WO2016192608A2 - 身份认证方法、身份认证系统和相关设备 - Google Patents

身份认证方法、身份认证系统和相关设备 Download PDF

Info

Publication number
WO2016192608A2
WO2016192608A2 PCT/CN2016/083924 CN2016083924W WO2016192608A2 WO 2016192608 A2 WO2016192608 A2 WO 2016192608A2 CN 2016083924 W CN2016083924 W CN 2016083924W WO 2016192608 A2 WO2016192608 A2 WO 2016192608A2
Authority
WO
WIPO (PCT)
Prior art keywords
access router
virtual access
client device
user
identity information
Prior art date
Application number
PCT/CN2016/083924
Other languages
English (en)
French (fr)
Other versions
WO2016192608A3 (zh
Inventor
包德伟
胡寅亮
魏启坤
潘栋成
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2016192608A2 publication Critical patent/WO2016192608A2/zh
Publication of WO2016192608A3 publication Critical patent/WO2016192608A3/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities

Definitions

  • the present invention relates to the field of communications, and in particular, to an identity authentication method, an identity authentication system, and related devices.
  • a traditional access router (AR) is placed on the user (enterprise) side.
  • the user performs point-to-point protocol over Ethernet (PPPoE) dial-up on the AR.
  • the carrier network device performs the user on the network. Authentication and authentication. After the authentication is passed, the wide area network (WAN) port is assigned an Internet Protocol (IP) address.
  • IP Internet Protocol
  • the PPPoE protocol provides a standard for connecting multiple hosts to a remote broadband access server in an Ethernet network. The essence is to establish a point-to-point tunnel on the Ethernet, with user authentication and IP address notification.
  • the PPPoE dialup is performed on the traditional AR, the user's authentication can be completed.
  • the carrier network device allocates the IP address of the public network to the WAN port of the AR.
  • the virtual access router moves most of the functions of the AR, such as IP routing, network address translation (NAT), firewall, to the carrier network, and the user-side thin user premises equipment (thin) Customer-premises equipment, ThinCPE) only retains simple access functionality.
  • the user purchases the vAR from the operator. After the purchase is successful, the vAR is dedicated to the user (there are different functional services according to the package selected by the user). The user needs to go through the operator's access network between the vARs they purchase. This is a Layer 2 network.
  • PPPoE dial-up authentication the current idea is to use the vAR as a PPPoE client to authenticate through a PPPoE server, for example, a Broadband Remote Access Server (BRAS).
  • BRAS Broadband Remote Access Server
  • Embodiments of the present invention provide an identity authentication method, an identity authentication system, and related devices, which are used to implement virtual access. Authentication and authentication of dial-up enterprise users in the router scenario.
  • the first aspect of the embodiments of the present invention provides an identity authentication method, which is applied to a network system including a virtual access router, where the network system further includes a client device and a PPPOE server, including:
  • the virtual access router receives the first PADI broadcast message that is sent by the client device and carries the first identity information of the user, where the first identity information of the user is an identifier of the user of the client device in the network system, where the A PADI broadcast message is used to request a PPPOE server service;
  • the virtual access router determines that the first identity information of the user matches the identity of the virtual access router, the virtual access router sends a second PADI broadcast message to the PPPOE server, the second PADI The broadcast message is used to request the PPPOE server service;
  • the virtual access router After the virtual access router receives the first PADO response message returned by the PPPOE server, the virtual access router sends a second PADO response message carrying routing identity information to the client device, where the route The identity information is an identifier of the virtual access router in the network system;
  • the virtual access router After the virtual access router establishes a first session with the PPPOE server and a second session with the client device, the virtual access router passes the first session and the a second session, the user second identity information sent by the client device is forwarded to the PPPOE server for identity authentication, where the user second identity information includes the first identity information of the user;
  • the virtual access router When the virtual access router receives the authentication failure message sent by the PPPOE server, the virtual access router interrupts the first session with the client device.
  • the method further includes:
  • the virtual access router receives an IP subnet address advertisement request sent by the client device, where the IP subnet address advertisement request is used to request to establish a mapping between the identifier of the first session and an intranet IP network segment.
  • the IP subnet address advertisement request includes an intranet IP network segment of the client device;
  • the virtual access router After the virtual access router determines the legality of the intranet IP network segment, the virtual access router saves the binding relationship between the identifier of the first session and the intranet IP network segment, and sends the binding relationship to the client.
  • the end device sends an IP subnet address advertisement response.
  • the second aspect of the embodiments of the present invention provides an identity authentication method, which is used for a network system including a virtual access router, where the network system further includes a client device and a PPPOE server, including:
  • the client device sends a first PADI broadcast message carrying the first identity information of the user in the network system, where the first PADI broadcast message is used to request the PPPoE server service, and the first identity information of the user is the client.
  • the identity of the user of the device in the network system is the identity of the user of the device in the network system;
  • the client device receives a second PADO response message that is sent by the virtual access router and carries the routing identity information, where the routing identity information is a unique identifier of the virtual access router in the network system;
  • the client device determines that the routing identity information matches the first identity information of the user, the client device establishes a first session with the virtual access router;
  • the client device sends the second identity information of the user to the virtual access router by using the first session, so that the virtual access router forwards the second identity information of the user to the PPPOE server for identity authentication.
  • the user first identity information includes the first identity information of the user.
  • the network system further includes a DHCP server, where the method further includes:
  • the client device acquires a configuration of an intranet IP network segment from the DHCP server;
  • IP subnet address advertisement request Sending, by the client device, an IP subnet address advertisement request to the virtual access router according to the configuration of the intranet IP network segment, where the IP subnet address advertisement request is used to request the virtual access router to establish a location A mapping between the identifier of the first session and the intranet IP network segment.
  • a third aspect of the embodiments of the present invention provides a virtual access router, including:
  • a first receiving module configured to receive a first PADI broadcast message that is sent by the client device and that carries the first identity information of the user, where the first identity information of the user is an identifier of the user of the client device in the network system,
  • the first PADI broadcast message is used to request a PPPOE server service;
  • a first sending module configured to send a second PADI broadcast when determining that the first identity information of the user carried in the first PADI broadcast message received by the first receiving module matches the identity of the virtual access router The message is sent to the PPPOE server, and the second PADI broadcast message is used to request the PPPOE server service;
  • a second sending module configured to: after receiving the first PADO response message returned by the PPPOE server, send a second PADO response message carrying routing identity information to the client device, where the routing identity information is An identifier of the virtual access router in the network system;
  • a forwarding module configured to forward the first session and the second session after establishing a first session with the PPPOE server and a second session with the client device
  • the second identity information sent by the client device is sent to the PPPOE server for identity authentication, where the second identity information of the user includes the first identity information of the user;
  • an interruption module configured to interrupt the first session with the client device when receiving an authentication failure message sent by the PPPOE server.
  • the virtual access router further includes:
  • a second receiving module configured to receive an IP subnet address advertisement request sent by the client device, where the IP subnet address advertisement request is used to request to establish an identifier between the identifier of the first session and an intranet IP network segment Mapping, the IP subnet address advertisement request includes an intranet IP network segment of the client device;
  • a saving module configured to save the identifier of the first session and the intranet IP network after determining the legality of the intranet IP network segment included in the IP subnet address advertisement request received by the second receiving module The binding relationship of the segment;
  • a third sending module configured to send an IP subnet address notification response to the client device after the saving module saves the binding relationship between the identifier of the first session and the intranet IP network segment.
  • a fourth aspect of the embodiments of the present invention provides a client device, including:
  • a fourth sending module configured to send, in the network system, a first PADI broadcast message carrying the first identity information of the user, where the first PADI broadcast message is used to request a PPPoE server service, where the first identity information of the user is An identifier of a user of the client device in the network system;
  • a third receiving module configured to receive a second PADO response message that is sent by the virtual access router and carries the routing identity information, where the routing identity information is a unique identifier of the virtual access router in the network system;
  • a establishing module configured to establish a first relationship with the virtual access router when determining that the routing identity information carried in the second PADO response message received by the third receiving module matches the first identity information of the user Conversation
  • a fifth sending module configured to send the user second identity information to the virtual access router by using the first session established by the establishing module, so that the virtual access router forwards the second identity information of the user to the
  • the PPPOE server performs identity authentication, and the second identity information of the user includes the first identity information of the user.
  • the client device further includes:
  • An obtaining module configured to acquire a configuration of an intranet IP network segment from a DHCP server
  • a sixth sending module configured to send an IP subnet address advertisement request to the virtual access router according to the configuration of the intranet IP network segment acquired by the acquiring module, where the IP subnet address advertisement request is used to request the
  • the virtual access router establishes a mapping between the identifier of the first session and the intranet IP network segment.
  • a fifth aspect of the embodiments of the present invention provides an identity authentication system, including:
  • the PPPOE server, the virtual access router according to the third aspect of the embodiment of the present invention or the first implementation manner of the third aspect, and the fourth implementation manner of the fourth aspect or the fourth aspect of the embodiment of the present invention The client device.
  • the embodiment of the present invention has the following advantages: in the embodiment of the present invention, the virtual access router only determines the first identity information of the user in the first PADI broadcast message sent by the received client. When the identity of the virtual access router matches, the second PADI broadcast message is sent to the PPPOE server to request the PPPOE server service, and the virtual access router also needs to send a second PADO response message carrying the routing identity information to the client device. The identity of the virtual access router is authenticated by the client device. Through such mutual authentication, the security of the access link between the client device and the virtual access router is ensured.
  • the virtual access router After the virtual access router establishes a first session with the PPPOE server and the second session with the client device, forwarding the second identity of the user sent by the client device through the first session and the second session The information is sent to the PPPOE server for identity authentication. If the authentication fails, the virtual access router receives the authentication failure message sent by the PPPOE server, and the virtual access router immediately interrupts the first session with the client device, and only The client device authenticated by the PPPOE server can continue to perform subsequent processing. In this way, the authentication and authentication of the dial-up enterprise user in the virtual access router scenario is implemented.
  • FIG. 1 is a schematic diagram of a signaling flow of an identity authentication method according to an embodiment of the present invention
  • FIG. 2 is a schematic flowchart of an identity authentication method according to an embodiment of the present invention.
  • FIG. 3 is a schematic flowchart of an identity authentication method according to an embodiment of the present invention.
  • FIG. 4 is a schematic structural diagram of a virtual access router according to an embodiment of the present invention.
  • FIG. 5 is another schematic structural diagram of a virtual access router according to an embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of a client device according to an embodiment of the present invention.
  • FIG. 7 is a schematic structural diagram of another embodiment of a client device according to an embodiment of the present invention.
  • FIG. 8 is another schematic structural diagram of a virtual access router according to an embodiment of the present invention.
  • the embodiment of the present invention provides an identity authentication method, which is applied to a network system including a virtual access router, a client device, and a PPPOE server, and is used for authenticating and authenticating a dial-up enterprise user in a virtual access router scenario. .
  • PADI is an abbreviation of PPPoE Active Discovery Initiation, indicating that PPPoE actively discovers the initial package
  • PADO is an abbreviation of PPPoE Active Discovery Offer, which indicates PPPoE active discovery proposal package
  • PADR is an abbreviation of PPPoE Active Discovery Request, indicating PPPoE active discovery request packet
  • PADS is an abbreviation of PPPoE Active Discovery Session-confirmation PPPoE, which indicates that the session confirmation packet is actively discovered.
  • DHCP is an abbreviation of Dynamic Host Configuration Protocol, which means dynamic host configuration protocol;
  • WAN is an abbreviation for wide area network, which means wide area network.
  • the following describes the identity authentication method in the embodiment of the present invention from the perspective of signaling interaction between the virtual access router, the client device, and the PPPOE server in the network system:
  • an embodiment of an identity authentication method in an embodiment of the present invention includes:
  • the client device sends, in the network system, a first PADI broadcast message carrying the first identity information of the user.
  • the first PADI broadcast message is used to request a PPPoE server service, and the first identity information of the user is a unique identifier of a user of the client device in the network system;
  • the first identity information of the user may be an account name of the user that is unique to the network that is allocated by the operator, or may be another identifier that can uniquely identify the user, which is not limited herein.
  • the packets sent by each device can carry the source (sender) MAC address and the destination (receiver) MAC address.
  • the source MAC address of the first PADI broadcast message may be the MAC address of the client device
  • the destination MAC address may be a broadcast address, that is, sent to all network devices connected to the network system.
  • the virtual access router determines that the first identity information of the user matches the identity of the virtual access router.
  • the virtual access router in the network system can receive the first PADI broadcast packet sent by the client device. It can be understood that the number of virtual access routers in the network system can be multiple, and each receives the The virtual access router of the first PADI broadcast message can determine whether the first identity information of the user in the first PADI broadcast message matches the identity of the virtual access router, and only the first identity information of the user is determined. The virtual access router that matches the identity of the virtual access router performs step 103.
  • the virtual access router is purchased by the user from the operator.
  • the operator creates the virtual access router, the first identity information of the user that is matched with the virtual access router has been allocated.
  • the virtual access router sends a second PADI broadcast message to the PPPOE server.
  • the virtual access router sends the second PADI broadcast message to the PPPOE service only when the virtual access router determines that the first identity information of the user in the first PADI broadcast message matches the identity of the virtual access router. Request the service of PPPOE.
  • the virtual access router can record the MAC address of the client device that sends the first PADI broadcast message.
  • the source MAC address of the second PADI broadcast packet may be the MAC address of the virtual access router, and the destination MAC address may be a broadcast address.
  • Each of the network devices in the network system may be able to receive the second PADI broadcast message, but only the PPPOE server can identify the second PADI broadcast message and give feedback.
