WO2015085872A1 - Method and device for access of guests - Google Patents

Method and device for access of guests Download PDF

Info

Publication number
WO2015085872A1
WO2015085872A1 PCT/CN2014/092564 CN2014092564W WO2015085872A1 WO 2015085872 A1 WO2015085872 A1 WO 2015085872A1 CN 2014092564 W CN2014092564 W CN 2014092564W WO 2015085872 A1 WO2015085872 A1 WO 2015085872A1
Authority
WO
WIPO (PCT)
Prior art keywords
guest
terminal device
access
authentication
user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2014/092564
Other languages
French (fr)
Inventor
Lina Zhang
Zhijian Lu
Wenyu Xu
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hangzhou H3C Technologies Co Ltd
Original Assignee
Hangzhou H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou H3C Technologies Co Ltd filed Critical Hangzhou H3C Technologies Co Ltd
Publication of WO2015085872A1 publication Critical patent/WO2015085872A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication

Definitions

  • BYOD Bring Your Own Device
  • FIG. 1 is an example of a flowchart of guess access in a Bring Your Own Device (BYOD) management system
  • FIG. 2 is a schematic diagram illustrating a hardware structure of a device includes a guest access logic, according to an example of the present disclosure.
  • FIG. 3 is a schematic diagram illustrating function modules of guest access logic, according to an example of the present disclosure.
  • the present disclosure is described by referring mainly to an example thereof.
  • numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. It will be readily apparent however, that the present disclosure may be practiced without limitation to these specific details. In other instances, some methods and structures have not been described in detail so as not to unnecessarily obscure the present disclosure.
  • the terms “a” and “an” are intended to denote at least one of a particular element, the term “includes” means includes but not limited to, the term “including” means including but not limited to, and the term “based on” means based at least in part on.
  • Bring Your Own Device (BYOD) technology may allow employees to use any device anytime, anywhere, for accessing the intranet of the enterprise to obtain information or related materials.
  • BYOD Bring Your Own Device
  • the enterprise network may need to support more types of access way, such as cable, Wi-Fi, VPN, etc. , need to support more types of terminal devices, such as PC, smart terminal, iPad, etc. , and need to support more operating systems which are running on terminal devices, such as Mac OS, Android and so on.
  • the BYOD management system in processing with guest’s access authorities within the enterprise network, the BYOD management system first sets up a different access account for each guest.
  • the guest may access the intranet of the enterprise.
  • this implementation in the BYOD management system is very complicated. The greater the number of guests, the greater workload of the administrator for setting guests’a ccounts. Moreover, the implementation is not good at centralized management for the guests. In addition, faced with the growing number of terminal devices in market, the BYOD management system may also not be able to accurately identify all the terminal device access. Therefore, in practice, the enterprises still usually take a unified access strategy to achieve unified management of guest, but this will cause BYOD management system to be under a potential security risk.
  • the present disclosure provides a method for access of guests, which is used in a Bring Your Own Device (BYOD) management system. It may create a default account for all guests, further designate accessible area in the enterprise to the guests, and bind the default account to an access device which is pre-deployed in an accessible area. All certified guest may use the default account to access the intranet of the enterprise. This may enable access of guest in a relatively quick fashion and also helps to keep the enterprise internet secure when accessed by the guest.
  • BYOD Bring Your Own Device
  • FIG. 1 is an example of a flowchart of guest access in a Bring Your Own Device (BYOD) management system.
  • BYOD Bring Your Own Device
  • the BYOD management system may create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area.
  • the administrator may, according to the actual situation of the enterprise area, divide the enterprise area into a plurality of sub-areas, and designate at least one sub-area as an accessible area in the enterprise to the guests.
  • the enterprise hall, the conference room or the staff lounge area may be selected as accessible areas.
  • the administrator may manage and control guest’s access authorities for accesses coming from the accessible area.
  • the guest users may access an intranet of an enterprise for basic information or the relevant data that is made publically available by the enterprise. But the guest users may not access the server used for the enterprise internal operations, and may not obtain the non-public data or internal information of the enterprise.
