WO2014101449A1 - 一种无线局域网中接入节点的控制方法及通信系统 - Google Patents

一种无线局域网中接入节点的控制方法及通信系统 Download PDF

Info

Publication number
WO2014101449A1
WO2014101449A1 PCT/CN2013/082385 CN2013082385W WO2014101449A1 WO 2014101449 A1 WO2014101449 A1 WO 2014101449A1 CN 2013082385 W CN2013082385 W CN 2013082385W WO 2014101449 A1 WO2014101449 A1 WO 2014101449A1
Authority
WO
WIPO (PCT)
Prior art keywords
access
list
authentication
access node
access controller
Prior art date
Application number
PCT/CN2013/082385
Other languages
English (en)
French (fr)
Inventor
梁乾灯
范亮
陈勇
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Priority to EP13868706.6A priority Critical patent/EP2903385A4/en
Priority to US14/439,405 priority patent/US9775032B2/en
Publication of WO2014101449A1 publication Critical patent/WO2014101449A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0892Network architectures or network communication protocols for network security for authentication of entities by using authentication-authorization-accounting [AAA] servers or protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/101Access control lists [ACL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W88/00Devices specially adapted for wireless communication networks, e.g. terminals, base stations or access point devices
    • H04W88/08Access point devices

Definitions

  • the present invention relates to the field of communications, and in particular, to a method and a communication system for an access point (AP) in a Wireless Local Area Network (WLAN).
  • AP access point
  • WLAN Wireless Local Area Network
  • WLANs include an AP (access node) and an access controller (Access Controller, AC) and the Authentication Authorization Accounting (AAA) server, after the user terminal device authenticates through the AAA server, it can access the network through the AP and the AC.
  • AP access node
  • AC Access Controller
  • AAA Authentication Authorization Accounting
  • BNG Broadband Network Gateway
  • the AC device is only responsible for the management and service configuration of the AP.
  • the network operator has more and more requirements for the deployment and speed of the AP.
  • the automatic deployment technology of the AP is also generated.
  • the current AP device is automatically deployed.
  • the dynamic host configuration protocol (DHCP) protocol is used to obtain the AC list from the DHCP server (Server) in the network. Then, select an AC from the list to communicate. Management of the AP, but in this technology, the DHCP server sends an AC list to the AP device regardless of whether the AP is legal.
  • the AP device that is connected to the AP is a private AP device, the AP will appear to the private AP. The device leaks legitimate AC device information.
  • the present invention provides a method and a communication system for controlling an AP in a WLAN.
  • the present invention provides a method for controlling an AP in a WLAN.
  • the method includes: authenticating an AP; after the authentication is passed, sending an AC list to the AP; the AP selecting from the AC list according to a preset rule. An AC that communicates with the selected AC.
  • the process of authenticating the AP is: the authentication server authenticates the AP.
  • the process of authenticating the AP includes: determining whether the AP accessing the geographical location information, the AP account key, and/or the AP authorization certificate is legal; if legal, determining whether the AP meets the policy requirements set by the authentication server. ; Yes, the AP is certified.
  • the AP control method provided by the present invention further includes: updating the AC list.
  • the updated AC list is: the BNG and/or the authentication server updates the original AC list according to the original AC list and the current load of each AC in the original AC list, and generates an AC list that is sent to the AP.
  • the AP selects an AC from the AC list according to a preset rule, and selects the selected one.
  • the process of the AC communicating is: the AP sends an access request to each AC in turn according to the order of the access controllers in the AC list, selects an AC with successful access to establish a communication connection, and communicates with the selected AC. .
  • the process of communicating with the selected AC is: the AP communicates with the selected AC through a Control and Provisioning of Wireless Access Points Protocol (CAPWAP).
  • CAPWAP Wireless Access Points Protocol
  • the present invention also provides a communication system.
  • the communication system includes: at least one AP, at least one AC, BNG, and an authentication server; the AP is connected to the AP and the authentication server through the BNG; wherein, the authentication server is configured To: Authenticate the AP and pass the certification Then, the AC list is sent to the AP; the AP is set to: select an AC from the AC list according to a preset rule, and communicate with the selected AC.
  • the BNG is further configured to: store an AC list, and send the stored AC list to the AP after the authentication server passes the AP authentication.
  • the BNG and/or authentication server is further configured to: update the AC list.
  • the authentication server is an AAA server and/or a DHCP server.
  • the authentication server sends the AC list to the AP device that passes the authentication only after the authentication of the AP device is passed, and solves the problem of information leakage caused by sending the AC list to the private AP device.
  • the security of network device information is not limited to, but not limited to, Wi-Fi Protected Access (WPA)
  • AAA server an AAA server and/or a DHCP server.
  • the authentication server sends the AC list to the AP device that passes the authentication only after the authentication of the AP device is passed, and solves the problem of information leakage caused by sending the AC list to the private AP device. The security of network device information.
  • FIG. 1 is a schematic diagram of a communication system according to an embodiment of the present invention.
  • FIG. 2 is a schematic diagram of a method for controlling an AP in a WLAN according to an embodiment of the present invention
  • FIG. 3 is a schematic diagram of a method for authenticating an AP according to an embodiment of the present invention
  • FIG. 4 is a schematic diagram of a method for controlling an AP in a WLAN according to a preferred embodiment of the present invention.
  • the embodiment of the present invention provides a control technology for an AP accessing a network in a WLAN, which can solve the problem that a private AP device can be accessed by sending an AC list to a private AP device caused by not authenticating the AP device in the prior art. Network and AC device information leakage issues.
  • the communication system 1 is a schematic diagram of a communication system according to an embodiment of the present invention.
  • the communication system 1 provided by the present invention includes at least one AP11, at least one AC12, BNG13, and an authentication server 14, which are connected.
  • the relationship is shown in Figure 1, ⁇ ⁇ through BNG13 and AP12 And the authentication server 14 is connected; wherein:
  • API 1 is used for relaying data signals between the user equipment and the web server
  • AC12 is used to manage and configure AP11.
  • BNG13 is used to transfer data and services between API 1 and AP 12 and authentication server 14;
  • the authentication server 14 is configured to authenticate the AP11, and after the authentication is passed, the AC list is sent to the AP11. Specifically, the authentication server 14 sends the AC list to the AP11 that passes the authentication through the BNG13.
  • the AP 11 is configured to select an AC12 from the received AC list according to a preset rule, and communicate with the AC12.
  • the AP11 receives the AC according to the preset rule.
  • the process of selecting an AC12 in the list and communicating with the AC12 may be: The AP11 sends an access request to each AC according to the order of the access controllers in the AC list, and selects an AC12 with successful access to establish a communication connection. , communicate with the selected AC12.
  • the AP 11 in the foregoing embodiment communicates with the selected AC 12. Specifically, the AP 11 communicates with the selected AC 12 through the CAPWAP to implement the AC 12 to manage and control the AP 11 .
  • the BNG 13 in the foregoing embodiment is further configured to store the AC list, and after the authentication server passes the AP authentication, the stored AC list is delivered to the authenticated AP.
  • the BNG13 storage AC list can be configured by the network administrator to configure the default AC list on the BNG through the command line or NMS (Network Management System).
  • the BNG 13 and/or the authentication server 14 in the foregoing embodiment updates the AC list before sending the AC list to the AP 11, so as to deliver an AC list in the latest state.
  • the update mode may specifically be: BNG13 and/or
  • the authentication server 14 updates the original AC list according to the original AC list and the current load of each AC12 in the original AC list, and generates the original AC list. AC list.
