WO2015085872A1 - Method and device for access of guests - Google Patents
Method and device for access of guests Download PDFInfo
- Publication number
- WO2015085872A1 WO2015085872A1 PCT/CN2014/092564 CN2014092564W WO2015085872A1 WO 2015085872 A1 WO2015085872 A1 WO 2015085872A1 CN 2014092564 W CN2014092564 W CN 2014092564W WO 2015085872 A1 WO2015085872 A1 WO 2015085872A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- guest
- terminal device
- access
- authentication
- user
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0876—Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
Definitions
- BYOD Bring Your Own Device
- FIG. 1 is an example of a flowchart of guess access in a Bring Your Own Device (BYOD) management system
- FIG. 2 is a schematic diagram illustrating a hardware structure of a device includes a guest access logic, according to an example of the present disclosure.
- FIG. 3 is a schematic diagram illustrating function modules of guest access logic, according to an example of the present disclosure.
- the present disclosure is described by referring mainly to an example thereof.
- numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. It will be readily apparent however, that the present disclosure may be practiced without limitation to these specific details. In other instances, some methods and structures have not been described in detail so as not to unnecessarily obscure the present disclosure.
- the terms “a” and “an” are intended to denote at least one of a particular element, the term “includes” means includes but not limited to, the term “including” means including but not limited to, and the term “based on” means based at least in part on.
- Bring Your Own Device (BYOD) technology may allow employees to use any device anytime, anywhere, for accessing the intranet of the enterprise to obtain information or related materials.
- BYOD Bring Your Own Device
- the enterprise network may need to support more types of access way, such as cable, Wi-Fi, VPN, etc. , need to support more types of terminal devices, such as PC, smart terminal, iPad, etc. , and need to support more operating systems which are running on terminal devices, such as Mac OS, Android and so on.
- the BYOD management system in processing with guest’s access authorities within the enterprise network, the BYOD management system first sets up a different access account for each guest.
- the guest may access the intranet of the enterprise.
- this implementation in the BYOD management system is very complicated. The greater the number of guests, the greater workload of the administrator for setting guests’a ccounts. Moreover, the implementation is not good at centralized management for the guests. In addition, faced with the growing number of terminal devices in market, the BYOD management system may also not be able to accurately identify all the terminal device access. Therefore, in practice, the enterprises still usually take a unified access strategy to achieve unified management of guest, but this will cause BYOD management system to be under a potential security risk.
- the present disclosure provides a method for access of guests, which is used in a Bring Your Own Device (BYOD) management system. It may create a default account for all guests, further designate accessible area in the enterprise to the guests, and bind the default account to an access device which is pre-deployed in an accessible area. All certified guest may use the default account to access the intranet of the enterprise. This may enable access of guest in a relatively quick fashion and also helps to keep the enterprise internet secure when accessed by the guest.
- BYOD Bring Your Own Device
- FIG. 1 is an example of a flowchart of guest access in a Bring Your Own Device (BYOD) management system.
- BYOD Bring Your Own Device
- the BYOD management system may create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area.
- the administrator may, according to the actual situation of the enterprise area, divide the enterprise area into a plurality of sub-areas, and designate at least one sub-area as an accessible area in the enterprise to the guests.
- the enterprise hall, the conference room or the staff lounge area may be selected as accessible areas.
- the administrator may manage and control guest’s access authorities for accesses coming from the accessible area.
- the guest users may access an intranet of an enterprise for basic information or the relevant data that is made publically available by the enterprise. But the guest users may not access the server used for the enterprise internal operations, and may not obtain the non-public data or internal information of the enterprise.
- the administrator may further, by the BYOD management system, create a default account for all guests, and bind the default account to an access device which is pre-deployed in the accessible area.
- Pre-deployed means that the access device is already deployed in the accessible area, such as the enterprise hall, conference room or staff lounge etc.