  • the administrator may further, by the BYOD management system, create a default account for all guests, and bind the default account to an access device which is pre-deployed in the accessible area.
  • Pre-deployed means that the access device is already deployed in the accessible area, such as the enterprise hall, conference room or staff lounge etc.
  • the BYOD management system may automatically set up and centrally manage the user name and the password of the default account.
  • the guest may conveniently access the network without manually entering the user name and the password.
  • the network coverage in the accessible area may be wireless, wired or both wired and wireless.
  • the access device may be a wireless access point.
  • the access device When the coverage of the accessible area is wired, the access device may be a router or a switch. After binding the default account to the access device which is pre-deployed in the accessible area, the guest may use the default account to login to the parts of the enterprise intranet which are made available to guests in the accessible area.
  • the BYOD management system may receive an access request from the accessible area that is initialized by a guest, and determine whether a terminal device of the guest is bound with an existing user, and if it determines the terminal device of the guest is bound with an existing user, then the guest may access the enterprise intranet corresponding to the accessible area, otherwise, it performs an authentication of the guest.
  • the terminal device may automatically send an access request to the access device.
  • the access device may determine whether the terminal device of the guest is bound with an existing user, and if the terminal device of the guest is bound with an existing user, the terminal device may be assigned an appropriate access control authorities based on information of the terminal device. Then, the terminal device may directly access the enterprise intranet. If the terminal device of the guest is not bound with an existing user, the access device may report the authentication request to the BYOD management system. After receiving the authentication request, the BYOD management system may perform a certification of the terminal device of the guest.
  • the BYOD management system may use the most common MAC address authentication, wherein the MAC address authentication process may also need to detect the terminal device’s MAC address is legitimate, such as whether there is a separator, capitalization, etc. If the guest’s MAC address is not valid, the authentication may fail and the guest may be rejected to access network.
  • the guest authentication method is not limited to the MAC address authentication. The security requirements of different enterprises are different, so the guest authentication methods may also have many other implementations.
  • the digital signature, the digital certificate authentication or encryption hardware of the terminal devices may be used for the guest authentication methods.
  • the SIM card of a mobile terminal may even be used for the guest authentication.
  • the guest may be marked as the default account after the guest passing the authentication, which allows the guest to use the default account for accessing network of the accessible area.
  • the BYOD management system may mark the guest as the default account.
  • the default account has already been bound with the access device in the accessible area.
  • the BYOD management system may send the MAC address of the terminal device to the access device in the accessible area.
  • the access device may add the MAC address into an access white list stored locally in the access device.
  • the certified guest may use the default account for rapidly accessing the intranet of the enterprise.
  • the guest may be asked to visit a registration web page of the enterprise to finish registration after the guest passing the authentication.
  • the registration web page may include three user options: a pre-registration option, a new registration options and a bind existing user option.
  • the guest may obtain the basic access permissions.
  • the registration information of the guest and the information of the terminal device may be deleted.
  • the guest may need to re-register.
  • the guest may be forced off line. After the guest is off line, the registration information of the guest and the information of the terminal device may be kept.
  • the BYOD management system may select, according to the terminal information of the guest, the appropriate access control policy for the guest.
  • the terminal device of the guest may bind with the existing user, and the guest may be forced off line.
  • the terminal device of the guest may obtain the appropriate access permissions of the existing user.