  • the authentication server 14 in the above embodiment may be an AAA server and/or a DHCP server; when the authentication server 14 is an AAA server, the authentication server 14 itself may implement the function of authenticating the AP 11 and delivering the AC list; When the server 14 is a DHCP server, other servers that can implement the authentication function (such as the AAA server) are required to authenticate the AP11, and the authentication result is transmitted to the DHCP server. When the authentication result is the authentication, the DHCP server passes the authentication. The AP11 sends an AC list.
  • an AP control method provided by the present application includes: Step S201: authenticating an AP; Go to step S202, otherwise, end the process;
  • Step S202 After the authentication is passed, the AC list is sent to the AP that passes the authentication.
  • the control method of the AP in the embodiment shown in FIG. 2 further includes: sending an IP address to the AP that passes the authentication after the authentication is passed.
  • the authentication of the AP in the embodiment shown in FIG. 2 is specifically: the authentication server authenticates the AP; further, the authentication server includes an AAA authentication server and/or a DHCP server.
  • FIG. 3 is a schematic diagram of an AP authentication method according to an embodiment of the present invention.
  • the process for authenticating an AP in the embodiment shown in FIG. 2 includes the following steps: Step S301: Determine an authentication of an access node Whether the information is legal; the authentication information of the access node includes the access location information of the access node, the account key of the access node, and/or the authorization certificate of the access node; if it is legal, step S302 is performed. If it is not legal, the authentication fails and the authentication process ends.
  • the authentication information of the AP is one of the APs deployed by the network operator, that is, whether the authentication information of the AP belongs to the list of M authentication information of all APs provided by the network server, and if so, The authentication is legal for the AP. Otherwise, the AP is invalid.
  • Step S302 Determine whether the access node meets the policy requirement set by the authentication server; if yes, perform step S303; if not, the authentication fails, and the authentication process ends.
  • Step S303 The access node passes the authentication and enters the process of sending the AC list (ie, step S202).
  • an AC list is sent to the AP, specifically: an authentication server (a server with an authentication function such as an AAA server and/or a DHCP server) and/or a BNG device is delivered to the AP that passes the authentication.
  • an authentication server a server with an authentication function such as an AAA server and/or a DHCP server
  • a BNG device is delivered to the AP that passes the authentication.
  • the method for controlling the AP in the embodiment shown in FIG. 2 further includes: updating the AC list.
  • the update method may be that the authentication server (the server such as the AAA server and the DHCP server) and/or the BNG device periodically obtains the load of each AC in the delivery list before the AC list is delivered, and the AC list is loaded according to the load of each AC.
  • the ACs are arranged in a manner that the ACs are arranged in order of their load from light to heavy; of course, the update manner may also be an authentication server (a server such as an AAA server and a DHCP server) and/or a BNG device periodically or Before the AC list is delivered, the ACs in the delivery list are obtained in real time, and the ACs in the AC list are arranged according to the location information of each AC.
  • the arrangement may be performed by arranging the ACs according to their distances AP from near to far. .
  • the AP in the embodiment shown in FIG. 2 selects an AC from the received AC list according to a preset rule, and the process of communicating with the AC may be: the AP follows the access control in the AC list. Sorting the devices, sending an access request to each AC in turn, selecting an AC with successful access to establish a communication connection, and communicating with the selected AC; of course, all AC devices that can be connected can form a new AC. List, select an AC from this new AC list to communicate.
  • 4 is a schematic diagram of a method for controlling an AP in a WLAN according to a preferred embodiment of the present invention. As shown in FIG.
  • a preferred embodiment of the method for controlling an AP in a WLAN according to the present invention includes the following steps: S401: The AP initiates an authentication request. Specifically, only the AP may send an authentication request to the authentication server through the BNG device, or may be
  • the BNG device sends an authentication request to the authentication server instead of the AP.
  • the authentication request carries the authentication information of the AP device that initiates the authentication request.
  • Step S402 The authentication server authenticates the AP. If the authentication succeeds, the authentication verification message is sent to the BNG, and step S403 is performed. Otherwise, the authentication failure message is fed back to the AP, and the process ends.
  • the authentication server performs authentication according to the authentication information in the received authentication request.
  • the authentication process is shown in Figure 3.
  • Step S403 Update the AC list; the BNG device obtains the latest AC list.
  • the process of obtaining the latest AC list by the BNG device may be: After the authentication server delivers the original AC list to the BNG device, the BNG device obtains the load (or location) of each AC in the original AC list delivered by the authentication server according to the periodic or real-time.
  • the ACs in the AC list are arranged according to the load (or location) of each AC, and the arrangement may be that the ACs are arranged in order according to their load from light to heavy (or each AC is from near to far according to its distance AP);
  • the BNG device configures the default original AC list on the BNG through the command line or the NMS, and obtains the load (or location) of each AC in the original AC list delivered by the authentication server according to the periodic or real-time, according to each The load (or position) of the AC is arranged in the AC list.
  • the arrangement may be such that the ACs are lightly and heavyly loaded according to their load (or each AC is close to far according to its distance AP).
  • the authentication server obtains the load (or location) of each AC in the original AC list delivered by the authentication server according to the periodicity or the real-time, and arranges the ACs in the AC list according to the load (or location) of each AC. It may be a formula according to which each of the AC load from light to heavy (or by each AC The APs are arranged in sequence according to their distance from the AP, and the updated AC list is formed and sent to the BNG device.
  • Step S404 The BNG device sends the latest AC list to the authenticated AP device.
  • Step S405 The AP device selects an AC from the received AC list, and communicates with the AC; the selection manner is not described again.
  • the AP accesses the network in various ways.
  • the AP can access the network through 802. IX, PPPoE, DHCPv4/v6, static IP, and VPDN.
  • the authentication server can pass the Web authentication, EAP authentication, and BNG proxy PPP. It is impossible to perform authentication for the AP device by the authentication mode of the PAP or CHAP authentication.
  • the following several representative access methods are used. The invention will be explained by way of example and in conjunction with FIG.
  • the AP accesses the network through EAP.
  • the AP device initiates authentication by means of EAP-MD5 (which may also be EAP-TLS, L-EAP, EAP-SIM, EAP-TTLS, P-EAP, etc. - EAP-mode).
  • EAP-MD5 which may also be EAP-TLS, L-EAP, EAP-SIM, EAP-TTLS, P-EAP, etc. - EAP-mode.
  • the WLAN provided by the present invention is provided.
  • the control method of the AP in the middle includes the following steps:
  • the AP sends an authentication start message to the BNG EAPoL-Start;
  • the BNG After receiving the authentication start message, the BNG feeds back the authentication protocol ID request message to the AP.
  • the AP sends a reply authentication protocol ID response message to the BNG.
  • EAP Identity Response
  • the BNG encapsulates the received EAP Identity Response message into the authentication access request message RADIUS Access Request and sends it to the server (the server is the AAA server at this time);
  • the AAA server generates the Challenge information, and sends the Challenge to the BNG through the RADIUS Access-Challenge message.
  • the BNG extracts the Challenge from the RADIUS Access-Challenge message and passes the EAP Request/MD5 Challenge (EAP-Request/MD5- Challenge ) The message is sent to the AP;
