CN100409645C - Broadband cut-in user managing method - Google Patents

Broadband cut-in user managing method Download PDF

Info

Publication number
CN100409645C
CN100409645C CNB02137497XA CN02137497A CN100409645C CN 100409645 C CN100409645 C CN 100409645C CN B02137497X A CNB02137497X A CN B02137497XA CN 02137497 A CN02137497 A CN 02137497A CN 100409645 C CN100409645 C CN 100409645C
Authority
CN
China
Prior art keywords
user
access
state
authentication
bag
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Lifetime
Application number
CNB02137497XA
Other languages
Chinese (zh)
Other versions
CN1491013A (en
Inventor
何茂平
田平
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Priority to CNB02137497XA priority Critical patent/CN100409645C/en
Publication of CN1491013A publication Critical patent/CN1491013A/en
Application granted granted Critical
Publication of CN100409645C publication Critical patent/CN100409645C/en
Anticipated expiration legal-status Critical
Expired - Lifetime legal-status Critical Current

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The present invention discloses a method for managing broadband access users, which comprises the following procedures: a user applies for access to a broadband access server by sending an IP packet; the access of the user who applies for accessing the server is authenticated; the access user who passes through the authentication is detected on line; register and off-line treatment are carried out for a detected off-line user and a user who does not satisfy an on-line condition. A novel method for managing access users is adopted by the present invention, and access users can be directly intercommunicated by a TCP/IP protocol on ETHERNET. Special access software is not needed, and the complete control to the access users can be realized.

