Method and apparatus for terminal to access network, and electronic device and storage medium

By receiving messages sent by the access device, determining its type based on terminal feature information and sending VLAN identifiers, the problem of difficulty in accessing the dumb terminals is solved, automatic identification and VLAN allocation of terminal devices are realized, operation and maintenance workload is reduced, and network management efficiency is improved.

WO2025102898A1PCT designated stage expired Publication Date: 2025-05-22RUIJIE NETWORKS CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/115229
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-16
Filing Date
2024-08-28
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

In the campus office network, the diversified types of dumb terminals have led to network managers facing large management and maintenance costs. Especially in a multi-service network environment, dumb terminals cannot be automatically accessed, and the administrator needs to configure it manually.

Method used

By receiving messages sent by the access device, determining their type based on the characteristic information of the terminal, and sending corresponding virtual local area network (VLAN) identification to the terminal, automatic authentication and network communication of the terminal are realized.

Benefits of technology

It realizes automatic identification of terminal device types and VLAN allocation, reduces operation and maintenance workload, supports changes in terminal locations while VLANs do not change, and improves network management efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024115229_22052025_PF_FP_ABST
    Figure CN2024115229_22052025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present application are a method and apparatus for a terminal to access a network, and an electronic device and a storage medium. The method comprises: receiving a first message sent by an access device, wherein the first message comprises feature information of a terminal connected to the access device; and when, on the basis of the feature information, it is determined that the type of the terminal is a first terminal type, sending to the terminal a first virtual local area network (VLAN) identifier corresponding to the first terminal type, wherein the first VLAN identifier is used by the terminal to perform network communication after passing authentication performed by the access device.
Need to check novelty before this filing date? Find Prior Art

Description

Method, device, electronic device and storage medium for terminal accessing network

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on November 16, 2023, with application number 202311525959.2 and application name “Method, network controller and terminal for terminal accessing network”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of data communications, and in particular to a method, device, electronic device, and storage medium for a terminal to access a network. Background Art

[0004] Within campus office networks, dumb terminals vary in type, including telephones, access control systems, printers, cash counters, electronic display screens, and interactive tablets. Compared to more "intelligent" intelligent terminals, dumb terminals are simple computer terminals with limited functionality and simple interaction methods. These dumb terminals impose significant management and maintenance costs on network administrators.

[0005] Summary of the Invention

[0006] Embodiments of the present application provide a method, apparatus, electronic device, and storage medium for a terminal to access a network.

[0007] A first aspect of an embodiment of the present application is to provide a method for a terminal to access a network, comprising: receiving a first message sent by an access device, wherein the first message includes characteristic information of a terminal connected to the access device; and when it is determined that the type of the terminal is a first terminal type based on the characteristic information, sending a first virtual local area network (VLAN) identifier corresponding to the first terminal type to the terminal, wherein the first VLAN identifier is used for the terminal to perform network communication after passing authentication by the access device.

[0008] In one possible implementation, sending the first VLAN identifier corresponding to the first terminal type to the terminal includes: sending the first VLAN identifier and a whitelist to the access device, wherein the access device is used to send the first VLAN identifier to the terminal after the terminal passes the authentication of the whitelist.

[0009] In one possible implementation, after receiving the first message sent by the access device, the method further includes: when it is determined that the type of the terminal is a second terminal type based on the characteristic information, receiving an authentication request initiated by the terminal; and when the terminal passes the authentication, sending a second VLAN identifier corresponding to the second terminal type to the terminal, wherein the second VLAN identifier is used for the terminal to conduct network communication.

[0010] In one possible implementation, before receiving the first message sent by the access device, the method further includes: sending a temporary IP address to the terminal in response to a first IP address acquisition request sent by the terminal through the access device, wherein the temporary IP address is used by the terminal to send the first message.

[0011] In a possible implementation, before sending the temporary IP address to the terminal, the method includes: determining the temporary IP address from a preset address pool.

[0012] In one possible implementation, after sending the temporary IP address to the terminal, the method further includes: in case the temporary IP address expires, in response to a second IP address acquisition request sent by the terminal through the access device, sending a non-temporary IP address to the terminal, wherein the lease corresponding to the non-temporary IP address is greater than the lease corresponding to the temporary IP address.

[0013] In a possible implementation, the temporary IP address is used by the terminal to send the first message through the access device in a default VLAN.

[0014] In a possible implementation, before determining the type of the terminal according to the characteristic information, the method further includes: determining a correspondence between the type of the terminal and a VLAN identifier, wherein the VLAN identifier includes the first VLAN identifier and the second VLAN identifier.

[0015] In a possible implementation, the first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

[0016] In a possible implementation, the first message includes the non-temporary IP address of the terminal.

[0017] A second aspect of an embodiment of the present application is to provide another method for terminal access to a network, which is applied in a network controller, including, when the terminal accesses a switch, receiving a first message sent by the switch containing characteristic information of the terminal; determining the type of the terminal based on the characteristic information; and when the terminal type is a first terminal type, assigning an identifier of an authorized virtual local area network VLAN corresponding to the first terminal type to the terminal, and sending a whitelist to the switch, so that the terminal can send a second message to the device in the authorized virtual local area network VLAN after passing the switch whitelist authentication.

[0018] In one possible implementation, the method further includes: when the terminal type is the second terminal type, receiving an authentication request initiated by the terminal; when the authentication is successful, assigning an identifier of the authorized virtual local area network VLAN corresponding to the second terminal type to the terminal, and instructing the switch to allow the message sent by the terminal to pass through, so that the terminal can send a second message to a device in the service network corresponding to the authorized virtual local area network VLAN through the switch.

[0019] In a possible implementation, before receiving the first message containing the characteristic information of the terminal sent by the switch, it also includes: sending a temporary IP address to the terminal, wherein the temporary IP address is used by the terminal to send the first message through the switch in the default VLAN according to the temporary IP address.

[0020] In a possible implementation, the first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

[0021] A third aspect of an embodiment of the present application is to provide another method for a terminal to access a network, comprising: sending a first message to a network controller through an access device, wherein the first message includes characteristic information of a terminal connected to the access device, and the characteristic information is used by the network controller to determine the type of the terminal; when the terminal type is a first terminal type, receiving a first VLAN identifier corresponding to the first terminal type sent by the network controller; and when the terminal passes the authentication of the access device, performing network communication according to the first VLAN identifier.