  • FIG. 2 is a schematic diagram illustrating a hardware structure of a device includes guest access logic, according to an example of the present disclosure.
  • the device 2 includes a processor 21, a storage 22, an interface 23, and an internal bus 24.
  • FIG. 3 is a schematic diagram illustrating function modules of guest access logic, according to an example of the present disclosure.
  • the guest access logic 20 includes a creating unit 201, an authentication unit 202, an access unit 203, and a registration unit 204.
  • the creating unit 201 may create a default account for all guests, and the default account may be bound to an access device which is pre-deployed in an accessible area.
  • the authentication unit 202 may receive an access request from the accessible area, and determine whether a terminal device of the guest binds with an existed user, and if the terminal device of the guest does not bind with an existed user, then perform an authentication of the guest.
  • the access unit 203 may mark the guest as a default user after the authentication of the guest is passing, and allow the guest to use the default account for accessing network of the accessible area.
  • the authentication of the guest by the guest access logic 20 of the BYOD management system may use the most common MAC address authentication.
  • the guest access logic 20 may also need to detect whether the terminal device’s MAC address is legitimate.
  • the guest access logic 20 may further includes a registration unit 204.
  • the registration unit 204 may visit a registration web page of the enterprise for the guest and may finish the registration of the guest, wherein the registration web page may include three user options: a pre-registration option, a new registration options and a bind existing user option.
  • the device 2 executes the guest access logic 20.
  • the guest access logic 20 may be understood as a computer program stored in the storage 22. As shown in FIG. 2, the storage 22 and the interface 23 are accessible by the processor 21 through the internal bus 24.
  • the storage 22 stores the guest access logic 20 of machine readable instructions executable by the processor 21.
  • the storage 22 in which the machine readable instructions are stored may be a volatile or non-volatile memory or storage media including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, DRAM and flash memory devices; magnetic disks, e.g. , internal hard disks or removable disks; magneto optical disks; and CD ROM and DVD-ROM disks.
  • the processor 21 of the device 2 reads the instructions of the corresponding modules of the guest access logic 20 stored in the storage 22 and executes the instructions.
  • the processor 21 may, according to the guest access logic 20, create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area.
  • the processor 21 may receive an access request from the accessible area that is initialized by a guest, and determine whether a terminal device of the guest is bound with an existing user, and if the terminal device of the guest does is not bound with an existing user, then perform an authentication of the guest.
  • the processor 21 may mark the guest as a default user after the authentication of the guest is passed, and allow the guest to use the default account for accessing network of the accessible area.
  • the processor 21 may perform a MAC address authentication of the terminal device of the guest corresponding to the authentication of the guest.
  • the processor 21 may, according to the instructions of the corresponding modules of the the guest access logic 20, detect whether the terminal device of the guest has a legitimate MAC address.
  • the processor 21 may read the instructions of the corresponding modules of the guest access logic 20 stored in the storage 22 to direct the guest to a registration web page of an enterprise and finish a registration of the guest.
  • processors may be implemented by hardware (including hardware logic circuitry) , software or firmware or a combination thereof.
  • the term ‘processor’ is to be interpreted broadly to include a processing unit, ASIC, logic unit, or programmable gate array etc.
  • the processes, methods and functional units may all be performed by the one or more processors; reference in this disclosure or the claims to a ‘processor’s hould thus be interpreted to mean ‘one or more processors’ .
  • the processes, methods and functional units described in this disclosure may be implemented in the form of a computer software product.
  • the computer software product is stored in a storage medium and comprises a plurality of instructions for making a processor to implement the methods recited in the examples of the present disclosure.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • Power Engineering (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Small-Scale Networks (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