- the BYOD management system may automatically set up and centrally manage the user name and the password of the default account.
- the guest may conveniently access the network without manually entering the user name and the password.
- the network coverage in the accessible area may be wireless, wired or both wired and wireless.
- the access device may be a wireless access point.
- the access device When the coverage of the accessible area is wired, the access device may be a router or a switch. After binding the default account to the access device which is pre-deployed in the accessible area, the guest may use the default account to login to the parts of the enterprise intranet which are made available to guests in the accessible area.
- the BYOD management system may receive an access request from the accessible area that is initialized by a guest, and determine whether a terminal device of the guest is bound with an existing user, and if it determines the terminal device of the guest is bound with an existing user, then the guest may access the enterprise intranet corresponding to the accessible area, otherwise, it performs an authentication of the guest.
- the terminal device may automatically send an access request to the access device.
- the access device may determine whether the terminal device of the guest is bound with an existing user, and if the terminal device of the guest is bound with an existing user, the terminal device may be assigned an appropriate access control authorities based on information of the terminal device. Then, the terminal device may directly access the enterprise intranet. If the terminal device of the guest is not bound with an existing user, the access device may report the authentication request to the BYOD management system. After receiving the authentication request, the BYOD management system may perform a certification of the terminal device of the guest.
- the BYOD management system may use the most common MAC address authentication, wherein the MAC address authentication process may also need to detect the terminal device’s MAC address is legitimate, such as whether there is a separator, capitalization, etc. If the guest’s MAC address is not valid, the authentication may fail and the guest may be rejected to access network.
- the guest authentication method is not limited to the MAC address authentication. The security requirements of different enterprises are different, so the guest authentication methods may also have many other implementations.
- the digital signature, the digital certificate authentication or encryption hardware of the terminal devices may be used for the guest authentication methods.
- the SIM card of a mobile terminal may even be used for the guest authentication.
- the guest may be marked as the default account after the guest passing the authentication, which allows the guest to use the default account for accessing network of the accessible area.
- the BYOD management system may mark the guest as the default account.
- the default account has already been bound with the access device in the accessible area.
- the BYOD management system may send the MAC address of the terminal device to the access device in the accessible area.
- the access device may add the MAC address into an access white list stored locally in the access device.
- the certified guest may use the default account for rapidly accessing the intranet of the enterprise.
- the guest may be asked to visit a registration web page of the enterprise to finish registration after the guest passing the authentication.
- the registration web page may include three user options: a pre-registration option, a new registration options and a bind existing user option.
- the guest may obtain the basic access permissions.
- the registration information of the guest and the information of the terminal device may be deleted.
- the guest may need to re-register.
- the guest may be forced off line. After the guest is off line, the registration information of the guest and the information of the terminal device may be kept.
- the BYOD management system may select, according to the terminal information of the guest, the appropriate access control policy for the guest.
- the terminal device of the guest may bind with the existing user, and the guest may be forced off line.
- the terminal device of the guest may obtain the appropriate access permissions of the existing user.
- FIG. 2 is a schematic diagram illustrating a hardware structure of a device includes guest access logic, according to an example of the present disclosure.
- the device 2 includes a processor 21, a storage 22, an interface 23, and an internal bus 24.
- FIG. 3 is a schematic diagram illustrating function modules of guest access logic, according to an example of the present disclosure.
- the guest access logic 20 includes a creating unit 201, an authentication unit 202, an access unit 203, and a registration unit 204.
- the creating unit 201 may create a default account for all guests, and the default account may be bound to an access device which is pre-deployed in an accessible area.
- the authentication unit 202 may receive an access request from the accessible area, and determine whether a terminal device of the guest binds with an existed user, and if the terminal device of the guest does not bind with an existed user, then perform an authentication of the guest.
- the access unit 203 may mark the guest as a default user after the authentication of the guest is passing, and allow the guest to use the default account for accessing network of the accessible area.