  • the AP After receiving the EAP-Request/MD5-Challenge message, the AP extracts the Challenge, performs MD5 operation on its own user password and Challenge information, obtains the encrypted user password (Challenged-Pass-word), and then carries the Challenged-Pass-word.
  • the BNG is sent to the BNG in the EAP Response/MD5 Challenge (EAP-Response/MD5-Challenge) message; the BNG sends the Challenge, Challenged-Pass-word and username to the AAA server through the Radius message; after receiving the Radius message, the AAA server receives the Radius message. , extract authentication information (Challenge,
  • the Challenged-Pass-word and the user name are used to perform the MD5 operation to determine whether the AP is legal. If it is legal, the authentication success message is sent to the BNG, which carries the AC list; otherwise, the authentication failure message is sent to the BNG.
  • the BNG After receiving the authentication success message, the BNG sends an EAP authentication success message to the AP. Correspondingly, after receiving the successful authentication failure, the BNG sends an EAP authentication failure message to the AP, and the process ends.
  • the BNG sends an announcement message to the AP, EAPoL- Announcement, carrying an AC list;
  • the AP extracts an AC list from the received EAPoL-Announcement message, and selects an AC device to implement AC management of the AP.
  • the AP communicates with the AC through the CAPWAP protocol, and obtains an IP address from the BNG device through DHCP or PPP to access the network.
  • the method for controlling the AP in the WLAN includes the following steps:
  • the PPPoE and PPP-LCP negotiation between the AP and the BNG determines the PPPoE session ID and user authentication mode.
  • the specific negotiation process is not mentioned here.
  • the AP sends an authentication request to the BNG, and carries the AP authentication information.
  • the BNG sends the authentication information sent by the AP to the AAA server through the Radius authentication request message.
  • the AAA server After receiving the Radius message, the AAA server extracts the authentication information and determines whether the AP is legal. If it is legal, it sends an authentication success message to the BNG, which carries the AC list; otherwise, sends an authentication failure message to the BNG;
  • the BNG After receiving the authentication success message, the BNG sends an EAP authentication success message to the AP. Otherwise, after receiving the successful authentication failure, the BNG sends an EAP authentication failure message to the AP, and the process ends.
  • the AP After receiving the authentication success message, the AP sends a PPP IPCP phase address request message to the BNG. After receiving the address request message, the BNG directly assigns an IP address to the AP or assigns an IP address to the AP through the DHCP server, and sends the assigned IP address to the user. Carry the AC list at the same time;
  • the AP extracts the AC list, selects an AC device to communicate through the CAPWAP protocol, implements AC management of the AP, and accesses the network by using the obtained IP address.
  • the third application example The AP accesses the network through the DHCP (specifically DHCPv4) mode.
  • the method for controlling the AP in the WLAN includes the following steps:
  • the network administrator configures a default AC list on the BNG through the command line or NMS (Network Management System);
  • the AP sends a DHCP Discover message to the BNG.
  • the AP carries the identifier information through Option 60 or other extended option in the Discover message, and inserts the AP geographical location information through the Option 82 or other extended option in the Discover message.
  • the BNG After receiving the DHCP Discover message, the BNG extracts the authentication information (such as the MAC information of the AP, the geographical location information of the AP, and/or the AP identification information), and sends the information to the AAA server to authenticate the AP through the Radius message. After receiving the Radius message, the AAA server extracts the authentication information and performs AP authentication. If the authentication succeeds, the AAA server sends an authentication success message to the BNG, and sends an authentication failure message to the BNG, and the process ends.
  • the authentication information such as the MAC information of the AP, the geographical location information of the AP, and/or the AP identification information
  • the BNG After receiving the authentication success message, the BNG extracts the internally configured AC list and sends it to the AP in the DHCP Offer message.
  • the AP sends a DHCP Request message to the BNG.
  • the BNG sends a DHCP Ack message to the AP.
  • the AP extracts the AC list from the received DHCP Offer, and selects an AC device to communicate through the CAPWAP protocol to implement AC management of the AP. It can be foreseen that in the above embodiment, the BNG can also be carried in the DHCP Ack message.
  • the AC list is sent to the AP.
  • the BNG can also carry the AC list through Option52 in the Advertise message or the Reply message.
  • the above three embodiments do not involve the function of the authentication server or the BNG device to update the AC list.
  • the following two examples are used for explanation. It is foreseeable that the dynamic update function can be applied to all the above embodiments. of.
  • the fourth application example The AP accesses the PPP+DHCPv6 mode.
  • the method for controlling the AP in the WLAN provided by the present invention includes the following steps: Each AC device periodically sends the number of APs managed by the respective AC to the BNG. ;
  • the PPPoE and PPP LCP are negotiated between the AP and the BNG to determine the PPPoE session ID and user authentication mode.
  • the AP sends an authentication request to the BNG to carry the AP authentication information.
  • the BNG sends the authentication information sent by the AP to the AAA server through the Radius authentication request message.
  • the AAA server After receiving the Radius message, the AAA server extracts the authentication information and determines whether the AP is legal. If it is legal, it sends an authentication success message to the BNG and carries the AC list; otherwise, sends an authentication failure message to the BNG;
  • the BNG receives the authentication success message, extracts the AC list and stores it, and sends a PPP authentication success message to the AP.
  • the AP and the BNG perform PPP IPv6CP phase message interaction to obtain an Interface-ID;
  • the AP sends a DHCPv6 Request message to the BNG to apply for an IPv6 address.
  • the BNG adjusts the order of the ACs in the list according to the AC list information sent by the AAA server and the load status of each AC device, and sends a DHCPv6 Reply message to send the IPv6 address of the AP to the AP, and carries the adjustment through Option52 in the message.
  • the AP extracts the AC list, selects an AC device to communicate through the CAPWAP protocol, and accesses the network according to the IP address.
  • the BNG can also be sent to the AP by using the extended field carrying the AC list in the message of the PPP IPCP phase; when the AP accesses through the PPP+ND mode, the BNG can also be the RA message of the icmpv6.
  • the extended option carries the AC list information to the AP, or sends the AC list to the AP through the extended field in the IPCP phase.
  • the fifth application example When the server type is a DHCP server, the method for controlling an AP in the WLAN provided by the present invention includes the following steps:
  • the network administrator configures a default AC list on the BNG through commands or the network management system.
  • Each AC device periodically sends the number of APs managed by the AC to the BNG.
  • the AP interacts with the BNG to complete identity authentication.
  • the authentication process is not described here.
  • the BNG sends an address request to the DHCP server instead of the AP;
  • the DHCP server sends an IP address assigned to the AP to the BNG and carries an AC list.
  • the BNG After receiving the address allocation message fed back by the DHCP server, the BNG extracts the AC list and according to The default AC list configured on the BNG and/or the load status of each AC device adjusts the order of the ACs in the list, and sends a DHCPv6 Reply message carrying the IP address and the adjusted AC list to the AP.
  • the AP extracts the AC list from the DHCPv6 Reply message, selects an AC device to communicate through the CAPWAP protocol, and accesses the network according to the IP address.
  • the AC list is sent to the AP device only when the AP device is authenticated.
  • the information leakage problem caused by sending the AC list to the private AP device in the prior art is solved.
  • the IP address is allocated to the AP device only when the AP device is authenticated, and the problem that the private AP device in the prior art can access the communication network is solved.
  • the BNG sends an address request to the DHCP server instead of the AP, which solves the problem that the AP device cannot obtain an IP address and an AC list from the server due to the unified management of the BNG in the prior art.

