Method, system and apparatus for determining access privilege of user, and device and storage medium
By uniformly defining user access permissions within the headquarters campus, the problem of cross-campus user permission management policies was solved, improving user experience and reducing deployment costs and network security risks.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-09
- Publication Date
- 2026-04-02
AI Technical Summary
In the multi-campus environment of high-tech enterprises, existing technologies are insufficient to implement policy-based user permissions, which means that employees need to reapply for permissions when moving between campuses, which is cumbersome and poses cybersecurity risks.
By deploying an access permission calculation system in the headquarters campus, the authentication access points in the branch campuses send user information to the headquarters campus, uniformly determining user access permissions. This avoids deploying separate access permission calculation systems in each branch campus, enabling seamless user access and reducing deployment costs.
It enables policy-based user permissions to be applied wherever needed, improving user experience, reducing deployment costs, and enhancing network security.
Smart Images

Figure CN2025120085_02042026_PF_FP_ABST
Abstract
Description
Method, system, device, apparatus and storage medium for determining user access rights
[0001] Cross-reference to related applications
[0002] This application claims priority to the Chinese patent application No. 202411364427.X, filed on September 27, 2024, and entitled "A method and device for determining cross-park user access rights", the entire content of which is incorporated herein by reference. TECHNICAL FIELD
[0003] The present application relates to the field of communication technology, in particular to a method, system, device, apparatus and storage medium for determining user access rights. BACKGROUND
[0004] In high-tech enterprises, the permissions of R&D personnel or related staff need to be finely managed. Meanwhile, for a multi-park enterprise, there may be a demand for collaborative work between employees of different parks. In order to ensure the experience of employees, policy following should be implemented, which means that the permissions or experience of an employee should remain unchanged regardless of which park the employee is located in. Otherwise, when the employee moves from one park to another, the employee needs to reapply for access rights, and accordingly, the network administrator also needs to reconfigure the employee's permissions on the firewall. When the employee leaves the park, the network administrator also needs to delete the employee's permissions, which is cumbersome and prone to network security problems.
[0005] In related technologies, there are mainly two schemes for implementing policy following. One is a distributed authentication and policy scheme, that is, an authentication system and a policy calculation system are deployed in each park, and authentication and policy calculation are completed in each branch park. The other is a centralized authentication and policy scheme, that is, only an authentication system and a policy calculation system are deployed in the headquarters park, and each branch park completes authentication through the headquarters park, and the headquarters park calculates the policy and then sends the policy calculation result to each branch park. SUMMARY
[0006] Embodiments of the present application provide a method, system, device, storage medium and program product for determining user access rights.
[0007] In a first aspect, the present application provides a method for determining user access rights, comprising:
[0008] The authentication access point of the branch park sends user information corresponding to a user terminal to an access right calculation system of the headquarters park; wherein the user information is used by the access right calculation system of the headquarters park to determine complete access rights or business authorization rules corresponding to the user information.
[0009] The method for determining cross-park user access permission provided by the embodiments of the present application is that the authentication access point of the branch park sends the user information corresponding to the user terminal located in the branch park to the access permission computing system of the headquarters park, so as to obtain the complete access permission or the service authorization rule corresponding to the user information. That is, the access permission of the user terminal located in the branch park is uniformly determined by the access permission computing system of the headquarters park, without separately deploying the access permission computing system in each branch park, so that the user can access without sensing and the deployment cost can be reduced.
[0010] In a possible design, the user information includes a username and a user IP address.
[0011] The authentication access point of the branch park sends the user information corresponding to the user terminal to the access permission computing system of the headquarters park, and the method includes the following steps.
[0012] The authentication access point of the branch park sends the user information corresponding to the user terminal to the access permission computing system of the headquarters park, and the method includes the following steps.
[0013] The authentication access point of the branch park sends the username and the user IP address to the authentication proxy point of the branch park, so as to allow the authentication proxy point of the branch park to send the username and the user IP address to the access permission computing system of the headquarters park; and the authentication proxy point of the branch park is deployed in a core switch or an aggregation switch.
[0014] The access permission computing system of the headquarters park stores a plurality of user groups and the access permission corresponding to each user group, the username is used to determine the user group to which the username belongs, and then the access permission corresponding to the username is determined according to the access permission corresponding to the user group. The user IP address is used to identify that the complete access permission or the service authorization rule returned by the access permission computing system of the headquarters park belongs to the user terminal corresponding to the user IP address.
[0015] In a possible design, after the authentication proxy point of the branch park sends the username and the user IP address to the access permission computing system of the headquarters park, the method further includes the following steps.
[0016] The policy execution point of the branch park receives the complete access permission returned by the access permission computing system of the headquarters park, or the authentication proxy point of the branch park receives the service authorization rule returned by the access permission computing system of the headquarters park; and the policy execution point of the branch park is deployed in a core switch or an aggregation switch.
[0017] The policy execution point of the branch park receives the complete access permission, and the authentication proxy point of the branch park receives the service authorization rule, so that the division of work is clear and the load is not too large.
[0018] In a possible design, after receiving the service authorization rule returned by the headquarters park's access right computing system, the branch park's authentication proxy point further includes:
[0019] The branch park's authentication proxy point sends the service authorization rule to the branch park's authentication access point, and the branch park's authentication access point modifies a virtual local area network (VLAN) of the user terminal according to the service authorization rule.
[0020] After receiving the complete access right returned by the headquarters park's access right computing system, the branch park's policy execution point further includes:
[0021] The branch park's policy execution point modifies the basic access right of the user terminal to the complete access right.
[0022] Since the operation of modifying the VLAN of the user terminal needs to be completed by the authentication access point connected with the user terminal, after receiving the service authorization rule, the branch park's authentication proxy point needs to send the service authorization rule to the branch park's authentication access point again; and after receiving the complete access right, the branch park's policy execution point can directly change the access right of the user terminal from the basic access right to the complete access right.
[0023] In a possible design, the user information includes a charging message, the charging message is generated after the branch park's authentication access point starts a charging copy function and the user terminal passes the authentication; the charging message is used to indicate that the headquarters park's access right computing system determines the complete access right or the service authorization rule of the user corresponding to the charging message; and
[0024] The branch park's authentication access point sends the user information corresponding to the user terminal to the headquarters park's access right computing system, including:
[0025] The branch park's authentication access point sends the charging message to the headquarters park's access right computing system.