  • the PPPOE server After receiving the second PADI broadcast message sent by the virtual access router, the PPPOE server sends a first PADO response message to the virtual access router.
  • the PPPOE server After receiving the second PADI broadcast message sent by the virtual access router for requesting the PPPOE server service, if the PPPOE server agrees to provide the service, the PPPOE server sends a first PADO response message to the virtual access router for responding to the second Service request for PADI broadcast messages.
  • the source MAC address of the first PADO response message is the PPPOE server, and the destination MAC address is the virtual access router that sends the second PADI broadcast message.
  • the virtual access router After receiving the first PADO response message sent by the PPPOE server, the virtual access router sends a second PADO response message carrying the routing identity information to the client device, where the routing identity information is a unique identifier of the virtual access router in the network system;
  • the virtual access router may record the MAC address of the PPPOE server carried in the first PADO response message, and then send a second PADO response message carrying the routing identity information to the Client device.
  • the routing identity information is a unique identifier of the virtual access router in the network system, and the routing identity information is used for authenticating the identity of the client device with the virtual access router.
  • the source MAC address of the second PADO response message is the virtual access router, and the destination MAC address is the MAC address of the client device that sends the first PADI broadcast message.
  • the client device determines that the received routing identity information matches the first identity information of the user.
  • the client device After receiving the second PADO response message, the client device authenticates whether the routing identity information carried in the second PADO response message matches the first identity information of the user, and determines that the routing identity information matches the first identity information of the user. The subsequent session establishment process is performed.
  • the client device sends a first PADR request message to the virtual access router, where the first PADR request message is used to request to establish a session with the virtual access router.
  • the client device After the client device determines that the received routing identity information matches the first identity information of the user, the client device The client device sends a first PADR request message to the virtual access router, where the first PADR request message is used to request to establish a session with the virtual access router.
  • the source MAC address of the first PADR request message is the MAC address of the client device, and the destination MAC address is the MAC address of the virtual access router to which the identity matches.
  • the virtual access router After receiving the first PADR request message sent by the client device, the virtual access router sends a second PADR request message to the PPPOE server, where the second PADR request message is used to request the PPPOE.
  • the server establishes a session;
  • the virtual access router After receiving the first PADR request message sent by the client device for requesting to establish a session, the virtual access router needs to determine whether a session can be established with the PPPOE server, and the virtual access router sends a second PADR request message to the PPPOE server.
  • the second PADR request message is used to request to establish a session with the PPPOE server.
  • the source MAC address of the second PADR request message is the MAC address of the virtual access router, and the destination MAC address is the MAC address of the PPPOE server.
  • the PPPOE server After receiving the second PADR request message, the PPPOE server sends a second PADS acknowledgment message to the virtual access router, where the second PADS acknowledgment message is used to confirm that a session is established with the virtual access router. ;
  • the PPPOE server After receiving the second PADR request message sent by the virtual access router to request to establish a session, if the PPPOE server agrees to establish a session, it sends a second PADS acknowledgement message to the virtual access router, and the second PADS acknowledgement message is used for confirming. Establish a session with the virtual access router.
  • the source MAC address of the second PADS acknowledgment message is the MAC address of the PPPOE server, and the destination MAC address is the MAC address of the virtual access router.
  • the virtual access router After receiving the second PADS acknowledgment message sent by the PPPOE server, the virtual access router establishes a first session with the PPPOE server, and sends a first PADS confirmation message to the client device, and the client. End device establishes a second session, where the first PADS confirmation message includes a session ID allocated for the client device;
  • the virtual access router After receiving the second PADS acknowledgment message sent by the PPPOE server, the virtual access router establishes a first session with the PPPOE server, and may save the information of the first session, where the information of the first session includes the first session. ID, at this time, the first PADR request message sent by the client device can be fed back, the first PADS confirmation message is sent to the client device, the second session is established with the client device, and the second session can be saved. Information.
  • the first session between the client device and the virtual access router and the second session between the virtual access router and the PPPOE server constitute a second session between the client device and the PPPOE server. PPPOE session.
  • each session has a session ID that uniquely identifies the session, and the session ID of the session between the virtual access router and the client device is allocated by the virtual access router, and is sent to the first PADS acknowledgement message of the client device.
  • the session ID assigned by the virtual access router to the client device is included.
  • the information of the saved first session includes the session ID information.
  • the session ID between the virtual access router and the PPPOE server is allocated by the PPPOE server, and the second PADS confirmation message sent to the virtual access router includes the session ID assigned by the PPPOE server to the virtual access router as the first The session ID of the session.
  • the source MAC address of the first PADS acknowledgment message is the MAC address of the virtual access router, and the destination MAC address is the MAC address of the client device.
  • the client device After receiving the first PADS acknowledgment message sent by the virtual access router, the client device sends the second identity information of the user to the PPPOE through the first session and the second session.
  • the server performs identity authentication, and the second identity information of the user includes the first identity information of the user.
  • the client device After receiving the first PADS acknowledgment message sent by the virtual access router, the client device indicates that the first session between the client device and the virtual access router has been established, and the client device sends the user second through the first session.
  • Identity information is sent to the virtual access router, and the virtual access router forwards the second identity information of the user to the PPPOE server for identity authentication through a third session with the PPPOE server, where the second identity information of the user includes the first identity of the user. information.
  • the PPPOE server performs authentication, authentication, and the like on the received second identity information of the user.
  • the user name, password, location information, and the like of the user are stored in the RADIUS of the carrier network.
  • the PPPoE server can compare and authenticate the second identity information of the user with the legal information of the user in the RADIUS server.
  • the second identity information of the user may further include information such as a user password, and/or port information of the intermediate agent on the PPPOE+ transmission line (which may indicate client location information), and is not limited herein.
  • the PPPOE server After the PPPOE server authenticates the sent user's second identity information, it will feed back the authentication result to the virtual access router:
  • the virtual access router interrupts the first session with the client device.
  • the virtual access router If the virtual access router receives the authentication success message sent by the PPPOE server, the virtual access router maintains the first session and the second session, and may continue to perform other processing.
  • the steps 101 to 111 implement the authentication and authentication of the dial-up enterprise user in the virtual access router scenario, improve the security of the access link in the virtual access router scenario, and implement the virtual connection. Authentication of the port information of the intermediate agent on the PPPOE+ transmission line in the router scenario.
  • the client device sends a new WAN port address configuration request message, requesting the WAN port of the virtual access router to obtain the public network IP address.
  • the virtual access router WAN interface obtains the public network IP address
  • the WAN port address configuration response message is sent, but the public network IP address is not sent to the client device, and the configuration information such as the public network IP address is saved on the virtual access router.
  • the embodiment shown in FIG. 1 may further include the following steps:
  • the client device acquires a configuration of an intranet IP network segment from a DHCP server.
  • the client device can obtain the configuration of the intranet IP network segment from the DHCP server (distributed inside the enterprise) of the intranet.
  • the DHCP server may be configured on the client device, or may be independent, and is not limited herein.
  • the internal network IP network segment refers to the address segment of the same IP network inside the enterprise side.
  • the network segment IP address plus the subnet mask is used to identify a network segment.
  • the client device sends an IP subnet address advertisement request to the virtual access router according to the configuration of the intranet IP network segment, where the IP subnet address advertisement request is used to request the virtual access router. Establishing a mapping between the ID of the first session and the intranet IP network segment;
  • the client device sends an IP subnet address advertisement request to the virtual access router according to the configured configuration of the intranet IP network segment, where the IP subnet address advertisement request is used to request the virtual access router to establish the ID of the first session. Mapping with the intranet IP network segment.
  • the IP subnet address advertisement request is used to establish a mapping between the PPPoE session (the first session and the second session layer 2) and the internal IP network segment, and it is assumed that there are multiple client devices dialing and one virtual access. There are multiple sessions between the router and multiple client devices. From the public network to the internal network, the data packet does not have the destination MAC address of the intranet. Only the destination IP address of the intranet needs to be mapped from the IP address. A PPPoE session is determined to determine the destination MAC.
  • the destination IP is the IP address of the virtual access router WAN port, and the virtual access router WAN port receives the packet after being virtualized.
  • the destination IP address of the access router is translated into the IP address of the intranet.
  • the PPPOE session is identified by the session ID, source address, and destination MAC address.
  • the packet does not carry the virtual access router to the client.
  • the virtual access router After receiving the IP subnet address advertisement request, the virtual access router detects the legality of the intranet IP network segment, and saves the ID of the first session and the IP network segment of the intranet. A relationship is sent to the client device to send an IP subnet address notification response.
  • the virtual access router After receiving the IP subnet address advertisement request sent by the client device, the virtual access router detects the legality of the intranet IP network segment in the IP subnet address advertisement request, and determines the ID of the first session after determining that the legality is met. The binding relationship with the IP network segment of the intranet is sent to the client device to send an IP subnet address advertisement response.
  • the client device can further obtain other configurations.
  • the enterprise user on the internal network can obtain the internal network IP configuration information from the DHCP server and access the client device to start normal data communication.
  • the client device may also send a subnet address configuration advertisement request to notify the subnet and mask (IP address segment) configured on the enterprise side user DHCP server that accesses the client device.
  • a subnet address configuration advertisement request to notify the subnet and mask (IP address segment) configured on the enterprise side user DHCP server that accesses the client device.
  • the client device may be a thin client ThinCPE or a PC with a dialing function, which is not limited herein.
  • the enterprise IT administrator can hold the enterprise user account, and the enterprise IT administrator can use the enterprise user account to authenticate to the PPPOE server to complete the configuration of the enterprise external network.
  • the PC of the employee holding the employee account in the intranet needs to be networked after the enterprise IT administrator completes the configuration of the enterprise external network.
  • the enterprise employee database may be stored in the virtual access router purchased by the enterprise intranet or the enterprise.
  • the virtual router can authenticate the employee. Specifically, the virtual access router can compare and verify the identity information sent by the employee accessing the network with the legal information of the user in the stored enterprise employee database, which is not limited herein.
  • the binding of the PPPOE session ID enables the interconnection between the devices in the intranet connected to the client device in the virtual router scenario and the PPPOE network, and is allocated through DHCP.
  • the configuration of the network IP network segment implements the network interworking requirements of the intranet devices, so that even if the access network fails, devices in the intranet can communicate normally.
  • another embodiment of the method for identity authentication in the embodiment of the present invention includes:
  • the virtual access router receives a first PADI broadcast message that is sent by the client device and carries the first identity information of the user.
  • the first identity information of the user is an identifier of a user of the client device in a network system, and the first PADI broadcast message is used to request a PPPOE server service.
  • the virtual access router determines that the first identity information of the user matches the identity of the virtual access router, the virtual access router sends a second PADI broadcast message to the PPPOE server, where The second PADI broadcast message is used to request the PPPOE server service;
  • the virtual access router After the virtual access router receives the first PADO response message returned by the PPPOE server, the virtual access router sends a second PADO response message carrying routing identity information to the client device.
  • the routing identity information is an identifier of the virtual access router in the network system;
  • step 105 Similar to step 105, it will not be described here.
  • the virtual access router After the virtual access router establishes a first session with the PPPOE server, and after a second session with the client device, the virtual access router passes the first session and Transmitting, by the second session, the user second identity information sent by the client device to the PPPOE server for identity authentication, where the user second identity information includes the first identity information of the user;
  • step 108 the process of establishing the first session and the second session is similar to the process of step 108 to step 110, and details are not described herein.
  • the virtual access router may forward the second identity information of the user sent by the client device to the PPPOE server for identity authentication, where the second identity information of the user includes the first identity of the user of the client device. information.
  • the PPPOE server performs authentication, authentication, and the like on the received second identity information of the user.
  • the user name, password, location information, and the like of the user are stored in the RADIUS of the carrier network.
  • the PPPoE server can compare and authenticate the second identity information of the user with the legal information of the user in the RADIUS server.
  • the second identity information of the user may further include information such as a user password, and/or port information of the intermediate agent on the PPPOE+ transmission line (which may indicate client location information), and is not limited herein.
  • the PPPOE server After the PPPOE server authenticates the sent user's second identity information, it will feed back the authentication result to the virtual access router:
  • the virtual access router maintains the first session and the second session, and other processing can be continued.
  • step 205 is triggered.
  • the virtual access router When the virtual access router receives the authentication failure message sent by the PPPOE server, the virtual access router interrupts the first session with the client device.
  • the virtual access router sends the second PADI only when it determines that the first identity information of the user in the first PADI broadcast message sent by the client matches the identity of the virtual access router. Broadcasting the message to the PPPOE server to request the PPPOE server service, the virtual access router also needs to send a second PADO response message carrying the routing identity information to the client device, and the client device authenticates the identity of the virtual access router. Through such mutual authentication, the security of the access link between the client device and the virtual access router is ensured.
  • the virtual access router After the virtual access router establishes a first session with the PPPOE server and the second session with the client device, forwarding the second identity of the user sent by the client device by using the first session and the second session The information is sent to the PPPOE server for identity authentication. If the authentication fails, the virtual access router receives the authentication failure message sent by the PPPOE server, and the virtual access router immediately interrupts the first session with the client device, and only The client device that is authenticated by the PPPOE server can continue the subsequent processing. In this way, the authentication and authentication of the dial-up enterprise user in the scenario of the virtual access router is implemented, and the security of the access link is ensured.
