (not shown), and multiple APs may be connected to the wireless controller through the switch. In one possible implementation, the authentication system may further include an authentication server. The authentication server is used to authenticate the user identity based on user information during the portal authentication process. The authentication server may be a remote authentication dial-in user service (RADIUS) server, a terminal access controller access-control system (TACACS), an HWTACACS server, a Lightweight Directory Access Protocol (LDAP) server, a Diameter server, etc. In another possible implementation, the authentication system may also not include an authentication server, and the wireless controller may store user information used for user identity authentication. During the portal authentication process, the wireless controller may locally authenticate the user identity based on the stored user information.
[0048] Wireless controllers and APs can communicate using the Control and Provisioning of Wireless Access Points (CAPWAP) protocol or other protocols, such as the Generic Routing Encapsulation (GRE) protocol. Using CAPWAP, wireless controllers can centrally manage and control their associated APs. The CAPWAP protocol includes two types of messages: management messages (control messages) and data messages. Management messages primarily carry information elements used by the AC to configure AP operating parameters and maintain CAPWAP tunnels. Data messages primarily carry data messages sent by terminal devices and are used to transmit upper-layer data for terminal devices. Management messages are forwarded through the CAPWAP control tunnel. User data messages can be forwarded using either tunnel forwarding (also known as "centralized forwarding") or direct forwarding (also known as "local forwarding"). Tunnel forwarding means that after reaching the AP, user data messages are encapsulated through the CAPWAP data tunnel and sent to the wireless controller, which then forwards them to the upper-layer network. Direct forwarding means that after user data packets reach the AP, they are directly forwarded to the upper-layer network without being encapsulated in the CAPWAP tunnel.
[0049] In this embodiment, the authentication control point is deployed on the wireless controller. Furthermore, the wireless controller includes a built-in portal server, which runs on the controller. The built-in server provides basic functions such as logging on and off via the web. During the portal authentication process, the built-in portal server provides the portal authentication page to the terminal device. Using the built-in portal server for portal authentication reduces authentication costs and interaction latency between the wireless controller and the portal server, as it eliminates the need for deploying an additional portal server.
[0050] In this embodiment, the wireless controller can implement MAC authentication. When a terminal device accesses a WLAN, it sends an association request to the AP, requesting association between the terminal device and the AP. Upon receiving the association request, the AP obtains the terminal device's MAC address and other information from the request, constructs a request message, and sends it to the wireless controller via a tunnel. Upon receiving the request message, the wireless controller obtains the terminal device's MAC address and determines whether the MAC address exists in a portal-free authentication list stored by the wireless controller. The portal-free authentication list contains the MAC addresses of terminal devices that have passed portal authentication. If the MAC address exists in the portal-free authentication list, the wireless controller confirms that the terminal device has been authenticated and sends a confirmation of authentication to the AP. If the MAC address does not exist in the portal-free authentication list, the terminal device is deemed to have failed authentication. When the terminal device initiates an HTTP / HTTPS request, the AP redirects the HTTP / HTTPS request to the wireless controller's built-in portal server, triggering the portal authentication process.
[0051] Implementing the MAC-priority portal authentication function on the wireless controller, on the one hand, can solve the problem that the built-in portal server does not support any extended functions of the external independent server, such as not supporting MAC-priority portal authentication. On the other hand, in the process of implementing MAC-priority portal authentication, the wireless controller does not need to frequently interact with the authentication server during the MAC authentication stage, which can simplify the authentication process and reduce the authentication delay. On the other hand, compared with the authentication control point being located at the AP, since the number of wireless controllers in the authentication system is less than that of APs, the authentication control point being located at the wireless controller can greatly reduce the authentication control point, thereby reducing the configuration complexity and the difficulty of data migration. On the other hand, the access authentication of the terminal device is centrally managed by the wireless controller, and the terminal device can realize wireless roaming between APs managed by the wireless controller. That is, when the terminal device switches APs, it can also realize seamless access based on the MAC-priority portal authentication function of the wireless controller, without the need for the terminal device to re-perform portal authentication.
[0052] As shown in Figure 5, Figure 5 is a schematic diagram of the interaction process of an authentication method provided by this application. This embodiment includes the following steps:
[0053] S501: The AP receives an association request message or a reassociation request message from a target terminal device.
