CN107800715B - portal authentication method and access equipment - Google Patents

portal authentication method and access equipment Download PDF

Info

Publication number
CN107800715B
CN107800715B CN201711115751.8A CN201711115751A CN107800715B CN 107800715 B CN107800715 B CN 107800715B CN 201711115751 A CN201711115751 A CN 201711115751A CN 107800715 B CN107800715 B CN 107800715B
Authority
CN
China
Prior art keywords
server
state
user
reachable
portal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201711115751.8A
Other languages
Chinese (zh)
Other versions
CN107800715A (en
Inventor
杨坤琪
吉帅
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Maipu Communication Technology Co Ltd
Original Assignee
Maipu Communication Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Maipu Communication Technology Co Ltd filed Critical Maipu Communication Technology Co Ltd
Priority to CN201711115751.8A priority Critical patent/CN107800715B/en
Publication of CN107800715A publication Critical patent/CN107800715A/en
Application granted granted Critical
Publication of CN107800715B publication Critical patent/CN107800715B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/101Access control lists [ACL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • H04L43/0805Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability
    • H04L43/0817Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability by checking functioning
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/50Network services
    • H04L67/55Push-based network services

Abstract

the invention relates to the field of data communication, and discloses a Portal authentication method and access equipment, which solve the problem that a user authentication page is not responded for a long time because the inaccessible state of a server cannot be sensed in Portal authentication in the traditional technology. The method comprises the following steps: a. when the access equipment receives a Portal authentication request initiated by a user, judging the state of a port, and if the port is in a server reachable state, entering the step b; if the server is in the unreachable state, entering the step c; b. entering a Portal normal authentication flow, if the server is found to be unreachable in the normal authentication flow, setting the port state as a server unreachable state, and entering the step c; c. and pushing a page which is inaccessible to the server to the user through the built-in web page of the access equipment, and informing the user whether specific resources which can be accessed exist or not by combining the configuration condition of the escape ACL.