- the authentication of the guest by the guest access logic 20 of the BYOD management system may use the most common MAC address authentication.
- the guest access logic 20 may also need to detect whether the terminal device’s MAC address is legitimate.
- the guest access logic 20 may further includes a registration unit 204.
- the registration unit 204 may visit a registration web page of the enterprise for the guest and may finish the registration of the guest, wherein the registration web page may include three user options: a pre-registration option, a new registration options and a bind existing user option.
- the device 2 executes the guest access logic 20.
- the guest access logic 20 may be understood as a computer program stored in the storage 22. As shown in FIG. 2, the storage 22 and the interface 23 are accessible by the processor 21 through the internal bus 24.
- the storage 22 stores the guest access logic 20 of machine readable instructions executable by the processor 21.
- the storage 22 in which the machine readable instructions are stored may be a volatile or non-volatile memory or storage media including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, DRAM and flash memory devices; magnetic disks, e.g. , internal hard disks or removable disks; magneto optical disks; and CD ROM and DVD-ROM disks.
- the processor 21 of the device 2 reads the instructions of the corresponding modules of the guest access logic 20 stored in the storage 22 and executes the instructions.
- the processor 21 may, according to the guest access logic 20, create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area.
- the processor 21 may receive an access request from the accessible area that is initialized by a guest, and determine whether a terminal device of the guest is bound with an existing user, and if the terminal device of the guest does is not bound with an existing user, then perform an authentication of the guest.
- the processor 21 may mark the guest as a default user after the authentication of the guest is passed, and allow the guest to use the default account for accessing network of the accessible area.
- the processor 21 may perform a MAC address authentication of the terminal device of the guest corresponding to the authentication of the guest.
- the processor 21 may, according to the instructions of the corresponding modules of the the guest access logic 20, detect whether the terminal device of the guest has a legitimate MAC address.
- the processor 21 may read the instructions of the corresponding modules of the guest access logic 20 stored in the storage 22 to direct the guest to a registration web page of an enterprise and finish a registration of the guest.
- processors may be implemented by hardware (including hardware logic circuitry) , software or firmware or a combination thereof.
- the term ‘processor’ is to be interpreted broadly to include a processing unit, ASIC, logic unit, or programmable gate array etc.
- the processes, methods and functional units may all be performed by the one or more processors; reference in this disclosure or the claims to a ‘processor’s hould thus be interpreted to mean ‘one or more processors’ .
- the processes, methods and functional units described in this disclosure may be implemented in the form of a computer software product.
- the computer software product is stored in a storage medium and comprises a plurality of instructions for making a processor to implement the methods recited in the examples of the present disclosure.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- Power Engineering (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
- Small-Scale Networks (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
A guest access method used in Bring Your Own Device (BYOD) management system is disclosed. First, it creates a default account for all guests, and binds the default account to an access device which is pre-deployed in an accessible area. Next, it receives an access request from the accessible area that is initialized by a guest, and determines whether a terminal device of the guest binds with an existed user, and if the terminal device of the guest does not bind with an existed user, then performs an authentication of the guest. Finally, it marks the guest as a default user after the authentication of the guest is passing, and allows the guest to use the default account for accessing network of the accessible area.
Description
With the development of network technology, more and more people use Bring Your Own Device (BYOD) to access an intranet of an enterprise for searching information of the enterprise or obtaining relevant information. In the intranet of the enterprise, there may be some temporary users who are not employees of the enterprise (hereinafter referred to as “guest” ) . How to ensure that internal company information or data will not be accessed by the guest is an important issue.
Brief Description of Drawings
Features of the present disclosure are illustrated by way of example and not limited in the following figure (s) , in which like numerals indicate like elements, in which:
FIG. 1 is an example of a flowchart of guess access in a Bring Your Own Device (BYOD) management system;
FIG. 2 is a schematic diagram illustrating a hardware structure of a device includes a guest access logic, according to an example of the present disclosure; and
FIG. 3 is a schematic diagram illustrating function modules of guest access logic, according to an example of the present disclosure.