[0022] In a possible implementation, when the terminal passes the authentication of the access device, network communication is performed according to the first VLAN identifier, including: when the terminal passes the whitelist authentication, network communication is performed according to the first VLAN identifier, wherein the whitelist is sent by the network controller to the access device.

[0023] In one possible implementation, sending the first message to the network controller through the access device includes: sending a MAC authentication request to the access device; and when the MAC authentication request fails to be sent, sending the first message to the network controller through the access device.

[0024] In one possible implementation, after sending the first message to the network controller through the access device, the method further includes: sending an authentication request to the network controller when the terminal type is a second terminal type; receiving a second VLAN identifier corresponding to the second terminal type sent by the network controller when the terminal passes the authentication; and performing network communication based on the second VLAN identifier.

[0025] In one possible implementation, before sending the first message to the network controller through the access device, the method also includes: sending a first IP address acquisition request to a Dynamic Host Configuration Protocol DHCP server through the access device; and receiving a temporary IP address sent by the DHCP server, wherein the temporary IP address is used by the terminal to send the first message.

[0026] In one possible implementation, after receiving the temporary IP address sent by the DHCP server, the method further includes: when the temporary IP address expires, sending a second IP address acquisition request to the DHCP server through the access device; and receiving a non-temporary IP address sent by the DHCP server, wherein the lease corresponding to the non-temporary IP address is greater than the lease corresponding to the temporary IP address.

[0027] In a possible implementation, when the temporary IP address expires, sending the second IP address acquisition request to the DHCP server through the access device includes: when the temporary IP address expires and renewal fails, sending the second IP address acquisition request to the DHCP server through the access device; or, when the access device receives a port control instruction sent by the network controller, sending the second IP address acquisition request to the DHCP server through the access device, wherein the port control instruction is used to instruct the terminal to re-initiate the IP address acquisition request.

[0028] In a possible implementation, the DHCP server is configured on the network controller.

[0029] In a possible implementation, the first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

[0030] In a possible implementation, the first message also carries the non-temporary IP address of the terminal.

[0031] The fourth aspect of the embodiments of the present application is to provide another method for terminal access to a network, which is applied to a terminal, including: sending a first message containing characteristic information of the terminal to a network controller through a switch, so that the network controller determines the type of the terminal based on the characteristic information; and when the terminal type is a first terminal type, receiving an identifier of an authorized virtual local area network VLAN corresponding to the first terminal type assigned by the network controller, and after the network controller sends a whitelist to the switch and the terminal passes the whitelist authentication, sending a second message to the device in the authorized virtual local area network VLAN through the switch.

[0032] In one possible implementation, sending a first message containing characteristic information of the terminal to a network controller through a switch includes: receiving a temporary IP address sent by the network controller; and sending the first message to the network controller through the switch in a default VLAN based on the temporary IP address.

[0033] In a possible implementation, after receiving the temporary IP address sent by the network controller, the method further includes: after the temporary IP address expires, receiving a non-temporary IP address corresponding to the authorized VLAN sent by the DHCP server; and sending a second message to a device in the service network corresponding to the authorized VLAN through the switch according to the non-temporary IP address.

[0034] The fifth aspect of the embodiments of the present application is to provide an apparatus for terminal access to a network, comprising: a first receiving module for receiving a first message sent by an access device, wherein the first message includes characteristic information of a terminal connected to the access device; and a first sending module for sending a first virtual local area network (VLAN) identifier corresponding to the first terminal type to the terminal when it is determined that the type of the terminal is a first terminal type based on the characteristic information, wherein the first VLAN identifier is used for the terminal to perform network communication after passing the authentication of the access device.

[0035] The sixth aspect of an embodiment of the present application is to provide another device for terminal access to a network, including: a second sending module for sending a first message to a network controller through an access device, wherein the first message includes characteristic information of the terminal, and the characteristic information is used by the network controller to determine the type of the terminal; a second receiving module for receiving a first VLAN identifier corresponding to the first terminal type sent by the network controller when the terminal type is the first terminal type; and a communication module for performing network communication according to the first VLAN identifier when the terminal passes the authentication of the access device.

[0036] The seventh aspect of the embodiments of the present application is to provide a network controller, including: a receiving module for receiving a first message containing characteristic information of the terminal sent by the switch when the terminal is accessed by the switch; an identification module for determining the type of the terminal based on the characteristic information; and a sending module for assigning an identifier of an authorized virtual local area network VLAN corresponding to the first terminal type to the terminal when the terminal type is the first terminal type, and sending a whitelist to the switch, so that the terminal can send a second message to the device in the authorized virtual local area network VLAN after passing the whitelist authentication of the switch.

[0037] The eighth aspect of the embodiments of the present application is to provide a terminal for accessing a network, including: a first sending module for sending a first message containing characteristic information of the terminal to a network controller through a switch, so that the network controller determines the type of the terminal based on the characteristic information; a first receiving module for receiving an identifier of an authorized virtual local area network VLAN corresponding to the first terminal type assigned by the network controller when the terminal type is the first terminal type; and a second sending module for sending a second message to the device in the authorized virtual local area network VLAN through the switch after the network controller sends a whitelist to the switch and the terminal passes the whitelist authentication.

[0038] The ninth aspect of an embodiment of the present application is to provide a system for terminal access to a network, comprising: an access device for sending a first message to a network controller, wherein the first message includes characteristic information of a terminal connected to the access device, and the characteristic information is used by the network controller to determine the type of the terminal; and a network controller for receiving the first message, and when determining that the type of the terminal is a first terminal type based on the characteristic information, sending a first virtual local area network (VLAN) identifier corresponding to the first terminal type to the terminal, wherein the first VLAN identifier is used by the terminal to perform network communication after passing authentication by the access device.

[0039] The tenth aspect of an embodiment of the present application is to provide another system for terminal access to a network, including a switch, for sending a first message containing characteristic information of the terminal to a network controller when the terminal accesses the switch; and a network controller, for receiving the first message; determining the type of the terminal based on the characteristic information; when the terminal type is the first terminal type, assigning an identifier of an authorized virtual local area network VLAN corresponding to the first terminal type to the terminal, and sending a whitelist to the switch, so that the terminal can send a second message to the device in the authorized virtual local area network VLAN after passing the whitelist authentication of the switch.