A guest access method used in Bring Your Own Device (BYOD) management system is disclosed. First, it creates a default account for all guests, and binds the default account to an access device which is pre-deployed in an accessible area. Next, it receives an access request from the accessible area that is initialized by a guest, and determines whether a terminal device of the guest binds with an existed user, and if the terminal device of the guest does not bind with an existed user, then performs an authentication of the guest. Finally, it marks the guest as a default user after the authentication of the guest is passing, and allows the guest to use the default account for accessing network of the accessible area.

Description

GUEST ACCESS Background
With the development of network technology, more and more people use Bring Your Own Device (BYOD) to access an intranet of an enterprise for searching information of the enterprise or obtaining relevant information. In the intranet of the enterprise, there may be some temporary users who are not employees of the enterprise (hereinafter referred to as “guest” ) . How to ensure that internal company information or data will not be accessed by the guest is an important issue.
Brief Description of Drawings
Features of the present disclosure are illustrated by way of example and not limited in the following figure (s) , in which like numerals indicate like elements, in which:
FIG. 1 is an example of a flowchart of guess access in a Bring Your Own Device (BYOD) management system;
FIG. 2 is a schematic diagram illustrating a hardware structure of a device includes a guest access logic, according to an example of the present disclosure; and
FIG. 3 is a schematic diagram illustrating function modules of guest access logic, according to an example of the present disclosure.
Detailed Description
For simplicity and illustrative purposes, the present disclosure is described by referring mainly to an example thereof. In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. It will be readily apparent however, that the present disclosure may be practiced without limitation to these specific details. In other instances, some methods and structures have not been described in detail so as not to unnecessarily obscure the present disclosure. As used herein, the terms “a” and “an” are intended to denote at least one of a particular element, the term “includes” means includes but not limited to, the term “including” means including but not limited to, and the term “based on” means based at least in part on.
Bring Your Own Device (BYOD) technology may allow employees to use any device anytime, anywhere, for accessing the intranet of the enterprise to obtain information or related materials. However, due to the diversity of the terminal devices used by employees and the differences of the access method, it may bring more challenges in security and management of the enterprise network. For example, in the BYOD scenarios, the enterprise network may need to support more types of access way, such as cable, Wi-Fi, VPN, etc. , need to support more types of terminal devices, such as PC, smart terminal, iPad, etc. , and need to support more operating systems which are running on terminal devices, such as Mac OS, Android and so on. In an example, in processing with guest’s access authorities within the enterprise network, the BYOD management system first sets up a different access account for each guest. After manually entering the account number and password and validating through, then the guest may access  the intranet of the enterprise. However, this implementation in the BYOD management system is very complicated. The greater the number of guests, the greater workload of the administrator for setting guests’a ccounts. Moreover, the implementation is not good at centralized management for the guests. In addition, faced with the growing number of terminal devices in market, the BYOD management system may also not be able to accurately identify all the terminal device access. Therefore, in practice, the enterprises still usually take a unified access strategy to achieve unified management of guest, but this will cause BYOD management system to be under a potential security risk.
The present disclosure provides a method for access of guests, which is used in a Bring Your Own Device (BYOD) management system. It may create a default account for all guests, further designate accessible area in the enterprise to the guests, and bind the default account to an access device which is pre-deployed in an accessible area. All certified guest may use the default account to access the intranet of the enterprise. This may enable access of guest in a relatively quick fashion and also helps to keep the enterprise internet secure when accessed by the guest.
FIG. 1 is an example of a flowchart of guest access in a Bring Your Own Device (BYOD) management system. As shown in FIG. 1, at block S101, the BYOD management system may create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area.
Before block S101, the administrator may, according to the actual situation of the enterprise area, divide the enterprise area into a plurality of  sub-areas, and designate at least one sub-area as an accessible area in the enterprise to the guests. For example, the enterprise hall, the conference room or the staff lounge area may be selected as accessible areas. The administrator may manage and control guest’s access authorities for accesses coming from the accessible area. For example, when in the accessible area, the guest users may access an intranet of an enterprise for basic information or the relevant data that is made publically available by the enterprise. But the guest users may not access the server used for the enterprise internal operations, and may not obtain the non-public data or internal information of the enterprise.
