WO2017084322A1 - 一种基于路由器的网络访问控制方法、系统及相关设备 - Google Patents

一种基于路由器的网络访问控制方法、系统及相关设备 Download PDF

Info

Publication number
WO2017084322A1
WO2017084322A1 PCT/CN2016/085421 CN2016085421W WO2017084322A1 WO 2017084322 A1 WO2017084322 A1 WO 2017084322A1 CN 2016085421 W CN2016085421 W CN 2016085421W WO 2017084322 A1 WO2017084322 A1 WO 2017084322A1
Authority
WO
WIPO (PCT)
Prior art keywords
user
router
access
fingerprint information
access control
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2016/085421
Other languages
English (en)
French (fr)
Inventor
黄启鑫
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Le Holdings Beijing Co Ltd
Leshi Zhixin Electronic Technology Tianjin Co Ltd
Original Assignee
Le Holdings Beijing Co Ltd
Leshi Zhixin Electronic Technology Tianjin Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Le Holdings Beijing Co Ltd, Leshi Zhixin Electronic Technology Tianjin Co Ltd filed Critical Le Holdings Beijing Co Ltd
Publication of WO2017084322A1 publication Critical patent/WO2017084322A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/069Authentication using certificates or pre-shared keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L47/00Traffic control in data switching networks
    • H04L47/70Admission control; Resource allocation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources

Definitions

  • the present application relates to the field of network technologies, and in particular, to a router-based network access control method, system, and related device.
  • a router also known as a gateway, is used to connect multiple logically separate networks.
  • a logical network is a single network or a subnet. When data is transferred from one subnet to another, it can be done through the routing function of the router. Therefore, the router has the function of judging the network address and selecting an IP (Internet Protocol) path, and can establish a flexible connection in a multi-network interconnection environment, and can connect various subnets by using completely different data packets and media access methods.
  • IP Internet Protocol
  • Network access control through routers is a feature supported by most routers.
  • the scheme for identifying an access user in the network access control generally has the following types.
  • the so-called access user refers to a user who connects to the router through an access device (for example, a mobile phone, a PC, etc.). specific:
  • Method 1 MAC (Media Access Control) address recognition.
  • the MAC address identification is to establish an access control policy for the MAC address connected to the router. For example, specifying certain MAC addresses cannot access certain websites, or cannot access other devices on the LAN, and so on.
  • a time period is set, which stipulates that all access devices cannot access certain websites or other access control policies during the time period.
  • Method 3 user account identification.
  • the user account identification refers to providing a user account and a password for each user connected to the router, and assigning different access control policies to different user accounts.
  • the scheme for identifying access users in the existing network access control has the following defects:
  • one access control policy is used for one time segment, and different access control policies cannot be established for different access users.
  • the user account identification scheme first of all, it is not guaranteed that the same user account and password are the same access user; secondly, the user account and password are easy to copy, and the input of the user account and password is cumbersome, and once the user forgets the password, it will also affect Users accessing the network normally may even pose a security risk.
  • the purpose of the present application is to provide a router-based network access control method, system, and related device, which can easily and effectively identify an access user, and is difficult to falsify, and implement different network access control policies for each access user. Thereby effectively improving the accuracy of network access control.
  • the present application provides a router-based network access control method.
  • the router uses the user's fingerprint information, user name, and corresponding network access control policy as one.
  • the record is saved, and the method includes:
  • the router instructs the access user to perform fingerprint verification
  • the router matches the user corresponding to the fingerprint information in the saved record according to the fingerprint information of the access user. If the matching is successful, the network access control policy corresponding to the matched user is obtained in the saved record, and the obtained network access control policy is obtained.
  • the network access control policy is configured to the MAC address of the access device.
  • the above method may further have the following features, and further includes:
  • the router searches for an access user on the access device, and if so, deletes the network access control policy configured for the access device.
  • the foregoing method may further have the following feature: an application APP is installed on the access device;
  • the router instructs the access user to perform fingerprint verification, which specifically includes:
  • the router sends a fingerprint verification request to the APP installed on the access device, instructing the access user to perform fingerprint verification;
  • the access device transmits the fingerprint information entered by the access user through the device and the MAC address of the device to the router through the APP installed on the device.
  • the foregoing method may further have the following feature: an application APP is installed on the access device;
  • the router saves the user's fingerprint information, the user name, and the corresponding network access control policy as a record, and specifically includes:
  • the router After the event that the user obtains the fingerprint information of the user is triggered, the router sends a notification message to the APP installed on the access device, indicating that the fingerprint information of the user is extracted.
  • the APP installed on the access device obtains the fingerprint information entered by the user on the device, and encodes the fingerprint information and sends the fingerprint information to the router.
  • the router saves the user's fingerprint information, as well as the user name and network access control policy set for the user, as a record in the router.
  • the present application also provides a router-based network access control system, including an access device and a router, where:
  • the access device is configured to perform fingerprint verification according to an access user sent by the router. Instructing, the access user accessing the router through the device enters fingerprint information, and transmits the fingerprint information entered by the access user through the device and the MAC address of the device to the router;
  • the router is configured to save a record composed of the user's fingerprint information, the user name, and the corresponding network access control policy for the user who needs to set the network access control policy; when the access user connects to the router by using the access device Instructing the access user to perform fingerprint verification; and matching the user corresponding to the fingerprint information in the saved record according to the fingerprint information of the access user, and if the matching is successful, obtaining the matched record in the saved record.
  • the router is further configured to: when an access device disconnects from the router, find whether an access user is input on the access device, and if yes, the connection is The network access control policy of the incoming device configuration is deleted.
  • the above system may further have the following feature: an application APP is installed on the access device;
  • the router is specifically configured to send a fingerprint verification request to an APP installed on the access device, and instruct the access user to perform fingerprint verification.
  • the access device is specifically configured to transmit the fingerprint information entered by the access user through the device and the MAC address of the device to the router by using an APP installed on the device.
  • the above system may further have the following feature: an application APP is installed on the access device;
  • the router is further configured to: after the event of acquiring the fingerprint information of the user is triggered, send a notification message to the APP installed on the access device, indicating that the fingerprint information of the user is extracted; and the fingerprint information of the user, and the user
  • the set user name and network access control policy are saved as a record in the router;
  • the access device is further configured to obtain fingerprint information recorded by the user on the device by using an APP installed on the device, and encode the fingerprint information and send the fingerprint information to the router.
  • the application also provides a router, including:
  • the storage module is configured to save, by the user who needs to set the network access control policy, a record composed of the fingerprint information, the user name, and the corresponding network access control policy of the user;
  • the indication module is configured to instruct the access user to perform fingerprint verification when the access user connects to the router by using the access device;
  • a receiving module configured to receive, by the access device, fingerprint information that is entered by the access user through the device, and a MAC address of the device;
  • a matching module configured to match, according to the fingerprint information of the access user, a user corresponding to the fingerprint information in a record saved by the storage module;
  • control module configured to: if the matching module is successfully matched, obtain a network access control policy corresponding to the matched user in the record saved by the storage module, and configure the obtained network access control policy to the MAC of the access device address.
  • control module is further configured to: when an access device disconnects from the router, find whether an access user is input on the access device, and if yes, the The network access control policy configured for the access device is deleted.
  • the router-based network access control method, system, and related device provided by the present application, for a user who needs to set a network access control policy, the router saves the fingerprint information, the user name, and the corresponding network access control policy of the user as one record.
  • the access user connects to the router by using the access device, the user is matched to the corresponding user through fingerprint verification, and a preset network access control policy is implemented for the user.
  • This solution solves the problem that the existing router-based network access control scheme cannot truly set the network access control policy for an access user, and can accurately and conveniently set the network access control policy for the specific connection to the router. And based on the fingerprint information, the access user can be accurately and effectively identified and it is difficult to falsify, thereby effectively improving the accuracy of the network access control.
  • FIG. 1 is a flowchart of a router-based network access control method according to Embodiment 1 of the present application.
  • FIG. 2 is a flowchart of a router-based network access control method according to Embodiment 2 of the present application.
  • FIG. 3 is a structural diagram of a router-based network access control system according to Embodiment 3 of the present application.
  • FIG. 4 is a structural block diagram of a router in Embodiment 4 of the present application.