[0040] An eleventh aspect of the embodiments of the present application is to provide an electronic device, comprising: a memory for storing a computer program; and a processor for implementing the method described in any one of the above aspects when executing the computer program stored in the memory.

[0041] The twelfth aspect of the embodiments of the present application is to provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method for terminal accessing a network as described in any of the above aspects.

[0042] According to the solution provided in the embodiment of the present application, the VLAN allocation of the terminal no longer depends on its location information, but mainly depends on its device type, so that VLAN allocation becomes simpler, and the terminal location can be changed without changing the VLAN. The terminal device is plug-and-play, which reduces the operation and maintenance workload of the terminal.

[0043] Other features and advantages of the present application will be described in the following description. The purpose and other advantages of the present application can be realized and obtained through the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. Obviously, the drawings introduced below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0045] FIG1 is a flow chart of a method for a terminal to access a network provided by an embodiment of the present application;

[0046] FIG2 is a flow chart of another method for a terminal to access a network provided in an embodiment of the present application;

[0047] FIG3 is a flow chart of another method for a terminal to access a network provided in an embodiment of the present application;

[0048] FIG4 is a flow chart of another method for a terminal to access a network provided in an embodiment of the present application;

[0049] FIG5 is a flow chart of a device for terminal accessing a network provided in an embodiment of the present application;

[0050] FIG6 is a structural diagram of another device for terminal accessing a network provided in an embodiment of the present application;

[0051] FIG7 is a flow chart of another method for a terminal to access a network provided in an embodiment of the present application. DETAILED DESCRIPTION

[0052] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of the technical solutions of this application, but not all of them. Based on the embodiments described in this application document, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the technical solutions of this application.

[0053] The terms "first" and "second" in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any of its variations are intended to cover non-exclusive protection. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices. "Multiple" in this application can mean at least two, for example, two, three or more, and the embodiments of this application are not limited thereto.

[0054] In addition, the term "and / or" in this document simply describes an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document, unless otherwise specified, generally indicates an "or" relationship between the related objects.

[0055] Within campus office networks, dumb terminals vary widely, including telephones, access control systems, printers, cash counters, electronic display screens, and interactive tablets. These dumb terminals impose significant management and maintenance costs on network administrators. Especially in multi-service network environments, dumb terminals cannot automatically join the network and require manual configuration by administrators.

[0056] Currently, there are several solutions to the problem of dumb terminals having difficulty accessing the network.

[0057] Solution 1: Using Media Access Control Address (MAC) authentication, administrators collect the MAC addresses of dumb terminals and pre-configure their authorized virtual local area networks (VLANs) and access policies on the authentication server. Once a dumb terminal accesses the network, it undergoes MAC-aware authentication and is automatically authorized to the corresponding service network, achieving seamless access for the dumb terminal.

[0058] Solution 2: Use a terminal access control solution. Enable the access control function on the interface of the access device to which the dumb terminal is connected. After the dumb terminal is connected to the network, the Software Defined Network (SDN) controller is triggered to pop up an approval page. After the administrator approves it on the web page, the dumb terminal automatically connects to the network.

[0059] Solution 3: Use static configuration to directly configure the dumb terminal's MAC address on the interface of the access device to which the dumb terminal is connected, so that the dumb terminal can be managed and connected to the network.

[0060] All of the above solutions have certain flaws. Solution 1 requires collecting the MAC information of dumb terminals in advance and entering it into the authentication server. If the authentication server does not support authorized VLAN configuration or does not support MAC import, Solution 1 cannot be implemented. Solution 2 can implement dumb terminal access control, but because the administrator will not modify the VLAN to which the dumb terminal is connected during approval, and one VLAN corresponds to one business network, which is an independent network isolated by VLAN, Solution 2 cannot support multiple business network scenarios and can only be applied to single business network scenarios. Solution 3 has high manual operation and maintenance costs. When the terminal is migrated, such as from one access device to another, or from one interface of an access device to another, the MAC address needs to be reconfigured, which will bring a large workload for operation and maintenance.

[0061] A first aspect of an embodiment of the present application is to provide a method for a terminal to access a network, which is applied in a network controller. As shown in FIG1 , the method includes the following steps.

[0062] S101: Receive a first message sent by an access device, where the first message includes feature information of a terminal connected to the access device.

[0063] In a possible implementation, the access device may be a switch, a router, or other network devices.

[0064] In a possible implementation, receiving the first message sent by the access device may include: when the terminal accesses a switch, receiving the first message including characteristic information of the terminal sent by the switch.

[0065] In a possible implementation, step S101 may specifically include: when the terminal accesses the switch and initiates MAC authentication but fails, receiving a first message including characteristic information of the terminal sent by the switch.

[0066] S103, when it is determined according to the characteristic information that the type of the terminal is the first terminal type, sending a first virtual local area network VLAN identifier corresponding to the first terminal type to the terminal, wherein the first VLAN identifier is used by the terminal to perform network communication after passing the authentication of the access device.

[0067] In a possible implementation, the first VLAN identifier is used to indicate a VLAN allocated by the controller to the terminal, which allows the terminal to perform network communication, that is, a VLAN authorized to the terminal. Therefore, the first VLAN identifier can be understood as a first authorized VLAN.

[0068] In one possible implementation, the first terminal type is a dumb terminal. A dumb terminal is a terminal that relies on a host for processing. Generally speaking, a dumb terminal lacks a processor, hard drive, or floppy disk, and only has a keyboard, a display, and a communication path to the host (usually through some type of controller). A dumb terminal cannot actively initiate authentication requests and lacks the authentication function. Consequently, a dumb terminal cannot obtain an authorized VLAN through authentication. Therefore, after a dumb terminal is connected to a switch, it can only rely on the network controller to identify the terminal type as a dumb terminal and actively assign a first authorized VLAN identifier to the dumb terminal. This allows the dumb terminal to conduct network communications based on the first VLAN identifier, for example, sending a second message to a device in the service network corresponding to the first VLAN.