After designating an accessible area for guests, the administrator may further, by the BYOD management system, create a default account for all guests, and bind the default account to an access device which is pre-deployed in the accessible area. Pre-deployed means that the access device is already deployed in the accessible area, such as the enterprise hall, conference room or staff lounge etc. The BYOD management system may automatically set up and centrally manage the user name and the password of the default account. Thus, the guest may conveniently access the network without manually entering the user name and the password. In addition, according to the actual situation, the network coverage in the accessible area may be wireless, wired or both wired and wireless. When the coverage of the accessible area is wireless, the access device may be a wireless access point. When the coverage of the accessible area is wired, the access device may be a router or a switch. After binding the default account to the access device which is pre-deployed in the accessible area, the guest may use the default account to login to the parts of the enterprise intranet which are made available to guests in the accessible area.
At block S102, the BYOD management system may receive an access request from the accessible area that is initialized by a guest, and determine whether a terminal device of the guest is bound with an existing user, and if it determines the terminal device of the guest is bound with an existing user, then the guest may access the enterprise intranet corresponding to the accessible area, otherwise, it performs an authentication of the guest.
When the terminal device of the guest try to access the enterprise intranet of the accessible area, the terminal device may automatically send an access request to the access device. After receiving the access request, the access device may determine whether the terminal device of the guest is bound with an existing user, and if the terminal device of the guest is bound with an existing user, the terminal device may be assigned an appropriate access control authorities based on information of the terminal device. Then, the terminal device may directly access the enterprise intranet. If the terminal device of the guest is not bound with an existing user, the access device may report the authentication request to the BYOD management system. After receiving the authentication request, the BYOD management system may perform a certification of the terminal device of the guest.
Further, in an example, for the certification of the terminal device, the BYOD management system may use the most common MAC address authentication, wherein the MAC address authentication process may also need to detect the terminal device’s MAC address is legitimate, such as whether there is a separator, capitalization, etc. If the guest’s MAC address is not valid, the authentication may fail and the guest may be rejected to access network. Obviously, the guest authentication method is not limited to the MAC address  authentication. The security requirements of different enterprises are different, so the guest authentication methods may also have many other implementations. For example, the digital signature, the digital certificate authentication or encryption hardware of the terminal devices may be used for the guest authentication methods. The SIM card of a mobile terminal may even be used for the guest authentication.
At block S103, the guest may be marked as the default account after the guest passing the authentication, which allows the guest to use the default account for accessing network of the accessible area.
In an example, after the guest passing the authentication, the BYOD management system may mark the guest as the default account. The default account has already been bound with the access device in the accessible area. The BYOD management system may send the MAC address of the terminal device to the access device in the accessible area. After receiving the MAC address of the terminal device, the access device may add the MAC address into an access white list stored locally in the access device. Thus, the certified guest may use the default account for rapidly accessing the intranet of the enterprise.
In another example, when the access control authorities of the guest is to be further divided by the BYOD management system, or the terminal device is to be registered to be a formal user in the BYOD management system, the guest may be asked to visit a registration web page of the enterprise to finish registration after the guest passing the authentication. The registration web page may include three user options: a pre-registration option, a new registration options and a bind existing user option.
After a successful registration in which the guest selects the pre-registration option, the guest may obtain the basic access permissions. When the guest is offline, the registration information of the guest and the information of the terminal device may be deleted. Thus, when the guest comes back on line, the guest may need to re-register.
After a successful registration in which the guest selects the new registration option, the guest may be forced off line. After the guest is off line, the registration information of the guest and the information of the terminal device may be kept. When the guest uses the registered account to re-login, the BYOD management system may select, according to the terminal information of the guest, the appropriate access control policy for the guest.
When the guest selects the bind existing user option, the terminal device of the guest may bind with the existing user, and the guest may be forced off line. When the guest uses the account of the existed user to re-login, the terminal device of the guest may obtain the appropriate access permissions of the existing user.
Corresponding to the aforementioned method, the present disclosure also provides a guest access logic 20 according to the BYOD management system. FIG. 2 is a schematic diagram illustrating a hardware structure of a device includes guest access logic, according to an example of the present disclosure. As shown in FIG. 2, the device 2 includes a processor 21, a storage 22, an interface 23, and an internal bus 24. FIG. 3 is a schematic diagram illustrating function modules of guest access logic, according to an example of the present disclosure. As shown in FIG. 3, the guest access logic 20 includes a creating  unit 201, an authentication unit 202, an access unit 203, and a registration unit 204.