  • the virtual access router may further receive the IP sent by the client device.
  • a subnet address advertisement request where the IP subnet address advertisement request is used to request to establish a mapping between the identifier of the first session and an intranet IP network segment, where the IP subnet address advertisement request includes the client
  • the internal network IP network segment of the device after the virtual access router determines the legality of the intranet IP network segment, the virtual access router saves the identifier of the first session and the IP network segment of the intranet The relationship is determined and an IP subnet address notification response is sent to the client device.
  • step 114 Similar to step 114, it will not be described here.
  • the devices in the intranet connected to the client device in the virtual router scenario are interconnected with the PPPOE network.
  • another embodiment of the method for identity authentication in the embodiment of the present invention includes:
  • the client device sends, in the network system, a first PADI broadcast message carrying the first identity information of the user, where the first PADI broadcast message is used to request a PPPoE server service, where the first identity information of the user is The identity of the user of the client device in the network system;
  • the client device may be a thin client ThinCPE or a dial-up PC. This is not a limitation.
  • the client device receives a second PADO response message that is sent by the virtual access router and carries the routing identity information, where the routing identity information is a unique identifier of the virtual access router in the network system.
  • the client device can confirm whether the routing identity information carried in the second PADO response message matches the first identity information of the user. Step 303 is performed only when the matching is determined.
  • the client device determines that the routing identity information matches the first identity information of the user, the client device establishes a first session with the virtual access router.
  • the client device determines that the routing identity information matches the first identity information of the user, the first session is established with the virtual access router.
  • the specific session establishment process is similar to the steps 107 to 110, and is not described here.
  • the client device sends the second identity information of the user to the virtual access router by using the first session, so that the virtual access router forwards the second identity information of the user to the PPPOE server for identity. Certification.
  • the client device may send the second identity information of the user to the virtual access router through the first session, so that the virtual access router will The user second identity information is forwarded to the PPPOE server for identity authentication.
  • the second identity information of the user may further include information such as a user password, and/or port information of the intermediate agent on the PPPOE+ transmission line (which may indicate client location information), and is not limited herein.
  • the process of sending the second identity information of the specific user and the authentication process are similar to the step 111, and are not described herein.
  • the client device sends the first PADI broadcast message carrying the first identity information of the user to the virtual access router, so that the virtual access router authenticates the first identity information of the user, and after the authentication is passed, Receiving a second PADO response message sent by the virtual access router and carrying the routing identity information, authenticating the routing identity information, and starting the session establishment process after the authentication is passed.
  • the third user identity information including the user's first identity information is sent to the PPPOE server for authentication, and the authentication and authentication of the dial-up enterprise user in the virtual access router scenario is implemented to ensure the access link. Security.
  • the network system may further include a DHCP server.
  • the client device After the third user identity information is successfully authenticated in the embodiment shown in FIG. 3, the client device is selected. And obtaining, by the DHCP server, a configuration of an intranet IP network segment, where the client device sends an IP subnet address advertisement request to the virtual access router according to the configuration of the intranet IP network segment, where the IP sub- The network address advertisement request is used to request the virtual access router to establish a mapping between the identifier of the first session and the intranet IP network segment.
  • step 113 Similar to step 113, it will not be described here.
  • the DHCP server may be configured on the client device, and is not limited herein.
  • the client device obtains the configuration of the intranet IP network segment from the DHCP server, and implements the network interworking requirement between the intranet devices, so that even if the access network fails, the devices in the intranet of the enterprise also Can communicate normally.
  • the IP subnet address advertisement request request establishes a mapping between the identifier of the first session and the intranet IP network segment, and implements a network between the devices and the PPPOE in the intranet connected to the client device in the virtual router scenario. Interoperability.
  • an embodiment of the virtual access router 400 in the embodiment of the present invention includes:
  • the first receiving module 401 is configured to receive a first PADI broadcast message that is sent by the client device and that carries the first identity information of the user, where the first identity information of the user is an identifier of the user of the client device in the network system.
  • the first PADI broadcast message is used to request a PPPOE server service;
  • the first sending module 402 is configured to send a second PADI when determining that the first identity information of the user carried in the first PADI broadcast message received by the first receiving module 401 matches the identity of the virtual access router Broadcasting the message to the PPPOE server, where the second PADI broadcast message is used to request the PPPOE server service;
  • the second sending module 403 is configured to: after receiving the first PADO response message returned by the PPPOE server, send a second PADO response message carrying routing identity information to the client device, where the routing identity information is Describe the identifier of the virtual access router in the network system;
  • the forwarding module 404 is configured to forward, by using the first session and the second session, after establishing a first session with the PPPOE server and a second session with the client device
  • the second identity information of the user sent by the client device is sent to the PPPOE server for identity authentication, where the second identity information of the user includes the first identity information of the user;
  • the interrupting module 405 is configured to interrupt the first session with the client device when receiving the authentication failure message sent by the PPPOE server.
  • the second identity information of the user may further include information such as a user password, and/or port information of the intermediate agent on the PPPOE+ transmission line (which may indicate client location information), and is not limited herein.
  • the first sending module is only determined when the first identity information of the user in the first PADI broadcast message sent by the client received by the first receiving module 401 is matched with the identity of the virtual access router.
  • the second PADI broadcast message is sent to the PPPOE server to request the PPPOE server service, and the second sending module 403 further needs to send a second PADO response message carrying the routing identity information to the client device, where the virtual device is used by the client device.
  • the identity of the access router is authenticated, and through such mutual authentication, the client is guaranteed. The security of the access link between the standby and virtual access routers.
  • the forwarding module 404 forwards the user sent by the client device through the first session and the second session.
  • the second identity information is sent to the PPPOE server for identity authentication. If the authentication fails, the authentication failure message sent by the PPPOE server is received, and the interruption module 405 immediately interrupts the first session with the client device, and only passes the PPPOE server.
  • the authenticated client device can continue to perform subsequent processing. In this way, the authentication and authentication of the dial-up enterprise user in the virtual access router scenario is implemented, and the security of the access link is ensured.
  • the virtual access router 400 shown in FIG. 4 may further include:
  • the second receiving module 501 is configured to receive an IP subnet address advertisement request sent by the client device, where the IP subnet address advertisement request is used to request to establish an identifier between the first session and an intranet IP network segment. Mapping, the IP subnet address advertisement request includes an intranet IP network segment of the client device;
  • the saving module 502 is configured to save the identifier of the first session and the intranet after determining the legality of the intranet IP network segment included in the IP subnet address advertisement request received by the second receiving module 501 Binding relationship of the IP network segment;
  • the third sending module 503 is configured to send an IP subnet address notification response to the client device after the saving module 502 saves the binding relationship between the identifier of the first session and the intranet IP network segment.
  • the storage module 502 binds the identifier of the first session to the IP network segment of the internal network, and implements interworking between the devices in the intranet connected to the client device in the virtual router scenario and the PPPOE network.
  • an embodiment of the client device 600 in the embodiment of the present invention includes:
  • the fourth sending module 601 is configured to send, in the network system, a first PADI broadcast message carrying the first identity information of the user, where the first PADI broadcast message is used to request a PPPoE server service, where the user first identity information An identifier for the user of the client device in the network system;
  • the third receiving module 602 is configured to receive a second PADO response message that is sent by the virtual access router and carries the routing identity information, where the routing identity information is a unique identifier of the virtual access router in the network system.
  • the establishing module 603 is configured to establish, when the routing identity information carried in the second PADO response message received by the third receiving module 602 matches the first identity information of the user, between the virtual access router and the virtual access router. First session;
  • the fifth sending module 604 is configured to send the second identity of the user by using the first session established by the establishing module 603.
  • the information is sent to the virtual access router, so that the virtual access router forwards the second identity information of the user to the PPPOE server for identity authentication.
  • the second identity information of the user may further include information such as a user password, and/or port information of the intermediate agent on the PPPOE+ transmission line (which may indicate client location information), and is not limited herein.
  • the client device may be a thin client ThinCPE or a dial-up PC, which is not limited herein.
  • the fourth sending module 601 sends the first PADI broadcast message carrying the first identity information of the user to the virtual access router, so that the virtual access router authenticates the first identity information of the user, and after the authentication is passed,
  • the third receiving module 602 can receive the second PADO response message that is sent by the virtual access router and carries the routing identity information, and authenticates the routing identity information.
  • the establishing module 603 starts the session establishing process.
  • the fifth sending module 604 further sends the third user identity information including the first identity information of the user to the PPPOE server for authentication, and implements authentication and authentication for the dial-up enterprise user in the scenario of the virtual access router. The security of the access link.
  • the client device 600 in the embodiment shown in FIG. 6 may further include:
  • the obtaining module 701 is configured to obtain, by using a DHCP server, a configuration of an intranet IP network segment;
  • the sixth sending module 702 is configured to send an IP subnet address advertisement request to the virtual access router according to the configuration of the intranet IP network segment acquired by the obtaining module 701, where the IP subnet address advertisement request is used for the request.
  • the virtual access router establishes a mapping between the identifier of the first session and the intranet IP network segment.
  • the DHCP server may exist independently or may be configured on the client device, which is not limited herein.
  • the obtaining module 701 obtains the configuration of the intranet IP network segment from the DHCP server, and implements the network interworking requirement between the intranet devices, so that even if the access network fails, the devices in the intranet of the enterprise also Can communicate normally.
  • the sixth sending module 702 establishes a mapping between the identifier of the first session and the intranet IP network segment by using the IP subnet address advertisement request, and implements the intranet connected to the client device in the virtual router scenario. The device communicates with the PPPOE network.
  • an embodiment of the present invention provides another virtual access router 800, including a memory 801, a processor 802, a receiver 803, and a transmitter 804 respectively connected to a bus, where:
  • the memory 801 is used to store information such as necessary files for storing the data processed by the processor 802, such as program code for storing the method for performing the identity authentication shown in FIG. 2 by the processor 802.
  • the processor 802 is configured to call the program code stored in the memory 801 to implement the following functions:
  • the control receiver 803 receives the first PADI broadcast message that is sent by the client device and carries the first identity information of the user, where the first identity information of the user is an identifier of the user of the client device in the network system, where the A PADI broadcast message is used to request a PPPOE server service;
  • the virtual access router determines that the first identity information of the user matches the identity of the virtual access router, the virtual access router sends a second PADI broadcast message to the PPPOE server, and the second PADI broadcast The message is used to request the PPPOE server service;
  • the control transmitter 804 sends a second PADO response message carrying the routing identity information to the client device, where the routing identity information is An identifier of the virtual access router in the network system;
  • the receiver 803 receives the authentication failure message sent by the PPPOE server, interrupting the first session with the client device;
  • processor 802 can also implement the following functions:
  • the control receiver 803 receives an IP subnet address advertisement request sent by the client device, where the IP subnet address advertisement request is used to request to establish a mapping between the identifier of the first session and an intranet IP network segment.
  • the IP subnet address advertisement request includes an intranet IP network segment of the client device;
  • the binding relationship between the identifier of the first session and the intranet IP network segment is saved to the memory 801, and the transmitter 804 is controlled to send to the client device. IP subnet address advertisement response.
  • the embodiment of the present invention further provides another client device, which has a structure similar to that of the virtual access router in FIG. 8 , and includes: a memory, a processor, a receiver, and a transmitter respectively connected to the bus, where:
  • the memory is used to store information such as necessary files for storing the processor to process data, such as program code for storing a method for executing the identity authentication shown in FIG.
  • a processor for calling program code stored in the memory to implement the following functions:
  • the control transmitter sends a first PADI broadcast message carrying the first identity information of the user in the network system, where the first PADI broadcast message is used to request the PPPoE server service, and the first identity information of the user is the client The identity of the user of the device in the network system;
  • the control receiver receives the second PADO response message sent by the virtual access router and carries the routing identity information.
  • the routing identity information is a unique identifier of the virtual access router in the network system;
  • the control transmitter sends the user second identity information to the virtual access router through the first session, so that the virtual access router forwards the user second identity information to the PPPOE server for identity authentication.
  • the processor can also implement the following functions:
  • control transmitter sends an IP subnet address advertisement request to the virtual access router according to the configuration of the intranet IP network segment, where the IP subnet address advertisement request is used to request the virtual access router to establish the A mapping between the identity of a session and the intranet IP network segment.
  • the DHCP server may be configured on the client device, which is not limited herein.
  • the embodiment of the invention further provides an identity authentication system, including:
  • the disclosed system, apparatus, and method may be implemented in other manners.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • the technical solution of the present invention is essentially Or the portion contributing to the prior art or all or part of the technical solution may be embodied in the form of a software product stored in a storage medium, including a plurality of instructions for causing a computer device ( It may be a personal computer, a server, or a network device, etc.) performing all or part of the steps of the method described in various embodiments of the present invention.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like, which can store program code. .