[0026] Embodiments of the present application further provide another way for sending the user information of the user terminal of the branch park to the headquarters park's access right computing system, that is, sending the charging message generated after the user terminal passes the authentication to the headquarters park's access right computing system directly through the authentication access point of the branch park, without sending the charging message through the authentication proxy point again, so that this way is more lightweight.
[0027] In a possible design, after the branch park's authentication access point sends the charging message to the headquarters park's access right computing system, the branch park's authentication access point further includes:
[0028] The authentication access point of the branch park receives the service authorization rule returned by the access right calculation system of the headquarter park, where the service authorization rule is used to instruct the authentication access point of the branch park to set the VLAN of the user terminal or set the ACL of the user terminal.
[0029] Corresponding to the sending of the charging message, the authentication access point of the branch park can directly receive the service authorization rule returned by the access right calculation system of the headquarter park without forwarding via the authentication proxy point of the branch park.
[0030] In a possible design, before the authentication access point of the branch park sends the user information corresponding to the user terminal to the access right calculation system of the headquarter park, the method further includes:
[0031] The authentication access point of the branch park receives the access request sent by the user terminal, where the access request includes the user information.
[0032] The authentication access point of the branch park sends the user information to the authentication system of the branch park, so as to allow the authentication system of the branch park to determine the authentication result of the user terminal.
[0033] The authentication access point of the branch park receives the authentication result sent by the authentication system of the branch park.
[0034] The authentication access point of the branch park sends the access request of the user terminal to the authentication system of the branch park, and then the authentication system of the branch park returns the authentication result to the authentication access point of the branch park; when the authentication is passed, the authentication access point of the branch park sends the user information corresponding to the user terminal to the access right calculation system of the headquarter park. Compared with the authentication in the headquarter park, the user terminal located in the branch park directly performs the authentication in the branch park, which can quickly determine the authentication result, so that the user has a better user experience.
[0035] In a second aspect, the embodiments of the present application further provide a method for user access right, where the method includes:
[0036] The access right calculation system of the headquarter park receives the user information corresponding to the user terminal sent by the authentication access point of the branch park; and the access right calculation system of the headquarter park determines the complete access right or the service authorization rule corresponding to the user information according to the user information.
[0037] The access permission computing system of the headquarters park receives the user information sent by the authentication access point of the branch park, determines the corresponding complete access permission or business authorization rule according to the user information, and determines the access permission of the user terminal located in the branch park by the access permission computing system of the headquarters park, so that the access permission computing system does not need to be separately deployed in each branch park, the strategy can be carried, and the deployment cost can be saved.
[0038] In a possible design, the user information includes a username and a user IP address.
[0039] The access permission computing system of the headquarters park determines the complete access permission corresponding to the user information according to the user information, and the complete access permission includes:
[0040] The access permission computing system of the headquarters park determines the user group to which the username belongs according to the username.
[0041] The access permission computing system of the headquarters park determines the complete access permission according to the access permission corresponding to the user group to which the username belongs, and the complete access permission further includes the user IP address, which is used to instruct the policy execution point of the branch park to modify the basic access permission of the user terminal corresponding to the user IP address to the complete access permission.
[0042] The user information received by the access permission computing system of the headquarters park includes two cases. In one case, the user information includes a username and a user IP address, the access permission computing system of the headquarters park stores a plurality of user groups and the access permissions corresponding to the user groups, the access permission computing system of the headquarters park determines the user group to which the username belongs according to the username, and takes the access permission corresponding to the user group as the access permission corresponding to the username. Since each user group corresponds to a different role, it is equivalent to determining the access permission corresponding to the username according to the role corresponding to the username. Similarly, the access permission computing system of the headquarters park also stores a business authorization rule file, and the access permission computing system of the headquarters park matches the username in the preconfigured business authorization rule file to determine the business authorization rule corresponding to the username.
[0043] In a possible design, the user information includes a username and a user IP address.
[0044] The access permission computing system of the headquarters park determines the business authorization rule corresponding to the user information according to the user information, and the business authorization rule includes:
[0045] The access permission computing system of the headquarters park determines the business authorization rule according to the username; wherein the business authorization rule further comprises the user IP address, and the authentication access point of the branch park sets the VLAN or the ACL of the user terminal according to the business authorization rule for the user terminal corresponding to the user IP address.
[0046] In a possible design, after the access permission computing system of the headquarters park determines the complete access permission according to the access permission corresponding to the user group to which the username belongs, the method further comprises:
[0047] The permission computing system of the headquarters park sends the complete access permission to the policy execution point of the branch park;
[0048] After the access permission computing system of the headquarters park determines the business authorization rule according to the matching result, the method further comprises:
[0049] The access permission computing system of the headquarters park sends the business authorization rule to the authentication proxy point of the branch park.
[0050] When the user information received by the access permission computing system of the headquarters park comprises the username and the user IP address, after the access permission computing system of the headquarters park completes the calculation, the complete access permission is sent to the policy execution point of the branch park, and the business authorization rule is sent to the authentication proxy point of the branch park.
[0051] In a possible design, the user information comprises a charging message; the charging message is generated after the authentication access point of the branch park starts the charging copy function and the user terminal is authenticated successfully;
[0052] The access permission computing system of the headquarters park determines the complete access permission or the business authorization rule corresponding to the user information according to the user information, comprising:
[0053] The access permission computing system of the headquarters park generates a user table item according to the charging message, and determines the complete access permission or the business authorization rule according to the username indicated by the user table item.
[0054] Another case of the content contained in the user information received by the access permission computing system of the headquarters park is that the user information comprises the charging message, the access permission computing system of the headquarters park can generate the user table item according to the charging message, and the user table item contains the username, therefore, the access permission computing system of the headquarters park can determine the complete access permission or the business authorization rule corresponding to the username indicated by the user table item.
[0055] In a possible design, after the headquarters park access right calculation system determines the complete access right or the business authorization rule corresponding to the user information according to the user information, the method further includes:
[0056] The headquarters park access right calculation system sends the complete access right to the policy execution point of the branch park, or
[0057] The headquarters park access right calculation system sends the business authorization rule to the authentication access point of the branch park.
[0058] When the user information received by the headquarters park access right calculation system includes a charging message, after the headquarters park access right calculation system completes the calculation, the complete access right is sent to the policy execution point of the branch park, and the business authorization rule is sent to the authentication access point of the branch park.
[0059] In a third aspect, an embodiment of the present application provides a system for determining user access right, wherein the system is applied to a branch park; and the system includes an authentication access point;
[0060] The authentication access point is configured to send user information corresponding to a user terminal to a headquarters park access right calculation system, wherein the user information is used by the headquarters park access right calculation system to determine a complete access right or a business authorization rule corresponding to the user information.