[0069] In one possible implementation, allocating the first VLAN identifier corresponding to the first terminal type to the terminal includes: sending the first VLAN identifier and a whitelist to the access device, wherein the access device is configured to send the first VLAN identifier to the terminal after the terminal passes authentication based on the whitelist. Furthermore, the terminal may send a second message to a device in the service network corresponding to the first VLAN identifier after passing authentication based on the whitelist on the access device.

[0070] To prevent devices impersonating dumb terminals from entering the network without authorization, which could pose a security risk to the service network, you can use a whitelist to authenticate terminals accessing the network to improve network security.

[0071] In a possible implementation, as shown in FIG2 , after receiving the first message sent by the access device, the method further includes the following steps.

[0072] S105: When it is determined according to the characteristic information that the type of the terminal is the second terminal type, receive an authentication request initiated by the terminal.

[0073] S107: If the terminal passes the authentication, send a second VLAN identifier corresponding to the second terminal type to the terminal, wherein the second VLAN identifier is used by the terminal for network communication.

[0074] In one possible implementation, the second terminal type is a smart terminal. The smart terminal has its own processor, storage device, and software program, can actively initiate an authentication request, and has the function of initiating authentication, so that the smart terminal can obtain the second VLAN identifier through authentication.

[0075] In a possible implementation, the second VLAN identifier is used to indicate the VLAN allocated by the controller to the terminal, which allows the terminal to perform network communication, that is, the VLAN authorized to the terminal. Therefore, the second VLAN identifier can be understood as the second authorized VLAN.

[0076] In one possible implementation, when the terminal passes the authentication of the network controller, the network controller sends a second VLAN identifier corresponding to the second terminal type to the terminal, and instructs the access device, such as a switch, to allow the message sent by the terminal to pass, so that the terminal can send a second message to the device in the service network corresponding to the second authorized VLAN through the switch.

[0077] Through the method of the embodiment of the present application, it is possible to automatically identify the terminal device type in scenarios where dumb terminals and smart terminals are shared. Corresponding VLAN identifiers are automatically assigned to different types of devices, without the need for the administrator to collect the terminal MAC address information in advance. In addition, in traditional technologies, when a terminal migrates, such as connecting from one access device to another access device, or from one interface of an access device to another interface, the access device needs to promptly collect the terminal's location information. The location information can be the information of the new access device connected to the terminal after migration, or the information of the new interface of the same access device connected to the terminal after migration. Based on the terminal's location information, the VLAN and corresponding permissions are reallocated to the terminal, and the MAC address on the access device interface to which the terminal is connected needs to be reconfigured, which will bring a large workload of operation and maintenance. In the embodiment of the present application, the VLAN allocation of the terminal no longer depends on its location information, but mainly depends on its device type, so that the VLAN allocation becomes simpler, and the VLAN can follow the terminal location change without changing the VLAN, that is, the VLAN is mobile, and the terminal is plug-and-play, which reduces the operation and maintenance workload of the terminal. At the same time, the physical network usually carries multiple virtual business networks, and one VLAN corresponds to one business network. Through the solution of the embodiment of the present application, different VLANs can be assigned to terminals based on the type of terminal device, thereby realizing multiple uses of one network and isolating different business networks from each other.

[0078] In a possible implementation, before receiving the first message sent by the access device and containing the characteristic information of the terminal, as shown in FIG3 , the method further includes the following steps.

[0079] S1011: In response to a first IP address acquisition request sent by the terminal through the access device, send a temporary IP address to the terminal, wherein the temporary IP address is used by the terminal to send the first message.

[0080] In one possible implementation, a dumb terminal has not yet been assigned an IP address before accessing the switch. Therefore, a temporary IP address must be obtained to facilitate communication between the dumb terminal and other network devices. A temporary IP address is an IP address with a lease shorter than the first time period. For example, if the first time period is 5 minutes, the IP address may have a lease of 1 or 2 minutes.

[0081] In a possible implementation, the temporary IP address is used by the terminal to send the first message through the switch in a default VLAN according to the temporary IP address.

[0082] In one possible implementation, the Dynamic Host Configuration Protocol (DHCP) can be deployed on the network controller, a DHCP temporary address pool can be set, the temporary IP address can be determined from the temporary address pool, and the temporary IP address can be sent to the terminal. The temporary IP address is pre-stored in the temporary address pool. At this time, the network controller is integrated with the DHCP function, so the temporary IP address can be allocated. In another possible implementation, the network controller does not have an integrated DHCP temporary address pool function, so the temporary IP address cannot be allocated. The access device needs to send the first IP address acquisition request to other devices independent of the network controller, such as a DHCP server, to obtain the temporary IP address. With the temporary IP address, the terminal can send the first message through the switch in the default VLAN.

[0083] In a possible implementation, after sending the temporary IP address to the terminal, the following step is also included: when the temporary IP address expires, in response to a second IP address acquisition request sent by the terminal through the access device, a non-temporary IP address is sent to the terminal.

[0084] In one possible implementation, the non-temporary IP address may be an IP address with a lease period exceeding the second time period, for example, the second time period is half a month, and the IP address has a lease period of one month or six months. The non-temporary IP address may also be a static IP address or a fixed IP address.

[0085] In a possible implementation, the lease period corresponding to the non-temporary IP address is longer than the lease period corresponding to the temporary IP address.

[0086] Through the solution of the embodiment of the present application, after the lease of the temporary IP address expires, the dumb terminal needs to reapply for a new IP address to ensure uninterrupted services.

[0087] In a possible implementation, the first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

[0088] In a possible implementation, before determining the type of the terminal according to the characteristic information, the method further includes: determining a correspondence between the type of the terminal and a VLAN identifier, wherein the VLAN identifier includes the first VLAN identifier and the second VLAN identifier.

[0089] In a possible implementation, the VLAN identifier may further include a VLAN identifier other than the first VLAN identifier and the second VLAN identifier.