Abstract

一种无线局域网中的接入节点的控制方法及通信系统。该方法包括:对接入节点进行认证;认证通过后,向接入节点下发接入控制器列表;接入节点根据预设规则从接入控制器列表中选择一接入控制器,与所选择的接入控制器进行通信。上述方案仅在接入节点认证通过的情况下,才将接入控制器列表发送给认证通过的接入节点,解决了向私设的接入节点下发接入控制器列表造成的接入控制器信息泄露的问题,保证了网络设备信息的安全。

Description

一种无线局域网中接入节点的控制方法及通信系统
技术领域
本发明涉及通信领域, 尤其涉及一种无线局域网 (Wireless Local Area Network, WLAN ) 中的接入节点 ( Access Point, AP ) 的控制方法及通信系 统。
背景技术
随着各种智能终端 (如智能手机、 平板电脑等) 的普及, 终端用户可以 随时随地 WLAN接入互联网进行办公等; 传统的 WLAN包括 AP (接入节 点 )和接入控制器( Access Controller, AC )及验证授权及记账( Authentication Authorization Accounting, AAA )服务器 , 用户终端设备在通过 AAA服务器 认证之后, 就可以通过 AP和 AC访问网络。 随着 WLAN和固定宽带网络的 融合, 各种类型的用户终端通过 WLAN和有线链路接入到固定宽带网络中, 统一由网络网关 (Broadband Network Gateway, BNG )进行用户鉴权和业务 控制, 而此时的 AC设备只负责 AP设备的管理和业务配置; 同时, 网络运 营商对 AP设备的部署数量及速度要求越来越高, 相应的, AP设备自动部署 技术也随之产生。 当前 AP设备自动部署方法是 AP上电后通过动态主机 ( Dynamic Host Configuration Protocol, DHCP )协议从网络中的 DHCP服务器(Server )处 获取 AC的列表之后, 从列表中选择一台 AC进行通信以实现 AP的管理, 但是在该技术中, 由于 DHCP Server不论 AP是否合法都会向该 AP设备下 发 AC列表, 当出现接入的 AP设备为私架的 AP设备时,就会出现向私架的 AP设备泄露合法 AC设备信息的问题。
发明内容
为了解决当前技术中存在的服务器向私架的 AP设备下发 AC列表所导 致的泄露合法 AC设备信息的问题, 本发明提供了一种 WLAN中的 AP的控 制方法及通信系统。
本发明提供了一种 WLAN中的 AP的控制方法, 在一个实施例中, 该方 法包括: 对 AP进行认证; 认证通过后, 向 AP下发 AC列表; AP根据预设 规则从 AC列表中选择一 AC, 与所选择的 AC进行通信。
优选地, 所述对 AP进行认证的过程为: 认证服务器对 AP进行认证。 优选地,所述对 AP进行认证的过程包括:判断 AP接入地理位置信息、 AP账号密钥和 /或 AP授权证书是否合法; 如合法, 则进一步判断该 AP是否 符合认证服务器设置的策略要求; 是, 则该 AP认证通过。
优选地,在向 AP下发 AC列表之前,本发明提供的 AP控制方法还包括: 更新 AC列表。
优选地, 所述更新 AC列表为: BNG和 /或认证服务器根据原始 AC列表 及所述原始 AC列表中各 AC的当前负载, 更新所述原始 AC列表, 生成向 AP下发的 AC列表。
优选地, 所述 AP根据预设规则从 AC列表中选择一 AC, 与所选择的
AC进行通信的过程为: 所述 AP按照所述 AC列表中接入控制器的排序,依 次向各 AC发送接入请求, 选择一个接入成功的 AC建立通信连接, 与所选 择的 AC进行通信。
优选地, 所述与所选择的 AC进行通信的过程为: 所述 AP通过无线接 入点控制及西己置协议 ( Control And Provisioning of Wireless Access Points Protocol, CAPWAP )与所选择的 AC进行通信。
同时本发明也提供了一种通信系统,在一个实施例中,该通信系统包括: 至少一个 AP、 至少一个 AC、 BNG及认证服务器; AP通过 BNG与 AP及认 证服务器连接; 其中, 认证服务器设置为: 对 AP进行认证, 并在认证通过 后, 向 AP下发 AC列表; AP设置为: 根据预设规则从 AC列表中选择一 AC, 与所选择的 AC进行通信。 优选地, 所述 BNG还设置为: 存储 AC列表, 并在认证服务器对 AP认 证通过后, 将其存储的 AC列表下发到所述 AP。 优选地, 所述 BNG和 /或认证服务器还设置为: 更新 AC列表。 优选地, 所述认证服务器为 AAA服务器和 /或 DHCP服务器。 通过本发明的实施, 认证服务器仅在对 AP设备认证通过的情况下, 才 将 AC列表发送给认证通过的 AP设备,解决向私设的 AP设备下发 AC列表 造成的信息泄露问题, 保证了网络设备信息的安全。
附图概述
图 1为本发明一实施例提供的通信系统的示意图;
图 2为本发明一实施例提供的 WLAN中的 AP的控制方法的示意图; 图 3为本发明一实施例提供的 AP的认证方法的示意图;
图 4为本发明一最佳实施例提供的 WLAN中的 AP的控制方法的示意图。
本发明的较佳实施方式
下面通过具体实施方式结合附图的方式对本发明做出进一步的诠释说 明。
本发明实施例提供了一种 WLAN中的 AP接入网络的控制技术,解决现 有技术中不对 AP设备进行认证所造成的向私设 AP设备下发 AC列表导致的 私设 AP设备可以接入网络及 AC设备信息泄露的问题。
图 1为本发明一实施例提供的通信系统的示意图; 由图 1可知, 在该实 施例中, 本发明提供的通信系统 1 包括至少一个 AP11、 至少一个 AC12、 BNG13及认证服务器 14,其连接关系如图 1所示,ΑΡΙ Ι通过 BNG13与 AP12 及认证服务器 14连接; 其中:
API 1用于在用户设备与网络服务器之间进行数据信号的中转;
AC12用于对 AP11进行管理和配置;
BNG13用于在 API 1与 AP12及认证服务器 14之间进行数据及业务的中 转;
认证服务器 14用于对 AP11进行认证, 并在认证通过后, 向 AP11下发 AC列表; 具体的, 可以是认证服务器 14通过 BNG13向通过认证的 AP11 下发 AC列表;
AP11用于根据预设规则从接收到的 AC列表中选择一个 AC12, 并与该 AC12进行通信;当 AC列表仅包括这个通信网络中的 AC12名单时,该 AP11 根据预设规则从接收到的 AC列表中选择一个 AC12,并与该 AC12进行通信 的过程可以是: AP11按照所述 AC列表中接入控制器的排序, 依次向各 AC 发送接入请求,选择一个接入成功的 AC12建立通信连接,与所选择的 AC12 进行通信。
优选地, 上述实施例中的 AP11与其所选择的 AC12进行通信具体的可 以是: AP11通过 CAPWAP与所选择的 AC12进行通信, 以达到 AC12对 AP11进行管理和控制的作用。 优选地, 上述实施例中的 BNG13还用于存储 AC列表, 并在认证服务 器对 AP认证通过后, 将其存储的 AC列表下发到通过认证的 AP。 BNG13 存储 AC 列表具体的可以是网络管理员通过命令行或 NMS ( Network Management System网络管理系统)在 BNG上配置默认的 AC列表。
优选地, 上述实施例中的 BNG13和 /或认证服务器 14在向 AP11 下发 AC列表之前, 更新 AC列表, 以便下发一个最新状态的 AC列表; 该更新方 式具体的可以是: BNG13和 /或认证服务器 14根据原始 AC列表及所述原始 AC列表中各 AC12的当前负载, 更新所述原始 AC列表, 生成向 API 1下发 的 AC列表。