[0054] Whether the terminal device accesses the AP for the first time or re-accesses the AP after being disconnected from the AP, a series of access interactions are required between the terminal device and the AP to complete the access of the terminal device. Situations in which the terminal device re-accesses the AP after being disconnected from the AP include, for example, the terminal device leaving the coverage of the AP's wireless signal and then re-entering the AP's coverage, the terminal device actively going offline and then coming back online, etc. When multiple virtual access points (VAPs) are created on the AP, re-access may also be required when switching between different VAPs of the AP. For example, a first VAP and a second VAP are created on the AP. If the service set identifiers (SSIDs) of the first VAP and the second VAP are different, if the terminal device accesses the first VAP of the AP and then switches to the second VAP of the AP, access interactions are also required between the terminal device and the AP before the terminal device can access the second VAP.
[0055] The target terminal device is the terminal device to be authenticated. The process of a target terminal device accessing a wireless network includes the scanning phase, the link authentication phase, and the association phase. During the scanning phase, the target terminal device obtains surrounding wireless network information, such as the AP's SSID, through active or passive scanning. During the link authentication phase, the target terminal device and the AP perform link authentication, and after successful authentication, a connection is established between the target terminal device and the AP. During the association phase, the target terminal device and the AP negotiate link services. During this phase, the target terminal device sends an association request message or a reassociation request message to the AP, requesting association between the AP and the target terminal device.
[0056] S502: The AP obtains a request message according to the association request message or the reassociation request message, where the request message includes the MAC address of the target terminal device.
[0057] Association / reassociation request messages are management messages. If the AP and wireless controller communicate using the CAPWAP protocol, the AP can send these messages to the primary wireless controller that manages the AP through a CAPWAP tunnel. Therefore, upon receiving an association / reassociation request message from a target terminal device, the AP performs CAPWAP encapsulation on the message to create a request message. This request message is used to request the wireless controller to associate the target terminal device with the AP.
[0058] In this embodiment, the request message includes the MAC address of the target terminal device. The MAC address of the target terminal device in the request message can be obtained by the AP from the source MAC address field in the message header of the association request message or the reassociation request message. After receiving the request message, the AP executes S502.
[0059] S503: The AP sends a request message to the first wireless controller.
[0060] S504: The first wireless controller determines whether the MAC address of the target terminal device is in the portal-free authentication list stored in the first wireless controller.
[0061] Because the request message for associating the AP with the target terminal device is sent to the first wireless controller during the AP's target terminal device access process, the request message enables the first wireless controller to perceive that the target terminal device is accessing the wireless network. The request message triggers the first wireless controller to perform MAC authentication on the target terminal device to determine whether portal authentication is required for the target terminal device's current wireless network access. MAC authentication is based on the terminal device's MAC address, eliminating the need for the user to enter user information such as their account and password. This provides high authentication efficiency and seamless authentication of the terminal device.
[0062] Specifically, in this embodiment, the first wireless controller stores a portal-free authentication list. The portal-free authentication list includes MAC addresses of terminal devices that do not currently require portal authentication. The MAC addresses in the portal-free authentication list are MAC addresses of terminal devices that have already passed portal authentication. Optionally, to improve the security of the WLAN, a validity period can be set for the MAC addresses in the portal-free authentication list. Specifically, when the time period since a MAC address was added to the portal-free authentication list exceeds a preset time period, that is, when the time interval since the terminal device last passed portal authentication is greater than the preset time period, the MAC address is confirmed to be invalid and deleted from the portal-free authentication list, thereby ensuring that the MAC addresses in the portal-free authentication list are all MAC addresses within the validity period. It should be noted that the portal-free authentication list refers to a collection of MAC addresses of terminal devices that do not currently require portal authentication, and does not limit the MAC addresses of terminal devices that do not currently require portal authentication to be stored in a data structure such as a list.