[0061] In a possible design, the system further includes an authentication agent point;
[0062] The authentication access point is configured to send user information corresponding to a user terminal to a headquarters park access right calculation system, including:
[0063] The authentication access point is configured to send the user information corresponding to the user terminal to the authentication agent point, and the user information includes a user name and a user IP address; and
[0064] The authentication agent point is configured to send the user name and the user IP address to the headquarters park access right calculation system.
[0065] In a possible design, the authentication agent point is further configured to receive the business authorization rule sent by the headquarters park access right calculation system, and send the business authorization rule to the authentication access point; and
[0066] The authentication access point receives the business authorization rule, and sets a VLAN of the user terminal or sets an ACL of the user terminal according to the business authorization rule.
[0067] In a possible design, the authentication access point is configured to send, to an access right calculation system of the headquarters park, user information corresponding to the user terminal, where the user information comprises:
[0068] The authentication access point of the branch park sends the charging message to the access right calculation system of the headquarters park, where the charging message is generated after the authentication access point starts a charging copy function and the user terminal passes the authentication, and the charging message is used to instruct the access right calculation system of the headquarters park to determine complete access rights or service authorization rules of a user corresponding to the charging message.
[0069] In a possible design, the system further comprises an authentication system.
[0070] Before the authentication access point of the branch park sends the user information corresponding to the user terminal to the access right calculation system of the headquarters park,
[0071] The authentication access point is configured to receive an access request sent by the user terminal, and send the access request to the authentication system of the branch park, where the access request comprises the user information.
[0072] The authentication system is configured to receive the access request, determine an authentication result of the user terminal according to the access request, and send the authentication result to the authentication access point.
[0073] The authentication access point receives the authentication result.
[0074] In a possible design, the system further comprises a policy enforcement point, where the policy enforcement point is deployed in a core switch or an aggregation switch.
[0075] The policy enforcement point is configured to receive complete access rights of the user terminal returned by the access right calculation system of the headquarters park.
[0076] The access right of the user terminal is set according to the complete access rights of the user terminal.
[0077] In a fourth aspect, the present application provides a device for determining user access rights, where the device comprises a transceiving unit and a processing unit, and the processing unit is configured to instruct the transceiving unit to perform the following steps:
[0078] The transceiving unit is instructed to send, to an access right calculation system of the headquarters park, user information corresponding to a user terminal, where the user information is used by the access right calculation system of the headquarters park to determine complete access rights or service authorization rules corresponding to the user information.
[0079] In a possible design, the user information includes a username and a user IP address; the transceiver is configured to send the username and the user IP address to the authentication proxy point of the branch park, to allow the authentication proxy point of the branch park to send the username and the user IP address to the access right calculation system of the headquarters park; and the authentication proxy point of the branch park is deployed on a core switch or an aggregation switch.
[0080] In a possible design, the user information includes a charging message, the charging message being generated after the authentication access point of the branch park starts a charging copy function and the user terminal passes the authentication; the charging message is used to instruct the access right calculation system of the headquarters park to determine complete access rights or service authorization rules of a user corresponding to the charging message; and the transceiver is specifically configured to send the charging message to the access right calculation system of the headquarters park.
[0081] In a possible design, the transceiver is configured to receive service authorization rules returned by the access right calculation system of the headquarters park, where the service authorization rules are used to instruct the processing unit to set a VLAN of the user terminal or set an ACL of the user terminal.
[0082] In a possible design, the transceiver is further configured to receive an access request sent by the user terminal, where the access request includes the user information; send the user information to the authentication system of the branch park, to allow the authentication system of the branch park to determine an authentication result of the user terminal; and receive the authentication result returned by the authentication system of the branch park.
[0083] In a fifth aspect, the present application provides a device for determining user access rights, including a transceiver and a processing unit.
[0084] The transceiver is configured to receive user information corresponding to a user terminal and sent by an authentication access point of a branch park; and the processing unit is configured to determine complete access rights or service authorization rules corresponding to the user information according to the user information.
[0085] In a possible design, the processing unit is specifically configured to determine a user group to which the username belongs according to the username, and determine the complete access rights according to access rights corresponding to the user group to which the username belongs; the complete access rights further include the user IP address, which is used to instruct a policy execution point of the branch park to modify basic access rights of a user terminal corresponding to the user IP address to the complete access rights; and each user group has a corresponding user role.
[0086] The processing unit is further configured to match the username in a preconfigured service authorization rule file, and the access right calculation system of the headquarters park determines the service authorization rule according to a matching result; the service authorization rule further comprises the user IP address, and the authentication access point of the branch park sets a VLAN or an ACL of the user terminal according to the service authorization rule for the user terminal corresponding to the user IP address.
[0087] In a possible design, the user information comprises a charging message; the charging message is generated after the authentication access point of the branch park starts a charging copy function and the user terminal passes the authentication; and the processing unit is specifically configured to generate a user entry according to the charging message, and determine the complete access right or the service authorization rule according to a username indicated by the user entry.
[0088] In a possible design, the transceiver unit is specifically configured to send the complete access right to a policy execution point of the branch park, and send the service authorization rule to the authentication access point of the branch park.
[0089] In a sixth aspect, the present application further provides a device for determining a cross-park user access right, which comprises a processor and a memory connected with the processor in communication;
[0090] The memory stores computer execution instructions.
[0091] The processor executes the computer execution instructions stored in the memory, so as to implement the method in the first aspect or the second aspect.
[0092] In a seventh aspect, the present application further provides a computer readable storage medium, which comprises a program, and the program causes an apparatus to execute the method in any one of the first aspect or the second aspect when the program is executed on the apparatus.
[0093] In an eighth aspect, the present application further provides a computer program product, which comprises a computer program, and the computer program implements the method in the first aspect or the second aspect when executed by a processor. BRIEF DESCRIPTION OF DRAWINGS
[0094] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.
[0095] FIG. 1 is a schematic diagram of a distributed authentication and policy solution provided in the related art.
[0096] FIG. 2 is a schematic diagram of a centralized authentication and policy solution provided in the related art.
[0097] FIG. 3 is a schematic diagram of a method for determining access rights of a cross-park user according to an embodiment of the present application.
[0098] FIG. 4 is a schematic diagram of a system architecture for determining access rights of a cross-park user according to an embodiment of the present application.