优选地,上述实施例中的认证服务器 14可以是 AAA服务器和 /或 DHCP 服务器; 当认证服务器 14为 AAA服务器时, 其自身就可以实现对 AP11的 认证及下发 AC列表的功能; 但是当认证服务器 14为 DHCP服务器时, 就 需要其他的可以实现认证功能的服务器(如 AAA服务器)对 AP11进行认证, 并将认证结果传送到 DHCP服务器, 当认证结果是认证通过时, DHCP服务 器向认证通过的 AP11下发 AC列表。
图 2为本发明一实施例提供的 WLAN中的 AP的控制方法的示意图; 由 图 2可知, 在一个实施例中, 本申请提供的 AP控制方法包括: 步骤 S201 : 对 AP进行认证; 如果通过, 执行步骤 S202, 否则, 结束流 程;
步骤 S202: 认证通过后, 向认证通过的 AP下发 AC列表; 步骤 S203: AP根据预设规则从 AC列表选择一 AC ,与该 AC进行通信。 优选地, 图 2所示实施例中的 AP的控制方法在认证通过之后还包括: 向通过认证的 AP下发 IP地址。 优选地, 图 2所示实施例中的对 AP进行认证具体的为: 认证服务器对 AP进行认证; 进一步的, 认证服务器包括 AAA认证服务器和 /或 DHCP服 务器。
图 3为本发明一实施例提供的 AP的认证方法的示意图; 如图 3所示, 图 2所示实施例中的对 AP进行认证的过程包括以下步骤: 步骤 S301 : 判断接入节点的认证信息是否合法; 该接入节点的认证信息 包括该接入节点的接入地理位置信息、接入节点的账号密钥和 /或接入节点的 授权证书等授权信息; 若合法, 则执行步骤 S302; 若不合法, 则认证失败, 认证流程结束。 具体的可以是认证该 AP的认证信息是否属于网络运营商部署的 AP中 的一个, 也即是验证该 AP 的认证信息是否属于网络服务器提供的所有 AP 的 M认证信息的列表, 如果属于, 则认证为该 AP合法, 否则, 该 AP不合 法。
步骤 S302: 判断所述接入节点是否符合认证服务器设置的策略要求; 若 符合, 则执行步骤 S303; 若不符合, 则认证失败, 认证流程结束。
步骤 S303:该接入节点认证通过,进入下发 AC列表的流程(即步骤 S202 )。 优选地, 图 2所示实施例中的向 AP下发 AC列表, 具体为: 认证服务 器(AAA服务器和 /或 DHCP服务器等具备认证功能的服务器)和 /或 BNG 设备向认证通过的 AP下发 AC列表。 优选地,图 2所示实施例中的 AP的控制方法在向 AP下发 AC列表之前, 还包括:更新 AC列表。更新的方式可以是认证服务器(AAA服务器和 DHCP 服务器等服务器)和 /或 BNG设备周期性或在下发 AC列表之前实时获取其 下发列表中各 AC的负载,按照各 AC的负载将 AC列表中的 AC进行排列, 排列方式可以是将各 AC按照其的负载由轻到重依次排列; 当然, 更新的方 式还可以是认证服务器 ( AAA服务器和 DHCP服务器等服务器)和 /或 BNG 设备周期性或在下发 AC列表之前实时的获取其下发列表中各 AC的位置, 按照各 AC的位置信息将 AC列表中的 AC进行排列, 排列方式可以是将各 AC按照其距离 AP由近到远依次排列。
优选地, 图 2所示实施例中的 AP根据预设规则从接收到的 AC列表中 选择一个 AC, 并与该 AC进行通信的过程具体的可以是: AP按照所述 AC 列表中接入控制器的排序, 依次向各 AC发送接入请求, 选择一个接入成功 的 AC建立通信连接, 与所选择的 AC进行通信; 当然, 也可以是将所有可 以接入的 AC设备形成一个新的 AC列表,从这个新的 AC列表任选一个 AC 进行通信。 图 4为本发明一最佳实施例提供的 WLAN中的 AP的控制方法的示意图; 由图 4可知,本发明提供的 WLAN中的 AP的控制方法的一种最佳实施例包 括以下步骤: 步骤 S401 : AP发起认证请求。 具体的可以只 AP通过 BNG设备向认证服务器发送认证请求,也可以是
BNG设备代替 AP向认证服务器发送认证请求; 该认证请求中携带有发起认 证请求的 AP设备的认证信息。 步骤 S402: 认证服务器对 AP进行认证; 若认证通过, 向 BNG反馈验 证通过消息,则执行步骤 S403 ,否则,向 AP反馈认证失败消息,流程结束。 认证服务器根据接收到的认证请求中的认证信息进行认证, 认证流程如图 3 所示。
步骤 S403: 更新 AC列表; BNG设备获取最新的 AC列表。
BNG设备获取最新的 AC列表的过程可以是: 认证服务器将原始 AC列 表下发到 BNG设备之后, BNG设备根据周期性或实时获取认证服务器下发 的原始 AC列表中各 AC的负载(或位置 ), 按照各 AC的负载(或位置)将 AC列表中的 AC进行排列,排列方式可以是将各 AC按照其的负载由轻到重 (或各 AC按照其距离 AP由近到远)依次排列; 或者, BNG设备在网络管 理员通过命令行或 NMS在 BNG上配置默认的原始 AC列表, 并根据周期性 或实时获取认证服务器下发的原始 AC列表中各 AC的负载(或位置 ), 按照 各 AC的负载(或位置)将 AC列表中的 AC进行排列, 排列方式可以是将 各 AC按照其的负载由轻到重 (或各 AC按照其距离 AP由近到远)依次排 歹 |J ; 或者, 认证服务器根据周期性或实时获取认证服务器下发的原始 AC列 表中各 AC的负载(或位置 ), 按照各 AC的负载(或位置)将 AC列表中的 AC进行排列,排列方式可以是将各 AC按照其的负载由轻到重(或各 AC按 照其距离 AP由近到远 )依次排列, 形成并下发更新后的 AC列表到 BNG设 备。
步骤 S404: BNG设备下发最新的 AC列表到通过验证的 AP设备。
步骤 S405: AP设备从接收到的 AC列表选择一 AC ,与该 AC进行通信; 选择方式不再赘述。
为了详细诠释本发明的思想,现结合实际应用对本发明做进一步的说明, 可以预见的是, 下述的实施例仅是本发明的一些实际运用实例, 并不用于对 本发明进行限定。 由于 AP接入网络的方式是多种多样的, 如 AP可以通过 802. IX、 PPPoE、 DHCPv4/v6、 静态 IP、 VPDN等方式接入网络, 认证服务 器可以通过 Web认证, EAP认证, BNG代理 PPP和 DHCP用户发起 PAP或 CHAP认证等认证方式对 AP设备进行认证, 不可能进行穷举, 为便于理解 及实施本发明提供的 AP接入控制技术, 下面以几个具有代表性的接入方式 的运用实例并结合图 4对本发明进行诠释说明。
第一应用实例: AP通过 EAP方式接入网络。 AP设备通过 EAP-MD5 (也 可以是 EAP-TLS、 L-EAP、 EAP-SIM, EAP-TTLS、 P-EAP等 -EAP-方式)方 式发起认证, 在该实施例中, 本发明提供的 WLAN中的 AP的控制方法包括 以下步骤:
AP向 BNG发送认证开始消息 EAPoL-Start;
BNG收到认证开始消息之后, 向 AP反馈认证协议 ID请求消息 EAP Identity Request;
AP向 BNG发送回复认证协议 ID应答消息 EAP Identity Response;
BNG将接收到的 EAP Identity Response消息封装到认证接入请求消息 RADIUS Access Request中发送给服务器 (此时服务器为 AAA服务器); AAA服务器产生 Challenge信息, 通过 RADIUS接入挑战(RADIUS Access-Challenge ) 消息将 Challenge 发送给 BNG; BNG 从 RADIUS Access-Challenge 消息中提取出 Challenge , 并通过 EAP 请求/ MD5 挑战 ( EAP-Request/MD5-Challenge ) 消息发送给 AP;
AP收到 EAP-Request/MD5-Challenge消息后提取 Challenge, 将自身的 用户密码和 Challenge 信息进行 MD5 运算, 得到加密后的用户密码 (即 Challenged-Pass-word ), 然后将 Challenged-Pass-word携带在 EAP响应/ MD5 挑战( EAP-Response/MD5-Challenge )消息中发送给 BNG; BNG将 Challenge, Challenged-Pass-word及用户名通过 Radius消息一并发送到 AAA服务器; AAA 服务器接收到 Radius 消息后, 提取认证信息 (Challenge ,