Description

Portal authentication method and access equipment
Technical Field
the invention relates to the field of data communication, in particular to a Portal authentication method and access equipment.
Background
in a traditional networking environment, as long as a user can access a local area network device, the user can access a device or a resource in a network, in order to ensure the security and operation management of network information, the legality verification of the user accessing the network is generally considered when the network is deployed, and in a specific scene, the legal user needs to be charged, namely authentication, authorization and charging.
Portal authentication is also commonly referred to as Web authentication, and Portal authentication Web sites are commonly referred to as Web portals. When the unauthenticated user accesses the network, the access equipment forces the user to log in the portal website, the user can freely access the network resources in the portal website, when the user needs to access more network resources, the user needs to authenticate the portal website, and the user can access the related network resources only after the authentication is passed.
In the existing network technology, the Portal authentication mode has the advantages of reducing the maintenance workload of the client and facilitating operation because the authentication client does not need to be installed, and can develop service expansion, technical maturity and the like on a Portal page, so that the Portal authentication mode is widely applied to networks such as operators, schools and the like.
Portal authentication is usually completed by matching access equipment, a Portal server and a RADIUS (remote authentication dial in user service) server to authenticate, authorize and charge a legal user access network, but in an actual application scene, the server is generally unreachable due to various problems (such as server network abnormality and access equipment network abnormality), and the reflected result is that an authentication page has no response for a long time and cannot normally access the network, and a user cannot perceive what problem occurs in the authentication process.
disclosure of Invention
The technical problem to be solved by the invention is as follows: a Portal authentication method and access equipment are provided, and the problem that a user authentication page is not reactive for a long time due to the fact that the inaccessible state of a server cannot be sensed in Portal authentication in the traditional technology is solved.
in one aspect, an embodiment of the present invention provides a Portal authentication method, which includes the following steps:
a. when the access equipment receives a Portal authentication request initiated by a user, judging the state of a port, and if the port is in a server reachable state, entering the step b; if the server is in the unreachable state, entering the step c;
b. Entering a Portal normal authentication flow, if the server is found to be unreachable in the normal authentication flow, setting the port state as a server unreachable state, and entering the step c;
c. and pushing a page which is inaccessible to the server to the user through the built-in web page of the access equipment, and informing the user whether specific resources which can be accessed exist or not by combining the configuration condition of the escape ACL.
as a further optimization, the method further comprises the steps of:
d. when the server is in the unreachable state, whether the server is reachable is detected regularly, and if the server is reachable, the port state is changed into the reachable state of the server.
As a further optimization, the server unreachable state is specifically a Portal server unreachable state or a RADIUS server unreachable state; the server is reachable, i.e. the Portal server is reachable, and the RADIUS server is reachable.
As a further optimization, step b specifically includes:
b1. The access equipment is connected with a Portal server for interaction, if the interaction is successful, the step b2 is entered, if the interaction is unsuccessful, the port state is set to be the inaccessible state of the Portal server, and the step c is entered;
b2. The access equipment is connected with the RADIUS server for interaction, and if the interaction is successful, an authentication result is fed back to the user; if the interaction is not successful, entering step b 3;
b3. And when all the RADIUS servers are unreachable, setting the port state as the unreachable state of the RADIUS servers.
as a further optimization, in step c, the pushing a page unreachable to the server to the user through the built-in web page of the access device specifically includes:
If the port state is the inaccessible state of the Portal server, pushing the inaccessible page of the Portal server to the user through the built-in web page of the access equipment;
And if the port state is the inaccessible state of the RADIUS server, pushing the inaccessible page of the RADIUS server to the user through the built-in web page of the access equipment.
as a further optimization, in step c, the informing whether the user has a specific resource that can be accessed in combination with the configuration of the escape ACL specifically includes:
if the access equipment is pre-configured with an escape ACL, informing a user of specific resources which can be accessed, and binding the user with the escape ACL;
and if the access equipment is not configured with the escape ACL in advance, informing the user that no available resources exist.
As a further optimization, step d specifically includes:
When the Portal server is not reachable, a TCP connection is established at regular time to detect whether the Portal server is reachable or not;
When the RADIUS server is not reachable, regularly sending a request message to detect whether the RADIUS server is reachable;
When detecting that a Portal server and any RADIUS server configured by a port are both in a reachable state, setting the port to be in a server reachable state;
and after the escape ACL of the user is unbound, redirecting the access request of the user to a normal Portal authentication flow.
In another aspect, an embodiment of the present invention further provides an access device, which includes:
The port state judging module is used for judging the state of the port when receiving a Portal authentication request initiated by a user;
The port state setting module is used for setting the port state as a server unreachable state if the server unreachable is found in the normal authentication process;
And the state pushing module is used for pushing the inaccessible page of the server to the user through the built-in web page when the condition that the server is in the inaccessible state is judged through the port state, and informing the user whether specific resources which can be accessed exist or not by combining the configuration condition of the escape ACL.
As a further optimization, the access device further comprises:
And the escape ACL configuration module is used for configuring an escape ACL based on a port on the access equipment, binding the escape ACL configured for the user when the port state is that the server is not reachable, and unbinding the escape ACL configured for the user when the port state is that the server is reachable.
as a further optimization, the access device further comprises:
the server detection module is used for periodically detecting the state of the server when the port state is that the server is unreachable, and triggering the port state setting module if the server state is reachable; the port state setting module is further used for changing the port state into the reachable state of the server when the server detection module detects that the server state is reachable.