For simplicity and illustrative purposes, the present disclosure is described by referring mainly to an example thereof. In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. It will be readily apparent however, that the present disclosure may be practiced without limitation to these specific details. In other instances, some methods and structures have not been described in detail so as not to unnecessarily obscure the present disclosure. As used herein, the terms “a” and “an” are intended to denote at least one of a particular element, the term “includes” means includes but not limited to, the term “including” means including but not limited to, and the term “based on” means based at least in part on.
Bring Your Own Device (BYOD) technology may allow employees to use any device anytime, anywhere, for accessing the intranet of the enterprise to obtain information or related materials. However, due to the diversity of the terminal devices used by employees and the differences of the access method, it may bring more challenges in security and management of the enterprise network. For example, in the BYOD scenarios, the enterprise network may need to support more types of access way, such as cable, Wi-Fi, VPN, etc. , need to support more types of terminal devices, such as PC, smart terminal, iPad, etc. , and need to support more operating systems which are running on terminal devices, such as Mac OS, Android and so on. In an example, in processing with guest’s access authorities within the enterprise network, the BYOD management system first sets up a different access account for each guest. After manually entering the account number and password and validating through, then the guest may access
the intranet of the enterprise. However, this implementation in the BYOD management system is very complicated. The greater the number of guests, the greater workload of the administrator for setting guests’a ccounts. Moreover, the implementation is not good at centralized management for the guests. In addition, faced with the growing number of terminal devices in market, the BYOD management system may also not be able to accurately identify all the terminal device access. Therefore, in practice, the enterprises still usually take a unified access strategy to achieve unified management of guest, but this will cause BYOD management system to be under a potential security risk.
The present disclosure provides a method for access of guests, which is used in a Bring Your Own Device (BYOD) management system. It may create a default account for all guests, further designate accessible area in the enterprise to the guests, and bind the default account to an access device which is pre-deployed in an accessible area. All certified guest may use the default account to access the intranet of the enterprise. This may enable access of guest in a relatively quick fashion and also helps to keep the enterprise internet secure when accessed by the guest.
FIG. 1 is an example of a flowchart of guest access in a Bring Your Own Device (BYOD) management system. As shown in FIG. 1, at block S101, the BYOD management system may create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area.
Before block S101, the administrator may, according to the actual situation of the enterprise area, divide the enterprise area into a plurality of
sub-areas, and designate at least one sub-area as an accessible area in the enterprise to the guests. For example, the enterprise hall, the conference room or the staff lounge area may be selected as accessible areas. The administrator may manage and control guest’s access authorities for accesses coming from the accessible area. For example, when in the accessible area, the guest users may access an intranet of an enterprise for basic information or the relevant data that is made publically available by the enterprise. But the guest users may not access the server used for the enterprise internal operations, and may not obtain the non-public data or internal information of the enterprise.
After designating an accessible area for guests, the administrator may further, by the BYOD management system, create a default account for all guests, and bind the default account to an access device which is pre-deployed in the accessible area. Pre-deployed means that the access device is already deployed in the accessible area, such as the enterprise hall, conference room or staff lounge etc. The BYOD management system may automatically set up and centrally manage the user name and the password of the default account. Thus, the guest may conveniently access the network without manually entering the user name and the password. In addition, according to the actual situation, the network coverage in the accessible area may be wireless, wired or both wired and wireless. When the coverage of the accessible area is wireless, the access device may be a wireless access point. When the coverage of the accessible area is wired, the access device may be a router or a switch. After binding the default account to the access device which is pre-deployed in the accessible area, the guest may use the default account to login to the parts of the enterprise intranet which are made available to guests in the accessible area.