  • the embodiment of the present invention provides a router-based network access control method, system, and related device, which can easily and effectively identify an access user, and is difficult to falsify, and implement different network access control policies for each access user. Effectively improve the accuracy of network access control.
  • the embodiments of the present application combine fingerprint identification and router-based network access control to facilitate identification. Users, and it is difficult to fake, to achieve the purpose of making different network access control policies for each access user, making network access control more accurate.
  • the router-based network access control method includes the following steps:
  • the router instructs the access user to perform fingerprint verification.
  • the access user once a user who has set a network access control policy on the router connects to the router using any access device, the access user must first perform fingerprint verification. Certificate to get the appropriate network access.
  • the router receives the fingerprint information that the access user transmits through the device and the MAC address of the device.
  • the router matches the user corresponding to the fingerprint information in the saved record according to the fingerprint information of the access user. If the matching is successful, the network access control policy corresponding to the matched user is obtained in the saved record, and the obtained network access control policy is obtained.
  • the network access control policy is configured to the MAC address of the access device.
  • the network access control method provided by the embodiment of the present application further includes the following steps, in order to prevent the network access control policy of the access user side from being used by the same access device after being accessed by different users:
  • the router searches for an access user on the access device, and if so, deletes the network access control policy configured for the access device.
  • the user is recorded as user
  • the router is recorded as the router
  • the access device is recorded as the client
  • the application installed in the client is recorded as the APP
  • the fingerprint information of the user is recorded.
  • the network access control policy is called policy. As shown in FIG. 2, the following steps are specifically included:
  • the user accesses the router that can obtain the fingerprint information to the router.
  • the administrator triggers an event of acquiring fingerprint information of the user on the router.
  • the router and the APP installed on the client interact, that is, send a notification message indicating that the user's fingerprint is extracted.
  • the APP installed on the client obtains the fingerprint of the user, and the APP encodes the fingerprint and transmits it to the router, and the user's fingerprint is completed.
  • the router will ask the administrator to set the policy for the user and provide a user name for the user to facilitate identification and management. After the administrator is set, the router will add the fingerprint+username+ The policy is a record and is stored in the router.
  • the router After S209 and the client access the router, the router sends a fingerprint verification request to the client APP, and asks the user to verify the fingerprint.
  • the APP After S210 ⁇ S211 and User enter the fingerprint through the client, the APP will transmit the fingerprint+client MAC address to the router.
  • S201 to S207 are pre-set user policy stages, and prepare for subsequent router-based network access control;
  • S208-S214 are router-based network access control stages, and use user's fingerprint to implement access user identification.
  • different pre-configured policies are used for different users;
  • S215-S217 is an optimization processing stage for disconnecting a certain client from the router, and ensuring smooth implementation of network access control based on the access user.
  • the processes in each phase are relatively independent.
  • the users and clients involved in each phase can be the same user and client, and of course can be different users and clients.
  • the embodiment of the present application provides a router-based network access control system. Since the principle of solving the problem is consistent with the network access control method, the implementation of the system can refer to the implementation of the method. Not to repeat. As shown in FIG. 3, the router-based network access control system provided by the embodiment of the present application includes an access device 301 and a router 302, where:
  • the access device 301 is configured to: according to the indication that the access user sends the fingerprint verification sent by the router 302, prompts the access user 300 accessing the router 302 of the device to enter the fingerprint information, and enters the fingerprint entered by the user 300 through the device. Information, and the MAC address of the device is transmitted to the router 302;
  • the router 302 is configured to save, by the user who needs to set the network access control policy, a record composed of the fingerprint information, the user name, and the corresponding network access control policy of the user; when the access user 300 connects to the user by using the access device 301
  • the access user 300 is instructed to perform fingerprint verification; and the fingerprint is matched in the saved record according to the fingerprint information of the access user.
  • the user corresponding to the information if the matching is successful, obtains the network access control policy corresponding to the matched user in the saved record, and configures the obtained network access control policy to the MAC address of the access device 301.
  • the router 302 is also used when an access device is used by the access device.
  • the router searches for the access user on the access device. If yes, the network access control policy configured for the access device is deleted.
  • an APP application
  • an APP application
  • the access device 301 In order to implement the solution, an APP (application) is generally installed on the access device 301.
  • APP application
  • the router 302 is configured to send a fingerprint verification request to the APP installed on the access device 301, and instruct the access user 300 to perform fingerprint verification.
  • the access device 301 is specifically configured to transmit the fingerprint information entered by the access user 300 through the device and the MAC address of the device to the router 302 through the APP installed on the device.
  • the router 302 is further configured to: after the event of acquiring the fingerprint information of the user is triggered, send a notification message to the APP installed on the access device 301, indicating that the fingerprint information of the user is extracted; and the fingerprint information of the user, and the user The set user name and network access control policy are saved as a record in the router;
  • the access device 301 is further configured to obtain the fingerprint information recorded by the user on the device by using the APP installed on the device, and encode the fingerprint information and send the fingerprint information to the router 302.
  • the embodiment of the present application further provides a possible structure of a router, as shown in FIG. 4, including:
  • the storage module 401 is configured to save, by the user who needs to set the network access control policy, a record composed of the fingerprint information, the user name, and the corresponding network access control policy of the user;
  • the indicating module 402 is configured to: when the access user connects to the router by using the access device, instruct the access user to perform fingerprint verification;
  • the receiving module 403 is configured to receive, by the access device, fingerprint information that is entered by the access user through the device, and a MAC address of the device;
  • the matching module 404 is configured to save in the storage module 401 according to the fingerprint information of the access user. Matching the user corresponding to the fingerprint information in the record;
  • the control module 405 is configured to: if the matching module is successfully matched, obtain a matching network access control policy corresponding to the user in the record saved by the storage module 401, and configure the obtained network access control policy to the MAC of the access device. address.
  • control module 405 is further configured to: when an access device disconnects from the router, find whether an access user is input on the access device, and if yes, configure network access control for the access device. Policy deletion.
  • the router-based network access control method, system, and related device provided by the embodiment of the present application, for a user who needs to set a network access control policy, the router performs the fingerprint information, the user name, and the corresponding network access control policy of the user as one record.
  • the access user connects to the router using the access device, the user is matched to the corresponding user through fingerprint verification, and a preset network access control policy is implemented for the user.
  • This solution solves the problem that the existing router-based network access control scheme cannot truly set the network access control policy for an access user, and can accurately and conveniently set the network access control policy for the specific connection to the router. And based on the fingerprint information, the access user can be accurately and effectively identified and it is difficult to falsify, thereby effectively improving the accuracy of the network access control.
  • embodiments of the present application can be provided as a method, system, device, or computer program product.
  • the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment in combination of software and hardware.
  • the application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) including computer usable program code.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • Biomedical Technology (AREA)
  • General Health & Medical Sciences (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本申请涉及一种基于路由器的网络访问控制方法、系统及相关设备,实现针对每个接入用户制定不同的网络访问控制策略,从而有效提升了网络访问控制的精准度。针对需要设置网络访问控制策略的用户,路由器将该用户的指纹信息、用户名以及对应的网络访问控制策略作为一条记录进行保存,所述方法包括:当接入用户使用接入设备连接到路由器时,路由器指示接入用户进行指纹验证;接收接入设备传送的接入用户的指纹信息、以及本设备的MAC地址;根据接入用户的指纹信息,在保存的记录中匹配指纹信息对应的用户,若匹配成功,在保存的记录中获取匹配到的用户对应的网络访问控制策略,并配置给接入设备的MAC地址。