The invention has the beneficial effects that:
1. when the server is not reachable, the state of the server and accessible resources are notified to the user through the built-in Web page, and the problems that the accessible resources are not clear and the network fails when the server is not reachable are solved. The method and the device enable the user to clearly determine the accessible resources, do not cause troubles to inaccessible resources, and facilitate the positioning of the network fault by the user.
2. The problem that the authentication page does not respond for a long time when each user is authenticated after the server is detected to be unreachable is solved by setting the port to be in the server unreachable state when the server is detected to be unreachable. The invalid interaction between the subsequent authentication user and the server after the unreachable server is detected, and the invalid access between the user and the resource which is not allowed to be accessed are greatly reduced.
Drawings
Fig. 1 is a block diagram of an access device according to an embodiment of the present invention;
FIG. 2 is a flowchart of a Portal authentication method according to an embodiment of the invention.
Detailed Description
The invention aims to provide a Portal authentication method and access equipment, and solves the problem that a user authentication page is not reactive for a long time because the inaccessible state of a server cannot be sensed in Portal authentication in the traditional technology.
The core idea is as follows: when the Portal server or all RADIUS servers are not reachable, the access equipment port is set to be in an unreachable state, the state of the server is informed through a built-in Web interface, and the accessible specific resources are informed in combination with the configuration condition of an escape ACL (access control list), so that the specific access authority of the user is released.
the scheme of the invention is further described by combining the drawings and the embodiment:
As shown in fig. 1, the access device in this embodiment includes: the system comprises a port state judging module, a port state setting module, a state pushing module, an escape ACL configuration module and a server detection module; in particular, the method comprises the following steps of,
the port state judging module is used for judging the state of the port when receiving a Portal authentication request initiated by a user;
The port state setting module is used for setting the port state as a server unreachable state if the server unreachable is found in the normal authentication process; and the port state is changed into the reachable state of the server when the server detection module detects that the state of the server is reachable.
And the state pushing module is used for pushing the inaccessible page of the server to the user through the built-in web page when the condition that the server is in the inaccessible state is judged through the port state, and informing the user whether specific resources which can be accessed exist or not by combining the configuration condition of the escape ACL.
And the escape ACL configuration module is used for configuring an escape ACL based on a port on the access equipment, binding the escape ACL configured for the user when the port state is that the server is not reachable, and unbinding the escape ACL configured for the user when the port state is that the server is reachable.
and the server detection module is used for periodically detecting the state of the server when the port state is that the server is unreachable, and triggering the port state setting module if the port state is detected to be reachable.
based on the above access device, a flow of a Portal authentication method provided by the embodiment of the present invention is shown in fig. 2, and the method includes the following implementation steps:
s201, a user initiates a request authentication to access equipment;
s202, the access equipment judges the state of a port; the port states in this embodiment are divided into three types: namely, server reachable (Portal server reachable and at least one RADIUS server reachable), Portal server not reachable, RADIUS server not reachable;
s203, if the current server is in the reachable state, the step S206 is executed;
s204, if the current state is the inaccessible state of the Portal server, the step S209 is entered;
s205, if the RADIUS server is not reachable currently, the step S213 is executed;
S206, entering a Portal authentication process under the current server reachable state, firstly, connecting the access equipment with a Portal server for interaction, if the interaction is successful, entering a step S207, and if the Portal server is found to be unreachable, entering a step S208;
S207, entering an RADIUS authentication flow, connecting the access equipment with an RADIUS server for interaction, and entering a step S210 if the interaction is successful; if the interaction is not successful, go to step 211;
s208, when finding that the Portal server is unreachable, setting the port to be in a Portal server unreachable state, and entering the step S209;
s209, pushing an inaccessible state of a Portal server and accessible resources of a user to the user through a built-in web page of the access equipment, wherein in the step, if an escape ACL is configured for the user in the access equipment in advance, the specific resources which can be accessed by the user are informed based on the escape ACL, and the configured escape ACL is bound for the user; if the escape ACL is not configured, informing the user that no resource can be accessed;
S210, if the interaction with the RADIUS server is successful, feeding back an authentication result to the user;
S211, if the RADIUS server appointed by the user is found to be unreachable, because the users with different domain names can walk through different RADIUS servers, whether all the RADIUS servers are reachable or not needs to be judged;
s212, when all the RADIUS servers are not reachable, setting the port state as a RADIUS server unreachable state, and entering the step S213;
S213, pushing an inaccessible state of the RADIUS server and accessible resources of the user to the user through a built-in web page of the access equipment, wherein in the step, if an escape ACL is configured for the user in the access equipment in advance, the specific resources which can be accessed by the user are informed based on the escape ACL, and the configured escape ACL is bound for the user; and if the escape ACL is not configured, informing the user that no resource can be accessed.
in addition, the invention also sets a detection mechanism when the server is not reachable, so as to recover the port state in time when the server is detected to be reachable and carry out normal Portal authentication, which is concretely as follows:
when the Portal server is not reachable, a TCP connection is established at regular time to detect whether the Portal server is reachable, when the RADIUS server is not reachable, a request message is sent at regular time to detect whether the RADIUS server is reachable, and when the Portal server and any one RADIUS server which are configured with the port are detected to be in reachable states, the port is set to be in a server reachable state; and after the escape ACL of the user is unbound, redirecting the access request of the user to a normal Portal authentication flow.