[0099] FIG. 5 is a schematic diagram of a system architecture for determining access rights of a cross-park user according to an embodiment of the present application.
[0100] FIG. 6 is a schematic diagram of an apparatus structure for determining access rights of a cross-park user according to an embodiment of the present application.
[0101] FIG. 7 is a schematic diagram of an apparatus structure for determining access rights of a cross-park user according to an embodiment of the present application. DETAILED DESCRIPTION
[0102] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.
[0103] The application scenarios described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation to the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art can know that, with the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems. In the description of the present application, unless otherwise specified, the meaning of "multiple" is two or more.
[0104] As described in the background section, in the related art, there are mainly two kinds of implementation strategies for the policy follow-up scheme. One is the distributed authentication and policy scheme shown in FIG. 1. In FIG. 1, there are multiple branch parks, which are branch park 1, branch park 2, and branch park n. In FIG. 1, there is also a headquarter park. The distributed authentication and policy scheme needs to deploy a set of authentication systems and access right calculation systems (the access right calculation system can also be referred to as a policy calculation system or a unified networking central (English: Unified Networking Central, abbreviated as UNC)) in each branch park. The users in each branch park are authenticated by the authentication system in the branch park and the access right of the user is determined by the access right calculation system in the branch park. That is, each of the branch park 1 to the branch park n needs to deploy a set of authentication systems and access right calculation systems. The user in the branch park 1 is authenticated by the authentication system in the branch park 1 and the access right is determined by the access right calculation system in the branch park 1. The user in the branch park n is authenticated by the authentication system in the branch park n and the access right is determined by the access right calculation system in the branch park n. The deployment cost of this scheme is relatively high.
[0105] Another scheme is the centralized authentication and policy scheme shown in FIG. 2. In FIG. 2, there are multiple branch parks and a headquarter park. The multiple branch parks are branch park 1 to branch park n. This scheme only needs to deploy a set of authentication systems and access right calculation systems in the headquarter park. The users in each branch park are authenticated by the authentication system in the headquarter park and the access right is determined by the access right calculation system in the headquarter park. Compared with the first scheme, this scheme can reduce the deployment cost, but the user experience is not good. Because the data transmission between the headquarter park and the branch park is easily affected by the network quality, especially the user authentication. The user authentication process can be divided into multiple sub-steps. If one of the sub-steps fails to be executed due to poor network quality, the authentication needs to be performed again, which takes a long time and affects the user experience.
[0106] The embodiment of the present application proposes a method for determining the access right of a cross-park user as shown in FIG. 3. The method specifically includes:
[0107] Step 300: The authentication access point of the branch park sends the user information corresponding to the user terminal to the access right calculation system of the headquarter park. Correspondingly, the access right calculation system of the headquarter park receives the user information corresponding to the user terminal sent by the authentication access point of the branch park.
[0108] Step 301: The access right calculation system of the headquarter park determines the complete access right or the service authorization rule corresponding to the user information according to the user information.
[0109] The embodiments of the present application provide two schemes for implementing the steps 300-301, wherein a system architecture diagram of the first scheme is shown in FIG. 4, and a system architecture diagram of the second scheme is shown in FIG. 5.
[0110] As shown in FIG. 4, the FIG. 4 includes a branch park and a headquarters park, wherein the branch park includes an authentication system, a user terminal, an authentication access point, an authentication proxy point, a policy execution point and a firewall; the authentication system of the branch park is configured to authenticate the user terminal located in the branch park.
[0111] As known by those skilled in the art, the network devices in the park network system can include an access switch, an aggregation switch and a core switch. For the wired user terminal, the authentication access point can be deployed on the access switch, and the authentication information of the wired user terminal is received on the access switch; for the wireless user terminal, the authentication access point can be deployed on an access controller (AC for short), and the authentication information of the wireless user terminal is received through an access point (AP for short) and sent to the AC. The authentication proxy point and the policy execution point can be deployed on the aggregation switch or the core switch, and can be flexibly set according to the scene requirements.
[0112] The authentication access point of the branch park can be deployed on a network access server (NAS for short) device and connected with the user terminal. The authentication access point of the branch park is configured to receive the access request of the user terminal, send the user information to the access right calculation system of the headquarters park, and set a virtual local area network (VLAN for short) for the user terminal according to the authorized right calculated by the access right calculation system of the headquarters park.
[0113] The authentication proxy point of the branch park is configured to proxy the authentication information, and when the proxied authentication information is radius authentication information, the authentication proxy point can also be referred to as a radius proxy. The authentication proxy point and the policy execution point of the branch park can be deployed on the core switch or the aggregation switch, and the authentication proxy point of the branch park is configured to send the access request of the user terminal to the authentication system of the branch park and send the user information to the access right calculation system of the headquarters park.
[0114] The policy execution point of the branch park is configured to receive the complete access right returned by the access right calculation system of the headquarters park and set the access right of the user terminal according to the complete access right.
[0115] The firewall of the branch park is used to monitor network attacks in real time, reduce network risks, and improve the security of communication between the branch park and the headquarters park.
[0116] The headquarters park includes an access permission calculation system, a user terminal, an authentication access point, an authentication proxy point, a policy execution point, and a firewall.
[0117] The authentication system of the headquarters park is used to authenticate the user terminal located in the headquarters park, and the access permission calculation system of the headquarters park is used to determine the complete access permission or business authorization rule corresponding to the user terminal located in the branch park and the headquarters park.
[0118] In addition, the branch park in FIG. 4 can also include a dynamic host configuration protocol (English: Dynamic Host Configuration Protocol, abbreviated as DHCP) server, which is managed by the access permission calculation system of the headquarters park, and dynamically allocates IP addresses or configuration information for the user terminals of the branch park.
[0119] It should be noted that one branch park in FIG. 4 is only an example, and the method for determining cross-park user access permission proposed in the embodiments of the present application is not only applicable to one branch park, but also applicable to multiple branch parks.
[0120] The following describes the specific process of the implementation of scheme one based on the system architecture shown in FIG. 4.
[0121] Exemplarily, before the authentication access point of the branch park sends the user information corresponding to the user terminal to the access permission calculation system of the headquarters park, the user terminal needs to be authenticated in the branch park first.
[0122] Specifically, the user terminal sends an access request to the authentication access point of the branch park. For example, a user wants to log in to a business system in the branch park to handle related business, and first needs to input the user name and user password and the like in the business system login interface and submit for verification. This process can be understood as the user terminal sending an access request. Correspondingly, the authentication access point of the branch park receives the access request sent by the user terminal, and the access request includes user information, such as the user input user name, the user input user password, the user IP address, the user MAC address, and the like.