Description

一种基于路由器的网络访问控制方法、系统及相关设备
交叉引用
本申请要求在2015年11月16日提交中国专利局、申请号为201510785241.6、发明名称为“一种基于路由器的网络访问控制方法、系统及相关设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及网络技术领域,尤其涉及一种基于路由器的网络访问控制方法、系统及相关设备。
背景技术
路由器(Router)又称网关设备(Gateway)是用于连接多个逻辑上分开的网络,所谓逻辑网络是代表一个单独的网络或者一个子网。当数据从一个子网传输到另一个子网时,可通过路由器的路由功能来完成。因此,路由器具有判断网络地址和选择IP(Internet Protocol,网际协议)路径的功能,它能在多网络互联环境中,建立灵活的连接,可用完全不同的数据分组和介质访问方法连接各种子网,路由器只接受源站或其他路由器的信息,属网络层的一种互联设备。
通过路由器进行网络访问控制,是大多数路由器支持的功能。目前网络访问控制中识别接入用户的方案一般有如下几种,所谓的接入用户是指通过接入设备(例如手机、PC等等)连接到路由器的用户。具体的:
方式一、MAC(Media Access Control,媒体访问控制)地址识别。
具体的,MAC地址识别是指针对连接到路由器的MAC地址,制定访问控制策略。比如指定某些MAC地址不能访问某些网站,或者不能访问局域网内其他设备,等等。
方式二、时间段控制。
通常情况下,设置一个时间段,规定该时间段内所有接入设备不能访问某些网站,或者其他访问控制策略。
方式三、用户账号识别。
具体的,用户账号识别是指为连接到路由器的每个用户提供用户账号、密码,并且为不同的用户账号分配不同的访问控制策略。
现有网络访问控制中识别接入用户的方案,具有如下缺陷:
针对MAC地址识别方案,只能识别接入设备的MAC地址,而无法识别使用该接入设备的接入用户,因此在同一接入设备不同接入用户使用的场景下,赋予了相同的访问控制策略。
针对时间段控制方案,一个时间段使用一种访问控制策略,不能为不同的接入用户制定不同的访问控制策略。
针对用户账号识别方案,首先,并不能保证使用同一用户账号、密码的是同一接入用户;其次,用户账号、密码容易复制,并且输入用户账号、密码比较繁琐,一旦用户忘记密码,也会影响用户正常接入网络甚至带来安全隐患。
可见,现有基于路由器的网络访问控制方案中,针对接入用户的识别度低,无法实现针对不同的接入用户制定不同的网络访问控制策略,导致无法精准地进行网络访问控制,因此亟待提供相应的解决方案。
发明内容
本申请的目的在于提供一种基于路由器的网络访问控制方法、系统及相关设备,能够方便、有效地识别接入用户,并且难以造假,实现针对每个接入用户制定不同的网络访问控制策略,从而有效提升了网络访问控制的精准度。
为实现上述目的,本申请提出了一种基于路由器的网络访问控制方法,针对需要设置网络访问控制策略的用户,所述路由器将该用户的指纹信息、用户名以及对应的网络访问控制策略作为一条记录进行保存,所述方法包括:
当接入用户使用接入设备连接到路由器时,路由器指示所述接入用户进行指纹验证;
路由器接收所述接入设备传送的所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址;
路由器根据所述接入用户的指纹信息,在保存的记录中匹配所述指纹信息对应的用户,若匹配成功,在保存的记录中获取匹配到的用户对应的网络访问控制策略,并将获取到的网络访问控制策略配置给所述接入设备的MAC地址。
进一步地,上述方法还可具有以下特点,还包括:
当某个接入设备从所述路由器断开时,路由器查找该接入设备上是否输入了接入用户,若是,将为该接入设备配置的网络访问控制策略删除。
进一步地,上述方法还可具有以下特点,所述接入设备上安装有应用程序APP;
所述路由器指示所述接入用户进行指纹验证,具体包括:
所述路由器向接入设备上安装的APP发送指纹验证请求,指示所述接入用户进行指纹验证;以及
所述接入设备通过本设备上安装的APP将所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址传送给路由器。
进一步地,上述方法还可具有以下特点,所述接入设备上安装有应用程序APP;以及
针对需要设置网络访问控制策略的用户,所述路由器将该用户的指纹信息、用户名以及对应的网络访问控制策略作为一条记录进行保存的实现方法,具体包括:
当路由器上获取用户的指纹信息的事件被触发后,路由器向接入设备上安装的APP发送通知消息,指示提取用户的指纹信息;
接入设备上安装的APP获取用户在本设备上录入的指纹信息,并将指纹信息编码后发送给路由器;
路由器将该用户的指纹信息,以及为该用户设置的用户名和网络访问控制策略作为一条记录,保存在本路由器中。
基于同一技术构思,本申请还提供了一种基于路由器的网络访问控制系统,包括接入设备和路由器,其中:
所述接入设备,用于根据所述路由器发送的接入用户进行指纹验证的 指示,提示通过本设备接入路由器的接入用户录入指纹信息,并将所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址传送给路由器;
所述路由器,用于针对需要设置网络访问控制策略的用户,保存由该用户的指纹信息、用户名以及对应的网络访问控制策略组成的一条记录;当接入用户使用接入设备连接到本路由器时,指示所述接入用户进行指纹验证;以及根据所述接入用户的指纹信息,在保存的记录中匹配所述指纹信息对应的用户,若匹配成功,在保存的记录中获取匹配到的用户对应的网络访问控制策略,并将获取到的网络访问控制策略配置给所述接入设备的MAC地址。
进一步地,上述系统还可具有以下特点,所述路由器,还用于当某个接入设备从本路由器断开时,查找该接入设备上是否输入了接入用户,若是,将为该接入设备配置的网络访问控制策略删除。
进一步地,上述系统还可具有以下特点,所述接入设备上安装有应用程序APP;以及
所述路由器,具体用于通过向接入设备上安装的APP发送指纹验证请求,指示所述接入用户进行指纹验证;