At block S102, the BYOD management system may receive an access request from the accessible area that is initialized by a guest, and determine whether a terminal device of the guest is bound with an existing user, and if it determines the terminal device of the guest is bound with an existing user, then the guest may access the enterprise intranet corresponding to the accessible area, otherwise, it performs an authentication of the guest.
When the terminal device of the guest try to access the enterprise intranet of the accessible area, the terminal device may automatically send an access request to the access device. After receiving the access request, the access device may determine whether the terminal device of the guest is bound with an existing user, and if the terminal device of the guest is bound with an existing user, the terminal device may be assigned an appropriate access control authorities based on information of the terminal device. Then, the terminal device may directly access the enterprise intranet. If the terminal device of the guest is not bound with an existing user, the access device may report the authentication request to the BYOD management system. After receiving the authentication request, the BYOD management system may perform a certification of the terminal device of the guest.
Further, in an example, for the certification of the terminal device, the BYOD management system may use the most common MAC address authentication, wherein the MAC address authentication process may also need to detect the terminal device’s MAC address is legitimate, such as whether there is a separator, capitalization, etc. If the guest’s MAC address is not valid, the authentication may fail and the guest may be rejected to access network. Obviously, the guest authentication method is not limited to the MAC address
authentication. The security requirements of different enterprises are different, so the guest authentication methods may also have many other implementations. For example, the digital signature, the digital certificate authentication or encryption hardware of the terminal devices may be used for the guest authentication methods. The SIM card of a mobile terminal may even be used for the guest authentication.
At block S103, the guest may be marked as the default account after the guest passing the authentication, which allows the guest to use the default account for accessing network of the accessible area.
In an example, after the guest passing the authentication, the BYOD management system may mark the guest as the default account. The default account has already been bound with the access device in the accessible area. The BYOD management system may send the MAC address of the terminal device to the access device in the accessible area. After receiving the MAC address of the terminal device, the access device may add the MAC address into an access white list stored locally in the access device. Thus, the certified guest may use the default account for rapidly accessing the intranet of the enterprise.
In another example, when the access control authorities of the guest is to be further divided by the BYOD management system, or the terminal device is to be registered to be a formal user in the BYOD management system, the guest may be asked to visit a registration web page of the enterprise to finish registration after the guest passing the authentication. The registration web page may include three user options: a pre-registration option, a new registration options and a bind existing user option.
After a successful registration in which the guest selects the pre-registration option, the guest may obtain the basic access permissions. When the guest is offline, the registration information of the guest and the information of the terminal device may be deleted. Thus, when the guest comes back on line, the guest may need to re-register.
After a successful registration in which the guest selects the new registration option, the guest may be forced off line. After the guest is off line, the registration information of the guest and the information of the terminal device may be kept. When the guest uses the registered account to re-login, the BYOD management system may select, according to the terminal information of the guest, the appropriate access control policy for the guest.
When the guest selects the bind existing user option, the terminal device of the guest may bind with the existing user, and the guest may be forced off line. When the guest uses the account of the existed user to re-login, the terminal device of the guest may obtain the appropriate access permissions of the existing user.
Corresponding to the aforementioned method, the present disclosure also provides a guest access logic 20 according to the BYOD management system. FIG. 2 is a schematic diagram illustrating a hardware structure of a device includes guest access logic, according to an example of the present disclosure. As shown in FIG. 2, the device 2 includes a processor 21, a storage 22, an interface 23, and an internal bus 24. FIG. 3 is a schematic diagram illustrating function modules of guest access logic, according to an example of the present disclosure. As shown in FIG. 3, the guest access logic 20 includes a creating
unit 201, an authentication unit 202, an access unit 203, and a registration unit 204.
The creating unit 201 may create a default account for all guests, and the default account may be bound to an access device which is pre-deployed in an accessible area.
The authentication unit 202 may receive an access request from the accessible area, and determine whether a terminal device of the guest binds with an existed user, and if the terminal device of the guest does not bind with an existed user, then perform an authentication of the guest.
