Background technology
Commercial wireless local area network (LAN) (wifi) field, increasing router can adopt the mode of access (portal) certification to carry out advertisement, or provides service on net for the employee in businessman or user.For the ease of the normal use of user, in same businessman shop, multiple router can be there is simultaneously, these routers have identical service set (SSID) and authentication mode, so wireless terminal user can the region of any wireless coverage in this businessman shop be surfed the Net, namely wireless terminal has carried out the operation of radio roaming.Along with popularizing of businessman wifi, the scene of radio roaming also gets more and more.So lifting user just seems extremely important for the experience of radio roaming.
In current existing WLAN (wireless local area network), wireless terminal access authentication method is about radio roaming scheme, as shown in Figure 1, specific as follows:
Step S101, wireless subscriber terminal connection route device a;
Does step S102, judge access authentication success? if so, enter step S104, if not, enter step S103;
If authentication success, the media interviews of cloud controller (AC) synchronous recording wireless terminal control (MAC) address, the MAC Address allowing online duration, router a and specific SSID, wherein, allow online duration can be 2 hours.
Step S103, without any operation;
Does step S104, roam into another router b? if so, enter step S105, if not, enter step S103;
If after half an hour, wireless terminal starts to move and is connected to router b.
Step S105, asks the authentication message of wireless terminal to cloud AC;
At this moment, router b can ask wireless terminal user whether once connect specific SSID by whereabouts cloud AC, and whether in permission online duration.
Step S106, waits for that cloud AC carries out alignment processing after replying response message.
Wait for that cloud AC replys response message, confirm that wireless terminal once connected specific SSID, and in permission online duration, then wireless terminal user directly can be surfed the Net and need not be accessed (portal), otherwise just needs again to access.
In sum, we can find a problem, if be exactly that router b is initiating inquiry request to cloud AC, but if cloud AC does not reply in time, this wireless terminal user just there will be situation about again accessing, and causes Consumer's Experience bad.
Summary of the invention
In order to solve the problems of the technologies described above, the present invention proposes wireless terminal access authentication method in a kind of WLAN (wireless local area network), described method comprises: when wireless terminal is by after router group first group of member's access authentication, described router group first crowd of member obtains the authentication information of described wireless terminal, and the authentication information of the described wireless terminal obtained is sent to router group cohort master; When described wireless terminal roaming is to router group second crowd of member, the described router group second crowd of members send the first request of the authentication information of described wireless terminal to described router group cohort cloud controller of advocating peace simultaneously respectively; Described router group second crowd of member determines whether to carry out access authentication to described wireless terminal according to the first response of the authentication information of the described wireless terminal obtained at first from described router group cohort master or described both cloud controllers.
Further, the authentication information of described wireless terminal comprises wireless terminal media accessing to control address, router group first group of member's media access control address, router group first group of member's service set and allows online duration.
Further, described router group first crowd of member, described router group second crowd of member and described router group cohort master adopt access authentication mode, and all have identical service set.
Further, described router group second crowd of member determines whether to carry out access authentication to described wireless terminal according to the first response of the authentication information of the described wireless terminal obtained at first from described router group cohort master or described cloud controller, specifically comprise: according to the first response of the authentication information of the described wireless terminal obtained at first, described router group second crowd of member determines that described wireless terminal connected described service set, and the online duration of described wireless terminal is within the scope of described permission online duration, then described wireless terminal is let pass, described wireless terminal is allowed to continue online, when according to the first response of the authentication information of the described wireless terminal obtained at first, described router group second crowd of member determines that described wireless terminal connected described service set, but the online duration of described wireless terminal within the scope of described permission online duration, does not then carry out access authentication to described wireless terminal.
Further, at described wireless terminal by before router group first group of member's access authentication, described method also comprises: described router group first crowd of member sends the second request of the authentication information of described wireless terminal to described router group cohort described cloud controller of advocating peace simultaneously respectively; Described router group first crowd of member determines to carry out access authentication to described wireless terminal according to the second response of the authentication information of the described wireless terminal obtained at first from described router group cohort master or described both cloud controllers.
Further, described router group first crowd of member determines to carry out access authentication to described wireless terminal according to the second response of the authentication information of the described wireless terminal obtained at first from described router group cohort master or described both cloud controllers, specifically comprise: according to the second response of the authentication information of the described described wireless terminal obtained at first, described router group first crowd of member determines that described wireless terminal had not connected described service set, then carry out access authentication to described wireless terminal.