[0063] The MAC addresses in the portal-free authentication list may include the MAC addresses of terminal devices that have passed portal authentication via the first wireless controller. Passing portal authentication via the first wireless controller means that the terminal device has accessed the AP managed by the first wireless controller, and then the first wireless controller participates in completing the portal authentication of the terminal device as an access device in the authentication system. Since the first wireless controller manages multiple APs, the MAC addresses in the portal-free authentication list may include the MAC addresses of terminal devices associated with multiple APs managed by the first wireless controller. The MAC address of the terminal device in the portal-free authentication list may not be bound to the AP associated with the terminal device, so that the terminal device roams between different APs managed by the first wireless controller, and when the MAC address of the terminal device is included in the portal-free authentication list, the terminal device can be exempted from portal authentication.
[0064] Optionally, the MAC addresses in the portal-free authentication list may also include MAC addresses of terminal devices that have passed portal authentication via other wireless controllers. For example, a WLAN includes multiple wireless controllers, and the multiple wireless controllers in the WLAN are divided into wireless roaming groups, and the wireless roaming group includes at least two wireless controllers. When a terminal device accessing an AP managed by a wireless controller passes portal authentication, the wireless controller will not only add the MAC address of the terminal device to its own stored portal-free authentication list, but will also send the MAC address of the terminal device to other wireless controllers in the same wireless roaming group. After receiving the MAC address of the terminal device, the other wireless controllers in the wireless roaming group will add it to their own stored portal-free authentication list. The wireless controllers in the wireless roaming group share the portal-free authentication list, so that when a terminal device roams between different wireless controllers in the same roaming group, and the MAC address of the terminal device is included in the portal-free authentication list of the wireless controller to which the terminal device is newly associated, the terminal device can be exempted from portal authentication.
[0065] Optionally, when the wireless controller sends the MAC address of a terminal device that has passed portal authentication to other wireless controllers in the same wireless roaming group, it may also send the remaining cache time of the terminal device. This allows the other wireless controllers to manage the MAC address of the terminal device in the portal authentication-free list based on the remaining cache time of the terminal device, and delete the terminal device from the portal authentication-free list when the remaining cache time reaches 0. Alternatively, when the wireless controller sends the MAC address of a terminal device that has passed portal authentication to other wireless controllers in the same wireless roaming group, it may not send the remaining cache time of the terminal device, but instead notify the other wireless controllers to delete the MAC address from the portal authentication-free list when the MAC address is invalid.
[0066] The MAC addresses in the portal-free authentication list are configured with an expiration date, for example, and the duration of the expiration date is a preset duration. When the time after the MAC address has been added to the portal-free authentication list is longer than the preset duration, the MAC address is considered to have exceeded the expiration date, and the wireless controller can delete it. The remaining cache duration when the MAC address is added to the portal-free authentication list is equal to the preset duration, and then the remaining cache duration will gradually decrease. The remaining cache time can be used to determine whether the current time interval from the MAC address being added to the portal-free authentication list is greater than the preset duration. When the remaining cache time is equal to 0, the current time interval from the MAC address being added to the portal-free authentication list is equal to the preset duration, and then the MAC address can be deleted.
[0067] In another implementation, the wireless controller sends the terminal device's MAC address and the authentication pass time to other wireless controllers. Each wireless controller then calculates the time interval between the current authentication pass time and the authentication pass time, and compares it with a preset duration. If the time interval exceeds the preset duration, the wireless controller removes the MAC address from the portal-free authentication list. Alternatively, the wireless controller starts a timer when the terminal device passes authentication, and when the timer reaches a preset duration, the wireless controller removes the MAC address from the portal-free authentication list.
[0068] Optionally, when a terminal device has passed portal authentication and the MAC address of the terminal device still exists in the portal-free authentication list (i.e., the MAC address is still valid), the terminal device may initiate active portal authentication. After the active portal authentication is passed, the wireless controller can add the MAC address to the portal-free authentication list again, and update the cache remaining time corresponding to the MAC address to be equal to the preset duration. Alternatively, the wireless controller can directly modify the cache remaining time corresponding to the MAC address. Optionally, the wireless controller can also send the MAC address and cache remaining time to other wireless controllers in the wireless roaming group so that other wireless controllers can update the cache remaining time corresponding to the MAC address.
[0069] Therefore, the MAC addresses in the portal-free authentication list stored in the first wireless controller can be updated timely and dynamically, ensuring that the MAC addresses in the portal-free authentication list are currently valid MAC addresses, thereby ensuring network security.