The access unit 203 may mark the guest as a default user after the authentication of the guest is passing, and allow the guest to use the default account for accessing network of the accessible area.
In an example, the authentication of the guest by the guest access logic 20 of the BYOD management system may use the most common MAC address authentication.
During performing the MAC address authentication, the guest access logic 20 may also need to detect whether the terminal device’s MAC address is legitimate.
In another example, when access control authorities of the guest need to be further divided by the guest access logic 20 of the BYOD management system or the terminal device needs to be registered to be a formal user in the BYOD
management system, the guest access logic 20 may further includes a registration unit 204.
The registration unit 204 may visit a registration web page of the enterprise for the guest and may finish the registration of the guest, wherein the registration web page may include three user options: a pre-registration option, a new registration options and a bind existing user option.
Implementation in software in combination with hardware as an example is discussed below. In the example, the device 2 executes the guest access logic 20. The guest access logic 20 may be understood as a computer program stored in the storage 22. As shown in FIG. 2, the storage 22 and the interface 23 are accessible by the processor 21 through the internal bus 24. The storage 22 stores the guest access logic 20 of machine readable instructions executable by the processor 21. The storage 22 in which the machine readable instructions are stored may be a volatile or non-volatile memory or storage media including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, DRAM and flash memory devices; magnetic disks, e.g. , internal hard disks or removable disks; magneto optical disks; and CD ROM and DVD-ROM disks. The processor 21 of the device 2 reads the instructions of the corresponding modules of the guest access logic 20 stored in the storage 22 and executes the instructions.
The processor 21 may, according to the guest access logic 20, create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area.
The processor 21 may receive an access request from the accessible area that is initialized by a guest, and determine whether a terminal device of the guest is bound with an existing user, and if the terminal device of the guest does is not bound with an existing user, then perform an authentication of the guest.
The processor 21 may mark the guest as a default user after the authentication of the guest is passed, and allow the guest to use the default account for accessing network of the accessible area.
The processor 21 may perform a MAC address authentication of the terminal device of the guest corresponding to the authentication of the guest.
When performing the MAC address authentication, the processor 21 may, according to the instructions of the corresponding modules of the the guest access logic 20, detect whether the terminal device of the guest has a legitimate MAC address.
Further, the processor 21 may read the instructions of the corresponding modules of the guest access logic 20 stored in the storage 22 to direct the guest to a registration web page of an enterprise and finish a registration of the guest.
The above are only preferred examples of the present disclosure is not intended to limit the disclosure within the spirit and principles of the present disclosure , any changes made , equivalent replacement , or improvement in the protection of the present disclosure should contain within the range.
The methods, processes and units described herein may be implemented by hardware (including hardware logic circuitry) , software or firmware or a
combination thereof. The term ‘processor’ is to be interpreted broadly to include a processing unit, ASIC, logic unit, or programmable gate array etc. The processes, methods and functional units may all be performed by the one or more processors; reference in this disclosure or the claims to a ‘processor’s hould thus be interpreted to mean ‘one or more processors’ .
Further, the processes, methods and functional units described in this disclosure may be implemented in the form of a computer software product. The computer software product is stored in a storage medium and comprises a plurality of instructions for making a processor to implement the methods recited in the examples of the present disclosure.
The figures are only illustrations of an example, wherein the units or procedure shown in the figures are not necessarily essential for implementing the present disclosure. The units in the examples described can be combined into one module or further divided into a plurality of sub-units.
Although the flowcharts described show a specific order of execution, the order of execution may differ from that which is depicted. For example, the order of execution of two or more blocks may be changed relative to the order shown. Also, two or more blocks shown in succession may be executed concurrently or with partial concurrence. All such variations are within the scope of the present disclosure.
Throughout the present disclosure, the word "comprise" , or variations such as "comprises" or "comprising" , will be understood to imply the inclusion of a stated element, integer or step, or group of elements, integers or steps, but not
the exclusion of any other element, integer or step, or group of elements, integers or steps.