The invention allows for wireless terminal access authentication system in a kind of WLAN (wireless local area network), described system comprises: router group first crowd of member, router group second crowd of member, router group cohort are advocated peace cloud controller, described router group first crowd of member, for when after access authentication wireless terminal, obtain the authentication information of described wireless terminal, and the authentication information of the described wireless terminal obtained is sent to described router group cohort master; Described router group second crowd of member, for when described wireless terminal roaming is to self, simultaneously sends the first request of the certification of described wireless terminal to described router group cohort cloud controller of advocating peace respectively; The first response also for the authentication information according to the described wireless terminal obtained at first from described router group cohort master or described both cloud controllers determines whether to carry out access authentication to described wireless terminal; Described router group cohort master, for receiving the authentication information of the described wireless terminal that described router group first crowd of member sends; Also for after the first request of authentication information receiving the described wireless terminal that described router group second crowd of member sends, send the first response of the authentication information of described wireless terminal to described router group second crowd of member; Described cloud controller, for receive the authentication information of the described wireless terminal that the described router group second crowd of members send the first request after, send the first response of the authentication information of described wireless terminal to described router group second crowd of member.
Further, the authentication information of described wireless terminal comprises wireless terminal media accessing to control address, router group first group of member's media access control address, router group first group of member's service set and allows online duration.
Further, described router group first crowd of member, described router group second crowd of member and described router group cohort master adopt access authentication mode, and all have identical service set.
Further, described router group second crowd of member, the first response also for the authentication information according to the described wireless terminal obtained at first from described router group cohort master or described cloud controller determines whether to carry out access authentication to described wireless terminal, specifically comprise: described router group second crowd of member, the first response also for the authentication information according to the described wireless terminal obtained at first determines that described wireless terminal connected described service set, and the online duration of described wireless terminal is within the scope of described permission online duration, then described wireless terminal is let pass, described wireless terminal is allowed to continue online, the first response also for the authentication information according to the described wireless terminal obtained at first determines that described wireless terminal connected described service set, but the online duration of described wireless terminal within the scope of described permission online duration, does not then carry out access authentication to described wireless terminal.
Further, described router group first crowd of member, also for before wireless terminal described in access authentication, after receiving the access request of wireless terminal, simultaneously send the second request of the authentication information of described wireless terminal respectively to described router group cohort described cloud controller of advocating peace; And determine to carry out access authentication to described wireless terminal according to the second response of the authentication information of the described wireless terminal obtained at first from described router group cohort master or described both cloud controllers.
Further, described router group first crowd of member, the second response also for the authentication information according to the described described wireless terminal obtained at first determines that described wireless terminal had not connected described service set, then carry out access authentication to described wireless terminal.
The router group cohort person that technical solution of the present invention wireless terminal roaming arrives no longer only asks the authentication information of wireless terminal to cloud AC, but the authentication information of cloud AC request wireless terminal of simultaneously advocating peace to router group cohort, respective handling is carried out according to the router group cohort response message of replying at first in cloud AC of advocating peace, if when avoiding cloud AC not reply in time, again can carry out access authentication to wireless terminal within the scope of permission online duration, cause Consumer's Experience extreme difference.Further, only by the main authentication information safeguarding wireless terminal in this group of router group cohort, then router group other group of member's burdens can not be increased the weight of.
Embodiment
The technical problem solved to make the application, technical scheme and beneficial effect are clearly understood, below in conjunction with drawings and Examples, are further elaborated to the application.Should be appreciated that specific embodiment described herein only in order to explain the application, and be not used in restriction the application.
As shown in Figure 2, be the schematic flow sheet of a kind of embodiment of wireless terminal access authentication method in WLAN (wireless local area network) provided by the invention, specific as follows:
Step S201, when wireless terminal is by after router group first group of member's access authentication, described router group first crowd of member obtains the authentication information of described wireless terminal;
Particularly, at wireless terminal by before router group first group of member's access authentication, cloud controller (AC) arranges router group, this router group comprises router group cohort and to advocate peace router group cohort person, the partitioning standards of router group is: have identical service set (SSID) in certain limit, call router group service set in the following text, and all adopt the router of access authentication mode to be divided into same router group, router group cohort master only has one, router group cohort person can be multiple, be designated as router group first crowd of member, router group second crowd of member, router group n-th crowd of member, n is more than or equal to 2.