Description

A kind of broadband cut-in user managing method
Technical field
The present invention relates to a kind of broadband cut-in user managing method on the BAS Broadband Access Server (BNAS) in the INTERNET access field, relate in particular to the Access Network part in INTERNET field.
Background technology
On BAS Broadband Access Server (be called for short BNAS), the user management method of PPPOE be used maximum a kind of.The access of PPPOE mode, physically client computer is connected with Ethernet with BNAS, and the IP message at first is encapsulated in the PPP frame, and the PPP frame is encapsulated in and delivers to BNAS in the Ether frame.This access requires client that PPPOE dialing software is housed.
Summary of the invention
The objective of the invention is in order to find a kind of novel access user management method, can make the access user directly interconnected, do not need special-purpose access software by the ICP/IP protocol on the ETHERNET, and the control fully of the access customer that can achieve a butt joint.
Method of the present invention may further comprise the steps:
A, user insert to the BAS Broadband Access Server application by sending the IP bag;
B, the user that application is linked into server carry out access authentication;
C, to by the authentication the access user carry out the online detection of timing;
D, to the detected user of rolling off the production line and the user that the do not satisfy online condition processing of keeping accounts and roll off the production line; Wherein, the online detection of the described timing of step C specifically comprises:
C1, inspection insert user's flow sign, if the flow sign is arranged, just remove this sign; Otherwise send out ICMP bag or ARP bag to the user, respond then the user has disconnected connection, execution in step D if can not receive; If receive response, then enter step C2;
Whether arrive C2, inspection user's service time, if arrive execution in step D service time; Otherwise enter step C3;
Whether expire C3, inspection user's maximum standby time, if expire, and execution in step D; Otherwise enter step C4;
Whether C4, inspection user's the IP rental period expires, if expire, and execution in step D; Otherwise enter step C5;
C5, reset regularly assay intervals timer.
According to said method:
The user can insert by the mode of dynamic application IP address or static allocation IP address.
Access authentication comprises WEB authentication and automated validation;
Described WEB authentication comprises step: the user is by portal website input username and password; This portal website delivers to access server with username and password, is responsible for authentication by the radius client on the access server.
Described automated validation comprises step: access server obtains the related data that inserts the user automatically; Automatically generate a username and password for the user; This username and password is delivered to the radius client request authentication.
For each certified access user sets different access states, adopt different timed events and action that the user is controlled at different access shapes.
According to user's access details and current state, each bag that the user is inserted inserts to be checked, if the user is by authentication, and receive that the consistent bag that just allows of data from data information in client or whereabouts client's the bag and user passes through, and for this user sets the flow sign, otherwise abandon this bag.
Detection is provided with certain fixed time interval, and the content of detection comprises: whether the rental period of break link, IP address expires, whether whether user's maximum idle time arrive to, user's service time, and statistics user's online data.
The present invention has adopted a kind of novel broadband cut-in user managing method, can make the access user directly interconnected by the ICP/IP protocol on the ETHERNET, does not need special-purpose access software, and the control fully of the access customer that can achieve a butt joint.
Description of drawings
Fig. 1 is a flow chart of the present invention;
Fig. 2 dynamically inserts user status transferring figure;
Fig. 3 is the static user status transferring figure that inserts;
Fig. 4 is online testing mechanism state transition diagram;
Embodiment
The objective of the invention is in order to find a kind of novel access user management method, can make the access user directly interconnected, do not need special-purpose access software by the ICP/IP protocol on the ETHERNET, and the control fully of the access customer that can achieve a butt joint.
The method of broadband cut-in user managing of the present invention sees also Fig. 1:
The first step: the user is by taking the IP address, to access to BAS Broadband Access Server by sending the application of I P packet mode.The user can insert with two kinds of forms: dynamically the mode of application (DHCP) and static allocation IP address inserts.
Insert if dynamically apply for the mode of IP address, just on client computer, the mode of client computer address acquisition is appointed as dynamic assignment, this client computer must be supported the DHCP agreement, and Dynamic Host Configuration Protocol server and access client computer are access in server (BNAS) isolates, and client computer has only by the dhcp relay agent on the access server just can get the IP address.
If an appointed IP address is just joined for client computer in static allocation IP address.
Second step: the user that application is inserted carries out access authentication.Access authentication is divided into dual mode: WEB authentication and automated validation.
The WEB authentication is meant that the user passes through a portal website, imports the username and password of oneself, and portal website delivers to access server (BNAS) with username and password then, is responsible for authentication by the radius client on the access server.Automated validation is an access server according to data such as the access user's who obtains automatically VLAN, access interface, MAC Address, when the user inserts for the first time, automatically generate a username and password for the user, deliver to the radius client request authentication then, this access user must bind by VLAN, MAC and access interface.
If the dynamic user who inserts, examine in the process of asking the IP address by the DHCP agreement at subscriber computer, access server obtains the information of client computer by DHCP relay, set up access details for inserting client computer, these data comprise: the port of user's IP address, MAC Address, VLAN, access server, IP ancestral phase, turn-on time etc.If the user is the user of WEB authentication, after the user obtained the IP address, access server only allowed the user to visit portal website in the limited time, did not allow to visit other IP addresses.If automated validation, after access server obtains to insert user's data automatically, with regard to request authentication.
If the static user who inserts, access server is just set up access details for the user automatically after receiving first IP bag that inserts the user.If the WEB authentication just allows the user to visit portal website in the limited time.If automated validation just is that the user generates the user name and password, a request authentication then automatically.