[0090] In one possible implementation, the first terminal type is a dumb terminal, and the first VLAN identifier corresponding to the first terminal type may include one or a group of VLAN identifiers. For example, dumb terminals may include devices such as cameras and printers, with cameras corresponding to VLAN identifier A and printers corresponding to VLAN identifier B. The second terminal type is a smart terminal, and the second VLAN identifier corresponding to the second terminal type may include one or a group of VLAN identifiers. For example, smart terminals may include devices such as switches and gateways, with switches corresponding to VLAN identifier C and gateways corresponding to VLAN identifier D. Furthermore, VLAN identifier A corresponds to the first service network, VLAN identifier B corresponds to the second service network, VLAN identifier C corresponds to the third service network, and VLAN identifier D corresponds to the fourth service network. By establishing a correspondence between terminal types and service networks, each service network corresponds to an authorized virtual local area network VLAN, thereby enabling corresponding service networks and corresponding permissions for different types of terminal devices.

[0091] In one possible implementation, the terminal can be assigned an identifier of an authorized virtual local area network VLAN corresponding to the first terminal type or the second terminal type through various management protocols such as the Network Configuration Protocol (NETCONF), the command-line interface (CLI), and the CPE WAN Management Protocol (also known as TR069).

[0092] In one possible implementation, the method also includes: receiving a first message sent by an access device, wherein the first message includes characteristic information of a terminal to which the access device is connected and a non-temporary IP address of the terminal; and, when determining that the type of the terminal is a first terminal type based on the characteristic information, sending a first virtual local area network VLAN identifier corresponding to the first terminal type to the terminal, so that after the terminal passes the authentication of the access device, it can send a second message to a device in a service network corresponding to the first VLAN identifier based on the non-temporary IP address.

[0093] In this embodiment, the first message includes the non-temporary IP address of the terminal, so that the terminal can directly obtain the assigned first VLAN identifier from the network controller based on the non-temporary IP address. This eliminates the need to obtain a temporary IP address from the network controller before sending the first message, and eliminates the need to re-initiate a DHCP (Dynamic Host Configuration Protocol) request to obtain a non-temporary IP address after the temporary IP address ages.

[0094] In one possible implementation, the method further includes: receiving a first message sent by an access device, wherein the first message includes characteristic information of a terminal to which the access device is connected and a non-temporary IP address of the terminal; in a case where it is determined that the type of the terminal is a second terminal type based on the characteristic information, receiving an authentication request initiated by the terminal; and in a case where the terminal passes the authentication, sending a second VLAN identifier corresponding to the second terminal type to the terminal, wherein the second VLAN identifier is used for the terminal to conduct network communication.

[0095] In a possible implementation, determining the type of the terminal according to the characteristic information includes: collecting the first message and determining the type of the terminal according to the terminal characteristic information in the collected first message.

[0096] In one possible implementation, terminal type identification technology can be used in conjunction with terminal anti-counterfeiting technology to achieve policy-based blocking of counterfeit terminals. Terminal anti-counterfeiting technology involves identifying a terminal's type when it first connects to an access device and re-identifying it the second time it connects to the same device. If the terminal type matches the two times, it indicates the terminal is legitimate. If the terminal type differs, it indicates the terminal is a counterfeit or illegal terminal. In this case, the illegal terminal can be blocked, including traffic blocking or excluding the terminal from whitelist authentication.

[0097] Another aspect of an embodiment of the present application is to provide a method for a terminal to access a network, which is applied to a terminal. As shown in FIG4 , the method includes the following steps.

[0098] S401: Send a first message to a network controller through an access device, wherein the first message includes characteristic information of the terminal, and the characteristic information is used by the network controller to determine the type of the terminal.

[0099] S403: When the terminal type is a first terminal type, receive a first VLAN identifier corresponding to the first terminal type and sent by the network controller.

[0100] S405 : When the terminal passes the authentication of the access device, perform network communication according to the first VLAN identifier.

[0101] In a possible implementation, when the terminal passes the authentication of the access device, network communication is performed according to the first VLAN identifier, including: when the terminal passes the whitelist authentication, network communication is performed according to the first VLAN identifier, wherein the whitelist is sent by the network controller to the access device.

[0102] In one possible implementation, sending the first message to the network controller through the access device includes: sending a MAC authentication request to the access device; and, if the MAC authentication request fails to be sent, sending the first message to the network controller through the access device.

[0103] When the first terminal type is a dumb terminal, since the dumb terminal does not have the function of initiating authentication, it cannot actively initiate an authentication request and obtain an authorized VLAN. After the dumb terminal is connected to an access device, such as a switch, it can only send a first message to the network controller. After the network controller recognizes that the terminal type is a dumb terminal, it actively assigns an authorized first VLAN identifier to the dumb terminal so that the dumb terminal can communicate on the network based on the first VLAN identifier.

[0104] In one possible implementation, after sending the first message to the network controller through the access device, it also includes: when the terminal type is a second terminal type, sending an authentication request to the network controller; when the terminal passes the authentication, receiving a second VLAN identifier corresponding to the second terminal type sent by the network controller; and performing network communication according to the second VLAN identifier.

[0105] In a possible implementation, the first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

[0106] In one possible implementation, the first message also carries the non-temporary IP address of the terminal. In this case, the terminal can directly obtain the assigned first VLAN identifier from the network controller based on the non-temporary IP address. This eliminates the need to obtain a temporary IP address from the network controller before sending the first message, and eliminates the need to re-initiate a DHCP (Dynamic Host Configuration Protocol) request to obtain a non-temporary IP address after the temporary IP address ages.

[0107] In a possible implementation, before sending the first message containing the characteristic information of the terminal to the network controller through the switch, it also includes: sending a first IP address acquisition request to a Dynamic Host Configuration Protocol DHCP server through the access device; and receiving a temporary IP address sent by the DHCP server, wherein the temporary IP address is used by the terminal to send the first message.

[0108] In a possible implementation, the temporary IP address is used by the terminal to send the first message according to a default VLAN.

[0109] In a possible implementation, the temporary IP address refers to an IP address with a lease shorter than the first time period, for example, the first time period is 5 minutes and the IP address has a lease of 1 minute or 2 minutes.

[0110] In a possible implementation, after receiving the temporary IP address sent by the DHCP server, the method further includes: sending a second IP address acquisition request to the DHCP server through the access device when the temporary IP address expires; and receiving a non-temporary IP address sent by the DHCP server.

[0111] In a possible implementation, the lease period corresponding to the non-temporary IP address is greater than the lease period corresponding to the temporary IP address.

[0112] In a possible implementation, when the lease of the temporary IP address expires, the terminal will automatically initiate a renewal. If the renewal fails, the terminal will re-initiate an IP address application.