所述接入设备,具体用于通过本设备上安装的APP将所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址传送给路由器。
进一步地,上述系统还可具有以下特点,所述接入设备上安装有应用程序APP;以及
所述路由器,还用于当获取用户的指纹信息的事件被触发后,向接入设备上安装的APP发送通知消息,指示提取用户的指纹信息;以及将该用户的指纹信息,以及为该用户设置的用户名和网络访问控制策略作为一条记录,保存在本路由器中;
所述接入设备,还用于通过本设备上安装的APP获取用户在本设备上录入的指纹信息,并将指纹信息编码后发送给路由器。
本申请还提供了一种路由器,包括:
存储模块,用于针对需要设置网络访问控制策略的用户,保存由该用户的指纹信息、用户名以及对应的网络访问控制策略组成的一条记录;
指示模块,用于当接入用户使用接入设备连接到本路由器时,指示所述接入用户进行指纹验证;
接收模块,用于接收所述接入设备传送的所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址;
匹配模块,用于根据所述接入用户的指纹信息,在存储模块保存的记录中匹配所述指纹信息对应的用户;
控制模块,用于若所述匹配模块匹配成功,在存储模块保存的记录中获取匹配到的用户对应的网络访问控制策略,并将获取到的网络访问控制策略配置给所述接入设备的MAC地址。
进一步地,上述路由器还可具有以下特点,所述控制模块,还用于当某个接入设备从本路由器断开时,查找该接入设备上是否输入了接入用户,若是,将为该接入设备配置的网络访问控制策略删除。
本申请提供的基于路由器的网络访问控制方法、系统及相关设备,针对需要设置网络访问控制策略的用户,路由器将该用户的指纹信息、用户名以及对应的网络访问控制策略作为一条记录进行保存,当接入用户使用接入设备连接到路由器时,通过指纹验证匹配到相应的用户,针对该用户实施预先设置的网络访问控制策略。本方案解决了现有基于路由器的网络访问控制方案中,无法真正做到针对某个接入用户设置网络访问控制策略的问题,可以精准、方便地针对具体连接到路由器的用户设置网络访问控制策略;并且基于指纹信息可以准确有效地识别接入用户而难以造假,从而有效提升了网络访问控制的精准度。
本申请的其它特征和优点将在随后的说明书中阐述,并且,部分地从说明书中变得显而易见,或者通过实施本申请而了解。本申请的目的和其他优点可通过在所写的说明书、权利要求书、以及附图中所特别指出的结构来实现和获得。
附图说明
附图用来提供对本申请的进一步理解,并且构成说明书的一部分,与本申请实施例一起用于解释本申请,并不构成对本申请的限制。在附图中:
图1为本申请实施例一中基于路由器的网络访问控制方法的流程图。
图2为本申请实施例二中基于路由器的网络访问控制方法的流程图。
图3为本申请实施例三中基于路由器的网络访问控制系统架构图。
图4为本申请实施例四中路由器的结构框图。
具体实施方式
本申请实施例提供一种基于路由器的网络访问控制方法、系统及相关设备,能够方便、有效地识别接入用户,并且难以造假,实现针对每个接入用户制定不同的网络访问控制策略,从而有效提升了网络访问控制的精准度。
以下结合说明书附图对本申请的优选实施例进行说明,应当理解,此处所描述的优选实施例仅用于说明和解释本申请,并不用于限定本申请。并且在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互组合。
实施例一
本申请人在申请过程中发现,目前相当一部分接入设备(例如手机、PC等)都具有指纹识别功能,本申请实施例将指纹识别和基于路由器的网络访问控制相结合,以便于识别接入用户,并且难以造假,达到真正地针对每个接入用户制定不同的网络访问控制策略的目的,使得网络访问控制更加精准。
需要说明的是,在执行网络访问控制之前,针对需要设置网络访问控制策略的用户,需要预先采集用户的指纹信息,为该用户制定网络访问控制策略,并将该用户的指纹信息、用户名以及对应的网络访问控制策略作为一条记录保存在路由器中,供后续网络访问控制时使用。基于上述前期准备工作的完成,如图1所示,本申请实施例提供的基于路由器的网络访问控制方法,包括如下步骤:
S101、当接入用户使用接入设备连接到路由器时,路由器指示该接入用户进行指纹验证。
具体实施中,一旦某个已经在路由器设置了网络访问控制策略的用户,使用任何接入设备连接到路由器时,该接入用户首先必须进行指纹验 证,以获得相应的网络访问权限。
S102、路由器接收接入设备传送的该接入用户通过本设备录入的指纹信息、以及本设备的MAC地址。
S103、路由器根据接入用户的指纹信息,在保存的记录中匹配该指纹信息对应的用户,若匹配成功,在保存的记录中获取匹配到的用户对应的网络访问控制策略,并将获取到的网络访问控制策略配置给接入设备的MAC地址。
至此,基于路由器的网络访问控制方法执行完成。为了避免同一接入设备在后续由不同的用户接入后,仍使用上一个接入用户侧的网络访问控制策略的问题,本申请实施例提供的网络访问控制方法,进一步包括如下步骤:
S104、当某个接入设备从路由器断开时,路由器查找该接入设备上是否输入了接入用户,若是,将为该接入设备配置的网络访问控制策略删除。
实施例二
下面对本申请实施例的具体实施过程进行详细说明,为了便于理解,将用户记作user,路由器记作router,接入设备记作client,安装在client的应用程序记作APP,用户的指纹信息记作fingerprint,网络访问控制策略记作policy。如图2所示,具体包括如下步骤:
S201、user将可获取指纹信息的client接入router。
S202、管理员在router上触发获取用户的指纹信息的事件。
S203、router和client上安装的APP交互,即发送通知消息,指示提取user的fingerprint。
S204、user在client上录入指纹信息;
S205、Client上安装的APP获取到该user的fingerprint,APP将fingerprint编码后传给router,user的fingerprint录入完成。