Whether the authentication result decision of sending back to according to radius client allows client computer to insert.If do not allow to insert, just delete this client's access details, the recovery system resource, and give back IP the address.If authentication is passed through, just allow authenticated user to insert.
Automated validation user's user name can adopt: the formation such as port numbers+vlan number of access server numbering+access, also can form with user's MAC address, and determine according to concrete needs.
The 3rd step: the accessed user is carried out online detection.The purpose of online detection is detect to insert the user whether the rental period of break link, IP address expires, whether whether user's maximum idle time arrive etc. to service time of, user, and statistics user's online data, these data mainly contain: flow (byte or bag number), line duration etc.The mode that detects adopts flow and sends out the mode that both combine of wrapping that detects.
After the user inserts, insert each bag that the user inserts and check, checking mainly is according to user's access details and current state.If the user is by authentication, and receive from the data information in client or whereabouts client's the bag, comprise IP address, MAC Address, VLAN, access interface etc., pass through with user's the consistent bag that just allows of data, and for this user sets the flow sign, otherwise abandon.
Online detection has certain fixed time interval, when being timed to, at first looks into the flow sign that inserts the user, if the flow sign is arranged, just removes this sign.If there is not the flow sign, just send out ICMP bag or ARP bag, if user's response IC MP agreement is not just sent out the ARP bag, by certain interval running fire three to five times to the user.Just prove that the user has disconnected connection if can not receive response all the time, at this moment just roll off the production line, to user's processing of rolling off the production line for accounting of user.
If receive response, whether arrive the service time of just looking into the user, if arrive service time, just rolls off the production line for accounting of user, to user's processing of rolling off the production line.
If do not arrive service time, whether arrive the maximum standby time of just looking into the user, if expire, just rolls off the production line for accounting of user, to user's processing of rolling off the production line.
If do not arrive user's standby time, whether the IP rental period of just looking into the user arrives, if arrive, just rolls off the production line for accounting of user, to user's processing of rolling off the production line.
If the IP rental period does not arrive, just reset regularly assay intervals timer.
In addition,, when receiving DHCPRELEASE bag and DHCPDECLINE bag, show initiatively off-line of client computer, forwarded for the 4th step to for the user of dynamic access.
Ether is not big to the setting of assay intervals, and best 5 seconds, because it relates to the statistical error of user's line duration and the timely discovery of user behavior.
The 4th step: offline user and the user that do not satisfy condition are done the record keeping and the processing of rolling off the production line.This cut-in method can be realized by several account keeping ways such as duration, flow, chartering, pre-payments.When user offline, connecting system is delivered to the radius client request with user's online duration, flow etc. and is kept accounts.And do the processing of rolling off the production line.Roll off the production line to handle and mainly do some and subscriber-related reprocessing work, can give the power of visiting portal website in limited time etc. such as user again the WEB authentication.It is fixed to come according to concrete configuration.
When realizing the used method of the present invention, for inserting user, each sets different access states, and adopt different timed events and action that the user is controlled at different access shapes.Fig. 2 to Fig. 4 is a kind of state transition diagram of realizing that adopts the present invention to realize.
Related to some timed events, action and state among Fig. 2, be described as follows.
User Status:
And do not insert: do not have user's data in the system, for system, at this moment the user is in and does not have access state.
Insert initialization: receive when system to enter this state after the DHCP of subscriber's main station asks that at this moment wait for IP address timer for the user establishes, if the automated validation user, the request radius client authenticates the user.
No IP: inserting init state, if authenticating by before also having selected rate, also do not obtain the IP address, the user just enters this state.
No IP does not have rate: inserting init state, the user is by authentication but do not obtain the IP address, do not select just to enter this state before the rate.Access can have a portal website, and the user can select the note expense mode of short-term in the above, if there is this user that such state is just arranged.Do not have this application, can not enter this state, fixed because this comes according to authentication result.The result that authentication is taken back does not require the selection rate, just directly enters no IP state, visit PORTAL WEB (portal website) timer when selecting rate just to limit as if requirement.
No authentication: inserting init state, obtain the IP address, do not obtain authentication result, if visit PORTAL web timer is just established in the WEB authentication, it is to be certified by timer that automated validation is just established etc., and enter this state.At this moment also to start regularly testing mechanism.
No rate: authentication is passed through, but will select rate in portal website, and obtains the IP address, just enters this state.And time visit PORTAL WEB (portal website) timer of limiting.
Keep accounts and begin: begin bag for the user initiates to keep accounts, but also do not receive when responding, just enter this state.And establish and wait for the beginning timer of keeping accounts.
Insert: begin response when receiving to keep accounts, after perhaps authenticated user does not obtain the IP address, just enter this state.At this moment the user just can access system provide service, begins to insert.
Timed events:
Wait for that IP address timer triggers: the user does not have the rate state at access initialization, no IP, no IP, and this timer triggers, and just with the subscriber data deletion, the user reenters does not have access state.
Trigger by timer etc. to be certified: the user is not having authentication state, and this timer triggers, and just with the subscriber data deletion, the user reenters does not have access state.
Visit PORTAL web timer triggers: the user does not have rate, does not have authentication state at no rate, no IP, and this timer triggers, and just with the subscriber data deletion, the user reenters does not have access state.