[0070] Optionally, the first wireless controller includes a non-volatile memory, and the portal-free authentication list is stored in the non-volatile memory, so that after the first wireless controller is powered off and restarted, the portal-free authentication list is still stored in the first wireless controller and will not be cleared, thereby improving the stability and reliability of the authentication system.
[0071] After receiving the request message, the first wireless controller obtains the MAC address of the target terminal device in the request message. The first wireless controller then determines whether the MAC address of the target terminal device exists in the portal authentication-free list. If the portal authentication-free list includes the MAC address of the target terminal device, that is, the MAC address of the target terminal device exists in the portal authentication-free list, it indicates that the target terminal device has previously passed portal authentication and access does not require portal authentication this time. S505a is executed. If the portal authentication-free list does not include the MAC address of the target terminal device, that is, the MAC address of the target terminal device is not in the portal authentication-free list, it indicates that the target terminal device has not previously passed portal authentication, or the time interval between the target terminal device's last portal authentication and the target terminal device's MAC address has been deleted from the portal authentication-free list. S505a is executed.
[0072] S505a: When the portal-free authentication list includes the MAC address of the target terminal device, the first wireless controller determines that the target terminal device passes the authentication.
[0073] The first wireless controller determining that the target terminal device has passed the authentication may include the first wireless controller sending an indication to the AP that the target terminal device has passed the authentication, so that the AP allows the target terminal device to access authorized network resources according to the indication. The first wireless controller sending the indication to the AP that the target terminal device has passed the authentication may be used to instruct the AP to cancel the pre-connection authorization of the target terminal device and open the target terminal device to access the entire network. Before portal authentication, the first wireless controller may configure pre-connection authorization to allow the target terminal device to have partial network access rights. Partial network access rights, for example, allow the target terminal device to access network resources such as a portal server, a domain name system (DNS) server, and a dynamic host configuration protocol (DHCP) server, but not allow access to network resources other than designated network resources. Therefore, after canceling the pre-connection authorization of the target terminal device, the target terminal device has access to the entire network.
[0074] S505b: When the portal-free authentication list does not include the MAC address of the target terminal device, the first wireless controller determines that the target terminal device fails the authentication.
[0075] If the portal-free authentication list does not include the MAC address of the target terminal device, the target terminal device fails to pass the authentication (MAC authentication fails), and the target terminal device still needs to perform portal authentication.
[0076] Optionally, the first wireless controller may send an indication to the AP that the target terminal device has failed authentication. The indication sent by the first wireless controller to the AP that the target terminal device has failed authentication may be an instruction to configure pre-connection authorization for the target terminal device. After MAC authentication fails, the target terminal device enters a pre-connection state. The pre-connection authorization configured on the target terminal device grants the target terminal device limited network access rights. Specifically, the target terminal device can only access the authorized portion of the network and has no access to other networks.
[0077] Optionally, if the target terminal device disconnects from the AP managed by the first wireless controller and then quickly reconnects to the AP, the first wireless controller may not have deleted the target terminal device's authentication information. Therefore, before step S504, after receiving the request message, the first wireless controller may first determine whether the first wireless controller has stored the target terminal device's authentication information based on the target terminal device's MAC address in the request message. If the first wireless controller has not deleted the target terminal device's authentication information, step S504 may be skipped and an authentication success indication for the target terminal device may be directly sent to the AP. This improves authentication efficiency. If the first wireless controller does not store the target terminal device's authentication information, step S504 is executed.
[0078] In this embodiment, the first wireless controller stores a portal-free authentication list, which includes the MAC addresses of terminal devices that have passed portal authentication. During the access process of the target terminal device, when the first wireless controller receives a request message for associating the target terminal device with the AP, it triggers the first wireless controller to determine whether the MAC address of the target terminal device is in the portal-free authentication list. When the MAC address of the target terminal device is in the portal-free authentication list and it is confirmed that the target terminal device has passed the MAC authentication, the first wireless controller sends an indication to the AP that the target terminal device has passed the authentication, so that the target terminal device does not need to perform portal authentication when accessing the network, and seamless authentication of the target terminal device can be achieved. In this embodiment, the MAC authentication of the terminal device is implemented by the wireless controller, that is, the MAC authentication function is offloaded to the wireless controller, reducing the access burden of the 3A server. Since MAC authentication in this embodiment does not require the terminal device to interact with the 3A server, it can also reduce the MAC authentication delay and improve the authentication efficiency.