S206~S207、user的fingerprint录入完成后,router会要求管理员为该user设置policy,并为该user提供一个用户名,以方便识别和管理;管理员设置完成后,router会将fingerprint+用户名+policy作为一条记录,保存在router中。
S208、假设某个设置了policy的user使用任意client再次连接到router。
S209、Client接入router后,router会发送指纹验证请求到client APP,要求user验证fingerprint。
S210~S211、User通过client录入fingerprint后,APP会将fingerprint+client MAC地址传送给router。
S212、Router通过算法匹配该fingerprint所对应的user。
S213~S214、如果匹配到了某个user,则获取之前保存的该user的policy,然后将该policy配置给client的MAC地址。
S215~S218、假设某个client从router断开,router查找该client是否输入了某个user,如果查找到某个user,则将该client对应的policy删除。
需要说明的是,S201~S207是预先设置user的policy阶段,为后续基于router的网络接入控制作准备;S208~S214是基于router的网络接入控制阶段,使用user的fingerprint实现接入用户识别以及针对不同的user使用预先配置的不同的policy;S215~S217是针对某个client从router断开的优化处理阶段,保证基于接入用户的网络接入控制顺利实施。各阶段流程相对独立,各阶段中所涉及的user和client,可以是相同的user和client,当然也可以是不同的user和client。
实施例三
基于同一技术构思,本申请实施例提供了一种基于路由器的网络访问控制系统,由于该系统解决问题的原理与网络访问控制方法相一致,因此该系统的实施可以参见方法的实施,重复之处不在赘述。如图3所示,本申请实施例提供的基于路由器的网络访问控制系统,包括接入设备301和路由器302,其中:
接入设备301,用于根据路由器302发送的接入用户进行指纹验证的指示,提示通过本设备接入路由器302的接入用户300录入指纹信息,并将接入用户300通过本设备录入的指纹信息、以及本设备的MAC地址传送给路由器302;
路由器302,用于针对需要设置网络访问控制策略的用户,保存由该用户的指纹信息、用户名以及对应的网络访问控制策略组成的一条记录;当接入用户300使用接入设备301连接到本路由器时,指示接入用户300进行指纹验证;以及根据接入用户的指纹信息,在保存的记录中匹配指纹 信息对应的用户,若匹配成功,在保存的记录中获取匹配到的用户对应的网络访问控制策略,并将获取到的网络访问控制策略配置给接入设备301的MAC地址。
较佳的,为了避免同一接入设备在后续由不同的用户接入后,仍使用上一个接入用户侧的网络访问控制策略的问题,路由器302,还用于当某个接入设备从本路由器断开时,查找该接入设备上是否输入了接入用户,若是,将为该接入设备配置的网络访问控制策略删除。
为了实施本方案,接入设备301上一般安装有APP(应用程序)。具体实施中:
路由器302,具体用于通过向接入设备301上安装的APP发送指纹验证请求,指示接入用户300进行指纹验证;
接入设备301,具体用于通过本设备上安装的APP将接入用户300通过本设备录入的指纹信息、以及本设备的MAC地址传送给路由器302。
为了预先在路由器中为用户制定网络访问控制策略,具体实施中:
路由器302,还用于当获取用户的指纹信息的事件被触发后,向接入设备301上安装的APP发送通知消息,指示提取用户的指纹信息;以及将该用户的指纹信息,以及为该用户设置的用户名和网络访问控制策略作为一条记录,保存在本路由器中;
接入设备301,还用于通过本设备上安装的APP获取用户在本设备上录入的指纹信息,并将指纹信息编码后发送给路由器302。
实施例四
本申请实施例还提供一种路由器的可能结构,如图4所示,包括:
存储模块401,用于针对需要设置网络访问控制策略的用户,保存由该用户的指纹信息、用户名以及对应的网络访问控制策略组成的一条记录;
指示模块402,用于当接入用户使用接入设备连接到本路由器时,指示接入用户进行指纹验证;
接收模块403,用于接收接入设备传送的所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址;
匹配模块404,用于根据接入用户的指纹信息,在存储模块401保存 的记录中匹配所述指纹信息对应的用户;
控制模块405,用于若所述匹配模块匹配成功,在存储模块401保存的记录中获取匹配到的用户对应的网络访问控制策略,并将获取到的网络访问控制策略配置给接入设备的MAC地址。
具体实施中,控制模块405,还用于当某个接入设备从本路由器断开时,查找该接入设备上是否输入了接入用户,若是,将为该接入设备配置的网络访问控制策略删除。
本申请实施例提供的基于路由器的网络访问控制方法、系统及相关设备,针对需要设置网络访问控制策略的用户,路由器将该用户的指纹信息、用户名以及对应的网络访问控制策略作为一条记录进行保存,当接入用户使用接入设备连接到路由器时,通过指纹验证匹配到相应的用户,针对该用户实施预先设置的网络访问控制策略。本方案解决了现有基于路由器的网络访问控制方案中,无法真正做到针对某个接入用户设置网络访问控制策略的问题,可以精准、方便地针对具体连接到路由器的用户设置网络访问控制策略;并且基于指纹信息可以准确有效地识别接入用户而难以造假,从而有效提升了网络访问控制的精准度。
本领域的技术人员应明白,本申请的实施例可提供为方法、系统、设备或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。
以上所述仅为本申请的较佳实施例,并不用以限制本申请,凡在本申请的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本申请的保护范围之内。