Wait for that the beginning timer of keeping accounts triggers: the user is at the record keeping initial state, and this timer triggers, and just with the subscriber data deletion, the user reenters does not have access state.
Action:
Receive DHCPdecline: the user does not have the IP state in access initialization, no IP, no rate, and when receiving DHCPdecline, just with the subscriber data deletion, the user reenters does not have access state.
Receive DHCPrelease: the user is not having authentication, no rate, when keeping accounts beginning, access state, when receiving DHCPrelease, just subscriber data is being deleted, the accounting of user that need keep accounts, and the user reenters does not have access state.
Detect subscriber's main station and disconnect connection: after the user obtains the IP address, just begun online testing mechanism, therefore, when not having authentication, no rate, record keeping beginning, access state, disconnect connection when detecting subscriber's main station, just with the subscriber data deletion, need the accounting of user of record keeping, the user reenters does not have access state.
Authenticated user initiatively rolls off the production line from PORTAL web: as user during at access state, if portal website provides the function that rolls off the production line, the user just can be rolled off the production line by this function, and system is accounting of user, and the user reenters does not have authentication state.Lay equal stress on and visit PORTAL web timer when limiting.
The IP rental period arrives: the user is not having authentication, no rate, when keeping accounts beginning, access state, when receiving DHCPrelease, just subscriber data is being deleted, the accounting of user that need keep accounts, and the user reenters does not have access state.
The longest inactive time arrives: the user just deletes subscriber data not having authentication, no rate, when keeping accounts beginning, access state, arriving when detecting user's maximum idle time, the accounting of user that need keep accounts, and the user reenters does not have access state.
System exception: the user is not when having authentication, no rate, record keeping beginning, access state, and system occurs unusual, just with the subscriber data deletion, and the accounting of user that need keep accounts, the user reenters does not have access state.
Arrive the turn-on time that the user selects: when the user at access state, after arriving the turn-on time that the user selects, system is accounting of user, the user reenters no rate state.
Fig. 3 is the state transition diagram of online testing mechanism, has related to some timed events, action and state, now is described as follows.
User Status:
And do not insert: do not have user's data in the system, for system, at this moment the user is in and does not have access state.
Insert initialization: do not having access state, system just enters this state after receiving first IP bag of Client-initiated.At this state, if visit PORTAL web timer is just established in WEB authentication, automated validation such as just establishes at the timer that passes through to be certified.At this moment also to start regularly testing mechanism.
No rate: authentication is passed through, and will select rate in portal website, just enters this state.And time visit PORTAL WEB (portal website) timer of limiting.
Keep accounts and begin: begin bag for the user initiates to keep accounts, but also do not receive when responding, just enter this state.And establish and wait for the beginning timer of keeping accounts.
Insert: after receiving that record keeping begins response or authenticated user is started testing mechanism, just enter this state.At this moment the user just can access system provide service, begins to insert.
Timed events:
Trigger by timer etc. to be certified: the user is not having authentication state, and this timer triggers, and just with the subscriber data deletion, the user reenters does not have access state.
Visit PORTAL web timer triggers: the user in no rate, do not have authentication state, this timer triggers, and just subscriber data is deleted, the user reenters does not have access state.
Wait for that the beginning timer of keeping accounts triggers: the user is at the record keeping initial state, and this timer triggers, and just with the subscriber data deletion, the user reenters does not have access state.
Action:
Detecting subscriber's main station disconnect to connect: when the user when inserting initialization, just begun online testing mechanism, therefore, when not having authentication, no rate, record keeping beginning, access state, disconnect connection when detecting subscriber's main station, just with the subscriber data deletion, need the accounting of user of record keeping, the user reenters does not have access state.
Authenticated user initiatively rolls off the production line from PORTAL web: as user during at access state, if portal website provides the function that rolls off the production line, the user just can be rolled off the production line by this function, and system is accounting of user, and the user reenters does not have authentication state.Lay equal stress on and visit the PORTALweb timer when limiting.
The longest inactive time arrives: the user just deletes subscriber data not having authentication, no rate, when keeping accounts beginning, access state, arriving when detecting user's maximum idle time, the accounting of user that need keep accounts, and the user reenters does not have access state.
System exception: the user is not when having authentication, no rate, record keeping beginning, access state, and system occurs unusual, just with the subscriber data deletion, and the accounting of user that need keep accounts, the user reenters does not have access state.
Arrive the turn-on time that the user selects: when the user at access state, after arriving the turn-on time that the user selects, system is accounting of user, the user reenters no rate state.
For inserting the user, as long as had the IP address, just start online testing mechanism, it is carried out online detection, the purpose of detection is to determine whether whether whether whether off-line, maximum idle time arrive to, maximum service time to, IP rental period subscriber's main station.Whether the maximum service time is to only effective to the user of the beginning of keeping accounts.Related to some timed events, action and state among Fig. 4, now be described as follows.
State:
Online detection begins: after subscriber's main station obtains the IP address, just start online testing mechanism, just enter this state.At this state, set up a definite subscriber's main station type timer.
Determine user type: when definite subscriber's main station type regularly triggers, online detection is just moved to this state from online detection initial state.At this state, machines is manufactured simple a mensuration, whether test subscriber's main frame response IC MP ECHO, method is must be to send out 3-5 ICMP request to subscriber's main station in the time interval, if can receive the ICMP ECHO of subscriber's main station, then subscriber's main station just comes subscriber's main station is detected with ICMP later with regard to response IC MP request.Otherwise just call for subscriber's main station is detected with ARP.To set up a timer of waiting for the PING response at this state.