Abstract

本发明实施例公开了身份认证方法和相关设备,用于实现虚拟接入路由器场景下对拨号企业用户的认证和鉴权。本发明实施例方法包括:虚拟接入路由器只有在确定接收到的客户端发送的第一PADI广播报文中的用户第一身份信息与该虚拟接入路由器的身份相匹配时,才发送第二PADI广播报文到PPPOE服务器请求PPPOE服务器服务,虚拟接入路由器还需要发送携带有路由身份信息的第二PADO应答消息给客户端设备进行路由身份信息的验证;虚拟接入路由器建立与PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,通过该第一会话和第二会话,转发客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证。

Description

身份认证方法、身份认证系统和相关设备
本申请要求于2015年6月4日提交中国专利局、申请号为201510304341.2、发明名称为“身份认证方法、身份认证系统和相关设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及通信领域,尤其涉及身份认证方法、身份认证系统和相关设备。
背景技术
传统的接入路由器(access router,AR)放置在用户(企业)侧,用户在AR上进行以太网上的点对点协议(Point-to-Point Protocol over Ethernet,PPPoE)拨号,运营商网络设备对用户进行认证和鉴权,认证通过后为其广域网(wide area network,WAN)口分配公网网络之间互连的协议(Internet Protocol,IP)地址。其中,PPPoE协议提供了在以太网网络中多台主机连接到远端的宽带接入服务器上的一种标准。其本质是在以太网上建立一个点对点的隧道,具有用户认证和IP地址通知功能。在传统的AR上进行PPPoE拨号,即可以完成对用户的认证,运营商网络设备为AR的WAN口分配公网的IP地址。
虚拟接入路由器(virtual AR,vAR)将AR的大部分功能,如IP路由,网络地址转换(network address translation,NAT),防火墙,上移到运营商网络,用户侧的瘦用户驻地设备(thin customer-premises equipment,ThinCPE)只保留简单的接入功能。用户从运营商处购买vAR,购买成功后此台vAR专为此用户服务(根据用户所选套餐具有不同的功能服务)。用户到其购买的vAR之间需要经过运营商的接入网,这是一个二层网络。为支持PPPoE拨号认证,目前通常思路是将vAR作为PPPoE客户端通过PPPoE服务器,例如,宽带远程接入服务器(Broadband Remote Access Server,BRAS),进行认证。
然而,在虚拟接入路由器场景下,采用这种方式进行认证,会使得企业用户侧和vAR之间的接入链路得不到认证,安全性没有保证。
发明内容
本发明实施例提供了身份认证方法、身份认证系统和相关设备,用于实现虚拟接入 路由器场景下对拨号企业用户的认证和鉴权。
本发明实施例第一方面提供了一种身份认证方法,应用于包括有虚拟接入路由器的网络系统,所述网络系统中还包括客户端设备和PPPOE服务器,包括:
虚拟接入路由器接收客户端设备发送的携带有用户第一身份信息的第一PADI广播报文,所述用户第一身份信息为所述客户端设备的用户在网络系统中的标识,所述第一PADI广播报文用于请求PPPOE服务器服务;
当所述虚拟接入路由器确定所述用户第一身份信息与所述虚拟接入路由器的身份相匹配时,所述虚拟接入路由器发送第二PADI广播报文到PPPOE服务器,所述第二PADI广播报文用于请求PPPOE服务器服务;
当所述虚拟接入路由器接收到所述PPPOE服务器返回的第一PADO应答消息后,所述虚拟接入路由器发送携带有路由身份信息的第二PADO应答消息给所述客户端设备,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的标识;
当所述虚拟接入路由器建立与所述PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,所述虚拟接入路由器通过所述第一会话和所述第二会话,转发所述客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息;
当所述虚拟接入路由器接收到所述PPPOE服务器发送的认证失败消息时,所述虚拟接入路由器中断与所述客户端设备之间的所述第一会话。
结合本发明实施例的第一方面,本发明实施例第一方面的第一种实现方式中,所述方法还包括:
所述虚拟接入路由器接收所述客户端设备发送的IP子网地址通告请求,所述IP子网地址通告请求用于请求建立所述第一会话的标识与内网IP网段之间的映射,所述IP子网地址通告请求中包含所述客户端设备的内网IP网段;
当虚拟接入路由器确定所述内网IP网段的合法性后,所述虚拟接入路由器保存所述第一会话的标识与所述内网IP网段的绑定关系,并向所述客户端设备发送IP子网地址通告应答。
本发明实施例第二方面提供了一种身份认证方法,用于包括有虚拟接入路由器的网络系统,所述网络系统中还包括客户端设备和PPPOE服务器,包括:
客户端设备在网络系统中发送携带有用户第一身份信息的第一PADI广播报文,所述第一PADI广播报文用于请求PPPoE服务器服务,所述用户第一身份信息为所述客户端设备的用户在所述网络系统中的标识;
所述客户端设备接收虚拟接入路由器发送的携带有路由身份信息的第二PADO应答消息,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的唯一标识;
当所述客户端设备确定所述路由身份信息与所述用户第一身份信息匹配时,所述客户端设备建立与所述虚拟接入路由器之间的第一会话;
所述客户端设备通过所述第一会话发送用户第二身份信息给所述虚拟接入路由器,使得所述虚拟接入路由器将所述用户第二身份信息转发到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息。
结合本发明实施例的第二方面,本发明实施例第二方面的第一种实现方式中,所述网络系统中还包括DHCP服务器,所述方法还包括:
所述客户端设备从所述DHCP服务器获取内网IP网段的配置;
所述客户端设备根据所述内网IP网段的配置,向所述虚拟接入路由器发送IP子网地址通告请求,所述IP子网地址通告请求用于请求所述虚拟接入路由器建立所述第一会话的标识与所述内网IP网段之间的映射。
本发明实施例第三方面提供了一种虚拟接入路由器,包括:
第一接收模块,用于接收客户端设备发送的携带有用户第一身份信息的第一PADI广播报文,所述用户第一身份信息为所述客户端设备的用户在网络系统中的标识,所述第一PADI广播报文用于请求PPPOE服务器服务;
第一发送模块,用于当确定所述第一接收模块接收到的第一PADI广播报文中携带的用户第一身份信息与所述虚拟接入路由器的身份相匹配时,发送第二PADI广播报文到PPPOE服务器,所述第二PADI广播报文用于请求PPPOE服务器服务;
第二发送模块,用于当接收到所述PPPOE服务器返回的第一PADO应答消息后,发送携带有路由身份信息的第二PADO应答消息给所述客户端设备,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的标识;
转发模块,用于当建立与所述PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,通过所述第一会话和所述第二会话,转发所述客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息;
中断模块,用于当接收到所述PPPOE服务器发送的认证失败消息时,中断与所述客户端设备之间的所述第一会话。
结合本发明实施例的第三方面,本发明实施例第三方面的第一种实现方式中,所述虚拟接入路由器还包括:
第二接收模块,用于接收所述客户端设备发送的IP子网地址通告请求,所述IP子网地址通告请求用于请求建立所述第一会话的标识与内网IP网段之间的映射,所述IP子网地址通告请求中包含所述客户端设备的内网IP网段;
保存模块,用于当确定所述第二接收模块接收到的IP子网地址通告请求中包含的内网IP网段的合法性后,保存所述第一会话的标识与所述内网IP网段的绑定关系;
第三发送模块,用于在所述保存模块保存所述第一会话的标识与所述内网IP网段的绑定关系后,向所述客户端设备发送IP子网地址通告应答。
本发明实施例第四方面提供了一种客户端设备,包括:
第四发送模块,用于在网络系统中发送携带有用户第一身份信息的第一PADI广播报文,所述第一PADI广播报文用于请求PPPoE服务器服务,所述用户第一身份信息为所述客户端设备的用户在所述网络系统中的标识;
第三接收模块,用于接收虚拟接入路由器发送的携带有路由身份信息的第二PADO应答消息,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的唯一标识;
建立模块,用于当确定第三接收模块接收的第二PADO应答消息中携带的所述路由身份信息与所述用户第一身份信息匹配时,建立与所述虚拟接入路由器之间的第一会话;
第五发送模块,用于通过所述建立模块建立的第一会话发送用户第二身份信息给所述虚拟接入路由器,使得所述虚拟接入路由器将所述用户第二身份信息转发到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息。
结合本发明实施例的第四方面,本发明实施例第四方面的第一种实现方式中,所述客户端设备还包括:
获取模块,用于从DHCP服务器获取内网IP网段的配置;
第六发送模块,用于根据所述获取模块获取的内网IP网段的配置,向所述虚拟接入路由器发送IP子网地址通告请求,所述IP子网地址通告请求用于请求所述虚拟接入路由器建立所述第一会话的标识与所述内网IP网段之间的映射。
本发明实施例第五方面提供了一种身份认证系统,包括:
PPPOE服务器,本发明实施例的第三方面或第三方面的第一种实现方式中所述的虚拟接入路由器,以及本发明实施例的第四方面或第四方面的第一种实现方式中所述的客户端设备。
从以上技术方案可以看出,本发明实施例具有以下优点:本发明实施例中,虚拟接入路由器只有在确定接收到的客户端发送的第一PADI广播报文中的用户第一身份信息 与该虚拟接入路由器的身份相匹配时,才发送第二PADI广播报文到PPPOE服务器请求PPPOE服务器服务,虚拟接入路由器还需要发送携带有路由身份信息的第二PADO应答消息给客户端设备,由客户端设备对该虚拟接入路由器的身份进行认证,通过这样的相互认证,保证了客户端设备与虚拟接入路由器之间接入链路的安全性。虚拟接入路由器建立与PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,通过该第一会话和第二会话,转发客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,如果认证不通过,虚拟接入路由器接收到PPPOE服务器发送的认证失败消息,则该虚拟接入路由器立即中断与该客户端设备之间第一会话,只有能通过PPPOE服务器的认证的客户端设备才能继续进行后续处理,这样,实现虚拟接入路由器场景下对拨号企业用户的认证和鉴权。