[0123] The authentication access point of the branch park sends the user information to the authentication proxy point of the branch park, and the authentication proxy point of the branch park sends the user information to the authentication system of the branch park, which performs a series of verifications on the user information.
[0124] In some embodiments, the authentication system of the branch park verifies whether the user password is correct, and if the user information is verified correctly, it indicates that the user information authentication is passed.
[0125] In some embodiments, in order to reduce the delay and improve the user experience, the authentication system of the branch park can set the basic access permission for the user terminal after the authentication of the user terminal is passed. For example, when the business system includes multiple user roles, the access permission levels corresponding to the user roles from low to high are respectively the browsing user, the first-level administrator, the second-level administrator, and the admin administrator. After the authentication of the user terminal is passed, the authentication system of the branch park can first set the access permission corresponding to the browsing user role for the user terminal. Finally, the authentication system of the branch park returns the authentication result of the user information to the authentication proxy point of the branch park, and the authentication proxy point of the branch park returns the authentication result to the authentication access point of the branch park.
[0126] In some embodiments, after the authentication access point of the branch park receives the authentication result returned by the authentication system of the branch park, if the authentication result indicates that the authentication fails, the user terminal can resubmit the access request, and the authentication access point of the branch park sends the new access request to the authentication system of the branch park again, and the authentication system of the branch park performs authentication again. If the authentication result indicates that the authentication is passed, the authentication access point of the branch park can send the user information corresponding to the user terminal to the access permission calculation system of the headquarters park to obtain the complete access permission or business authorization rule corresponding to the user information. The complete access permission can be understood as the real access permission of the user terminal. For example, after a certain user terminal is authenticated, it obtains the access permission corresponding to the browsing user role, but actually the role of the user terminal is the second-level administrator, and the complete access permission of the user terminal is the access permission corresponding to the second-level administrator role.
[0127] In some embodiments, after the user terminal is authenticated, the authentication access point of the branch park sends the user information to the authentication proxy point of the branch park, where the user information includes the username and the user IP address. The authentication access point of the branch park sends the username and the user IP address to the authentication proxy point of the branch park, and then the authentication proxy point of the branch park sends the username and the user IP address to the access right computing system of the headquarters park. Specifically, the authentication proxy point of the branch park sends the username and the user IP address to the access right computing system of the headquarters park by using the Google Remote Procedure Call (gRPC) protocol, which is based on the Hypertext Transfer Protocol 2.0 (HTTP2.0) and has high transmission speed and stability. Accordingly, the access right computing system of the headquarters park receives the username and the user IP address sent by the authentication proxy point of the branch park, and determines the corresponding complete access right or business authorization rule according to the username and the user IP address.
[0128] In some embodiments, the access right computing system of the headquarters park stores a plurality of user groups and the access rights corresponding to the user groups, and each user group corresponds to a different user role. The access right computing system of the headquarters park determines the user group to which the username belongs according to the received username, and determines the complete access right according to the access right corresponding to the user group to which the username belongs. Since each user group corresponds to a different user role, it is equivalent to determining the complete access right according to the user role corresponding to the username. For example, the access right computing system of the headquarters park stores four user groups, which are denoted as user group 1 to user group 4, and each user group includes a plurality of usernames. The user role corresponding to the user group 1 is a browsing user, the user role corresponding to the user group 2 is a first-level administrator, the user role corresponding to the user group 3 is a second-level administrator, and the user role corresponding to the user group 4 is an admin administrator. If the access right computing system of the headquarters park determines that the user group to which the username belongs is the user group 3, then the complete access right corresponding to the user is the access right corresponding to the second-level administrator role.
[0129] In some embodiments, after the headquarters park access right computing system determines the complete access right according to the access right corresponding to the user group to which the username belongs, the headquarters park access right computing system sends the complete access right to the policy enforcement point of the branch park through a network configuration protocol (NETCONF). Accordingly, the policy enforcement point of the branch park receives the complete access right returned by the headquarters park access right computing system. In addition, the complete access right also includes a user IP address, which is used to instruct the policy enforcement point of the branch park to modify the basic access right of the user terminal corresponding to the user IP address to the complete access right. For example, if the complete access right is “second-level administrator, 1.1.1.1”, the complete access right instructs the policy enforcement point of the branch park to modify the access right of the user terminal with the IP address 1.1.1.1 to the access right corresponding to the second-level administrator role.
[0130] In some embodiments, the headquarters park access right computing system also stores a preconfigured business authorization rule file, which is used by the headquarters park access right computing system to determine the business authorization rule according to the user information. Specifically, the headquarters park access right computing system matches the received username in the preconfigured business authorization rule file, and the headquarters park access right computing system determines the business authorization rule of the user terminal according to the matching result. The business authorization rule can be in the format of a change of authorization (CoA) message, and the CoA message can include a VLAN, which is used to instruct the authentication access point of the branch park to set the VLAN of the user terminal.
[0131] In some embodiments, after the headquarters park access right computing system determines the business authorization rule according to the matching result, the headquarters park access right computing system sends the business authorization rule to the authentication proxy point of the branch park through a remote authentication dial-in user service (RADIUS). Accordingly, the authentication proxy point of the branch park receives the business authorization rule returned by the headquarters park access right computing system, and sends the business authorization rule to the authentication access point of the branch park. The authentication access point of the branch park modifies the VLAN of the user terminal according to the business authorization rule. In addition, the business authorization rule also includes a user IP address, which is used to instruct the authentication access point of the branch park to modify the VLAN of the user terminal corresponding to the user IP address according to the business authorization rule. For example, if the business authorization rule is “30, 2.2.2.2”, the business authorization rule instructs the authentication access point of the branch park to modify the VLAN of the user terminal with the IP address 2.2.2.2 to 30.
[0132] It should be noted that the business authorization rule can also be used to instruct the authentication access point of the branch park to modify the access control list (Access Control List, ACL for short) for the user terminal. The ACL can control the access rights of the user to the network resources, for example, the ACL can control the access rights of the user to the network traffic or the database, etc., and thus the modification of the ACL is also a way of modifying the access rights of the user.
[0133] The following describes the specific process of the second scheme based on the system architecture shown in FIG. 5.