[0113] In a possible implementation, when the temporary IP address expires, sending the second IP address acquisition request to the DHCP server through the access device includes: when the access device receives a port control instruction sent by the network controller, sending the second IP address acquisition request to the DHCP server through the access device, wherein the port control instruction is used to instruct the terminal to re-initiate the IP address acquisition request.

[0114] In one possible implementation, the network controller proactively sends a port control instruction to the access device when the lease of a temporary IP address expires. Upon receiving the port control instruction from the network controller, the terminal, such as a switch, can initiate an IP address request from the DHCP server to obtain a non-temporary IP address sent by the DHCP server. The port control instruction instructs the terminal to refresh the network card and re-initiate an IP address request. Compared to the terminal initiating an IP address re-application through automatic lease renewal, proactively notifying the terminal to re-apply for an IP address through the network controller results in a shorter and faster response time.

[0115] In one possible implementation, an IP address can also be obtained from another device with DHCP functionality, such as a network controller. In this case, the DHCP server is provided on the network controller, i.e., the network controller is equipped with DHCP functionality. In this case, the terminal device can directly send a first IP address acquisition request to the network controller to obtain a temporary IP address, or can directly send a second IP address acquisition request to the network controller to obtain a non-temporary IP address.

[0116] In one possible implementation, the non-temporary IP address may be an IP address with a lease period exceeding the second time period, for example, the second time period is half a month, and the IP address has a lease period of one month or six months. The non-temporary IP address may also be a static IP address or a fixed IP address.

[0117] The method of the embodiments of the present application enables automatic identification of terminal device types in scenarios where dumb terminals and smart terminals are used together. VLAN identifiers are automatically assigned to different types of devices, eliminating the need for administrators to pre-collect terminal MAC address information. Furthermore, in conventional technologies, when a terminal migrates, such as from one access device to another, or from one interface of one access device to another, the access device must promptly collect the terminal's location information, such as the information about the access device or interface connected to the access device after the migration. Based on the terminal's location information, the VLAN and corresponding permissions must be reassigned, and the MAC address of the access device interface to which the terminal is connected must be reconfigured, resulting in a significant operational and maintenance workload. In the embodiments of the present application, VLAN assignment for a device no longer depends on its location information, but primarily on its device type. This simplifies VLAN assignment, allows for changes in terminal location without changing the VLAN, and enables plug-and-play terminal devices, reducing terminal operational and maintenance workload. Furthermore, physical networks typically carry multiple virtual service networks, with each VLAN corresponding to a service network. The solutions of the embodiments of the present application enable different VLANs to be assigned to terminals based on their device type, thus achieving multi-purpose use of a single network and isolating different service networks from each other.

[0118] Another aspect of an embodiment of the present application is to provide a device for a terminal to access a network, which is applied in a network controller. As shown in FIG5 , the device includes the following modules.

[0119] The first receiving module 501 is configured to receive a first message sent by an access device, wherein the first message includes feature information of a terminal connected to the access device.

[0120] The first sending module 503 is used to send a first virtual local area network VLAN identifier corresponding to the first terminal type to the terminal when it is determined that the type of the terminal is the first terminal type based on the characteristic information, wherein the first VLAN identifier is used by the terminal to perform network communication after passing the authentication of the access device.

[0121] According to the solution provided in the embodiment of the present application, the VLAN allocation of the device no longer depends on its location information, but mainly depends on its device type, so that VLAN allocation becomes simpler, and the terminal location can be changed without changing the VLAN. The terminal device is plug-and-play, which reduces the terminal operation and maintenance workload.

[0122] In a possible implementation, the first sending module 503 is further configured to send a whitelist to the access device, wherein the whitelist is used by the access device to authenticate the terminal.

[0123] In one possible implementation, the first sending module 503 is further used to receive an authentication request initiated by the terminal, wherein the characteristic information indicates that the type of the terminal is a second terminal type; and when the terminal passes the authentication, send a second VLAN identifier corresponding to the second terminal type to the terminal, wherein the second VLAN identifier is used for the terminal to perform network communication.

[0124] In a possible implementation, the first message also carries the non-temporary IP address of the terminal.

[0125] In a possible implementation, the first sending module 503 is further used to send a temporary IP address to the terminal in response to a first IP address acquisition request sent by the terminal through the access device, wherein the temporary IP address is used by the terminal to send the first message.

[0126] In a possible implementation, the apparatus further includes a determining module, configured to determine the temporary IP address from a preset address pool before sending the temporary IP address to the terminal.

[0127] In a possible implementation, the first sending module 503 is further configured to send a non-temporary IP address to the terminal in response to a second IP address acquisition request sent by the terminal through the access device when the temporary IP address expires.

[0128] In a possible implementation, the lease period corresponding to the non-temporary IP address is greater than the lease period corresponding to the temporary IP address.

[0129] In a possible implementation, the determination module is further configured to determine a correspondence between the type of the terminal and a VLAN identifier, wherein the VLAN identifier includes the first VLAN identifier and the second VLAN identifier.

[0130] In a possible implementation, the first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

[0131] In a possible implementation, the temporary IP address is used by the terminal to send the first message through the access device in a default VLAN.

[0132] Another aspect of the embodiments of the present application is to provide an apparatus for a terminal to access a network, which is applied to a terminal and includes the following modules as shown in FIG6 .

[0133] The second sending module 601 is configured to send a first message to the network controller through an access device, wherein the first message includes characteristic information of the terminal, and the characteristic information is used by the network controller to determine the type of the terminal.

[0134] The second receiving module 603 is configured to receive, when the terminal type is a first terminal type, a first VLAN identifier corresponding to the first terminal type and sent by the network controller.

[0135] The communication module 605 is configured to perform network communication according to the first VLAN identifier when the terminal passes the authentication of the access device.

[0136] According to the solution provided in the embodiment of the present application, the VLAN allocation of the device no longer depends on its location information, but mainly depends on its device type, so that VLAN allocation becomes simpler, and the terminal location can be changed without changing the VLAN. The terminal device is plug-and-play, which reduces the terminal operation and maintenance workload.

[0137] In a possible implementation, the communication module 605 is further configured to perform network communication according to the first VLAN identifier when the terminal passes whitelist authentication, wherein the whitelist is sent by the network controller to the access device.