附图说明
图1为本发明实施例中身份认证方法一个信令流程示意图;
图2为本发明实施例中身份认证方法一个流程示意图;
图3为本发明实施例中身份认证方法一个流程示意图;
图4为本发明实施例中虚拟接入路由器一个结构示意图;
图5为本发明实施例中虚拟接入路由器另一个结构示意图;
图6为本发明实施例中客户端设备一个结构示意图;
图7为本发明实施例中客户端设备另一个结构示意图;
图8为本发明实施例中虚拟接入路由器另一个结构示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
本发明实施例提供了一种身份认证方法,应用于包括有虚拟接入路由器,客户端设备和PPPOE服务器的网络系统中,用于实现虚拟接入路由器场景下对拨号企业用户的认证和鉴权。
本发明实施例中出现的:
PADI为PPPoE Active Discovery Initiation的缩写,表示PPPoE主动发现初始包;
PADO为PPPoE Active Discovery Offer的缩写,表示PPPoE主动发现提议包;
PADR为PPPoE Active Discovery Request的缩写,表示PPPoE主动发现请求包;
PADS为PPPoE Active Discovery Session-confirmation PPPoE的缩写,表示主动发现会话确认包;
DHCP为Dynamic Host Configuration Protocol的缩写,表示动态主机配置协议;
WAN为wide area network的缩写,表示广域网。
下面从该网络系统中虚拟接入路由器,客户端设备和PPPOE服务器这三个设备的信令交互的角度,对本发明实施例中身份认证方法进行描述:
请参阅图1,本发明实施例中身份认证方法一个实施例包括:
101、客户端设备在网络系统中发送携带有用户第一身份信息的第一PADI广播报文;
其中,所述第一PADI广播报文用于请求PPPoE服务器服务,所述用户第一身份信息为所述客户端设备的用户在所述网络系统中的唯一标识;
可选的,该用户第一身份信息可以为运营商分配的全网唯一的用户的账户名,或者可以为其它能够唯一标识该用户的标识ID,此处不作限定。
可以理解的是,在实际应用中,各设备发送的报文都可以携带源(发送方)MAC地址,和目的(接收方)MAC地址。例如,该第一PADI广播报文的源MAC地址可以为该客户端设备的MAC地址,目的MAC地址可以为广播地址,即对网络系统中所有与之相连的网络设备发送。
102、虚拟接入路由器确定所述用户第一身份信息与该虚拟接入路由器的身份相匹配;
本步骤中,网络系统中的虚拟接入路由器可以接收客户端设备发送的第一PADI广播报文,可以理解的是,网络系统中虚拟接入路由器的数目可以为多个,每个接收到该第一PADI广播报文的虚拟接入路由器,都可以判断该第一PADI广播报文中的用户第一身份信息是否与该虚拟接入路由器的身份相匹配,只有确定该用户第一身份信息与该虚拟接入路由器的身份相匹配的虚拟接入路由器才执行步骤103。
需要说明的是,虚拟接入路由器是用户从运营商处购买的,运营商创建虚拟接入路由器时已经在虚拟接入路由器上分配了与之匹配的用户第一身份信息。
103、所述虚拟接入路由器发送第二PADI广播报文到所述PPPOE服务器;
只有在虚拟接入路由器确定第一PADI广播报文中的用户第一身份信息与该虚拟接入路由器的身份相匹配时,该虚拟接入路由器才发送第二PADI广播报文到PPPOE服务 器,请求PPPOE的服务。
可以理解的是,确定用户第一身份信息与该虚拟接入路由器的身份信息相匹配后,该虚拟接入路由器可以记录发送该第一PADI广播报文的客户端设备的MAC地址。
本步骤中,该第二PADI广播报文的源MAC地址可以为该虚拟接入路由器的MAC地址,目的MAC地址可以为广播地址。网络系统中的各网络设备可能都能接收到该第二PADI广播报文,然而只有其中的PPPOE服务器能识别该第二PADI广播报文并给予反馈。
104、所述PPPOE服务器接收到所述虚拟接入路由器发送的第二PADI广播报文后,发送第一PADO应答消息给所述虚拟接入路由器;
PPPOE服务器接收到虚拟接入路由器发送的用于请求PPPOE服务器服务的第二PADI广播报文后,若同意提供服务,则向该虚拟接入路由器发送第一PADO应答消息,用于应答该第二PADI广播报文的服务请求。
本步骤中,该第一PADO应答消息的源MAC地址为该PPPOE服务器,目的MAC地址为该发出第二PADI广播报文的虚拟接入路由器。
105、所述虚拟接入路由器接收到所述PPPOE服务器发送的第一PADO应答消息后,发送携带有路由身份信息的第二PADO应答消息给所述客户端设备,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的唯一标识;
该虚拟接入路由器接收到PPPOE服务器发出的第一PADO应答消息后,可以记录该第一PADO应答消息中携带的PPPOE服务器的MAC地址,然后发送携带有路由身份信息的第二PADO应答消息给该客户端设备。
其中,该路由身份信息为该虚拟接入路由器在该网络系统中的唯一标识,该路由身份信息用于客户端设备认证与该虚拟接入路由器的身份一致性。
该第二PADO应答消息的源MAC地址为该虚拟接入路由器,目的MAC地址为发出第一PADI广播报文的客户端设备的MAC地址。
106、客户端设备确定接收到的所述路由身份信息与所述用户第一身份信息匹配;
客户端设备接收到第二PADO应答消息后,认证该第二PADO应答消息中携带的路由身份信息与自己的用户第一身份信息是否匹配,确定该路由身份信息与用户第一身份信息匹配后,才执行后续会话建立流程。
107、客户端设备向所述虚拟接入路由器发送第一PADR请求消息,所述第一PADR请求消息用于请求与所述虚拟接入路由器建立会话;
客户端设备确定接收到的路由身份信息与自己的用户第一身份信息相匹配后,该客 户端设备向该虚拟接入路哟器发送第一PADR请求消息,该第一PADR请求消息用于请求与该虚拟接入路由器建立会话。
该第一PADR请求消息的源MAC地址为该客户端设备的MAC地址,目的MAC地址为该身份匹配的虚拟接入路由器的MAC地址。
108、所述虚拟接入路由器接收到所述客户端设备发送的第一PADR请求消息后,向所述PPPOE服务器发送第二PADR请求消息,所述第二PADR请求消息用于请求与所述PPPOE服务器建立会话;
虚拟接入路由器接收到客户端设备发送的用于请求建立会话的第一PADR请求消息后,需要先确定是否能与PPPOE服务器建立会话,则该虚拟接入路由器向PPPOE服务器发送第二PADR请求消息,该第二PADR请求消息用于请求与PPPOE服务器建立会话。
该第二PADR请求消息的源MAC地址为该虚拟接入路由器的MAC地址,目的MAC地址为该PPPOE服务器的MAC地址。
109、所述PPPOE服务器接收到所述第二PADR请求消息后,发送第二PADS确认消息给所述虚拟接入路由器,所述第二PADS确认消息用于确认与所述虚拟接入路由器建立会话;
该PPPOE服务器接收到虚拟接入路由器发送的请求建立会话的第二PADR请求消息后,若同意建立会话,则发送第二PADS确认消息给该虚拟接入路由器,该第二PADS确认消息用于确认与该虚拟接入路由器建立会话。
该第二PADS确认消息的源MAC地址为该PPPOE服务器的MAC地址,目的MAC地址为该虚拟接入路由器的MAC地址。
110、所述虚拟接入路由器接收到所述PPPOE服务器发送的第二PADS确认消息后,与所述PPPOE服务器建立第一会话,发送第一PADS确认消息给所述客户端设备,与所述客户端设备建立第二会话,所述第一PADS确认消息中包含有为所述客户端设备分配的会话ID;
虚拟接入路由器接收到PPPOE服务器发送的第二PADS确认消息后,即建立与该PPPOE服务器建立第一会话,并可以保存该第一会话的信息,该第一会话的信息中包括该第一会话的ID,此时可以对客户端设备发出的第一PADR请求消息进行反馈,发送第一PADS确认消息给该客户端设备,确认与该客户端设备建立第二会话,并可以保存该第二会话的信息。该客户端设备与虚拟接入路由器之间的第一会话和虚拟接入路由器与PPPOE服务器之间的第二会话这二层会话组成了该客户端设备到PPPOE服务器之间 的PPPOE会话。
需要说明的是,各会话都有唯一标识该会话的会话ID,虚拟接入路由器与客户端设备之间会话的会话ID由虚拟接入路由器分配,发送给客户端设备的第一PADS确认消息中包含有该虚拟接入路由器为该客户端设备分配的会话ID,作为该第二会话的会话ID,保存的第一会话的信息中包含有该会话ID的信息。虚拟接入路由器与PPPOE服务器之间的会话ID由PPPOE服务器分配,发送给虚拟接入路由器的第二PADS确认消息中包含有该PPPOE服务器为该虚拟接入路由器分配的会话ID,作为该第一会话的会话ID。
该第一PADS确认消息的源MAC地址为该虚拟接入路由器的MAC地址,目的MAC地址为该客户端设备的MAC地址。
111、所述客户端设备接收到所述虚拟接入路由器发送的所述第一PADS确认消息后,通过所述第一会话和所述第二会话发送所述用户第二身份信息到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息。
客户端设备接收到该虚拟接入路由器发送的第一PADS确认消息后,表示客户端设备与虚拟接入路由器之间的第一会话已经建立,客户端设备通过该第一会话,发送用户第二身份信息到该虚拟接入路由器,由虚拟接入路由器通过与PPPOE服务器间的第三会话,转发该用户第二身份信息到PPPOE服务器进行身份认证,该用户第二身份信息中包括用户第一身份信息。
可以理解的是,该PPPOE服务器会对接收到的该用户第二身份信息进行鉴权,认证等操作。
具体的,运营商网络中RADIUS中存放了用户的用户名、密码、位置信息等信息。PPPoE服务器可以将该用户第二身份信息与RADIUS服务器中的用户合法信息做对比认证。
可选的,该用户第二身份信息还可以包括用户密码,和/或PPPOE+传输线路上中间代理的端口信息(可以表示客户端位置信息)等信息,此处不作限定。
PPPOE服务器对发送的用户第二身份信息进行认证后,会反馈认证结果给虚拟接入路由器:
若所述虚拟接入路由器接收到所述PPPOE服务器发送的认证失败消息,则该虚拟接入路由器中断与所述客户端设备之间的第一会话。
若该虚拟接入路由器接收到该PPPOE服务器发送的认证成功消息,则虚拟接入路由器维持该第一会话和第二会话,可以继续进行其他处理。
本发明实施例中,步骤101至步骤111实现了虚拟接入路由器场景下对拨号企业用户的认证和鉴权,提升了虚拟接入路由器场景下接入链路的安全性,同时实现了虚拟接入路由器场景下对PPPOE+传输线路上中间代理的端口信息的认证。
在实际应用中,客户端设备的身份认证成功后,客户端设备发送一条新的WAN口地址配置请求消息,请求虚拟接入路由器的WAN口去获取公网IP地址。虚拟接入路由器WAN口获取公网IP地址后发送WAN口地址配置应答消息,但公网IP地址不发送给客户端设备,在虚拟接入路由器上保存公网IP地址等配置信息。
可选的,为了实现与客户端设备相连的企业内网互通的需求,图1所述实施例还可以包括如下步骤:
112、所述客户端设备从DHCP服务器获取内网IP网段的配置;
客户端设备可以从内网的DHCP服务器(部署在企业内部)获取内网IP网段的配置。