Claims (10)

1. A Portal authentication method is characterized by comprising the following steps:
a. when the access equipment receives a Portal authentication request initiated by a user, judging the state of a port, and if the port is in a server reachable state, entering the step b; if the server is in the unreachable state, entering the step c;
b. Entering a Portal normal authentication flow, if the server is found to be unreachable in the normal authentication flow, setting the port state as a server unreachable state, and entering the step c;
c. and pushing a page which is inaccessible to the server to the user through the built-in web page of the access equipment, and informing the user whether specific resources which can be accessed exist or not by combining the configuration condition of the escape ACL.
2. a method of Portal authentication as recited in claim 1, the method further comprising the steps of:
d. When the server is in the unreachable state, whether the server is reachable is detected regularly, and if the server is reachable, the port state is changed into the reachable state of the server.
3. A method of Portal authentication as claimed in claim 2, wherein the server-unreachable status is in particular a Portal server-unreachable status or a RADIUS server-unreachable status; the server is reachable, i.e. the Portal server is reachable, and the RADIUS server is reachable.
4. a method of Portal authentication as claimed in claim 3, wherein step b specifically comprises:
b1. The access equipment is connected with a Portal server for interaction, if the interaction is successful, the step b2 is entered, if the interaction is unsuccessful, the port state is set to be the inaccessible state of the Portal server, and the step c is entered;
b2. the access equipment is connected with the RADIUS server for interaction, and if the interaction is successful, an authentication result is fed back to the user; if the interaction is not successful, entering step b 3;
b3. And when all the RADIUS servers are unreachable, setting the port state as the unreachable state of the RADIUS servers.
5. the Portal authentication method of claim 3, wherein in step c, said pushing a server-inaccessible page to the user through the access device built-in web page specifically comprises:
If the port state is the inaccessible state of the Portal server, pushing the inaccessible page of the Portal server to the user through the built-in web page of the access equipment;
and if the port state is the inaccessible state of the RADIUS server, pushing the inaccessible page of the RADIUS server to the user through the built-in web page of the access equipment.
6. A method for Portal authentication according to claim 2, wherein in step c, said informing the user whether there is a specific resource that can be accessed in combination with the configuration of the escape ACL specifically comprises:
If the access equipment is pre-configured with an escape ACL, informing a user of specific resources which can be accessed, and binding the user with the escape ACL;
and if the access equipment is not configured with the escape ACL in advance, informing the user that no available resources exist.
7. a method of Portal authentication according to any of claims 2 to 6, wherein step d specifically comprises:
when the Portal server is not reachable, a TCP connection is established at regular time to detect whether the Portal server is reachable or not;
When the RADIUS server is not reachable, regularly sending a request message to detect whether the RADIUS server is reachable;
when detecting that a Portal server and any RADIUS server configured by a port are both in a reachable state, setting the port to be in a server reachable state;
And after the escape ACL of the user is unbound, redirecting the access request of the user to a normal Portal authentication flow.
8. an access device, comprising:
The port state judging module is used for judging the state of the port when receiving a Portal authentication request initiated by a user;
The port state setting module is used for setting the port state as a server unreachable state if the server unreachable is found in the normal authentication process;
and the state pushing module is used for pushing the inaccessible page of the server to the user through the built-in web page when the condition that the server is in the inaccessible state is judged through the port state, and informing the user whether specific resources which can be accessed exist or not by combining the configuration condition of the escape ACL.
9. the access device of claim 8, wherein the access device further comprises:
And the escape ACL configuration module is used for configuring an escape ACL based on a port on the access equipment, binding the escape ACL configured for the user when the port state is that the server is not reachable, and unbinding the escape ACL configured for the user when the port state is that the server is reachable.
10. an access device according to claim 8 or 9, characterised in that the access device further comprises:
the server detection module is used for periodically detecting the state of the server when the port state is that the server is unreachable, and triggering the port state setting module if the server state is reachable; the port state setting module is further used for changing the port state into the reachable state of the server when the server detection module detects that the server state is reachable.
CN201711115751.8A 2017-11-13 2017-11-13 portal authentication method and access equipment Active CN107800715B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201711115751.8A CN107800715B (en) 2017-11-13 2017-11-13 portal authentication method and access equipment

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201711115751.8A CN107800715B (en) 2017-11-13 2017-11-13 portal authentication method and access equipment

Publications (2)

Publication Number Publication Date
CN107800715A CN107800715A (en) 2018-03-13
CN107800715B true CN107800715B (en) 2019-12-10

Family

ID=61535030

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201711115751.8A Active CN107800715B (en) 2017-11-13 2017-11-13 portal authentication method and access equipment

Country Status (1)

Country Link
CN (1) CN107800715B (en)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108769016B (en) * 2018-05-29 2020-02-11 新华三信息安全技术有限公司 Service message processing method and device
CN112202813B (en) * 2020-10-29 2023-04-18 杭州迪普科技股份有限公司 Network access method and device