[0079] If the MAC address of the target terminal device is not included in the portal authentication-free list, portal authentication is required for the target terminal device. In this embodiment, the first wireless controller includes a built-in portal server. During the portal authentication process for the target terminal device, the built-in portal server in the first wireless controller provides portal authentication services for the target terminal device.
[0080] As shown in Figure 6, Figure 6 is a schematic diagram of the interaction process of another authentication method provided by this application. This embodiment is based on the authentication method embodiment in Figure 5, and similar steps are not repeated in this embodiment. This embodiment includes the following steps:
[0081] S601: The terminal device sends an association request message / reassociation request message to the AP.
[0082] S602: The AP obtains a request message according to the association request message or the reassociation request message, where the request message includes the MAC address of the target terminal device.
[0083] S603: The AP sends a request message to the first wireless controller.
[0084] S604: The first wireless controller determines whether the MAC address of the target terminal device is in the portal-free authentication list stored in the first wireless controller.
[0085] S605a: When the MAC address of the target terminal device is included in the portal-free authentication list, the first wireless controller sends an indication that the target terminal device has passed the authentication to the AP.
[0086] This step is similar to S505a and will not be described again here.
[0087] S606a: The target terminal device sends an HTTP / HTTPS request message to the AP.
[0088] S607a: The AP forwards the HTTP / HTTPS request message.
[0089] The target terminal device has passed authentication. Therefore, upon receiving the HTTP / HTTPS request message from the target terminal device, the AP allows the HTTP / HTTPS request message from the target terminal device to pass, that is, forwards the HTTP / HTTPS request message from the target terminal device.
[0090] The AP can forward HTTP / HTTPS request packets from the target terminal device in a local forwarding mode or a centralized forwarding mode. There is no restriction here.
[0091] S605b: When the portal-free authentication list does not include the MAC address of the target terminal device, the first wireless controller sends an indication to the AP that the target terminal device has failed authentication.
[0092] This step is similar to S505b and will not be described again here.
[0093] S606b: The target terminal device sends an HTTP / HTTPS request message to the AP.
[0094] S607b: The AP redirects the address of the HTTP / HTTPS request message to the built-in portal server in the first wireless controller.
[0095] The AP sends an HTTP / HTTPS redirect message to the target terminal device. The redirect message includes the URL (URL) address or IP address of the built-in portal server, redirecting the client's HTTP / HTTPS request message to the built-in portal server.
[0096] It should be noted that if the target terminal device accesses the built-in portal server in the first wireless controller using active portal authentication, S606b and S607b are not executed, but S608b is executed after S605b.
[0097] S608b: The target terminal device sends an HTTP / HTTPS request message to the built-in portal server of the first wireless controller.
[0098] S609b: The built-in portal server of the first wireless controller sends an HTTP / HTTPS response message, where the HTTP / HTTPS response message includes a portal authentication page.
[0099] S610b: The target terminal device sends a portal authentication request message to the built-in portal server of the first wireless controller.
[0100] After the user enters user information on the portal authentication page, the target terminal device initiates a portal authentication request to the built-in portal server in the first wireless controller. The portal authentication request includes the user information entered by the target terminal device on the portal authentication page.
[0101] The portal authentication page can be an account and password authentication page, a text message authentication page, or a WeChat authentication page, etc. There is no restriction here.
[0102] S611b: The first wireless controller determines whether the target terminal device passes the portal authentication according to the portal authentication request message.
[0103] If the first wireless controller uses local authentication, that is, it stores user information, then after receiving the portal authentication request message, the first wireless controller obtains the user information in the portal authentication request message and compares the user information stored in the first wireless controller with the user information in the portal authentication request message to see if the user information is consistent. If the user information is consistent, the target terminal device is determined to have passed portal authentication. If the user information is consistent, the target terminal device is determined to have failed portal authentication.