[0138] In one possible implementation, the second sending module 601 is further used to send an authentication request to the network controller when the terminal type is a second terminal type; the second receiving module 603 is further used to receive a second VLAN identifier corresponding to the second terminal type sent by the network controller when the terminal passes the authentication of the network controller; and the communication module 605 is further used to perform network communication based on the second VLAN identifier.

[0139] In a possible implementation, the first message also carries the non-temporary IP address of the terminal.

[0140] In one possible implementation, the second sending module 601 is further used to send a first IP address acquisition request to a Dynamic Host Configuration Protocol DHCP server through the access device before sending the first message to the network controller through the access device; and the second receiving module 603 is further used to receive a temporary IP address sent by the DHCP server, wherein the temporary IP address is used by the terminal to send the first message.

[0141] In a possible implementation, the second sending module 601 is further used to send a second IP address acquisition request to the DHCP server through the access device when the temporary IP address expires; and the second receiving module 603 is further used to receive a non-temporary IP address sent by the DHCP server.

[0142] In a possible implementation, the lease period corresponding to the non-temporary IP address is greater than the lease period corresponding to the temporary IP address.

[0143] In a possible implementation, the second sending module 601 is further used to send a second IP address acquisition request to the DHCP server through the access device when the temporary IP address expires and renewal fails; or, when the access device receives a port control instruction sent by the network controller, send the second IP address acquisition request to the DHCP server through the access device, wherein the port control instruction is used to instruct the terminal to re-initiate the IP address acquisition request.

[0144] In a possible implementation, the DHCP server is configured on the network controller.

[0145] In a possible implementation, the second sending module 601 is further configured to send a MAC authentication request to the access device; and, if the MAC authentication request fails to be sent, send the first message to the network controller through the access device.

[0146] In a possible implementation, the first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

[0147] FIG7 is a flow chart of another method for a terminal to access a network provided in an embodiment of the present application. As shown in FIG7 , the method includes the following steps.

[0148] S701: When a terminal is not configured with an IP address, the terminal sends a first DHCP discovery message to an access device.

[0149] S702: The access device forwards the first DHCP discovery message to a network controller, where the network controller is integrated with DHCP capability.

[0150] S703: The network controller allocates a temporary IP address to the terminal and sends it to the access device.

[0151] S704: The access controller forwards the temporary IP address to the terminal.

[0152] S705 : The terminal sends a first message to the network controller through the access device based on the default VLAN and the temporary IP address. The first message carries characteristic information of the terminal.

[0153] S706: The access device forwards the first message to the network controller.

[0154] S707: The network controller identifies the terminal as a dumb terminal according to the characteristic information, and sends a first VLAN identifier and an authentication whitelist to the access device.

[0155] S708 : The access device authenticates the terminal based on the whitelist, and forwards the first VLAN identifier to the terminal if the terminal passes the authentication.

[0156] S709 , when the temporary IP address expires, the network controller sends a port configuration instruction to the access device, indicating that the temporary address of the terminal has expired and that a new IP address application needs to be initiated.

[0157] S710: The access device notifies the terminal to re-initiate an IP address application.

[0158] S711: The terminal sends a second DHCP discover message.

[0159] S712: The access device forwards the second DHCP message to the gateway.

[0160] S713: The gateway forwards the second DHCP message to the network controller.

[0161] S714: The network controller sends the non-temporary IP address allocated to the terminal to the gateway.

[0162] S715: The gateway forwards the non-temporary IP address to the terminal.

[0163] Another aspect of the embodiments of the present application is to provide a system for a terminal to access a network, including the following devices.

[0164] An access device is used to send a first message to a network controller, wherein the first message includes characteristic information of a terminal connected to the access device, and the characteristic information is used by the network controller to determine the type of the terminal.

[0165] A network controller is used to receive the first message, and when it is determined that the type of the terminal is a first terminal type based on the characteristic information, send a first virtual local area network VLAN identifier corresponding to the first terminal type to the terminal, wherein the first VLAN identifier is used for the terminal to perform network communication after passing the authentication of the access device.

[0166] According to the solution provided in the embodiment of the present application, the VLAN allocation of the device no longer depends on its location information, but mainly depends on its device type, so that VLAN allocation becomes simpler, and the terminal location can be changed without changing the VLAN. The terminal device is plug-and-play, which reduces the terminal operation and maintenance workload.

[0167] Another aspect of the embodiments of the present application is to provide a computer-readable storage medium, which, when instructions in the computer-readable storage medium are executed by a processor in an electronic device, enables the electronic device to implement the method steps in the above embodiments.

[0168] Another aspect of the embodiments of the present application is to provide an electronic device, including: a memory configured to store processor-executable instructions; and a processor configured to execute the processor-executable instructions to implement the method steps in the above embodiments.

[0169] According to the solution provided in the embodiment of the present application, the VLAN allocation of the device no longer depends on its location information, but mainly depends on its device type, so that VLAN allocation becomes simpler, and the terminal location can be changed without changing the VLAN. The terminal device is plug-and-play, which reduces the terminal operation and maintenance workload.

[0170] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0171] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow process and / or box in the flow chart and / or block diagram, as well as the combination of the flow processes and / or boxes in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a controller of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the controller of the computer or other programmable data processing device produce a device for implementing the function specified in one or more flow processes in the flow chart and / or one or more boxes in the block diagram.

[0172] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0173] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0174] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.

[0175] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

[0176] The present invention is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0177] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0178] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0179] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A method for a terminal to access a network, comprising: receiving a first message sent by an access device, wherein the first message includes characteristic information of a terminal connected to the access device; and When it is determined according to the characteristic information that the type of the terminal is a first terminal type, a first virtual local area network VLAN identifier corresponding to the first terminal type is sent to the terminal, wherein the first VLAN identifier is used for the terminal to perform network communication after passing the authentication of the access device.

2. The method of claim 1, wherein: Sending the first VLAN identifier corresponding to the first terminal type to the terminal includes: The first VLAN identifier and the white list are sent to the access device, wherein the access device is used to send the first VLAN identifier to the terminal after the terminal passes the authentication of the white list.