Detect the ICMP mode: testing mechanism if receive the PING response, is just set up an online detection timer at definite user type state, enters this state, the user is started the detection of ICMP mode.
The online detection of user (ICMP): testing mechanism is when detecting ICMP mode state, and online detection timer triggers, and just enters this state, at this state, the user is detected by the mode that flow and ICMP request combine.The step that detects is as follows:
1) is there there flow? having changes 2), do not change 5);
2) arrive service time? less than changeing 3), to changeing 7);
Does 3) the IP rental period arrive? less than changeing 4), to changeing 6);
4) reset online detection timer, and enter the ICMP mode state that detects;
Does 5) maximum idle time arrive? less than changeing 9), to changeing 10);
6) establish IP rental period timer (length of timer is the remaining IP rental period), change 4);
Does 7) the IP rental period arrive? less than changeing 8), to changeing 6);
Service timer (length of timer is remaining service time) changes 4 when 8) limiting);
9) send out 3-5 ICMP request to subscriber's main station, and establish and wait for PING response timer.Change 11);
10) enter online detection done state;
11) receive the PING response? receiving changes 12), wait for that PING response timer triggers commentaries on classics 10);
12) KILL waits for PING response timer, changes 4).
Detect the ARP mode: testing mechanism triggers if wait for PING response timer at definite user type state, just sets up an online detection timer, enters this state, the user is started the detection of ARP mode.
The online detection of user (ARP): testing mechanism is when detecting ARP mode state, and online detection timer triggers, and just enters this state, at this state, the user is detected by the mode that flow and ARP request combine.The step that detects is as follows:
1) is there there flow? having changes 2), do not change 5);
2) arrive service time? time is less than changeing 3), the time is to changeing 7);
Does 3) the IP rental period arrive? rental period is less than changeing 4), the rental period forwards 6 to);
4) reset online detection timer, and enter the ARP mode state that detects;
Does 5) maximum idle time arrive? time is less than changeing 9), the time is to changeing 10).
6) establish IP rental period timer (length of timer is the remaining IP rental period), change 4);
Does 7) the IP rental period arrive? the rental period limit is less than changeing 8), the rental period is to changeing 6);
Service timer (length of timer is remaining service time) changes 4 when 8) limiting).
9) send out 3-5 ARP request to subscriber's main station, and establish and wait for the arp response timer, commentaries on classics 11);
10) enter online detection done state.
11) receive arp response? receiving changes 12), wait for that the arp response timer triggers commentaries on classics 10);
12) KILL waits for the arp response timer, changes 4).
Online detection finishes: online testing mechanism IP rental period and serve the timer triggering in limited time, just enters this state when detecting the ICMP mode and detecting the ARP mode.When user online detection ICMP and the online detection of user ARP state, system exception occurs, maximum idle time arrives and wait for the PING response or the triggering of wait arp response timer, also enter this state.At this state, the detected user's of announcement connecting system testing result.Connecting system is done corresponding processing according to the configuration (looking concrete condition) of system.Just the keeping accounts of rolling off the production line of should keeping accounts roll off the production line, and should carry out state transition, just carries out state transition, and carry out the setting of state flag bit.
Timed events:
Customer type detects timer and triggers: testing mechanism is at online detection initial state, and this timer triggers, and just the state transition of testing mechanism is arrived and determines the user type state.The purpose of setting up this timer is to examine for anti-dynamic to ask the address user main frame, when just obtaining the address, and response IC MP request.If a timer can be sent out the ICMP request to it after a while again after subscriber's main station obtains the address.
Wait for that PING response timer triggers: testing mechanism is at definite user type state, and this timer triggers, and just the state transition of testing mechanism is arrived the ARP mode state that detects.At the online detection of user (ICMP) state, just online detection done state is arrived in the state transition of testing mechanism.The purpose of this timer is in order to receive response in the regular hour, if do not receive response in the regular hour, just this timer can trigger, when receiving response, this timer is just killed.
Wait for that the arp response timer triggers: testing mechanism just arrives online detection done state with the state transition of testing mechanism at the online detection of user (ARP) state.The purpose of this timer is in order to receive response in the regular hour, if do not receive response in the regular hour, just this timer can trigger, when receiving response, this timer is just killed.
Online detection timer triggers: testing mechanism just arrives the online detection of user (ICMP) state with the state transition of testing mechanism detecting ICMP mode state.Detecting ARP mode state, just the online detection of user (ARP) state is arrived in the state transition of testing mechanism.
Action:
Receive ping response: testing mechanism is received the PING response at definite user type state, just state transition is arrived the ICMP mode state that detects.When the online detection of user (ICMP) state, receive the PING response, just again state transition is arrived the ICMP mode state that detects.
Receive arp response: testing mechanism is received arp response at definite user type state, just state transition is arrived the ARP mode state that detects.When the online detection of user (ARP) state, receive arp response, just again state transition is arrived the ARP mode state that detects.
Flow is arranged: testing mechanism just arrives the state transition of testing mechanism the ICMP mode state that detects at the online detection of user (ICMP) state.At the online detection of user (ARP) state, just the state transition of testing mechanism is arrived the ARP mode state that detects.
Free time arrives: when online detection of user (ICMP) or the online detection of user (ARP) state, maximum idle time arrives, and just online detection done state is arrived in the state transition of testing mechanism.
System exception: when online detection of user (ICMP) or the online detection of user (ARP) state, system occurs unusual, just online detection done state is arrived in the state transition of testing mechanism.
Can find out that by the foregoing description the present invention can make the user directly interconnected by ICP/IP protocol on the ETHERNET and BAS Broadband Access Server, does not need special-purpose access software.