Claims (10)

  1. 一种基于路由器的网络访问控制方法,其特征在于,针对需要设置网络访问控制策略的用户,所述路由器将该用户的指纹信息、用户名以及对应的网络访问控制策略作为一条记录进行保存,所述方法包括:
    当接入用户使用接入设备连接到路由器时,路由器指示所述接入用户进行指纹验证;
    路由器接收所述接入设备传送的所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址;
    路由器根据所述接入用户的指纹信息,在保存的记录中匹配所述指纹信息对应的用户,若匹配成功,在保存的记录中获取匹配到的用户对应的网络访问控制策略,并将获取到的网络访问控制策略配置给所述接入设备的MAC地址。
  2. 根据权利要求1所述的方法,其特征在于,还包括:
    当某个接入设备从所述路由器断开时,路由器查找该接入设备上是否输入了接入用户,若是,将为该接入设备配置的网络访问控制策略删除。
  3. 根据权利要求1所述的方法,其特征在于,所述接入设备上安装有应用程序APP;
    所述路由器指示所述接入用户进行指纹验证,具体包括:
    所述路由器向接入设备上安装的APP发送指纹验证请求,指示所述接入用户进行指纹验证;以及
    所述接入设备通过本设备上安装的APP将所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址传送给路由器。
  4. 根据权利要求1所述的方法,其特征在于,所述接入设备上安装有应用程序APP;以及
    针对需要设置网络访问控制策略的用户,所述路由器将该用户的指纹信息、用户名以及对应的网络访问控制策略作为一条记录进行保存的实现方法,具体包括:
    当路由器上获取用户的指纹信息的事件被触发后,路由器向接入设备上安装的APP发送通知消息,指示提取用户的指纹信息;
    接入设备上安装的APP获取用户在本设备上录入的指纹信息,并将指纹信息编码后发送给路由器;
    路由器将该用户的指纹信息,以及为该用户设置的用户名和网络访问控制策略作为一条记录,保存在本路由器中。
  5. 一种基于路由器的网络访问控制系统,其特征在于,包括接入设备和路由器,其中:
    所述接入设备,用于根据所述路由器发送的接入用户进行指纹验证的指示,提示通过本设备接入路由器的接入用户录入指纹信息,并将所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址传送给路由器;
    所述路由器,用于针对需要设置网络访问控制策略的用户,保存由该用户的指纹信息、用户名以及对应的网络访问控制策略组成的一条记录;当接入用户使用接入设备连接到本路由器时,指示所述接入用户进行指纹验证;以及根据所述接入用户的指纹信息,在保存的记录中匹配所述指纹信息对应的用户,若匹配成功,在保存的记录中获取匹配到的用户对应的网络访问控制策略,并将获取到的网络访问控制策略配置给所述接入设备的MAC地址。
  6. 根据权利要求5所述的系统,其特征在于,
    所述路由器,还用于当某个接入设备从本路由器断开时,查找该接入设备上是否输入了接入用户,若是,将为该接入设备配置的网络访问控制策略删除。
  7. 根据权利要求6所述的系统,其特征在于,所述接入设备上安装有应用程序APP;以及
    所述路由器,具体用于通过向接入设备上安装的APP发送指纹验证请求,指示所述接入用户进行指纹验证;
    所述接入设备,具体用于通过本设备上安装的APP将所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址传送给路由器。
  8. 根据权利要求5所述的系统,其特征在于,所述接入设备上安装有应用程序APP;以及
    所述路由器,还用于当获取用户的指纹信息的事件被触发后,向接入 设备上安装的APP发送通知消息,指示提取用户的指纹信息;以及将该用户的指纹信息,以及为该用户设置的用户名和网络访问控制策略作为一条记录,保存在本路由器中;
    所述接入设备,还用于通过本设备上安装的APP获取用户在本设备上录入的指纹信息,并将指纹信息编码后发送给路由器。
  9. 一种路由器,其特征在于,包括:
    存储模块,用于针对需要设置网络访问控制策略的用户,保存由该用户的指纹信息、用户名以及对应的网络访问控制策略组成的一条记录;
    指示模块,用于当接入用户使用接入设备连接到本路由器时,指示所述接入用户进行指纹验证;
    接收模块,用于接收所述接入设备传送的所述接入用户通过本设备录入的指纹信息、以及本设备的MAC地址;
    匹配模块,用于根据所述接入用户的指纹信息,在存储模块保存的记录中匹配所述指纹信息对应的用户;
    控制模块,用于若所述匹配模块匹配成功,在存储模块保存的记录中获取匹配到的用户对应的网络访问控制策略,并将获取到的网络访问控制策略配置给所述接入设备的MAC地址。
  10. 根据权利要求9所述的路由器,其特征在于,
    所述控制模块,还用于当某个接入设备从本路由器断开时,查找该接入设备上是否输入了接入用户,若是,将为该接入设备配置的网络访问控制策略删除。
PCT/CN2016/085421 2015-11-16 2016-06-12 一种基于路由器的网络访问控制方法、系统及相关设备 Ceased WO2017084322A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510785241.6A CN105871749A (zh) 2015-11-16 2015-11-16 一种基于路由器的网络访问控制方法、系统及相关设备
CN201510785241.6 2015-11-16