可选的,该DHCP服务器可以配置在该客户端设备上,也可以独立存在,此处不作限定。
其中,内网IP网段,是指在企业侧内部处于同一个IP网络的地址段,采用网段IP地址加上子网掩码来标识一个网段。
113、所述客户端设备根据所述内网IP网段的配置,向所述虚拟接入路由器发送IP子网地址通告请求,所述IP子网地址通告请求用于请求所述虚拟接入路由器建立所述第一会话的ID与所述内网IP网段的映射;
客户端设备根据获取到的内网IP网段的配置,向虚拟接入路由器发送IP子网地址通告请求,该IP子网地址通告请求用于请求该虚拟接入路由器建立该第一会话的ID与内网IP网段的映射。
具体的,该IP子网地址通告请求用于建立PPPoE会话(第一会话与第二会话二层)与内部IP网段之间的映射,假设有多个客户端设备拨号,一台虚拟接入路由器与多个客户端设备之间有多路会话,而从公网到内网方向,数据包是没有内网的目的MAC地址的,只有内网的目的IP地址,所以需要从IP地址映射到某一路PPPoE会话,进而确定目的MAC。
可以理解的是,从网络往客户端设备方向的报文在到达虚拟接入路由器之前,目的IP是虚拟接入路由器WAN口的IP地址,虚拟接入路由器WAN口收到报文后,在虚拟接入路由器上经过NAT地址转换目的IP转换为内网的IP地址。而各路PPPOE会话由会话ID、源地址和目的MAC地址标识,此时的报文中不携带虚拟接入路由器到客户 端设备之间的会话信息,因此需要建立内网IP子网地址到PPPoE会话的绑定关系。
114、所述虚拟接入路由器接收到所述IP子网地址通告请求后,检测所述内网IP网段的合法性,保存所述第一会话的ID与所述内网IP网段的绑定关系,向所述客户端设备发送IP子网地址通告应答。
虚拟接入路由器接收到客户端设备发送的IP子网地址通告请求后,检测该IP子网地址通告请求中内网IP网段的合法性,确定合法性满足后,保存该第一会话的ID与内网IP网段的绑定关系,再向客户端设备发送IP子网地址通告应答。
可以理解的是,客户端设备接收到IP子网地址通告应答后,还可以进一步获取其它配置。配置完成后,内网的企业侧用户可以从DHCP服务器获取内网IP配置信息,并接入该客户端设备,开始正常的数据通信。
该客户端设备还可以发送子网地址配置通告请求,通告接入该客户端设备的企业侧用户DHCP服务器上配置的子网和掩码(IP地址段)。
可选的,在本实施例中,该客户端设备可以为瘦客户端ThinCPE,也可以为具备拨号功能的PC,此处不作限定。
在实际应用中,企业IT管理员可以持有企业用户账号,该企业IT管理员可以利用该企业用户账号到PPPOE服务器认证,完成企业外网的配置。企业内网中持有员工账号的员工的PC需要在该企业IT管理员完成企业外网的配置后,才能联网。
同时,该企业内网中或该企业购买的虚拟接入路由器中还可以保存有企业员工数据库,企业中员工通过该虚拟接入路由器访问网络时,该虚拟路由器可以对该员工进行认证。具体的,该虚拟接入路由器可以将访问网络的员工发送的身份信息与存储的企业员工数据库中用户合法信息做对比认证,此处不作限定。
本发明实施例中,步骤112至114中,通过PPPOE会话ID的绑定,实现了在虚拟路由器场景下与客户端设备相连的企业内网中各设备与PPPOE的网络互通,通过DHCP分配的内网IP网段的配置,实现了各内网设备之间网络互通的需求,使得即使接入网故障,企业内网中各设备之间也能正常通信。
下面分别从客户端设备和虚拟接入路由器的角度,对本发明实施例中身份认证的方法进行描述:
一、从虚拟接入路由器的角度:
请参阅图2,本发明实施例中身份认证的方法另一个实施例包括:
201、虚拟接入路由器接收客户端设备发送的携带有用户第一身份信息的第一PADI广播报文;
其中,所述用户第一身份信息为所述客户端设备的用户在网络系统中的标识,所述第一PADI广播报文用于请求PPPOE服务器服务。
202、当所述虚拟接入路由器确定所述用户第一身份信息与该虚拟接入路由器的身份相匹配时,所述虚拟接入路由器发送第二PADI广播报文到所述PPPOE服务器,所述第二PADI广播报文用于请求PPPOE服务器服务;
与步骤102和103类似,此处不作赘述。
203、当所述虚拟接入路由器接收到所述PPPOE服务器返回的第一PADO应答消息后,所述虚拟接入路由器发送携带有路由身份信息的第二PADO应答消息给所述客户端设备,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的标识;
与步骤105类似,此处不作赘述。
204、当所述虚拟接入路由器建立与所述PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,所述虚拟接入路由器通过所述第一会话和所述第二会话,转发所述客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息;
本步骤中,第一会话和第二会话的建立过程与步骤108至步骤110类似,此处不作赘述。
该第一会话和第二会话建立后,虚拟接入路由器可以转发客户端设备发送的用户第二身份信息到PPPOE服务器进行身份认证,该用户第二身份信息中包括客户端设备的用户第一身份信息。
可以理解的是,该PPPOE服务器会对接收到的该用户第二身份信息进行鉴权,认证等操作。
具体的,运营商网络中RADIUS中存放了用户的用户名、密码、位置信息等信息。PPPoE服务器可以将该用户第二身份信息与RADIUS服务器中的用户合法信息做对比认证。
可选的,该用户第二身份信息还可以包括用户密码,和/或PPPOE+传输线路上中间代理的端口信息(可以表示客户端位置信息)等信息,此处不作限定。
PPPOE服务器对发送的用户第二身份信息进行认证后,会反馈认证结果给虚拟接入路由器:
若结果为认证成功,则虚拟接入路由器维持该第一会话和第二会话,可以继续进行其他处理。
若结果为认证失败,则触发步骤205。
205、当所述虚拟接入路由器接收到所述PPPOE服务器发送的认证失败消息时,所述虚拟接入路由器中断与所述客户端设备之间的所述第一会话。
本发明实施例中,虚拟接入路由器只有在确定接收到的客户端发送的第一PADI广播报文中的用户第一身份信息与该虚拟接入路由器的身份相匹配时,才发送第二PADI广播报文到所述PPPOE服务器请求PPPOE服务器服务,虚拟接入路由器还需要发送携带有路由身份信息的第二PADO应答消息给客户端设备,由客户端设备对该虚拟接入路由器的身份进行认证,通过这样的相互认证,保证了客户端设备与虚拟接入路由器之间接入链路的安全性。虚拟接入路由器建立与PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,通过该第一会话和第二会话,转发客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,如果认证不通过,虚拟接入路由器接收到PPPOE服务器发送的认证失败消息,则该虚拟接入路由器立即中断与该客户端设备之间第一会话,只有能通过PPPOE服务器的认证的客户端设备才能继续进行后续处理,这样,实现虚拟接入路由器场景下对拨号企业用户的认证和鉴权,保证了接入链路的安全性。
可选的,作为本发明实施例中身份认证的方法另一个实施例,图2所示实施例中中第三用户身份信息认证成功后,该虚拟接入路由器还可以接收客户端设备发送的IP子网地址通告请求,所述IP子网地址通告请求用于请求建立所述第一会话的标识与内网IP网段之间的映射,所述IP子网地址通告请求中包含所述客户端设备的内网IP网段;当虚拟接入路由器确定所述内网IP网段的合法性后,所述虚拟接入路由器保存所述第一会话的标识与所述内网IP网段的绑定关系,并向所述客户端设备发送IP子网地址通告应答。
与步骤114类似,此处不作赘述。
本发明实施例中,通过将第一会话的标识与内网IP网段的绑定,实现了虚拟路由器场景下与客户端设备相连的企业内网中各设备与PPPOE的网络互通。
二、从客户端设备的角度:
请参阅图3,本发明实施例中身份认证的方法另一个实施例包括:
301、客户端设备在网络系统中发送携带有用户第一身份信息的第一PADI广播报文,所述第一PADI广播报文用于请求PPPoE服务器服务,所述用户第一身份信息为所述客户端设备的用户在所述网络系统中的标识;
与步骤101类似,此处不作赘述。
可选的,该客户端设备可以为瘦客户端ThinCPE,也可以为具备拨号功能的PC, 此处不作限定。
302、所述客户端设备接收虚拟接入路由器发送的携带有路由身份信息的第二PADO应答消息,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的唯一标识;
客户端设备接收到第二PADO应答消息后,可以确认该第二PADO应答消息中携带的路由身份信息是否与用户第一身份信息匹配,只有确定匹配时,才执行步骤303。
303、当所述客户端设备确定所述路由身份信息与所述用户第一身份信息匹配时,所述客户端设备建立与所述虚拟接入路由器之间的第一会话;
客户端设备确定路由身份信息与用户第一身份信息匹配时,建立与该虚拟接入路由器之间的第一会话,具体会话建立过程与步骤107至110类似,此处不作赘述。
304、所述客户端设备通过所述第一会话发送用户第二身份信息给所述虚拟接入路由器,使得所述虚拟接入路由器将所述用户第二身份信息转发到所述PPPOE服务器进行身份认证。
客户端设备与虚拟接入路由器之间的第一会话建立完成后,该客户端设备可以通过该第一会话发送用户第二身份信息给所述虚拟接入路由器,使得所述虚拟接入路由器将所述用户第二身份信息转发到所述PPPOE服务器进行身份认证。
可选的,该用户第二身份信息还可以包括用户密码,和/或PPPOE+传输线路上中间代理的端口信息(可以表示客户端位置信息)等信息,此处不作限定。
具体用户第二身份信息的发送过程与认证过程,与步骤111类似,此处不作赘述。
本发明实施例中,客户端设备发送携带有用户第一身份信息的第一PADI广播报文给虚拟接入路由器,使得虚拟接入路由器对该用户第一身份信息进行认证,认证通过后,可以接收虚拟接入路由器发送的携带有路由身份信息的第二PADO应答消息,对该路由身份信息进行认证,认证通过后才开始会话建立过程。在会话建立完成后,还发送包含有用户第一身份信息的第三用户身份信息到PPPOE服务器进行认证,实现虚拟接入路由器场景下对拨号企业用户的认证和鉴权,保证了接入链路的安全性。
可选的,作为本发明实施例中身份认证方法另一个实施例,该网络系统中还可以包括有DHCP服务器,图3所示实施例中第三用户身份信息认证成功后,所述客户端设备可以从所述DHCP服务器获取内网IP网段的配置;所述客户端设备根据所述内网IP网段的配置,向所述虚拟接入路由器发送IP子网地址通告请求,所述IP子网地址通告请求用于请求所述虚拟接入路由器建立所述第一会话的标识与所述内网IP网段之间的映射。
与步骤113类似,此处不作赘述。
可选的,该DHCP服务器可以独立存在,也可以配置在该客户端设备上,此处不作限定。
本发明实施例中,客户端设备从DHCP服务器获取内网IP网段的配置,实现了各内网设备之间网络互通的需求,使得即使接入网故障,企业内网中各设备之间也能正常通信。通过IP子网地址通告请求请求建立第一会话的标识与所述内网IP网段之间的映射,实现了在虚拟路由器场景下与客户端设备相连的企业内网中各设备与PPPOE的网络互通。