[0104] If authentication is performed using an external authentication server, the first wireless controller forwards the portal authentication request message to the authentication server, which then authenticates the user information. The authentication server compares the user information stored on the authentication server with the user information in the portal authentication request message to see if it matches. If so, the target terminal device is determined to have passed portal authentication. If not, the target terminal device is determined to have failed portal authentication. After receiving the portal authentication result, the authentication server sends it to the first wireless controller.
[0105] S612b: If the target terminal device passes the portal authentication, the first wireless controller adds the MAC address of the target terminal device to the portal authentication-free list.
[0106] After the target terminal device passes portal authentication, the first wireless controller adds the target terminal device's MAC address to the portal-free authentication list. Therefore, if the target terminal device disconnects from its currently associated AP and then reconnects to that AP, or to another AP managed by the first wireless controller, the first wireless controller can determine whether the target terminal device can be authenticated without portal authentication based on the target terminal device's MAC address and the portal-free authentication list.
[0107] S613b: The first wireless controller sends the portal authentication result to the target terminal device.
[0108] Optionally, after S612b, the method further includes: the first wireless controller sending the MAC address of the target terminal device to the second wireless controller.
[0109] The second wireless controller can be a backup wireless controller for the first wireless controller, thereby ensuring that in the event of a failure of the first wireless controller, the second wireless controller can achieve seamless access for terminal devices corresponding to the MAC addresses in the portal-free authentication list, thereby ensuring the stability of the WLAN system. The second wireless controller can also be a controller belonging to the same wireless roaming group as the first wireless controller. The first wireless controller can proactively send the MAC address of the target terminal device to the second wireless controller. In another implementation, the second wireless controller can also request the first wireless controller to share or synchronize its portal-free authentication list. The first wireless controller responds to the second wireless controller's request and sends the MAC address of the target terminal device to the second wireless controller.
[0110] After the second wireless controller receives the MAC address of the target terminal device, it adds the MAC address of the target terminal device to its own stored list of portal-free authentication, and the second wireless controller manages the MAC address of the target terminal device. Thus, when the target terminal device disconnects from the currently associated AP and accesses an AP managed by the second wireless controller, the second wireless controller can determine whether the target terminal device can be exempted from portal authentication based on the MAC address of the target terminal device and its own stored list of portal-free authentication. That is, when the MAC address of the target terminal device exists in the second wireless controller's list of portal-free authentication, the target terminal device can access the AP managed by the second wireless controller without portal authentication. When the target terminal device roams between wireless controllers, it can still access the AP seamlessly.
[0111] Optionally, the first wireless controller may further send the cache remaining time of the target terminal device to the second wireless controller, so that the second wireless controller may determine when to delete the MAC address of the target terminal device in the portal-free authentication list according to the cache remaining time.
[0112] Optionally, when the MAC address of the target terminal device is added to the portal-free authentication list for longer than a preset time, that is, when the remaining cache time of the target terminal device reaches 0, the first wireless controller deletes the MAC address of the target terminal device from the portal-free authentication list stored in itself.
[0113] In this embodiment, the first wireless controller includes a built-in portal server. Built-in portal servers offer advantages such as convenient networking, low cost, and easy maintenance. However, devices with built-in portal servers only implement simple portal server functions, providing users with basic online and offline functionality via the web. They do not support any extended functions of an external independent server, such as RADIUS or other AAA servers. Specifically, the built-in portal server does not support MAC-based portal authentication. When a terminal device reconnects to the wireless network after being in sleep mode or disconnected from the wireless network, it is redirected to the portal server's authentication page, requiring the user to re-enter their account and password for built-in portal authentication. This results in long service recovery times and poor user experience. In this embodiment, the first wireless controller implements MAC authentication, with both the MAC authentication point and the portal authentication point located on the first wireless controller. This allows the first wireless controller to implement MAC-based portal authentication, overcoming the drawback of built-in portal servers that do not support MAC-based portal authentication. Consequently, with a built-in portal server, user-aware access is achieved. Currently, MAC authentication is implemented by the authentication server. During the authentication process, the access device (such as the first wireless controller) needs to frequently interact with the authentication server, which increases the access burden of the authentication server. In this embodiment, the MAC authentication of the terminal device is implemented by the wireless controller, that is, the MAC authentication function is unloaded to the wireless controller, which reduces the access burden of the authentication server. Since MAC authentication in this embodiment does not require the terminal device to interact with the authentication server, it can also reduce the MAC authentication delay and improve the authentication efficiency. In addition, the MAC-priority portal authentication implemented by the wireless controller can also achieve seamless access in scenarios where the terminal device roams between AP / VAPs or roams between wireless controllers, thereby improving the coverage of the portal-free authentication function.