[0134] As shown in FIG. 5, FIG. 5 includes a branch park and a headquarters park, wherein the branch park includes an authentication system, a user terminal, an authentication access point, a policy enforcement point and a firewall; wherein the authentication system of the branch park is used to authenticate the user terminal located in the branch park.
[0135] The authentication access point of the branch park can be deployed on a NAS device and connected with the user terminal. The authentication access point of the branch park is used to receive the access request of the user terminal, send the user information to the access right calculation system of the headquarters park, and set the VLAN for the user terminal according to the authorization right calculated by the access right calculation system of the headquarters park.
[0136] The policy enforcement point of the branch park can be deployed on a core switch or a convergence switch, and is used to receive the complete access right returned by the access right calculation system of the headquarters park and set the access right of the user terminal according to the complete access right.
[0137] The firewall of the branch park is used to monitor network attacks in real time, reduce network risks, and can improve the security of communication between the branch park and the headquarters park.
[0138] The headquarters park includes an access right calculation system, a user terminal, an authentication access point, a policy enforcement point and a firewall.
[0139] The authentication system of the headquarters park is used to authenticate the user terminal located in the headquarters park, and the access right calculation system of the headquarters park is used to determine the complete access right and the business authorization rule corresponding to the user terminal located in the branch park and the headquarters park.
[0140] Similarly to the first scheme, before the authentication access point of the branch park sends the user information corresponding to the user terminal to the access right calculation system of the headquarters park, the user terminal needs to be authenticated in the branch park first. Specifically, the authentication access point of the branch park sends the access request of the user terminal to the authentication system of the branch park; correspondingly, the authentication system of the branch park returns the authentication result to the authentication access point of the branch park.
[0141] In some embodiments, the NAS device deployed by the authentication access point of the branch site is provided with a charging copy function. The charging function refers to the recording of the use of network resources by the user terminal after the authentication of the user terminal is passed, such as the type of service used, the start time, the data traffic, and the like, and the recorded content can be referred to as a charging message. Scheme two needs to enable the charging copy function of the NAS device, and when the user terminal connected to the authentication access point of the branch site is authenticated, the authentication access point of the branch site generates a charging message corresponding to the user terminal, and copies and sends the charging message to the UNC.
[0142] Generally, after the authentication of the user terminal is passed, the user terminal is allowed to log in and the basic access right of the user terminal is set. In the embodiments of the present application, a safer way of granting the user terminal to log in is also provided: after the authentication of the user terminal is passed, the user terminal is not allowed to log in, but after the charging message is sent to the access right calculation system of the headquarters site and the charging message is also authenticated by the access right calculation system of the headquarters site, the user terminal is allowed to log in. That is, the user terminal is allowed to log in only after the authentication of the authentication system of the branch site and the authentication of the access right calculation system of the headquarters site are passed, which is equivalent to that the user is allowed to log in only after the double verification is passed, and has better security.
[0143] In some embodiments, after the authentication of the user terminal is passed, the authentication access point of the branch site sends the user information to the access right calculation system of the headquarters site through the RADIUS protocol, and at this time, the user information includes the charging message. The charging message is generated after the charging copy function of the NAS device deployed by the authentication access point of the branch site is enabled and the authentication of the user terminal is passed, and is used to instruct the access right calculation system of the headquarters site to determine the complete access right or the service authorization rule of the user corresponding to the charging message.
[0144] In some embodiments, after the access right calculation system of the headquarters site receives the charging message, a user table item is generated according to the charging message, and the complete access right is determined according to the username indicated by the user table item. Specifically, the user table item generated by the access right calculation system of the headquarters site includes a username and a user IP address, the access right calculation system of the headquarters site determines the user group to which the username belongs according to the username indicated by the user table item, and determines the complete access right according to the access right corresponding to the user group to which the username belongs.
[0145] In some embodiments, after the headquarters park access right computing system determines the complete access right according to the username indicated by the user table item, the headquarters park access right computing system sends the complete access right to the policy enforcement point of the branch park by using the NETCONF protocol. Accordingly, the policy enforcement point of the branch park receives the complete access right returned by the headquarters park access right computing system and modifies the basic access right of the user terminal to the complete access right.
[0146] In some embodiments, the headquarters park access right computing system can also determine the corresponding service authorization rule according to the username indicated by the user table item. Specifically, the headquarters park access right computing system matches the username indicated by the user table item in the preconfigured service authorization rule file, and determines the service authorization rule of the user terminal according to the matching result.
[0147] In some embodiments, after the headquarters park access right computing system determines the service authorization rule according to the username indicated by the user table item, the headquarters park access right computing system sends the service authorization rule to the authentication access point of the branch park by using the RADIUS protocol. Accordingly, the authentication access point of the branch park receives the service authorization rule returned by the headquarters park access right computing system and modifies the VLAN of the user terminal according to the service authorization rule.
[0148] Compared with scheme one, the data transmission between the authentication access point of the branch park and the access right computing system of the headquarters park does not need to pass through the authentication proxy point of the branch park, so it is more lightweight and fast. The transmission protocols used between the authentication proxy point of the branch park and the access right computing system of the headquarters park in scheme one are gRPC protocol and NETCONF protocol, which are more stable than the RADIUS protocol used between the authentication access point of the branch park and the access right computing system of the headquarters park, so the transmission process between the authentication proxy point of the branch park and the access right computing system of the headquarters park is more stable and reliable. Users can choose between the above two schemes according to actual business needs.
[0149] The method for determining cross-park user access rights provided in the present application only needs to deploy a set of access right computing system in the headquarters park to realize the seamless access of cross-park users, without the need to deploy access right computing systems in each branch park, which can reduce the deployment cost; and the authentication of the user terminal is performed in the branch park, which can improve the user experience.
[0150] FIG. 6 and FIG. 7 are structural schematic diagrams of possible devices for determining cross-garden user access rights provided by embodiments of the present application. The devices for determining cross-garden user access rights can be used to implement the functions of the authentication access point of the branch garden in the above-mentioned method embodiments, or to implement the functions of the access right calculation system of the headquarters garden in the above-mentioned method embodiments, and thus can also achieve the beneficial effects possessed by the above-mentioned method embodiments.
[0151] As shown in FIG. 6, the device 600 for determining cross-garden user access rights includes a transceiver unit 610 and a processing unit 620, and the device 600 for determining cross-garden user access rights is suitable for unified user access right management of users located in branch gardens by the headquarters garden. The device 600 for determining cross-garden user access rights is used to implement the functions of the authentication access point of the branch garden or the access right calculation system of the headquarters garden in the above-mentioned method embodiment shown in FIG. 3.