下面对本发明实施例中虚拟接入路由器进行描述,请参阅图4,本发明实施例中虚拟接入路由器400一个实施例包括:
第一接收模块401,用于接收客户端设备发送的携带有用户第一身份信息的第一PADI广播报文,所述用户第一身份信息为所述客户端设备的用户在网络系统中的标识,所述第一PADI广播报文用于请求PPPOE服务器服务;
第一发送模块402,用于当确定所述第一接收模块401接收到的第一PADI广播报文中携带的用户第一身份信息与该虚拟接入路由器的身份相匹配时,发送第二PADI广播报文到PPPOE服务器,所述第二PADI广播报文用于请求PPPOE服务器服务;
第二发送模块403,用于当接收到所述PPPOE服务器返回的第一PADO应答消息后,发送携带有路由身份信息的第二PADO应答消息给所述客户端设备,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的标识;
转发模块404,用于当建立与所述PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,通过所述第一会话和所述第二会话,转发所述客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息;
中断模块405,用于当接收到所述PPPOE服务器发送的认证失败消息时,中断与所述客户端设备之间的所述第一会话。
可选的,该用户第二身份信息还可以包括用户密码,和/或PPPOE+传输线路上中间代理的端口信息(可以表示客户端位置信息)等信息,此处不作限定。
本发明实施例中,只有在确定第一接收模块401接收到的客户端发送的第一PADI广播报文中的用户第一身份信息与该虚拟接入路由器的身份相匹配时,第一发送模块402才发送第二PADI广播报文到所述PPPOE服务器请求PPPOE服务器服务,第二发送模块403还需要发送携带有路由身份信息的第二PADO应答消息给客户端设备,由客户端设备对该虚拟接入路由器的身份进行认证,通过这样的相互认证,保证了客户端设 备与虚拟接入路由器之间接入链路的安全性。虚拟接入路由器建立与PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,转发模块404通过该第一会话和第二会话,转发客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,如果认证不通过,接收到PPPOE服务器发送的认证失败消息,中断模块405立即中断与该客户端设备之间第一会话,只有能通过PPPOE服务器的认证的客户端设备才能继续进行后续处理,这样,实现虚拟接入路由器场景下对拨号企业用户的认证和鉴权,保证了接入链路的安全性。
可选的,请参阅图5,作为本发明实施例中虚拟接入路由器500另一个实施例,上述图4所示虚拟接入路由器400还可以包括:
第二接收模块501,用于接收所述客户端设备发送的IP子网地址通告请求,所述IP子网地址通告请求用于请求建立所述第一会话的标识与内网IP网段之间的映射,所述IP子网地址通告请求中包含所述客户端设备的内网IP网段;
保存模块502,用于当确定所述第二接收模块501接收到的IP子网地址通告请求中包含的内网IP网段的合法性后,保存所述第一会话的标识与所述内网IP网段的绑定关系;
第三发送模块503,用于在所述保存模块502保存所述第一会话的标识与所述内网IP网段的绑定关系后,向所述客户端设备发送IP子网地址通告应答。
本发明实施例中,通过保存模块502将第一会话的标识与内网IP网段的绑定,实现了虚拟路由器场景下与客户端设备相连的企业内网中各设备与PPPOE的网络互通。
下面对本发明实施例中客户端设备进行描述,请参阅图6,本发明实施例中客户端设备600一个实施例包括:
第四发送模块601,用于在网络系统中发送携带有用户第一身份信息的第一PADI广播报文,所述第一PADI广播报文用于请求PPPoE服务器服务,所述用户第一身份信息为所述客户端设备的用户在所述网络系统中的标识;
第三接收模块602,用于接收虚拟接入路由器发送的携带有路由身份信息的第二PADO应答消息,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的唯一标识;
建立模块603,用于当确定第三接收模块602接收的第二PADO应答消息中携带的所述路由身份信息与所述用户第一身份信息匹配时,建立与所述虚拟接入路由器之间的第一会话;
第五发送模块604,用于通过所述建立模块603建立的第一会话发送用户第二身份 信息给所述虚拟接入路由器,使得所述虚拟接入路由器将所述用户第二身份信息转发到所述PPPOE服务器进行身份认证。
可选的,该用户第二身份信息还可以包括用户密码,和/或PPPOE+传输线路上中间代理的端口信息(可以表示客户端位置信息)等信息,此处不作限定。
可选的,该客户端设备可以为瘦客户端ThinCPE,也可以为具备拨号功能的PC,此处不作限定。
本发明实施例中,第四发送模块601发送携带有用户第一身份信息的第一PADI广播报文给虚拟接入路由器,使得虚拟接入路由器对该用户第一身份信息进行认证,认证通过后,第三接收模块602可以接收虚拟接入路由器发送的携带有路由身份信息的第二PADO应答消息,对该路由身份信息进行认证,认证通过后建立模块603才开始会话建立过程。在会话建立完成后,第五发送模块604还发送包含有用户第一身份信息的第三用户身份信息到PPPOE服务器进行认证,实现虚拟接入路由器场景下对拨号企业用户的认证和鉴权,保证了接入链路的安全性。
可选的,请参阅图7,作为本发明实施例中客户端设备700另一个实施例,上述图6所示实施例中客户端设备600还可以包括:
获取模块701,用于从DHCP服务器获取内网IP网段的配置;
第六发送模块702,用于根据所述获取模块701获取的内网IP网段的配置,向所述虚拟接入路由器发送IP子网地址通告请求,所述IP子网地址通告请求用于请求所述虚拟接入路由器建立所述第一会话的标识与所述内网IP网段之间的映射。
可选的,所述DHCP服务器可以独立存在,也可以配置在所述客户端设备上,此处不作限定。
本发明实施例中,获取模块701从DHCP服务器获取内网IP网段的配置,实现了各内网设备之间网络互通的需求,使得即使接入网故障,企业内网中各设备之间也能正常通信。第六发送模块702通过IP子网地址通告请求请求建立第一会话的标识与所述内网IP网段之间的映射,实现了在虚拟路由器场景下与客户端设备相连的企业内网中各设备与PPPOE的网络互通。
请参阅图8,本发明实施例提供了另一种虚拟接入路由器800,包括分别连接到总线的存储器801,处理器802,接收器803和发射器804,其中:
存储器801用来储存储存处理器802处理数据的必要文件等信息,比如储存处理器802执行图2所示的身份认证的方法的程序代码等信息。
处理器802,用于调用存储器801中储存的程序代码,以实现如下功能:
控制接收器803接收客户端设备发送的携带有用户第一身份信息的第一PADI广播报文,所述用户第一身份信息为所述客户端设备的用户在网络系统中的标识,所述第一PADI广播报文用于请求PPPOE服务器服务;
当所述虚拟接入路由器确定所述用户第一身份信息与该虚拟接入路由器的身份相匹配时,所述虚拟接入路由器发送第二PADI广播报文到PPPOE服务器,所述第二PADI广播报文用于请求PPPOE服务器服务;
当接收器803接收到所述PPPOE服务器返回的第一PADO应答消息后,控制发射器804发送携带有路由身份信息的第二PADO应答消息给所述客户端设备,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的标识;
当建立与所述PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,控制接收器803和发射器804通过所述第一会话和所述第二会话,转发所述客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息;
当接收器803接收到所述PPPOE服务器发送的认证失败消息时,中断与所述客户端设备之间的所述第一会话;
可选的,该处理器802还可以实现如下功能:
控制接收器803接收所述客户端设备发送的IP子网地址通告请求,所述IP子网地址通告请求用于请求建立所述第一会话的标识与内网IP网段之间的映射,所述IP子网地址通告请求中包含所述客户端设备的内网IP网段;
当确定所述内网IP网段的合法性后,保存所述第一会话的标识与所述内网IP网段的绑定关系到存储器801,并控制发射器804向所述客户端设备发送IP子网地址通告应答。
本发明实施例还提供另一种客户端设备,其结构与上述图8中虚拟接入路由器的结构类似,包括:分别连接在总线的存储器、处理器,接收器和发射器,其中:
存储器用来储存储存处理器处理数据的必要文件等信息,比如储存处理器执行图4所示的身份认证的方法的程序代码等信息。
处理器,用于调用存储器中储存的程序代码,以实现如下功能:
控制发射器在网络系统中发送携带有用户第一身份信息的第一PADI广播报文,所述第一PADI广播报文用于请求PPPoE服务器服务,所述用户第一身份信息为所述客户端设备的用户在所述网络系统中的标识;
控制接收器接收虚拟接入路由器发送的携带有路由身份信息的第二PADO应答消 息,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的唯一标识;
当确定所述路由身份信息与所述用户第一身份信息匹配时,建立与所述虚拟接入路由器之间的第一会话;
控制发射器通过所述第一会话发送用户第二身份信息给所述虚拟接入路由器,使得所述虚拟接入路由器将所述用户第二身份信息转发到所述PPPOE服务器进行身份认证。
可选的,该处理器还可以实现如下功能:
从所述DHCP服务器获取内网IP网段的配置;
根据所述内网IP网段的配置,控制发射器向所述虚拟接入路由器发送IP子网地址通告请求,所述IP子网地址通告请求用于请求所述虚拟接入路由器建立所述第一会话的标识与所述内网IP网段之间的映射。
其中,该DHCP服务器独立存在,也可以配置在该客户端设备上,此处不作限定。
本发明实施例还提供了一种身份认证系统,包括:
PPPOE服务器,图4、图5或图8中任一个对应的实施例所示的虚拟接入路由器,以及图6或图7对应的实施例所示的虚拟接入路由器。
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统,装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。
在本申请所提供的几个实施例中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本发明的技术方案本质上 或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本发明各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(read-only memory,ROM)、随机存取存储器(random access memory,RAM)、磁碟或者光盘等各种可以存储程序代码的介质。
以上所述,以上实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的范围。