The creating unit 201 may create a default account for all guests, and the default account may be bound to an access device which is pre-deployed in an accessible area.
The authentication unit 202 may receive an access request from the accessible area, and determine whether a terminal device of the guest binds with an existed user, and if the terminal device of the guest does not bind with an existed user, then perform an authentication of the guest.
The access unit 203 may mark the guest as a default user after the authentication of the guest is passing, and allow the guest to use the default account for accessing network of the accessible area.
In an example, the authentication of the guest by the guest access logic 20 of the BYOD management system may use the most common MAC address authentication.
During performing the MAC address authentication, the guest access logic 20 may also need to detect whether the terminal device’s MAC address is legitimate.
In another example, when access control authorities of the guest need to be further divided by the guest access logic 20 of the BYOD management system or the terminal device needs to be registered to be a formal user in the BYOD  management system, the guest access logic 20 may further includes a registration unit 204.
The registration unit 204 may visit a registration web page of the enterprise for the guest and may finish the registration of the guest, wherein the registration web page may include three user options: a pre-registration option, a new registration options and a bind existing user option.
Implementation in software in combination with hardware as an example is discussed below. In the example, the device 2 executes the guest access logic 20. The guest access logic 20 may be understood as a computer program stored in the storage 22. As shown in FIG. 2, the storage 22 and the interface 23 are accessible by the processor 21 through the internal bus 24. The storage 22 stores the guest access logic 20 of machine readable instructions executable by the processor 21. The storage 22 in which the machine readable instructions are stored may be a volatile or non-volatile memory or storage media including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, DRAM and flash memory devices; magnetic disks, e.g. , internal hard disks or removable disks; magneto optical disks; and CD ROM and DVD-ROM disks. The processor 21 of the device 2 reads the instructions of the corresponding modules of the guest access logic 20 stored in the storage 22 and executes the instructions.
The processor 21 may, according to the guest access logic 20, create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area.
The processor 21 may receive an access request from the accessible area that is initialized by a guest, and determine whether a terminal device of the guest is bound with an existing user, and if the terminal device of the guest does is not bound with an existing user, then perform an authentication of the guest.
The processor 21 may mark the guest as a default user after the authentication of the guest is passed, and allow the guest to use the default account for accessing network of the accessible area.
The processor 21 may perform a MAC address authentication of the terminal device of the guest corresponding to the authentication of the guest.
When performing the MAC address authentication, the processor 21 may, according to the instructions of the corresponding modules of the the guest access logic 20, detect whether the terminal device of the guest has a legitimate MAC address.
Further, the processor 21 may read the instructions of the corresponding modules of the guest access logic 20 stored in the storage 22 to direct the guest to a registration web page of an enterprise and finish a registration of the guest.
The above are only preferred examples of the present disclosure is not intended to limit the disclosure within the spirit and principles of the present disclosure , any changes made , equivalent replacement , or improvement in the protection of the present disclosure should contain within the range.
The methods, processes and units described herein may be implemented by hardware (including hardware logic circuitry) , software or firmware or a  combination thereof. The term ‘processor’ is to be interpreted broadly to include a processing unit, ASIC, logic unit, or programmable gate array etc. The processes, methods and functional units may all be performed by the one or more processors; reference in this disclosure or the claims to a ‘processor’s hould thus be interpreted to mean ‘one or more processors’ .
Further, the processes, methods and functional units described in this disclosure may be implemented in the form of a computer software product. The computer software product is stored in a storage medium and comprises a plurality of instructions for making a processor to implement the methods recited in the examples of the present disclosure.
The figures are only illustrations of an example, wherein the units or procedure shown in the figures are not necessarily essential for implementing the present disclosure. The units in the examples described can be combined into one module or further divided into a plurality of sub-units.
Although the flowcharts described show a specific order of execution, the order of execution may differ from that which is depicted. For example, the order of execution of two or more blocks may be changed relative to the order shown. Also, two or more blocks shown in succession may be executed concurrently or with partial concurrence. All such variations are within the scope of the present disclosure.
Throughout the present disclosure, the word "comprise" , or variations such as "comprises" or "comprising" , will be understood to imply the inclusion of a stated element, integer or step, or group of elements, integers or steps, but not  the exclusion of any other element, integer or step, or group of elements, integers or steps.