Claims (8)
- A method for access of guests, which is used in a Bring Your Own Device (BYOD) management system, the method comprises:creating a default account for all guests, and binding the default account to an access device which is pre-deployed in an accessible area; andreceiving an access request from the accessible area that is initialized by a guest;determining whether a terminal device of the guest is bound with an existing user, and if the terminal device of the guest is not bound with an existing user, then perform an authentication of the guest; andmarking the guest as a default user after the authentication of the guest is passed, and allowing the guest to use the default account for accessing network of the accessible area.
- The method according to claim 1, wherein the authentication of the guest performed by the BYOD management system is to perform a MAC address authentication of the terminal device of the guest.
- The method as claimed in claim 2, further comprising detecting whether the terminal device of the guest has a legitimate MAC address.
- The method of claim 1, wherein, when access control permissions of the guest are to be further divided by the BYOD management system or the terminal device is to be registered to be a formal user in the BYOD management system, the method further comprises:providing a registration web page of an enterprise and finishing a registration of the guest, wherein the registration web page includes three user options: a pre-registration option, a new registration options and a bind existing user option.
- A non-transitory computer readable storage medium on which is stored machine readable instructions that when executed by a processor cause the processor to:create a default account for all guests, and bind the default account to an access device which is pre-deployed in an accessible area;receive an access request from the accessible area that is initialized by a guest;determine whether a terminal device of the guest is bound with an existing user, and if the terminal device of the guest is not bound with an existing user, then perform an authentication of the guest; andmark the guest as a default user after the authentication of the guest is passed, and allow the guest to use the default account for accessing network of the accessible area.
- The non-transitory computer readable storage medium according to claim 5, wherein the machine readable instructions are further to cause the processor to:perform an authentication of the guest by performing a MAC address authentication of the terminal device of the guest.
- The non-transitory computer readable storage medium according to claim 6, wherein the machine readable instructions are further to cause the processor to:detect whether the terminal device of the guest has a legitimate MAC address.
- The non-transitory computer readable storage medium according to claim 5, wherein the machine readable instructions are further to cause the processor to:direct a guest user to a registration web page of an enterprise to register the guest;wherein the registration web page includes three user options: a pre-registration option, a new registration option and a bind existing user option.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201310677018.0A CN104717062B (en) | 2013-12-11 | 2013-12-11 | The method and device that a kind of visitor based on BYOD management systems quickly accesses |
| CN201310677018.0 | 2013-12-11 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2015085872A1 true WO2015085872A1 (en) | 2015-06-18 |
Family
ID=53370609
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2014/092564 Ceased WO2015085872A1 (en) | 2013-12-11 | 2014-11-28 | Method and device for access of guests |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN104717062B (en) |
| WO (1) | WO2015085872A1 (en) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115601866A (en) * | 2022-09-19 | 2023-01-13 | 一站发展(北京)云计算科技有限公司(Cn) | Traffic management method, device, equipment and readable storage medium |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN106375262B (en) * | 2015-07-21 | 2020-03-13 | 株式会社理光 | Access control method and device |
| CN107612888B (en) * | 2017-08-23 | 2020-09-04 | 北京小米移动软件有限公司 | Enterprise user space creation method and device |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101582769A (en) * | 2009-07-03 | 2009-11-18 | 杭州华三通信技术有限公司 | Authority setting method of user access network and equipment |