[0114] As shown in Figure 7, Figure 7 is a schematic diagram of the structure of a communication device provided in this application. Communication device 700 is applied to a wireless controller. Communication device 700 can be a software functional module in the wireless controller or a hardware module in the wireless controller, such as a chip. Communication device 700 of this embodiment includes a transceiver module 701 and a processing module 702.
[0115] The transceiver module 701 is configured to receive a request message from an AP requesting association of a target terminal device with the AP, the request message including the terminal's Media Access Control (MAC) address. The processing module 702 is configured to determine whether the target terminal device's MAC address is in a portal-free authentication list stored by the first wireless controller, the portal-free authentication list including the MAC addresses of terminal devices that have passed portal authentication. The processing module 702 is configured to determine that the target terminal device has passed authentication if the target terminal device's MAC address is included in the portal-free authentication list.
[0116] In a possible implementation, the transceiver module 701 is further configured to send an indication to the AP indicating that the target terminal device has passed authentication.
[0117] In one possible implementation, the wireless controller includes a built-in portal server. The transceiver module 701 is further configured to, upon receiving a Hypertext Transfer Protocol (HTTP) / Hypertext Transfer Protocol Secure (HTTPS) request message from a target terminal device, send an HTTP / HTTPS response message to the target terminal device, the HTTP / HTTPS response message including a portal authentication page.
[0118] In a possible implementation, the processing module 702 is configured to add the MAC address of the target terminal device to a portal authentication-free list when the user information of the target terminal device passes the portal authentication, and the user information is collected through the portal authentication page.
[0119] In a possible implementation, the processing module 702 is configured to delete the MAC address of the target terminal device from the portal-free authentication list when the duration for which the MAC address of the target terminal device has been added to the portal-free authentication list exceeds a preset duration.
[0120] In a possible implementation, the transceiver module 701 is further configured to send the MAC address of the target terminal device to the second wireless controller. Alternatively, the transceiver module 701 is further configured to send the MAC address of the target terminal device and the portal cache remaining time of the target terminal device to the second wireless controller.
[0121] As shown in Figure 8, which is a schematic diagram of the structure of a network device provided by this application, in this embodiment, the network device 800 may be a wireless controller.
[0122] The network device 800 includes a bus 801 , a processor 802 , a communication interface 803 , and a memory 804 . The processor 802 , the memory 804 , and the communication interface 803 communicate with each other via the bus 801 .
[0123] Bus 801 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. Buses can be categorized as address buses, data buses, and control buses. For ease of illustration, FIG8 shows only one thick line, but this does not imply that there is only one bus or only one type of bus.
[0124] The processor 802 may be any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0125] The memory 804 may include volatile memory, such as random access memory (RAM). The memory 804 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0126] The memory 804 may be used to store software codes related to the network authentication method, and the processor 802 may execute the steps of the authentication method and may also schedule other units to implement corresponding functions.
[0127] It should be understood that the network device 800 can be a centralized or distributed device, and the processor 802 in the network device 800 can be a hardware circuit (such as an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a general-purpose processor, a digital signal processor (DSP), a microprocessor or a microcontroller, etc.), or a combination of these hardware circuits. For example, the processor can be a hardware system with an instruction execution function, such as a CPU, DSP, etc., or a hardware system without an instruction execution function, such as an ASIC, FPGA, etc., or a combination of the above-mentioned hardware systems without an instruction execution function and hardware systems with an instruction execution function.
[0128] The present application also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a computer, the network verification method process of any of the above method embodiments is implemented.
[0129] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0130] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical or other forms.
[0131] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0132] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0133] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the technical solution of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
Claims
1. An authentication method, characterized in that: The method comprises: The first wireless controller receives a request message from an access point AP, wherein the request message is used to request association of a target terminal device with the AP, and the request message includes a media access control MAC address of the terminal; The first wireless controller determines whether the MAC address of the target terminal device is in a portal-free authentication list stored by the first wireless controller, the portal-free authentication list including MAC addresses of terminal devices that have passed portal authentication; When the portal-free authentication list includes the MAC address of the target terminal device, the first wireless controller determines that the target terminal device passes the authentication.