Claims (9)

  1. 一种身份认证方法,应用于包括有虚拟接入路由器的网络系统,所述网络系统中还包括客户端设备和PPPOE服务器,其特征在于,包括:
    虚拟接入路由器接收客户端设备发送的携带有用户第一身份信息的第一PADI广播报文,所述用户第一身份信息为所述客户端设备的用户在网络系统中的标识,所述第一PADI广播报文用于请求PPPOE服务器服务;
    当所述虚拟接入路由器确定所述用户第一身份信息与所述虚拟接入路由器的身份相匹配时,所述虚拟接入路由器发送第二PADI广播报文到PPPOE服务器,所述第二PADI广播报文用于请求PPPOE服务器服务;
    当所述虚拟接入路由器接收到所述PPPOE服务器返回的第一PADO应答消息后,所述虚拟接入路由器发送携带有路由身份信息的第二PADO应答消息给所述客户端设备,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的标识;
    当所述虚拟接入路由器建立与所述PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,所述虚拟接入路由器通过所述第一会话和所述第二会话,转发所述客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息;
    当所述虚拟接入路由器接收到所述PPPOE服务器发送的认证失败消息时,所述虚拟接入路由器中断与所述客户端设备之间的所述第一会话。
  2. 根据权利要求1所述的方法,其特征在于,所述方法还包括:
    所述虚拟接入路由器接收所述客户端设备发送的IP子网地址通告请求,所述IP子网地址通告请求用于请求建立所述第一会话的标识与内网IP网段之间的映射,所述IP子网地址通告请求中包含所述客户端设备的内网IP网段;
    当虚拟接入路由器确定所述内网IP网段的合法性后,所述虚拟接入路由器保存所述第一会话的标识与所述内网IP网段的绑定关系,并向所述客户端设备发送IP子网地址通告应答。
  3. 一种身份认证方法,用于包括有虚拟接入路由器的网络系统,所述网络系统中还包括客户端设备和PPPOE服务器,其特征在于,包括:
    客户端设备在网络系统中发送携带有用户第一身份信息的第一PADI广播报文,所述第一PADI广播报文用于请求PPPoE服务器服务,所述用户第一身份信息为所述客户端设备的用户在所述网络系统中的标识;
    所述客户端设备接收虚拟接入路由器发送的携带有路由身份信息的第二PADO应 答消息,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的唯一标识;
    当所述客户端设备确定所述路由身份信息与所述用户第一身份信息匹配时,所述客户端设备建立与所述虚拟接入路由器之间的第一会话;
    所述客户端设备通过所述第一会话发送用户第二身份信息给所述虚拟接入路由器,使得所述虚拟接入路由器将所述用户第二身份信息转发到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息。
  4. 根据权利要求3所述的方法,其特征在于,所述网络系统中还包括DHCP服务器,所述方法还包括:
    所述客户端设备从所述DHCP服务器获取内网IP网段的配置;
    所述客户端设备根据所述内网IP网段的配置,向所述虚拟接入路由器发送IP子网地址通告请求,所述IP子网地址通告请求用于请求所述虚拟接入路由器建立所述第一会话的标识与所述内网IP网段之间的映射。
  5. 一种虚拟接入路由器,其特征在于,包括:
    第一接收模块,用于接收客户端设备发送的携带有用户第一身份信息的第一PADI广播报文,所述用户第一身份信息为所述客户端设备的用户在网络系统中的标识,所述第一PADI广播报文用于请求PPPOE服务器服务;
    第一发送模块,用于当确定所述第一接收模块接收到的第一PADI广播报文中携带的用户第一身份信息与所述虚拟接入路由器的身份相匹配时,发送第二PADI广播报文到PPPOE服务器,所述第二PADI广播报文用于请求PPPOE服务器服务;
    第二发送模块,用于当接收到所述PPPOE服务器返回的第一PADO应答消息后,发送携带有路由身份信息的第二PADO应答消息给所述客户端设备,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的标识;
    转发模块,用于当建立与所述PPPOE服务器之间的第一会话,以及与所述客户端设备之间的第二会话之后,通过所述第一会话和所述第二会话,转发所述客户端设备发送的用户第二身份信息到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息;
    中断模块,用于当接收到所述PPPOE服务器发送的认证失败消息时,中断与所述客户端设备之间的所述第一会话。
  6. 根据权利要求5所述的虚拟接入路由器,其特征在于,所述虚拟接入路由器还包括:
    第二接收模块,用于接收所述客户端设备发送的IP子网地址通告请求,所述IP子 网地址通告请求用于请求建立所述第一会话的标识与内网IP网段之间的映射,所述IP子网地址通告请求中包含所述客户端设备的内网IP网段;
    保存模块,用于当确定所述第二接收模块接收到的IP子网地址通告请求中包含的内网IP网段的合法性后,保存所述第一会话的标识与所述内网IP网段的绑定关系;
    第三发送模块,用于在所述保存模块保存所述第一会话的标识与所述内网IP网段的绑定关系后,向所述客户端设备发送IP子网地址通告应答。
  7. 一种客户端设备,其特征在于,包括:
    第四发送模块,用于在网络系统中发送携带有用户第一身份信息的第一PADI广播报文,所述第一PADI广播报文用于请求PPPoE服务器服务,所述用户第一身份信息为所述客户端设备的用户在所述网络系统中的标识;
    第三接收模块,用于接收虚拟接入路由器发送的携带有路由身份信息的第二PADO应答消息,所述路由身份信息为所述虚拟接入路由器在所述网络系统中的唯一标识;
    建立模块,用于当确定第三接收模块接收的第二PADO应答消息中携带的所述路由身份信息与所述用户第一身份信息匹配时,建立与所述虚拟接入路由器之间的第一会话;
    第五发送模块,用于通过所述建立模块建立的第一会话发送用户第二身份信息给所述虚拟接入路由器,使得所述虚拟接入路由器将所述用户第二身份信息转发到所述PPPOE服务器进行身份认证,所述用户第二身份信息中包括所述用户第一身份信息。
  8. 根据权利要求7所述的客户端设备,其特征在于,所述客户端设备还包括:
    获取模块,用于从DHCP服务器获取内网IP网段的配置;
    第六发送模块,用于根据所述获取模块获取的内网IP网段的配置,向所述虚拟接入路由器发送IP子网地址通告请求,所述IP子网地址通告请求用于请求所述虚拟接入路由器建立所述第一会话的标识与所述内网IP网段之间的映射。
  9. 一种身份认证系统,其特征在于,包括:
    PPPOE服务器,权利要求5或6所述的虚拟接入路由器,以及权利要求7或8所述的客户端设备。
PCT/CN2016/083924 2015-06-04 2016-05-30 身份认证方法、身份认证系统和相关设备 WO2016192608A2 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510304341.2 2015-06-04
CN201510304341.2A CN106302353B (zh) 2015-06-04 2015-06-04 身份认证方法、身份认证系统和相关设备

Publications (2)

Publication Number Publication Date
WO2016192608A2 true WO2016192608A2 (zh) 2016-12-08
WO2016192608A3 WO2016192608A3 (zh) 2017-02-09

Family

ID=57440150

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/083924 WO2016192608A2 (zh) 2015-06-04 2016-05-30 身份认证方法、身份认证系统和相关设备

Country Status (2)

Country Link
CN (2) CN106302353B (zh)
WO (1) WO2016192608A2 (zh)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110620751A (zh) * 2018-06-20 2019-12-27 深圳市云猫信息技术有限公司 一种wifi路由终端、接入网关及其认证方法、认证系统
CN112651522A (zh) * 2021-01-13 2021-04-13 广州视源电子科技股份有限公司 设备的配置方法、系统、计算机可读存储介质和处理器
CN113038472A (zh) * 2021-03-15 2021-06-25 南京林业大学 一种高校校园网禁止无线路由器dhcp获取地址的方法
CN113453226A (zh) * 2021-06-29 2021-09-28 新华三大数据技术有限公司 一种双栈用户准出认证方法及装置
CN114006759A (zh) * 2021-10-29 2022-02-01 中国联合网络通信集团有限公司 网络接入方法、网络连接设备和可读存储介质

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3598711B1 (en) 2017-04-01 2021-09-08 Huawei Technologies Co., Ltd. User authentication method and device
CN109309627B (zh) * 2017-07-27 2022-05-20 中兴通讯股份有限公司 负荷分担方法、系统及计算机可读存储介质
CN110688637A (zh) * 2019-09-29 2020-01-14 广州大白互联网科技有限公司 一种内外网设备之间的认证方法和认证系统

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101087232A (zh) * 2007-07-27 2007-12-12 杭州华三通信技术有限公司 一种基于以太网上点对点协议的接入方法、系统和设备
WO2008125603A1 (en) * 2007-04-12 2008-10-23 Nokia Siemens Networks Oy Method for forwarding data packets in an access network and device
CN101399830A (zh) * 2007-09-29 2009-04-01 联想(北京)有限公司 虚拟机系统及其共享以太网点对点协议链接的方法
US20110292942A1 (en) * 2010-05-27 2011-12-01 Fujitsu Limited Router, information processing device and program

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7698456B2 (en) * 2003-09-29 2010-04-13 Cisco Technology, Inc. Methods and apparatus to support routing of information
US7342920B2 (en) * 2004-01-28 2008-03-11 Sbc Knowledge Ventures, L.P. Voice over internet protocol (VoIP) telephone apparatus and communications systems for carrying VoIP traffic
CN101192909B (zh) * 2006-11-22 2011-08-24 中国电信股份有限公司 利用一条adsl实现宽带上网和iptv接入的系统和方法
US8081569B2 (en) * 2009-04-20 2011-12-20 Telefonaktiebolaget L M Ericsson (Publ) Dynamic adjustment of connection setup request parameters
CN101931564B (zh) * 2009-06-25 2012-07-25 成都市华为赛门铁克科技有限公司 协议异常测试方法和系统、测试设备及控制设备
CN102946337A (zh) * 2012-12-11 2013-02-27 上海市共进通信技术有限公司 Adsl路由器终端自动检测pvc的控制方法
CN103347010A (zh) * 2013-06-21 2013-10-09 苏州经贸职业技术学院 一种园区网络中多服务商PPPoE的接入认证处理方法
CN104243254B (zh) * 2014-09-29 2017-08-25 中国联合网络通信集团有限公司 一种PPPoE接入方法及设备

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2008125603A1 (en) * 2007-04-12 2008-10-23 Nokia Siemens Networks Oy Method for forwarding data packets in an access network and device
CN101087232A (zh) * 2007-07-27 2007-12-12 杭州华三通信技术有限公司 一种基于以太网上点对点协议的接入方法、系统和设备
CN101399830A (zh) * 2007-09-29 2009-04-01 联想(北京)有限公司 虚拟机系统及其共享以太网点对点协议链接的方法
US20110292942A1 (en) * 2010-05-27 2011-12-01 Fujitsu Limited Router, information processing device and program

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110620751A (zh) * 2018-06-20 2019-12-27 深圳市云猫信息技术有限公司 一种wifi路由终端、接入网关及其认证方法、认证系统
CN110620751B (zh) * 2018-06-20 2022-11-25 深圳市云猫信息技术有限公司 一种wifi路由终端、接入网关及其认证方法、认证系统
CN112651522A (zh) * 2021-01-13 2021-04-13 广州视源电子科技股份有限公司 设备的配置方法、系统、计算机可读存储介质和处理器
CN113038472A (zh) * 2021-03-15 2021-06-25 南京林业大学 一种高校校园网禁止无线路由器dhcp获取地址的方法
CN113453226A (zh) * 2021-06-29 2021-09-28 新华三大数据技术有限公司 一种双栈用户准出认证方法及装置
CN113453226B (zh) * 2021-06-29 2023-12-26 新华三大数据技术有限公司 一种双栈用户准出认证方法及装置
CN114006759A (zh) * 2021-10-29 2022-02-01 中国联合网络通信集团有限公司 网络接入方法、网络连接设备和可读存储介质
CN114006759B (zh) * 2021-10-29 2023-08-15 中国联合网络通信集团有限公司 网络接入方法、网络连接设备和可读存储介质

Also Published As

Publication number Publication date
CN110958272B (zh) 2021-10-15
WO2016192608A3 (zh) 2017-02-09
CN106302353B (zh) 2020-01-10
CN110958272A (zh) 2020-04-03
CN106302353A (zh) 2017-01-04

Similar Documents

Publication Publication Date Title
WO2016192608A2 (zh) 身份认证方法、身份认证系统和相关设备
JP6722820B2 (ja) ブロードバンドリモートアクセスサーバの制御プレーン機能と転送プレーン機能の分離
US8488569B2 (en) Communication device
US6801528B2 (en) System and method for dynamic simultaneous connection to multiple service providers
US9131026B2 (en) Method and system for establishing media channel based on relay
WO2016210196A1 (en) Media relay server
WO2016210193A1 (en) Media session
WO2006116926A1 (fr) Procede, systeme et serveur pour mettre en œuvre l’attribution de securite d’adresse dhcp
US20110202670A1 (en) Method, device and system for identifying ip session
WO2013056585A1 (zh) 一种虚拟私云接入认证方法及相关装置
WO2016210202A1 (en) Media relay server
EP3068139B1 (en) Electronic device and method for controlling electronic device
WO2012034413A1 (zh) 一种双栈用户管理方法及宽带接入服务器
WO2021218886A1 (zh) Vxlan接入认证方法以及vtep设备
JP4852379B2 (ja) パケット通信装置
WO2011140919A1 (zh) 接入业务批发网络的方法、设备、服务器和系统
KR20030070309A (ko) 통신 네트워크에서 가상 사설 네트워크 서비스 접속을위한 보안 시스템 및 방법
JP2014510480A (ja) ネットワーク通信システムおよび方法
WO2014110984A1 (zh) 用户终端接入网络的认证方法及装置
EP3664403B1 (en) User authentication of bras under architecture of mutually separated forwarding and control
WO2009082950A1 (fr) Procédé, dispositif et système de distribution de clés
CN106131177B (zh) 一种报文处理方法及装置
JP5261432B2 (ja) 通信システム、パケット転送方法、ネットワーク交換装置、アクセス制御装置、及びプログラム
WO2012041168A1 (zh) 用于IPv6网络的网络连接处理方法及其装置
CN107046568B (zh) 一种认证方法和装置

Legal Events

Date Code Title Description
NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16802531

Country of ref document: EP

Kind code of ref document: A2