Claims (8)

  1. A method for access of guests, which is used in a Bring Your Own Device (BYOD) management system, the method comprises:
    creating a default account for all guests, and binding the default account to an access device which is pre-deployed in an accessible area; and
    receiving an access request from the accessible area that is initialized by a guest;
    determining whether a terminal device of the guest is bound with an existing user, and if the terminal device of the guest is not bound with an existing user, then perform an authentication of the guest; and
    marking the guest as a default user after the authentication of the guest is passed, and allowing the guest to use the default account for accessing network of the accessible area.
  2. The method according to claim 1, wherein the authentication of the guest performed by the BYOD management system is to perform a MAC address authentication of the terminal device of the guest.
  3. The method as claimed in claim 2, further comprising detecting whether the terminal device of the guest has a legitimate MAC address.
  4. The method of claim 1, wherein, when access control permissions of the guest are to be further divided by the BYOD management system or the terminal device is to be registered to be a formal user in the BYOD management system, the method further comprises:
    providing a registration web page of an enterprise and finishing a registration of the guest, wherein the registration web page includes three user options: a pre-registration option, a new registration options and a bind existing user option.
  5. A non-transitory computer readable storage medium on which is stored machine readable instructions that when executed by a processor cause the processor to:
    create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area;
    receive an access request from the accessible area that is initialized by a guest;
    determine whether a terminal device of the guest is bound with an existing user, and if the terminal device of the guest is not bound with an existing user, then perform an authentication of the guest; and
    mark the guest as a default user after the authentication of the guest is passed, and allow the guest to use the default account for accessing network of the accessible area.
  6. The non-transitory computer readable storage medium according to claim 5, wherein the machine readable instructions are further to cause the processor to:
    perform an authentication of the guest by performing a MAC address authentication of the terminal device of the guest.
  7. The non-transitory computer readable storage medium according to claim 6, wherein the machine readable instructions are further to cause the processor to:
    detect whether the terminal device of the guest has a legitimate MAC address.
  8. The non-transitory computer readable storage medium according to claim 5, wherein the machine readable instructions are further to cause the  processor to:
    direct a guest user to a registration web page of an enterprise to register the guest;
    wherein the registration web page includes three user options: a pre-registration option, a new registration option and a bind existing user option.
PCT/CN2014/092564 2013-12-11 2014-11-28 Method and device for access of guests Ceased WO2015085872A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310677018.0A CN104717062B (en) 2013-12-11 2013-12-11 The method and device that a kind of visitor based on BYOD management systems quickly accesses
CN201310677018.0 2013-12-11

Publications (1)

Publication Number Publication Date
WO2015085872A1 true WO2015085872A1 (en) 2015-06-18

Family

ID=53370609

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/092564 Ceased WO2015085872A1 (en) 2013-12-11 2014-11-28 Method and device for access of guests

Country Status (2)

Country Link
CN (1) CN104717062B (en)
WO (1) WO2015085872A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115601866A (en) * 2022-09-19 2023-01-13 一站发展(北京)云计算科技有限公司(Cn) Traffic management method, device, equipment and readable storage medium