| US8392712B1 (en) * | 2012-04-04 | 2013-03-05 | Aruba Networks, Inc. | System and method for provisioning a unique device credential |
| CN103079201A (en) * | 2011-10-26 | 2013-05-01 | 中兴通讯股份有限公司 | Fast authentication method, access controller (AC) and system for wireless local area network |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CA2557143C (en) * | 2004-02-27 | 2014-10-14 | Sesame Networks Inc. | Trust inheritance in network authentication |
| CN102143165B (en) * | 2011-01-24 | 2014-07-09 | 华为技术有限公司 | Method, network switch and network system for authenticating terminals |
| CN102378175A (en) * | 2011-10-08 | 2012-03-14 | 华为终端有限公司 | Wireless local area network (WLAN) authentication method and mobile terminal |
| CN102594846B (en) * | 2012-04-05 | 2015-10-07 | 北京网御星云信息技术有限公司 | A kind of shared access management algorithm based on IP header and system |
| CN103414709A (en) * | 2013-08-02 | 2013-11-27 | 杭州华三通信技术有限公司 | User identity binding and user identity binding assisting method and device |
-
2013
- 2013-12-11 CN CN201310677018.0A patent/CN104717062B/en active Active
-
2014
- 2014-11-28 WO PCT/CN2014/092564 patent/WO2015085872A1/en not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101582769A (en) * | 2009-07-03 | 2009-11-18 | 杭州华三通信技术有限公司 | Authority setting method of user access network and equipment |
| CN103079201A (en) * | 2011-10-26 | 2013-05-01 | 中兴通讯股份有限公司 | Fast authentication method, access controller (AC) and system for wireless local area network |
| US8392712B1 (en) * | 2012-04-04 | 2013-03-05 | Aruba Networks, Inc. | System and method for provisioning a unique device credential |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115601866A (en) * | 2022-09-19 | 2023-01-13 | 一站发展(北京)云计算科技有限公司(Cn) | Traffic management method, device, equipment and readable storage medium |
Also Published As
| Publication number | Publication date |
|---|---|
| CN104717062B (en) | 2018-03-16 |
| CN104717062A (en) | 2015-06-17 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP6259032B2 (en) | Managing wireless network login password sharing | |
| US10321316B1 (en) | Wireless multi-factor authentication with captive portals | |
| CN104540186B (en) | Method, device and system for wireless network access | |
| US20190384917A1 (en) | Method and apparatus for secure device boot | |
| US9843930B2 (en) | Trusted execution environment initialization method and mobile terminal | |
| US9565194B2 (en) | Utilizing a social graph for network access and admission control | |
| CN101668293A (en) | Control method and system of network access authority in WLAN | |
| US20170347388A1 (en) | Transparently Connecting Mobile Devices to Multiple Wireless Local Area Networks | |
| US11575567B2 (en) | Wireless communication equipment and method for configuring mesh network thereof | |
| US9832203B2 (en) | Application permission management device and method therefor | |
| US20200195656A1 (en) | Anchoring Client Devices for Network Service Access Control | |
| JP2011523250A5 (en) | ||
| WO2016155220A1 (en) | Single sign-on method, system and terminal | |
| US20170078100A1 (en) | Providing device, terminal device, providing method, non-transitory computer readable storage medium, and authentication processing system | |
| US9251331B2 (en) | Simplified user registration | |
| US20210195391A1 (en) | Different profiles for selecting different network interfaces for communications of an electronic device | |
| CN109067715B (en) | Verification method and device | |
| US10848958B2 (en) | Profile prioritization in a roaming consortium environment | |
| CN104717062B (en) | The method and device that a kind of visitor based on BYOD management systems quickly accesses | |
| WO2016061980A1 (en) | Wlan sharing method and system, and wlan sharing registration server | |
| US10939298B2 (en) | Application access based on network | |
| WO2016112591A1 (en) | Hotspot access method and device, terminal and computer storage medium | |
| CN104539446A (en) | Shared WLAN management achieving method and system and WLAN shared registering server | |
| CN105592453A (en) | Method and system for realizing WLAN sharing and WLAN sharing register server | |
| US20140344562A1 (en) | Method and device for preventing access to administrative privilege |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 14870469 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 14870469 Country of ref document: EP Kind code of ref document: A1 |