3. The method of claim 1, wherein: After receiving the first message sent by the access device, the method further includes: In a case where it is determined according to the characteristic information that the type of the terminal is a second terminal type, receiving an authentication request initiated by the terminal; and In a case where the terminal passes the authentication, a second VLAN identifier corresponding to the second terminal type is sent to the terminal, wherein the second VLAN identifier is used for the terminal to perform network communication.

4. The method according to any one of claims 1 to 3, wherein: Before receiving the first message sent by the access device, the method further includes: In response to a first IP address acquisition request sent by the terminal through the access device, a temporary IP address is sent to the terminal, wherein the temporary IP address is used by the terminal to send the first message.

5. The method of claim 4, wherein: Before sending the temporary IP address to the terminal, the method further includes: The temporary IP address is determined from a preset address pool.

6. The method according to claim 4 or 5, wherein: After sending the temporary IP address to the terminal, the method further includes: When the temporary IP address expires, in response to a second IP address acquisition request sent by the terminal through the access device, a non-temporary IP address is sent to the terminal, wherein the lease corresponding to the non-temporary IP address is greater than the lease corresponding to the temporary IP address.

7. The method according to any one of claims 4 to 6, wherein: The temporary IP address is used by the terminal to send the first message through the access device in the default VLAN.

8. The method according to any one of claims 3 to 7, wherein: Before determining the type of the terminal according to the characteristic information, the method further includes: Determine a correspondence between the type of the terminal and the VLAN identifier, wherein the VLAN identifier includes the first VLAN identifier and the second VLAN identifier.

9. The method according to any one of claims 3 to 8, wherein: The first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

10. A method for a terminal to access a network, comprising: Sending a first message to a network controller through an access device, wherein the first message includes characteristic information of a terminal connected to the access device, and the characteristic information is used by the network controller to determine the type of the terminal; In a case where the terminal type is a first terminal type, receiving a first VLAN identifier corresponding to the first terminal type and sent by the network controller; and When the terminal passes the authentication of the access device, network communication is performed according to the first VLAN identifier.

11. The method of claim 10, wherein: When the terminal passes the authentication of the access device, performing network communication according to the first VLAN identifier includes: In a case where the terminal passes the whitelist authentication, network communication is performed according to the first VLAN identifier, wherein the whitelist is sent by the network controller to the access device.

12. The method according to claim 10 or 11, wherein: Sending the first message to the network controller through the access device includes: Sending a MAC authentication request to the access device; and When the MAC authentication request fails to be sent, the first message is sent to the network controller through the access device.

13. The method of claim 10, wherein: After sending the first message to the network controller through the access device, the method further includes: When the terminal type is the second terminal type, sending an authentication request to the network controller; When the terminal passes the authentication, receiving a second VLAN identifier corresponding to the second terminal type and sent by the network controller; and Network communication is performed according to the second VLAN identifier.

14. The method according to any one of claims 10 to 13, wherein: Before sending the first message to the network controller through the access device, the method further includes: Sending a first IP address acquisition request to a Dynamic Host Configuration Protocol DHCP server through the access device; and A temporary IP address sent by the DHCP server is received, wherein the temporary IP address is used by the terminal to send the first message.

15. The method according to claim 14, characterized in that After receiving the temporary IP address sent by the DHCP server, the method further includes: When the temporary IP address expires, sending a second IP address acquisition request to the DHCP server through the access device; and A non-temporary IP address sent by the DHCP server is received, wherein a lease period corresponding to the non-temporary IP address is greater than a lease period corresponding to the temporary IP address.

16. The method according to claim 15, characterized in that When the temporary IP address expires, sending the second IP address acquisition request to the DHCP server through the access device includes: When the temporary IP address expires and the lease renewal fails, sending a request for obtaining the second IP address to the DHCP server through the access device; or, When the access device receives the port control instruction sent by the network controller, the second IP address acquisition request is sent to the DHCP server through the access device, wherein the port control instruction is used to instruct the terminal to re-initiate the IP address acquisition request.

17. The method according to any one of claims 14 to 16, characterized in that The DHCP server is arranged on the network controller.

18. The method according to any one of claims 10 to 17, wherein: The first terminal type is a dumb terminal, and the second terminal type is a smart terminal.

19. A device for a terminal to access a network, comprising: The first receiving module is used to receive a first message sent by an access device, wherein: The first message includes characteristic information of a terminal connected to the access device; as well as The first sending module is used to send a first virtual local area network VLAN identifier corresponding to the first terminal type to the terminal when it is determined that the type of the terminal is a first terminal type according to the characteristic information, wherein the first VLAN identifier is used for the terminal to perform network communication after passing the authentication of the access device.

20. A device for a terminal to access a network, comprising: A second sending module, configured to send a first message to a network controller through an access device, wherein the first message includes characteristic information of the terminal, and the characteristic information is used by the network controller to determine the type of the terminal; A second receiving module is configured to receive, when the terminal type is a first terminal type, a first VLAN identifier corresponding to the first terminal type and sent by the network controller; and A communication module is used to perform network communication according to the first VLAN identifier when the terminal passes the authentication of the access device.

21. A system for a terminal to access a network, comprising: An access device, configured to send a first message to a network controller, wherein the first message includes characteristic information of a terminal connected to the access device, and the characteristic information is used by the network controller to determine a type of the terminal; and A network controller is used to receive the first message, and when it is determined that the type of the terminal is a first terminal type based on the characteristic information, send a first virtual local area network VLAN identifier corresponding to the first terminal type to the terminal, wherein the first VLAN identifier is used for the terminal to perform network communication after passing the authentication of the access device.

22. An electronic device, comprising: a memory configured to store processor-executable instructions; as well as A processor is configured to execute the processor-executable instructions to implement the method according to any one of claims 1 to 9 or 10 to 18.

23. A computer-readable storage medium, wherein: When the instructions in the computer-readable storage medium are executed by a processor in an electronic device, the electronic device implements the method as claimed in any one of claims 1 to 9 or 10 to 18.

Citation Information

Patent Citations

  • Distribution method for virtual local area network and related device

    CN102055641A

  • Method and device for IP address switch

    CN103475751A

  • SDN-based strategy management method and device, and electronic equipment

    CN110519404A

  • Network access authentication system and authentication method based on port mirror image

    CN114124473A

  • User domain dumb terminal management method, device and system and storage medium

    CN114629725A