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106375262B (en) * 2015-07-21 2020-03-13 株式会社理光 Access control method and device
CN107612888B (en) * 2017-08-23 2020-09-04 北京小米移动软件有限公司 Enterprise user space creation method and device

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101582769A (en) * 2009-07-03 2009-11-18 杭州华三通信技术有限公司 Authority setting method of user access network and equipment
US8392712B1 (en) * 2012-04-04 2013-03-05 Aruba Networks, Inc. System and method for provisioning a unique device credential
CN103079201A (en) * 2011-10-26 2013-05-01 中兴通讯股份有限公司 Fast authentication method, access controller (AC) and system for wireless local area network

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CA2557143C (en) * 2004-02-27 2014-10-14 Sesame Networks Inc. Trust inheritance in network authentication
CN102143165B (en) * 2011-01-24 2014-07-09 华为技术有限公司 Method, network switch and network system for authenticating terminals
CN102378175A (en) * 2011-10-08 2012-03-14 华为终端有限公司 Wireless local area network (WLAN) authentication method and mobile terminal
CN102594846B (en) * 2012-04-05 2015-10-07 北京网御星云信息技术有限公司 A kind of shared access management algorithm based on IP header and system
CN103414709A (en) * 2013-08-02 2013-11-27 杭州华三通信技术有限公司 User identity binding and user identity binding assisting method and device

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101582769A (en) * 2009-07-03 2009-11-18 杭州华三通信技术有限公司 Authority setting method of user access network and equipment
CN103079201A (en) * 2011-10-26 2013-05-01 中兴通讯股份有限公司 Fast authentication method, access controller (AC) and system for wireless local area network
US8392712B1 (en) * 2012-04-04 2013-03-05 Aruba Networks, Inc. System and method for provisioning a unique device credential

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115601866A (en) * 2022-09-19 2023-01-13 一站发展(北京)云计算科技有限公司(Cn) Traffic management method, device, equipment and readable storage medium

Also Published As

Publication number Publication date
CN104717062B (en) 2018-03-16
CN104717062A (en) 2015-06-17

Similar Documents

Publication Publication Date Title
JP6259032B2 (en) Managing wireless network login password sharing
US10321316B1 (en) Wireless multi-factor authentication with captive portals
CN104540186B (en) Method, device and system for wireless network access
US20190384917A1 (en) Method and apparatus for secure device boot
US9843930B2 (en) Trusted execution environment initialization method and mobile terminal
US9565194B2 (en) Utilizing a social graph for network access and admission control
CN101668293A (en) Control method and system of network access authority in WLAN
US20170347388A1 (en) Transparently Connecting Mobile Devices to Multiple Wireless Local Area Networks
US11575567B2 (en) Wireless communication equipment and method for configuring mesh network thereof
US9832203B2 (en) Application permission management device and method therefor
US20200195656A1 (en) Anchoring Client Devices for Network Service Access Control
JP2011523250A5 (en)
WO2016155220A1 (en) Single sign-on method, system and terminal
US20170078100A1 (en) Providing device, terminal device, providing method, non-transitory computer readable storage medium, and authentication processing system
US9251331B2 (en) Simplified user registration
US20210195391A1 (en) Different profiles for selecting different network interfaces for communications of an electronic device
CN109067715B (en) Verification method and device
US10848958B2 (en) Profile prioritization in a roaming consortium environment
CN104717062B (en) The method and device that a kind of visitor based on BYOD management systems quickly accesses
WO2016061980A1 (en) Wlan sharing method and system, and wlan sharing registration server
US10939298B2 (en) Application access based on network
WO2016112591A1 (en) Hotspot access method and device, terminal and computer storage medium
CN104539446A (en) Shared WLAN management achieving method and system and WLAN shared registering server
CN105592453A (en) Method and system for realizing WLAN sharing and WLAN sharing register server
US20140344562A1 (en) Method and device for preventing access to administrative privilege

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14870469

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14870469

Country of ref document: EP

Kind code of ref document: A1