Challenged-Pass-word及用户名)进行 MD5运算, 判断 AP是否合法; 如果 合法, 则向 BNG发送认证成功消息, 其中携带 AC列表; 否则, 向 BNG发 送认证失败消息;
BNG接收到认证成功消息后,向 AP发送 EAP认证成功消息;相应的, BNG接收到认证成功失败后, 向 AP发送 EAP认证失败消息, 流程结束;
BNG向 AP发送通告消息 EAPoL- Announcement, 携带 AC列表;
AP从接收到的 EAPoL-Announcement消息中提取 AC列表,从中选择一 台 AC设备, 实现 AC对 AP的管理;
AP通过 CAPWAP协议与 AC进行通信,并通过 DHCP或 PPP等方式从 BNG设备获取 IP地址以接入网络。 第二应用实例: AP通过 PPP方式接入网络, 在该实施例中, 本发明提 供的 WLAN中的 AP的控制方法包括以下步骤:
AP与 BNG间进行 PPPoE及 PPP-LCP协商, 确定 PPPoE Session ID和 用户认证方式; 具体的协商过程不再赘述; AP向 BNG发送认证请求, 携带 AP认证信息;
BNG将 AP发送认证信息通过 Radius认证请求消息发送给 AAA服务器;
AAA服务器接收到 Radius消息后, 提取认证信息并判断 AP是否合法, 如果合法, 则向 BNG发送认证成功消息,其中携带 AC列表; 否则, 向 BNG 发送认证失败消息;
BNG接收到认证成功消息后, 向 AP发送 EAP认证成功消息; 否则, BNG接收到认证成功失败后, 向 AP发送 EAP认证失败消息, 流程到此结 束;
AP收到认证成功消息后向 BNG发送 PPP IPCP阶段地址请求消息; BNG收到地址请求消息后 ,直接为 AP分配 IP地址或通过 DHCP Server 为 AP分配 IP地址, 将分配的 IP地址发送给用户, 同时携带 AC列表;
AP提取 AC列表,从中选择一台 AC设备通过 CAPWAP协议进行通信, 实现 AC对 AP的管理, 并利用获取的 IP地址接入网络。
第三应用实例: AP通过 DHCP (具体为 DHCPv4 )方式接入网络, 在该 实施例中, 本发明提供的 WLAN中的 AP的控制方法包括以下步骤:
网络管理员通过命令行或 NMS ( Network Management System网络管理 系统 )在 BNG上配置默认的 AC列表;
AP向 BNG发送 DHCP Discover消息; AP在 Discover消息中通过 Option 60或其它扩展选项携带标识信息, 在 Discover消息中通过 Option82或其它 扩展选项插入 AP地理位置信息;
BNG在收到 DHCP Discover消息后 , 提取认证信息 (如 AP的 MAC信 息、 AP的地理位置信息和 /或 AP标识信息 ),并通过 Radius消息发送给 AAA 服务器对 AP进行认证; AAA服务器接收到 Radius消息后,提取认证信息进行 AP认证,如果认 证通过, 则向 BNG发送认证成功消息, 向 BNG发送认证失败消息, 流程结 束;
BNG接收到认证成功消息后, 提取内部配置的 AC列表, 携带在 DHCP Offer消息中发送给 AP;
AP向 BNG发送 DHCP Request消息;
BNG向 AP发送 DHCP Ack消息;
AP从接收到的 DHCP Offer中提取 AC列表, 从中选择一台 AC设备通 过 CAPWAP协议进行通信, 实现 AC对 AP的管理。 可以预见的是, 在上述实施例中, BNG也可以在 DHCP Ack消息中携带
AC列表发送给 AP; 相应的, 当 AP通过 DHCPv6方式接入时, BNG也可以 在 Advertise消息或 Reply消息中通过 Option52携带 AC列表。 上述三个实施例中,并没有涉及认证服务器或 BNG设备更新 AC列表的 功能, 下面通过另外两个运用实例进行诠释说明, 可以预见的是, 该动态更 新功能是可以运用到上述所有实施例中的。
第四应用实例: AP通过 PPP+DHCPv6方式接入, 在该实施例中, 本发 明提供的 WLAN中的 AP的控制方法包括以下步骤: 各个 AC设备周期性的将各自管理的 AP数量发送给 BNG;
AP与 BNG间进行 PPPoE和 PPP LCP阶段协商,确定 PPPoE Session ID 和用户认证方式;
AP向 BNG发送认证请求, 携带 AP认证信息;
BNG将 AP发送认证信息通过 Radius认证请求消息发送给 AAA服务器; AAA服务器接收到 Radius消息后, 提取认证信息并判断 AP是否合法, 如果合法, 则向 BNG发送认证成功消息, 并携带 AC列表; 否则, 向 BNG 发送认证失败消息;
BNG收到认证成功消息, 提取其中的 AC列表并进行存储, 同时向 AP 发送 PPP认证成功消息;
AP和 BNG进行 PPP IPv6CP阶段消息交互获取 Interface-ID;
AP向 BNG发送 DHCPv6 Request消息申请 IPv6地址;
BNG根据 AAA服务器发送的 AC列表信息和各台 AC设备的负载情况 对列表中的 AC设顺序进行调整, 并发送 DHCPv6 Reply消息将 AP的 IPv6 地址发送给 AP, 并在该消息中通过 Option52携带调整后的 AC列表信息; AP提取 AC列表,从中选择一台 AC设备通过 CAPWAP协议进行通信, 并根据 IP地址接入网络。
可以预见的是, 在上述实施例中, BNG也可以在 PPP IPCP阶段的消息 中通过扩展字段携带 AC列表发送给 AP; 当 AP通过 PPP+ND方式接入时, BNG也可以在 icmpv6的 RA消息中携带扩展选项携带 AC列表信息发送给 AP, 或在 IPCP阶段的消息中通过扩展字段携带 AC列表发送给 AP。
第五应用实例: 当服务器类型为 DHCP服务器时, 本发明提供的 WLAN 中的 AP的控制方法包括以下步骤:
网络管理员通过命令或网络管理系统在 BNG上配置默认的 AC列表; 各个 AC设备定期将各自管理的 AP数量发送给 BNG;
AP与 BNG交互完成身份认证, 认证过程不再赘述;
BNG代替 AP向 DHCP Server发送地址请求;
DHCP Server向 BNG发送为 AP分配的 IP地址, 并携带 AC列表;
BNG收到 DHCP Server反馈的地址分配消息后, 提取 AC列表, 并根据 BNG上配置的默认 AC列表和 /或各个 AC设备的负载情况对列表中的 AC的 顺序进行调整, 并在向 AP发送携带 IP地址及调整后的 AC列表的 DHCPv6 Reply消息;
AP从 DHCPv6 Reply消息中提取 AC列表, 从选择一台 AC设备通过 CAPWAP协议进行通信, 并根据 IP地址接入网络。 以上仅是本发明的具体实施方式而已, 并非对本发明做任何形式上的限 变化或修饰, 均仍属于本发明技术方案的保护范围。
工业实用,!·生
上述方案至少具备以下优点:
1、仅在对 AP设备认证通过的情况下,才将 AC列表发送给该 AP设备, 解决了现有技术中向私设 AP设备下发 AC列表造成的信息泄露问题;
2、 仅在对 AP设备认证通过的情况下, 才给该 AP设备分配 IP, 解决了 现有技术中私设的 AP设备可以接入通信网络的问题;
3、 动态更新 AC列表, 解决了现有技术中存在的静态 AC地址列表不灵 活、 无法实现基于负载均衡的动态更新 AC列表的问题;
4、 由 BNG代替 AP向 DHCP Server发送地址请求, 解决了现有技术中 存在的由于 BNG进行统一管理所造成的 AP设备无法向服务器获取 IP地址 及 AC列表的问题。