[0152] When the device 600 for determining cross-garden user access rights is used to implement the functions of the authentication access point of the branch garden in the method embodiment shown in FIG. 3, the processing unit 620 calls the transceiver unit 610 to perform the following: sending user information corresponding to a user terminal to the access right calculation system of the headquarters garden; the user information is used by the access right calculation system of the headquarters garden to determine complete access rights or service authorization rules corresponding to the user information.
[0153] In some embodiments, the user information includes a user name and a user IP address; the transceiver unit 610 is specifically configured to send the user name and the user IP address to the authentication proxy point of the branch garden, and send the user name and the user IP address to the access right calculation system of the headquarters garden; the authentication proxy point of the branch garden is deployed on a core switch or a convergence switch.
[0154] In some embodiments, the transceiver unit 610 is further configured to receive complete access rights returned by the access right calculation system of the headquarters garden; or, receive service authorization rules returned by the access right calculation system of the headquarters garden; the policy enforcement point of the branch garden is deployed on a core switch or a convergence switch.
[0155] In some embodiments, the transceiver unit 610 is specifically configured to send the service authorization rules to the authentication access point of the branch garden; the processing unit 620 is specifically configured to set a virtual local area network (VLAN) of the user terminal according to the service authorization rules, and set basic access rights of the user terminal as the complete access rights.
[0156] In some embodiments, the user information includes a charging message, the charging message is generated after a network access server (NAS) device deployed by an authentication access point of the branch campus starts a charging copy function and the user terminal is authenticated; the charging message is used to instruct an access right calculation system of the headquarters campus to determine complete access rights or service authorization rules of a user corresponding to the charging message. The transceiver 610 is specifically configured to send the charging message to the access right calculation system of the headquarters campus.
[0157] In some embodiments, the transceiver 610 is configured to receive service authorization rules returned by the access right calculation system of the headquarters campus, the service authorization rules are used to instruct the processing unit to set a VLAN of the user terminal; or the transceiver 610 is configured to receive complete access rights returned by the access right calculation system of the headquarters campus, and the processing unit 620 is configured to set basic access rights of the user terminal as the complete access rights.
[0158] In some embodiments, the transceiver 610 is further configured to receive an access request sent by the user terminal, the access request includes the user information; and send the user information to an authentication system of the branch campus and receive an authentication result returned by the authentication system of the branch campus, the authentication system of the branch campus is configured to set basic access rights for a user terminal that passes authentication.
[0159] When the device 600 for determining cross-campus user access rights is used to implement the function of the access right calculation system of the headquarters campus in the method embodiment shown in FIG. 3: the transceiver 610 is configured to receive user information corresponding to a user terminal sent by an authentication access point of the branch campus; and the processing unit 620 is configured to determine complete access rights or service authorization rules corresponding to the user information according to the user information.
[0160] In some embodiments, the processing unit 620 is specifically configured to determine a user group to which a user name belongs according to the user name, and the access right calculation system of the headquarters campus determines the complete access rights according to access rights corresponding to the user group to which the user name belongs; the complete access rights further include a user IP address, which is used to instruct a policy enforcement point of the branch campus to modify basic access rights of a user terminal corresponding to the user IP address to the complete access rights; wherein each user group has a corresponding user role.
[0161] The processing unit 620 is further configured to match the username in a preconfigured service authorization rule file, and determine the service authorization rule according to a matching result by the access right calculation system of the headquarters park; the service authorization rule further comprises the user IP address, and is used to instruct the authentication access point of the branch park to set a VLAN for a user terminal corresponding to the user IP address according to the service authorization rule.
[0162] In some embodiments, the transceiver unit 610 is specifically configured to send the complete access right to a policy enforcement point of the branch park, and send the service authorization rule to an authentication proxy point of the branch park.
[0163] In some embodiments, the user information comprises a charging message; the charging message is generated after the authentication access point of the branch park deploys a NAS device to start a charging copy function and the user terminal passes the authentication; and the processing unit 620 is specifically configured to generate a user entry according to the charging message, and determine the complete access right or the service authorization rule according to a username indicated by the user entry.
[0164] In some embodiments, the transceiver unit 610 is specifically configured to send the complete access right to a policy enforcement point of the branch park, and send the service authorization rule to an authentication access point of the branch park.
[0165] For more detailed description of the transceiver unit 610 and the processing unit 620, refer to the related description in the method embodiment shown in FIG. 3 directly, which will not be repeated here.
[0166] As shown in FIG. 7, the device 700 for determining cross-park user access right comprises a processor 710 and an interface circuit 720. The processor 710 and the interface circuit 720 are coupled with each other. It can be understood that the interface circuit 720 can be a transceiver or an input / output interface. Optionally, the device 700 for determining cross-park user access right further comprises a memory 730, which is used to store instructions executed by the processor 710 or input data required by the processor 710 to run instructions or store data generated after the processor 710 runs instructions.
[0167] When the device 700 for determining cross-park user access right is used to implement the method shown in FIG. 3, the processor 710 is used to implement the functions of the processing unit 620, and the interface circuit 720 is used to implement the functions of the transceiver unit 610.
[0168] The division of units in the embodiments of the present application is illustrative, and is only a logical function division. In actual implementation, another division manner can be used. In addition, each function unit in each embodiment of the present application can be integrated in one processor, or can be a separate physical existence, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware, or in the form of a software function unit.
[0169] Although the preferred embodiments of the present application have been described, those skilled in the art who understand the basic inventive concept can make additional changes and modifications to the embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.
[0170] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also intends to include these modifications and variations.
Claims
1. A method for determining user access rights, comprising: sending, by an authentication access point of a branch park, user information corresponding to a user terminal to an access right computing system of a headquarters park; wherein the user information is used by the access right computing system of the headquarters park to determine complete access rights or service authorization rules corresponding to the user information.
2. The method of claim 1, wherein, The user information includes a username and a user IP address. The authentication access point of the branch park sends the user information corresponding to the user terminal to the access right computing system of the headquarters park, comprising: The authentication access point of the branch park sends the username and the user IP address to an authentication proxy point of the branch park to allow the authentication proxy point of the branch park to send the username and the user IP address to the access right computing system of the headquarters park; wherein the authentication proxy point of the branch park is deployed on a core switch or a convergence switch.