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101668017A (en) * 2009-09-16 2010-03-10 杭州华三通信技术有限公司 Authentication method and equipment
CN102523220A (en) * 2011-12-19 2012-06-27 北京星网锐捷网络技术有限公司 Web authentication method, and client and access layer device used for web authentication

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101448277B (en) * 2008-12-30 2010-09-08 中国移动通信集团北京有限公司 Method, system and device for processing wireless access network faults
CN102201945A (en) * 2010-03-24 2011-09-28 英业达股份有限公司 Testing system for simulating storage area network
CN102082733B (en) * 2011-02-25 2013-06-26 杭州华三通信技术有限公司 Portal system and access method thereof
CN103139772A (en) * 2011-11-23 2013-06-05 中国移动通信集团上海有限公司 Method for processing terminal accessed to local area network and method and device for used data statistic
CN103457740B (en) * 2013-09-06 2017-12-19 上海斐讯数据通信技术有限公司 A kind of portal certification system and its method
CN103501495A (en) * 2013-10-16 2014-01-08 苏州汉明科技有限公司 Perception-free WLAN (Wireless Local Area Network) authentication method fusing Portal/Web authentication and MAC (Media Access Control) authentication
CN105592458B (en) * 2014-10-22 2018-10-09 中国电信股份有限公司 The authentication method and system of wireless local area network service, server
CN104410990B (en) * 2014-11-14 2018-10-30 迈普通信技术股份有限公司 Realize the method and system of access authentication server switching
CN105959295A (en) * 2016-06-21 2016-09-21 福建富士通信息软件有限公司 Portal escaping method and device
CN106453409B (en) * 2016-11-28 2019-12-10 迈普通信技术股份有限公司 Message processing method and access device

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101668017A (en) * 2009-09-16 2010-03-10 杭州华三通信技术有限公司 Authentication method and equipment
CN102523220A (en) * 2011-12-19 2012-06-27 北京星网锐捷网络技术有限公司 Web authentication method, and client and access layer device used for web authentication

Also Published As

Publication number Publication date
CN107800715A (en) 2018-03-13

Similar Documents

Publication Publication Date Title
US20190361414A1 (en) Modifying access to an electronic lock based on movement of an electronic key
CN109905476B (en) Method, computer system, and medium for synchronizing data
CN109005185B (en) Multi-layered authentication method to facilitate communication between smart home devices and cloud-based servers
CN101674285B (en) Single sign-on system and method thereof
CN104980448B (en) Remote monitoring method, device and system
CN102333081B (en) Authentication method, equipment and system
CN104168339A (en) Method and device for preventing domain name from being intercepted
CN104811462A (en) Access gateway redirection method and access gateway
CN103796278A (en) Mobile terminal wireless network access control method
CN106506503B (en) System and method for promoting uniform user terminal behaviors of B/S and C/S mixed architecture
CN103874065A (en) Method and device for judging user position abnormity
CN103747433A (en) Method and mobile terminal for realizing root request management through manufacturer server
CN106982430B (en) Portal authentication method and system based on user use habits
CN106686592B (en) Network access method and system with authentication
CN104065921A (en) Security and protection wide area network embedded type monitoring device and control method thereof
CN107800715B (en) portal authentication method and access equipment
CN104837134A (en) Web authentication user registration method, device and system
EP2693691B1 (en) Method and apparatus for initializing gateway in device management system
CN103888465A (en) Method and device for detecting webpage hijacking
CN113411286B (en) Access processing method and device based on 5G technology, electronic equipment and storage medium
CN111726328A (en) Method, system and related device for remotely accessing a first device
CN102075504A (en) Method and system for realizing two-layer Portal authentication and Portal server
CN102045310A (en) Industrial Internet intrusion detection as well as defense method and device
CN102045398A (en) Portal-based distributed control method and equipment
CN111901298A (en) Method and device for determining cloud short message platform during SSLVPN authentication and electronic equipment

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
CP02 Change in the address of a patent holder
CP02 Change in the address of a patent holder

Address after: 610041 nine Xing Xing Road 16, hi tech Zone, Sichuan, Chengdu

Patentee after: MAIPU COMMUNICATION TECHNOLOGY Co.,Ltd.

Address before: 610041, 17 floor, maple building, 1 building, 288 Tianfu street, Chengdu, Sichuan.

Patentee before: MAIPU COMMUNICATION TECHNOLOGY Co.,Ltd.