Claims

权 利 要 求 书
1. 一种无线局域网中接入节点的控制方法, 包括:
对接入节点进行认证;
认证通过后, 向所述接入节点下发接入控制器列表;
所述接入节点根据预设规则从所述接入控制器列表中选择一接入控制器, 与所选择的接入控制器进行通信。
2. 如权利要求 1所述的无线局域网中接入节点的控制方法, 其中, 所 述对接入节点进行认证的过程为: 认证服务器对接入节点进行认证。
3. 如权利要求 2 所述的无线局域网中接入节点的控制方法, 其中, 所 述对接入节点进行认证的过程包括:
判断接入节点的接入地理位置信息、接入节点的账号密钥和 /或接入节点 的授权证书是否合法;
如合法, 则判断所述接入节点是否符合认证服务器设置的策略要求; 是, 则所述接入节点认证通过。
4. 如权利要求 1 所述的无线局域网中接入节点的控制方法, 其中, 在 认证通过后, 向所述接入节点下发接入控制器列表之前, 还包括: 更新接入 控制器列表。
5. 如权利要求 4 所述的无线局域网中接入节点的控制方法, 其中, 所 述更新接入控制器列表的过程为: 网络网关和 /或认证服务器根据原始接入控 制器列表及所述原始接入控制器列表中各接入控制器的当前负载, 更新所述 原始接入控制器列表, 生成向所述接入节点下发的接入控制器列表。
6. 如权利要求 1至 5任一项所述的无线局域网中接入节点的控制方法, 其中, 所述接入节点根据预设规则从所述接入控制器列表中选择一接入控制 器, 与所选择的接入控制器进行通信的过程为: 所述接入节点按照所述接入 控制器列表中接入控制器的排序, 依次向各接入控制器发送接入请求, 选择 一个接入成功的接入控制器进行通信。
7. 如权利要求 6 所述的无线局域网中接入节点的控制方法, 其中, 所 述与所选择的接入控制器进行通信的过程为: 所述接入节点通过无线接入点 控制及配置协议与所选择的接入控制器进行通信。
8. 一种通信系统, 包括至少一个接入节点、 至少一个接入控制器、 网 络网关及认证服务器 , 所述接入节点通过所述网络网关与所述接入控制器及 所述认证服务器连接; 其中,
所述认证服务器设置为: 对所述接入节点进行认证, 并在认证通过后, 向所述接入节点下发接入控制器列表;
所述接入节点设置为: 根据预设规则从所述接入控制器列表中选择一接 入控制器, 与所选择的接入控制器进行通信。
9. 如权利要求 8 所述的通信系统, 其中, 所述网络网关还设置为: 存 储所述接入控制器列表, 并在所述认证服务器对所述接入节点认证通过后, 将其存储的所述接入控制器列表下发到所述接入节点。
10. 如权利要求 9所述的通信系统, 其中, 所述网络网关和 /或所述认证 服务器还设置为: 更新所述接入控制器列表。
11. 如权利要求 8至 10任一项所述的通信系统, 其中, 所述认证服务 器为验证授权及记账服务器和 /或动态主机协议服务器。
PCT/CN2013/082385 2012-12-31 2013-08-27 一种无线局域网中接入节点的控制方法及通信系统 WO2014101449A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP13868706.6A EP2903385A4 (en) 2012-12-31 2013-08-27 METHOD FOR ACCESS POINT CONTROL IN A WIRELESS LOCAL NETWORK AND COMMUNICATION SYSTEM
US14/439,405 US9775032B2 (en) 2012-12-31 2013-08-27 Method for controlling access point in wireless local area network, and communication system