The authentication information of wireless terminal comprises wireless terminal media access control (MAC) address, router group first group of member's media access control address, router group service set and allows online duration.
At wireless terminal by before router group first group of member's access authentication, after router group first crowd of member receives wireless terminal access request, send the second request of the authentication information of wireless terminal respectively to router group cohort cloud controller of advocating peace simultaneously; Router group first crowd of member determines to carry out access authentication to wireless terminal according to the second response of the authentication information of the wireless terminal obtained at first from both router group cohort master or cloud controller;
According to the second response of the authentication information of the wireless terminal obtained at first, router group first crowd of member determines that wireless terminal did not connect router group service set identifier, then access authentication is carried out to wireless terminal, wherein, described second response is the authentication information not finding wireless terminal.
Step S202, the authentication information of the described wireless terminal obtained is sent to router group cohort master by router group first crowd of member;
Particularly, router group cohort master is by the mode of broadcast, periodically broadcast from the information as router group cohort master to router group cohort person, the each group person of router group receives and records the main information of router group cohort, and the main information of router group cohort is: the main media access control address of router group cohort, the main service set of router group cohort (router group service set).
Step S203, when described wireless terminal roaming is to router group second crowd of member, the described router group second crowd of members send the first request of the authentication information of described wireless terminal to described router group cohort cloud controller of advocating peace simultaneously respectively;
After wireless terminal connection route device group first group of member's authentication success, the media access control address of cloud controller synchronous recording wireless terminal, permission online duration, router group first group of member's wireless access controller address and router group first group of member's service set (router group service set).
Step S204, described router group second crowd of member determines whether to carry out access authentication to described wireless terminal according to the first response of the authentication information of the described wireless terminal obtained at first from described router group cohort master or described both cloud controllers.
According to the first response of the authentication information of the described wireless terminal obtained at first, described router group second crowd of member determines that described wireless terminal connected described router group service set, and the online duration of described wireless terminal is within the scope of described permission online duration, then described wireless terminal is let pass, allow described wireless terminal to continue online;
When according to the first response of the authentication information of the described wireless terminal obtained at first, described router group second crowd of member determines that described wireless terminal connected router group service set identifier, but the online duration of described wireless terminal within the scope of described permission online duration, does not then carry out access authentication to described wireless terminal.
Fig. 3 is the schematic flow sheet of the another kind of embodiment of wireless terminal access authentication method in WLAN (wireless local area network) provided by the invention, specific as follows:
Step S301, wireless subscriber terminal connection route device group group person 1;
Particularly, wireless terminal is by before router group cohort person 1 access authentication, cloud controller arranges router group, this router group comprises router group cohort and to advocate peace router group cohort person, router group cohort master, router group cohort person adopt access authentication mode, and all have identical service set, and router group cohort person can be multiple, be designated as router group cohort person 1, router group cohort person 2 ..., router group cohort person n, n is more than or equal to 2.
At described wireless terminal by before router group cohort person 1 access authentication, router group cohort person 1 sends the second request of the authentication information of described wireless terminal to router group cohort cloud controller of advocating peace simultaneously respectively; Router group cohort person 1 determines to carry out access authentication to described wireless terminal according to the second response of the authentication information of the wireless terminal obtained at first from both router group cohort master or cloud controller;
According to the second response of the authentication information of the described wireless terminal obtained at first, router group cohort person 1 determines that described wireless terminal did not connect router group service set identifier, then carry out access authentication to described wireless terminal;
Wherein, the authentication information of wireless terminal comprises wireless terminal media accessing to control address, router group cohort person 1 media access control address, router group service set and allows online duration.
Does step S302, judge access authentication success? if success, enters step S304, if access unsuccessful, enters step S303;
If authentication success, the media access control address of cloud controller synchronous recording wireless terminal, wireless terminal allow online duration, wireless terminal online duration, the MAC Address of router group cohort person 1 and router group service set, wherein, online duration is allowed can be 2 hours.
Step S303, without any operation;
Step S304, to the authentication information of the main transmission wireless terminal of router group cohort;
The authentication information of the wireless terminal of acquisition is sent to router group cohort master by router group cohort person 1; The authentication information of the main reception wireless terminal of router group cohort, and record the online duration of wireless terminal.
Does step S305, roam into router group cohort person 2? if so, enter step S306, if not, enter step S303;
After couple in router group group person 1, wireless terminal moves at random and is connected on router group cohort person 2.