2. The method according to claim 1, characterized in that The first wireless controller determining that the target terminal device passes the authentication includes: The first wireless controller sends an indication to the AP that the target terminal device has passed authentication.
3. The method according to claim 1 or 2, characterized in that: The first wireless controller includes a built-in portal server, and the method further includes: If the first wireless controller receives a Hypertext Transfer Protocol (HTTP) / Hypertext Transfer Protocol Secure (HTTPS) request message from the target terminal device, the first wireless controller sends an HTTP / HTTPS response message to the target terminal device, where the HTTP / HTTPS response message includes a portal authentication page.
4. The method according to claim 3, characterized in that The method further comprises: If the user information of the target terminal device passes the portal authentication, the first wireless controller adds the MAC address of the target terminal device to the portal authentication-free list, and the user information is collected through the portal authentication page.
5. The method according to any one of claims 1 to 4, characterized in that The method further comprises: When the duration for which the MAC address of the target terminal device is added to the portal-free authentication list exceeds a preset duration, the first wireless controller deletes the MAC address of the target terminal device from the portal-free authentication list.
6. The method according to any one of claims 1 to 5, characterized in that After the first wireless controller determines that the target terminal device passes the portal authentication, the method further includes: The first wireless controller sends the MAC address of the target terminal device to the second wireless controller; or The first wireless controller sends the MAC address of the target terminal device and the portal cache remaining time of the target terminal device to the second wireless controller.
7. A communication device, characterized in that: The device is applied to a wireless controller, and the device includes: A transceiver module, used to receive a request message from an AP, wherein the request message is used to request to associate a target terminal device with the AP, and the request message includes a media access control MAC address of the terminal; a processing module, configured to determine whether the MAC address of the target terminal device is in a portal-free authentication list stored in the first wireless controller, wherein the portal-free authentication list includes MAC addresses of terminal devices that have passed portal authentication; The processing module is configured to determine that the target terminal device has passed the authentication when the MAC address of the target terminal device is included in the portal-free authentication list.
8. The device according to claim 7, characterized in that The transceiver module is also used to send an indication that the target terminal device has passed authentication to the AP.
9. The device according to claim 7 or 8, characterized in that The wireless controller includes a built-in portal server; The transceiver module is also used to send a Hypertext Transfer Protocol (HTTP) / Secure Hypertext Transfer Protocol (HTTPS) response message to the target terminal device when receiving a Hypertext Transfer Protocol (HTTP) / Secure Hypertext Transfer Protocol (HTTPS) request message from the target terminal device, wherein the HTTP / HTTPS response message includes a portal authentication page.
10. The device according to claim 9, characterized in that The processing module is used to add the MAC address of the target terminal device to the portal authentication-free list when the user information of the target terminal device passes the portal authentication, and the user information is collected through the portal authentication page.
11. The device according to any one of claims 7 to 10, characterized in that The processing module is configured to delete the MAC address of the target terminal device from the portal-free authentication list when the time duration for which the MAC address of the target terminal device is added to the portal-free authentication list exceeds a preset time duration.
12. The device according to any one of claims 7 to 11, characterized in that The transceiver module is further used to send the MAC address of the target terminal device to the second wireless controller; or The transceiver module is further used to send the MAC address of the target terminal device and the portal cache remaining time of the target terminal device to the second wireless controller.
13. A network device, characterized in that: The device includes a processor and a memory, wherein the processor is coupled to the memory, and the processor is configured to execute the authentication method according to any one of claims 1 to 6 based on instructions stored in the memory.
14. A computer-readable storage medium, characterized in that: The computer-readable storage medium comprises instructions, which, when the computer-readable storage medium is executed on a network device, causes the network device to execute the authentication method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Wireless information transmission method and equipment
CN103702312A
Offline user authentication state maintenance method and system
CN109451503A
Access authentication method and device
CN109495878A
Wireless visitor non-perception authentication method
CN114390527A
Information processing system, information processing method, information processing device, and program
JP6266049B1