Publications (1)

Publication Number Publication Date
WO2017084322A1 true WO2017084322A1 (zh) 2017-05-26

Family

ID=56623656

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/085421 Ceased WO2017084322A1 (zh) 2015-11-16 2016-06-12 一种基于路由器的网络访问控制方法、系统及相关设备

Country Status (2)

Country Link
CN (1) CN105871749A (zh)
WO (1) WO2017084322A1 (zh)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108347730B (zh) * 2017-01-25 2022-12-09 中兴通讯股份有限公司 一种无线通信处理方法及装置
CN107196933A (zh) * 2017-05-18 2017-09-22 西南大学 一种新型指纹认证联网设备及其联网方法
CN107612742A (zh) * 2017-10-09 2018-01-19 郑州云海信息技术有限公司 一种路由设备配置终端指纹的方法
CN114448671B (zh) * 2021-12-27 2025-02-14 航天信息股份有限公司 一种基于智能路由器对上网权限进行控制的方法及系统

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100064372A1 (en) * 2008-07-21 2010-03-11 Workshare Technology, Inc. Methods and systems to implement fingerprint lookups across remote agents
CN102625303A (zh) * 2011-01-27 2012-08-01 西安龙飞软件有限公司 一种通过指纹进行wfii/3g路由器接入认证方法
CN203466847U (zh) * 2013-05-10 2014-03-05 龙旗电子(惠州)有限公司 一种3g/wifi路由器指纹接入检测装置
CN104469762A (zh) * 2013-09-12 2015-03-25 西安龙飞网络科技有限公司 一种3g/wifi无线路由器用户分级控制方法
CN104902477A (zh) * 2015-06-26 2015-09-09 努比亚技术有限公司 鉴权终端、无线路由器、无线路由器的连接方法及系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101188603A (zh) * 2006-11-16 2008-05-28 中兴通讯股份有限公司 一种根据用户权限访问外部网络的方法
CN100499554C (zh) * 2007-06-28 2009-06-10 杭州华三通信技术有限公司 网络准入控制方法及网络准入控制系统
US20110034248A1 (en) * 2009-08-07 2011-02-10 Steelseries Hq Apparatus for associating physical characteristics with commands

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100064372A1 (en) * 2008-07-21 2010-03-11 Workshare Technology, Inc. Methods and systems to implement fingerprint lookups across remote agents
CN102625303A (zh) * 2011-01-27 2012-08-01 西安龙飞软件有限公司 一种通过指纹进行wfii/3g路由器接入认证方法
CN203466847U (zh) * 2013-05-10 2014-03-05 龙旗电子(惠州)有限公司 一种3g/wifi路由器指纹接入检测装置
CN104469762A (zh) * 2013-09-12 2015-03-25 西安龙飞网络科技有限公司 一种3g/wifi无线路由器用户分级控制方法
CN104902477A (zh) * 2015-06-26 2015-09-09 努比亚技术有限公司 鉴权终端、无线路由器、无线路由器的连接方法及系统

Also Published As

Publication number Publication date
CN105871749A (zh) 2016-08-17

Similar Documents

Publication Publication Date Title
US12126997B2 (en) Mobile authentication in mobile virtual network
CN110311929B (zh) 一种访问控制方法、装置及电子设备和存储介质
CN104767715B (zh) 网络接入控制方法和设备
TWI654534B (zh) 身份認證方法、裝置及伺服器
CN110968848B (zh) 基于用户的权限管理方法、装置及计算设备
CN111385180B (zh) 通信隧道构建方法、装置、设备及介质
CN115996381B (zh) 一种无线专网的网络安全管控方法、系统、装置及介质
WO2017084322A1 (zh) 一种基于路由器的网络访问控制方法、系统及相关设备
CN113271299B (zh) 一种登录方法和服务器
CN102984261B (zh) 基于手机终端的网络业务登录方法、设备和系统
WO2017219748A1 (zh) 访问权限的确定、页面的访问方法及装置
US10204073B2 (en) Managing actions of a network device based on policy settings corresponding to a removable wireless communication device
CN109936515A (zh) 接入配置方法、信息提供方法及装置
WO2014206152A1 (zh) 一种网络安全监控方法和系统
CN106685785A (zh) 一种基于IPsec VPN代理的Intranet接入系统
CN105141418A (zh) 认证鉴权方法及系统
WO2020248368A1 (zh) 一种内网访问方法、系统及相关装置
CN109788528B (zh) 接入点及其上网业务开通方法和系统
WO2016152416A1 (ja) 通信管理システム、アクセスポイント、通信管理装置、接続制御方法、通信管理方法、及びプログラム
WO2020248369A1 (zh) 一种防火墙切换方法及相关装置
CN105978866B (zh) 一种用户访问控制的实现方法和系统、第三方用户服务器
CN107395641A (zh) 基于sslvpn服务器的认证管理方法及装置
JP4886651B2 (ja) Lan制御情報管理装置、lan制御システムおよびlan制御情報管理方法
CN116390025B (zh) 确定设备所属办公区域的方法、系统、装置及设备
CN106209670B (zh) 一种接口控制方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16865503

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16865503

Country of ref document: EP

Kind code of ref document: A1