Claims (9)

1. broadband cut-in user managing method is characterized in that may further comprise the steps:
A, user insert to the BAS Broadband Access Server application by sending the IP bag;
B, the user that application is linked into server carry out access authentication;
C, to by the authentication the access user carry out the online detection of timing;
D, to the detected user of rolling off the production line and the user that the do not satisfy online condition processing of keeping accounts and roll off the production line;
Wherein, the online detection of the described timing of step C specifically comprises:
C1, inspection insert user's flow sign, if the flow sign is arranged, just remove this sign; Otherwise send out ICMP bag or ARP bag to the user, respond then the user has disconnected connection, execution in step D if can not receive; If receive response, then enter step C2;
Whether arrive C2, inspection user's service time, if arrive execution in step D service time; Otherwise enter step C3;
Whether expire C3, inspection user's maximum standby time, if expire, and execution in step D; Otherwise enter step C4;
Whether C4, inspection user's the IP rental period expires, if expire, and execution in step D; Otherwise enter step C5;
C5, reset regularly assay intervals timer.
2. method according to claim 1 is characterized in that: the user is by the dynamically mode application access of application IP address or static allocation IP address.
3. method according to claim 1 is characterized in that: access authentication comprises WEB authentication and automated validation.
4. method according to claim 3 is characterized in that:
The WEB authentication comprises step:
The user is by portal website input username and password;
This portal website delivers to access server with username and password, is responsible for authentication by the radius client on the access server.
5. method according to claim 3, it is characterized in that: automated validation comprises step:
Access server obtains the related data that inserts the user automatically;
Automatically for the user generates a username and password, this user name adopts the port numbers+vlan number of access server numbering+access or adopts user's MAC address;
This username and password is delivered to the radius client request authentication.
6. method according to claim 1 is characterized in that: step B is included as each certified access user with step C and sets different access states, adopts different timed events and action that the user is controlled at different access shapes.
7. according to claim 1 or 6 described methods, it is characterized in that step B also comprises: according to user's access details and current state, each bag that the user is inserted inserts to be checked, if the user is by authentication, and receive that the consistent bag that just allows of data from data information in client or whereabouts client's the bag and user passes through, and for this user sets the flow sign, otherwise abandon this bag.
8. method according to claim 7 is characterized in that: for the user of dynamic access, when receiving DHCPRELEASE bag and DHCPDECLINE bag, be judged as client computer and want initiatively off-line, change accounting of user over to and the treatment step that rolls off the production line.
9. according to claim 1 or 8 described methods, it is characterized in that: system delivers to radius client request record keeping with this user's online duration, flow and relevant information during user offline.
CNB02137497XA 2002-10-14 2002-10-14 Broadband cut-in user managing method Expired - Lifetime CN100409645C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNB02137497XA CN100409645C (en) 2002-10-14 2002-10-14 Broadband cut-in user managing method

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNB02137497XA CN100409645C (en) 2002-10-14 2002-10-14 Broadband cut-in user managing method

Publications (2)

Publication Number Publication Date
CN1491013A CN1491013A (en) 2004-04-21
CN100409645C true CN100409645C (en) 2008-08-06

Family

ID=34147047

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB02137497XA Expired - Lifetime CN100409645C (en) 2002-10-14 2002-10-14 Broadband cut-in user managing method

Country Status (1)

Country Link
CN (1) CN100409645C (en)

Families Citing this family (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101360021B (en) * 2008-10-14 2011-12-21 中国电信股份有限公司 Monitoring method and system for wireless wideband user status
CN101771899B (en) * 2008-12-31 2013-06-12 中兴通讯股份有限公司 Method for binding wideband access equipment
CN101854380B (en) * 2010-04-15 2013-09-25 深圳创维-Rgb电子有限公司 Method for realizing cross-platform point-to-point (P2P) video chat
CN104767718A (en) * 2014-01-06 2015-07-08 中国移动通信集团北京有限公司 User terminal offline method and device
CN107517138A (en) * 2016-06-16 2017-12-26 中兴通讯股份有限公司 Equipment detection method and device
CN107612709A (en) * 2017-08-10 2018-01-19 姜月娟 Broadband user's sorting technique, device and computer-readable recording medium
CN108156168A (en) * 2017-12-31 2018-06-12 深圳键桥通讯技术股份有限公司 Broadband cut-in user managing method

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
宽带接入认证和计费方式分析. 邹洁.广东通信技术,第22卷第6期. 2002
宽带接入认证和计费方式分析. 邹洁.广东通信技术,第22卷第6期. 2002 *
宽带网计费中的用户身份问题. 徐郁峰,陈平,金连甫.计算计工程,第28卷第2期. 2002
宽带网计费中的用户身份问题. 徐郁峰,陈平,金连甫.计算计工程,第28卷第2期. 2002 *

Also Published As

Publication number Publication date
CN1491013A (en) 2004-04-21

Similar Documents

Publication Publication Date Title
US7437552B2 (en) User authentication system and user authentication method
EP1703699B1 (en) Systems, method and session manager for web-based applications
CN100586106C (en) Message processing method, system and equipment
CN101453495B (en) Method, system and equipment for preventing authentication address resolution protocol information loss
CN100536438C (en) Method for testing DHCPv6 service and client
CN109862565A (en) A kind of WLAN unaware control method, system and readable storage medium storing program for executing
CN109413649B (en) Access authentication method and device
CN101026589A (en) Route selecting method and router
US8332513B2 (en) Method and device for detecting connectivity termination of internet protocol version 6 access networks
CN104270325B (en) Cpe device realizes the system and method for public network access customer number limitation based on Linux
CN101820432A (en) Safety control method and device of stateless address configuration
CN102571729A (en) Internet protocol version (IPV)6 network access authentication method, device and system
CN109510878A (en) A kind of long connection session keeping method and device
CN104601743A (en) IP (internet protocol) forwarding IPoE (IP over Ethernet) dual-stack user access control method and equipment based on Ethernet
CN102685812A (en) Access point (AP) associated terminal control method, device and system
CN100409645C (en) Broadband cut-in user managing method
CN101197811B (en) Method for improving server reliability in dynamic main unit configuration protocol under proxy mode
CN101325587A (en) Method for monitoring DHCP conversation
CN101729314A (en) Method and device for recovering dynamic table entries and dynamic host configuration protocol snoopingsnooping equipment
CN106131177B (en) Message processing method and device
CN101335652A (en) Status detection method, apparatus and system of dynamic host configuring protocol
CN100349433C (en) Method of distributing switchin-in address for user terminal
CN104009961A (en) PPPoE session ID distribution method and equipment thereof
CN107277043A (en) Network admittance control system based on cluster service
CN100370768C (en) Method for triggering user IP address assignment

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CX01 Expiry of patent term

Granted publication date: 20080806

CX01 Expiry of patent term