Step S306, the authentication message of cloud AC request wireless terminal of simultaneously advocating peace to router group cohort;
At this moment, router group cohort person 2 asks wireless terminal user whether once to connect router group service set identifier to cloud AC, and whether in permission online duration.
Step S307, waits for that router group cohort master or cloud AC reply response message;
Router group cohort person 2 waits for that the response message that router group cohort master or cloud AC reply comprises: allow online duration, wireless terminal online duration, wireless terminal media accessing to control address, router group first group of member's media access control address, router group service set.
Step S308, carries out alignment processing according to the response message of replying at first.
According to response message, router group cohort person 2 confirms that wireless terminal once connected router group service set identifier, and wireless terminal online duration is in permission online duration, then wireless terminal user directly can be surfed the Net and need not be accessed; Confirm that wireless terminal once connected router group service set identifier, but online duration is not within the scope of permission online duration, otherwise just needs again to access.
Be illustrated in figure 4 the structural representation of a kind of embodiment of wireless terminal access authentication system in WLAN (wireless local area network), in the present embodiment, wireless terminal access authentication system comprises: router group 40 and cloud controller 41, router group 40 comprises router group cohort master 42 and router group cohort person 43, router group cohort person 43 has n many router group cohort persons, be respectively router group first crowd of member 431, router group second crowd of member 432 ... router group n-th crowd of member 43n, n be more than or equal to 2 natural number.
Router group first crowd of member 431, for when after access authentication wireless terminal, obtains the authentication information of described wireless terminal, and the authentication information of the described wireless terminal obtained is sent to router group cohort master 42;
Router group second crowd of member 432, for when described wireless terminal roaming is to self, sends the first request of the certification of described wireless terminal simultaneously respectively to router group cohort master 42 and cloud controller 41; The first response also for the authentication information according to the described wireless terminal obtained at first from both router group cohort master 42 or cloud controller 41 determines whether to carry out access authentication to described wireless terminal;
Router group cohort master 42, for the authentication information of the described wireless terminal that receiving router group first crowd of member 431 sends; Also for after the first request of authentication information receiving the described wireless terminal that router group second crowd of member 432 sends, send the first response of the authentication information of described wireless terminal to described router group second crowd of member;
Cloud controller 41, for receive the authentication information of the described wireless terminal that the router group second crowd of members 432 send the first request after, send the first response of the authentication information of described wireless terminal to described router group second crowd of member 432.
Wherein, the authentication information of described wireless terminal comprises wireless terminal media accessing to control address, router group first group of member's media access control address, router group first group of member's service set and allows online duration.
Router group first crowd of member 431, router group second crowd of member 432 ... router group n-th crowd of member 43n and router group cohort master 42 adopt access authentication mode, and all have identical service set.
Described router group second crowd of member, the first response specifically for the authentication information according to the described wireless terminal obtained at first from described router group cohort master 42 or cloud controller 41 determines that described wireless terminal connected described service set, and the online duration of described wireless terminal is within the scope of described permission online duration, then described wireless terminal is let pass, allow described wireless terminal to continue online; The first response also for the authentication information according to the described wireless terminal obtained at first determines that described wireless terminal connected described service set, but the online duration of described wireless terminal within the scope of described permission online duration, does not then carry out access authentication to described wireless terminal.
Before wireless terminal described in router group first member 431 access authentication, described system also comprises:
Router group first crowd of member 431, also for before wireless terminal described in access authentication, after receiving the access request of wireless terminal, sends the second request of the authentication information of described wireless terminal simultaneously respectively to router group cohort master 42 and cloud controller 41; And determine to carry out access authentication to described wireless terminal according to the second response of the authentication information of the described wireless terminal obtained at first from both described router group cohort master 42 or cloud controller 41.
Router group first crowd of member 431, the second response for the authentication information according to the described wireless terminal obtained at first from described router group cohort master or described both cloud controllers determines that described wireless terminal had not connected described service set, then carry out access authentication to described wireless terminal.
Last it is noted that above embodiment is only in order to illustrate the technical scheme of the application, be not intended to limit; Although with reference to previous embodiment to present application has been detailed description, those of ordinary skill in the art is to be understood that: it still can be modified to the technical scheme described in foregoing embodiments, or carries out equivalent replacement to wherein portion of techniques feature; And these amendments or replacement, do not make the essence of appropriate technical solution depart from the scope of each embodiment technical scheme of the application.