3. The method of claim 1, wherein, The user information includes a billing message, which is generated after the authentication access point of the branch park starts a billing copy function and the user terminal is authenticated; the billing message is used to indicate the access right computing system of the headquarters park to determine complete access rights or service authorization rules of the user corresponding to the billing message. And The authentication access point of the branch park sends the billing message to the access right computing system of the headquarters park. The method further comprises:
4. The method of any one of claims 1 to 3, wherein, The authentication access point of the branch park receives service authorization rules returned by the access right computing system of the headquarters park, wherein the service authorization rules are used to instruct the authentication access point of the branch park to set a VLAN of the user terminal or set an ACL of the user terminal. Before the authentication access point of the branch park sends the user information corresponding to the user terminal to the access right computing system of the headquarters park, the method further comprises:
5. The method of any one of claims 1-4, wherein, The authentication access point of the branch park receives an access request sent by the user terminal, wherein the access request includes the user information; The authentication access point of the branch park sends the user information to an authentication system of the branch park to allow the authentication system of the branch park to determine an authentication result of the user terminal; and The authentication access point of the branch park receives the authentication result sent by the authentication system of the branch park. The method comprises:
6. A method of determining user access rights, wherein, The access right computing system of the headquarters park receives the user information corresponding to the user terminal sent by the authentication access point of the branch park; and The access right computing system of the headquarters park determines complete access rights or service authorization rules corresponding to the user information according to the user information. The user information includes a username and a user IP address.
7. The method of claim 6, wherein, The access right computing system of the headquarters park determines complete access rights corresponding to the user information according to the user information, comprising: The headquarters park access permission computing system determines a user group to which the username belongs according to the username; and the headquarters park access permission computing system determines the complete access permission according to the access permission corresponding to the user group to which the username belongs; wherein the complete access permission further comprises the user IP address, which is used to instruct the policy execution point of the branch park to modify the basic access permission of the user terminal corresponding to the user IP address to the complete access permission.
8. The method of claim 6, wherein, The user information comprises a username and a user IP address; The headquarters park access permission computing system determines a business authorization rule corresponding to the user information according to the user information, comprising: The headquarters park access permission computing system determines the business authorization rule according to the username; wherein the business authorization rule further comprises the user IP address, which is used to instruct the authentication access point of the branch park to set a VLAN for the user terminal corresponding to the user IP address or to set an ACL of the user terminal according to the business authorization rule.
9. The method of claim 8, wherein, The user information comprises a charging message; the charging message is generated after the authentication access point of the branch park starts a charging copy function and the user terminal passes the authentication; The headquarters park access permission computing system determines a complete access permission or a business authorization rule corresponding to the user information according to the user information, comprising: The headquarters park access permission computing system generates a user table item according to the charging message, and determines the complete access permission or the business authorization rule according to a username indicated by the user table item.
10. The method of any one of claims 6-9, wherein, After the headquarters park access permission computing system determines a complete access permission or a business authorization rule corresponding to the user information according to the user information, the method further comprises: The headquarters park access permission computing system sends the complete access permission to the policy execution point of the branch park; or The headquarters park access permission computing system sends the business authorization rule to the authentication access point of the branch park.
11. A system for determining user access rights, wherein, The system is applied to a branch park; the system comprises an authentication access point; The authentication access point is used to send user information corresponding to a user terminal to a headquarters park access permission computing system; wherein the user information is used by the headquarters park access permission computing system to determine a complete access permission or a business authorization rule corresponding to the user information.
12. The system of claim 11, wherein, The system further comprises an authentication proxy point; The authentication access point is used to send user information corresponding to a user terminal to a headquarters park access permission computing system, comprising: The authentication access point is used to send the user information corresponding to the user terminal to the authentication proxy point; the user information comprises a username and a user IP address; and The authentication proxy point is used to send the username and the user IP address to the headquarters park access permission computing system.
13. The system according to claim 12, wherein, The authentication proxy point is further used to receive the business authorization rule sent by the headquarters park access permission computing system, and send the business authorization rule to the authentication access point; and The authentication access point receives the service authorization rule and sets a VLAN of the user terminal or sets an ACL of the user terminal according to the service authorization rule.
14. The system of claim 11, wherein, The authentication access point is configured to send user information corresponding to the user terminal to an access right calculation system of the headquarters campus. The authentication access point of the branch campus sends the charging message to the access right calculation system of the headquarters campus; wherein the charging message is generated after the authentication access point starts a charging copy function and the user terminal passes the authentication; and the charging message is used to instruct the access right calculation system of the headquarters campus to determine complete access rights or service authorization rules of a user corresponding to the charging message.
15. The system of any one of claims 11 to 14, wherein, The system further comprises an authentication system; Before the authentication access point of the branch campus sends the user information corresponding to the user terminal to the access right calculation system of the headquarters campus, The authentication access point is configured to receive an access request sent by the user terminal and send the access request to the authentication system of the branch campus; wherein the access request comprises the user information; and The authentication system is configured to receive the access request, determine an authentication result of the user terminal according to the access request, and send the authentication result to the authentication access point; and The authentication access point receives the authentication result.
16. The system of any one of claims 11 to 15, wherein, The system further comprises a policy enforcement point, wherein the policy enforcement point is deployed in a core switch or a convergence switch; The policy enforcement point is configured to receive complete access rights of the user terminal returned by the access right calculation system of the headquarters campus; and According to the complete access rights of the user terminal, set access rights of the user terminal.
17. An apparatus for determining user access rights, wherein, The apparatus comprises a transceiver unit and a processing unit; the processing unit invokes the transceiver unit to perform: send user information corresponding to a user terminal to an access right calculation system of a headquarters campus; wherein the user information is used by the access right calculation system of the headquarters campus to determine complete access rights or service authorization rules corresponding to the user information.
18. An apparatus for determining user access rights, wherein, The apparatus comprises a transceiver unit and a processing unit; The transceiver unit is configured to receive user information corresponding to a user terminal sent by an authentication access point of a branch campus; and The processing unit is configured to determine complete access rights or service authorization rules corresponding to the user information according to the user information.
19. An apparatus for determining user access rights, wherein, comprise: a processor, and a memory connected to the processor in communication; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the method of any one of claims 1-10.
20. A computer readable storage medium, wherein, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method of any one of claims 1-10.
Citation Information
Patent Citations
Authority setting method of user access network and equipment
CN101582769A
Access control method of limited area network, authentication method and authentication equipment
CN105337936A
Wireless network providing method and device and storage medium
CN112333711A
Network authority control method and equipment based on policy accompanying, and medium
CN115412319A
Method and system for dynamic security using authentication server
US20100024009A1