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201210592081.X 2012-12-31
CN201210592081.XA CN103916853A (zh) 2012-12-31 2012-12-31 一种无线局域网中接入节点的控制方法及通信系统

Publications (1)

Publication Number Publication Date
WO2014101449A1 true WO2014101449A1 (zh) 2014-07-03

Family

ID=51019849

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/082385 WO2014101449A1 (zh) 2012-12-31 2013-08-27 一种无线局域网中接入节点的控制方法及通信系统

Country Status (4)

Country Link
US (1) US9775032B2 (zh)
EP (1) EP2903385A4 (zh)
CN (1) CN103916853A (zh)
WO (1) WO2014101449A1 (zh)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9949305B2 (en) * 2009-10-02 2018-04-17 Blackberry Limited Methods and apparatus for peer-to-peer communications in a wireless local area network
CN104219094B (zh) * 2014-08-29 2018-10-26 新华三技术有限公司 一种ap分组配置的方法和设备
CN105991786A (zh) * 2015-02-15 2016-10-05 中国移动通信集团江苏有限公司 一种Wi-Fi接入配置方法、Wi-Fi终端及接入设备
CN105120462B (zh) * 2015-09-11 2018-10-02 中国联合网络通信集团有限公司 网络接入方法及装置
US9686279B2 (en) * 2015-09-30 2017-06-20 Konica Minolta Laboratory U.S.A., Inc. Method and system for providing GPS location embedded in an IPv6 address using neighbor discovery
EP3598693A1 (en) * 2017-04-17 2020-01-22 Huawei Technologies Co., Ltd. Method for accessing fixed network and access gateway network element
CN107547616A (zh) * 2017-05-27 2018-01-05 新华三技术有限公司 Ap负载均衡方法和装置
CN108449799A (zh) * 2018-03-06 2018-08-24 新华三技术有限公司 一种连接建立方法及装置
CN108769984A (zh) * 2018-06-22 2018-11-06 新华三技术有限公司 一种连接建立方法及装置
CN109495878B (zh) * 2018-12-24 2021-05-28 新华三技术有限公司 一种接入认证方法及装置
WO2022059813A1 (ko) * 2020-09-16 2022-03-24 엘지전자 주식회사 무선 통신 시스템에서 네트워크의 진위 여부를 판단하는 방법 및 이를 위한 장치

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101247295A (zh) * 2007-02-13 2008-08-20 华为技术有限公司 一种在无线局域网获得接入控制器信息的方法和装置
CN101252498A (zh) * 2008-04-03 2008-08-27 杭州华三通信技术有限公司 接入点、接入控制器及其通信方法
CN101815365A (zh) * 2010-04-02 2010-08-25 北京傲天动联技术有限公司 无线接入控制器发现、关联以及配置方法

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7450940B2 (en) * 2003-04-28 2008-11-11 Chantry Networks, Inc. Wireless network communication system and method
US8023478B2 (en) * 2006-03-06 2011-09-20 Cisco Technology, Inc. System and method for securing mesh access points in a wireless mesh network, including rapid roaming
US8000698B2 (en) * 2006-06-26 2011-08-16 Microsoft Corporation Detection and management of rogue wireless network connections
US8102814B2 (en) * 2006-11-14 2012-01-24 Cisco Technology, Inc. Access point profile for a mesh access point in a wireless mesh network
US8155007B2 (en) * 2007-01-25 2012-04-10 Cisco Technology, Inc. Path optimization for mesh access points in a wireless mesh network
CN101217440B (zh) * 2008-01-15 2011-03-30 杭州华三通信技术有限公司 无线局域网中ap接入ac的方法及接入设备
CN101771612B (zh) 2010-01-13 2012-07-04 华为技术有限公司 隧道建立方法、设备及网络系统
WO2012171222A1 (zh) 2011-06-17 2012-12-20 华为技术有限公司 地址处理方法及网关设备、ap

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101247295A (zh) * 2007-02-13 2008-08-20 华为技术有限公司 一种在无线局域网获得接入控制器信息的方法和装置
CN101252498A (zh) * 2008-04-03 2008-08-27 杭州华三通信技术有限公司 接入点、接入控制器及其通信方法
CN101815365A (zh) * 2010-04-02 2010-08-25 北京傲天动联技术有限公司 无线接入控制器发现、关联以及配置方法

Also Published As

Publication number Publication date
CN103916853A (zh) 2014-07-09
US20150304844A1 (en) 2015-10-22
EP2903385A4 (en) 2015-10-21
EP2903385A1 (en) 2015-08-05
US9775032B2 (en) 2017-09-26

Similar Documents

Publication Publication Date Title
WO2014101449A1 (zh) 一种无线局域网中接入节点的控制方法及通信系统
US7542572B2 (en) Method for securely and automatically configuring access points
CN101578828B (zh) 一种网络接入处理方法、装置和系统
US8509440B2 (en) PANA for roaming Wi-Fi access in fixed network architectures
CN103200172B (zh) 一种802.1x接入会话保活的方法及系统
US9749320B2 (en) Method and system for wireless local area network user to access fixed broadband network
KR101002799B1 (ko) 이동통신 네트워크 및 상기 이동통신 네트워크에서 이동 노드의 인증을 수행하는 방법 및 장치
CN101127600A (zh) 一种用户接入认证的方法
WO2013107136A1 (zh) 终端接入认证的方法及用户端设备
WO2006063511A1 (fr) Procede permettant de realiser une authentification synchrone parmi differents dispositifs de commande d'authentification
CN108738019B (zh) 融合网络中的用户认证方法及装置
US20140307651A1 (en) Internet Protocol Address Registration
EP2894904B1 (en) Wlan user fixed network access method and system
WO2014176964A1 (zh) 一种通信管理方法及通信系统
WO2012034413A1 (zh) 一种双栈用户管理方法及宽带接入服务器
WO2009082910A1 (fr) Procédé et dispositif de configuration de réseau pour un terminal d'utilisateur
WO2014067334A1 (zh) 数据报文的管理方法、装置及系统
CN102577299B (zh) 简化的接入网认证信息承载协议
JP4584776B2 (ja) ゲートウェイ装置およびプログラム
WO2013067911A1 (zh) 一种接入认证方法、系统及设备
CN102282800A (zh) 一种终端认证方法及装置
CN101997904A (zh) 一种会话区分方法和装置
WO2013034056A1 (zh) 一种位置信息处理方法和系统
TW201709694A (zh) 家庭基站及ip配置的方法
Huawei Technologies Co., Ltd. WAN Fundamentals

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13868706

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 14439405

Country of ref document: US

Ref document number: 2013868706

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE