Method system and server for implementing dhcp address security allocation
8 claims: 3 independent, 5 dependent
- 1A method for realizing a secure assignment of a DHCP address, comprising:receiving, by an access server, a DHCP Discovery message (91);inserting, by the access server, location information of the DHCP client into the DHCP Discovery message (93);sending, by the access server, the DHCP Discovery message with the location information of the DHCP client to a DHCP authentication server (93);receiving, by the DHCP authentication server, the DHCP Discovery message with the location information of the DHCP client (93), characterized in that : the DHCP authentication server is a DHCP server having an authentication function configured locally, the DHCP authentication server comprises a local database comprising identification information saved for a valid subscriber locally;wherein the method further comprises: performing, by the DHCP authentication server, an authentication of the DHCP client based on the location information and the identification information saved for the valid subscriber locally;and sending, by the DHCP authentication server, a DHCP message with address information that is assigned to the DHCP client which has passed the authentication via the access server, after the authentication of the DHCP client is passed (96).
- 5A DHCP authentication server for realizing a secure assignment of a DHCP address, comprising a DHCP server for assigning an IP address to a DHCP client which requests for an IP address, characterized in that :the DHCP authentication server has an authentication function configured locally, and the DHCP authentication server further comprises: an authentication processing module, and a local database comprising identification information saved for a valid subscriber locally, wherein: the authentication processing module is adapted to obtain location information of a client initiating a DHCP process, perform a validity authentication of the client according to the location information and the identification information saved for the valid subscriber, and send a DHCP Discovery message of a DHCP client which has passed the validity authentication to the DHCP server;and the DHCP server is adapted to receive the DHCP Discovery message sent by the authentication processing module and send a DHCP Offer message to the DHCP client, and assign an IP address to a corresponding DHCP client in an address pool of the DHCP server when the DHCP client sends a DHCP request message.
- 7A system for realizing a secure assignment of a DHCP address, comprising an access server and a DHCP authentication server; wherein the access server is adapted to receive the DHCP Discovery message sent from the DHCP client, insert location information of the DHCP client into the DHCP Discovery message and send the DHCP Discovery message with the location information to the DHCP authentication server; characterized in that :the DHCP authentication server has an authentication function configured locally, and is adapted to receive the DHCP Discovery message with the location information of the DHCP client and perform an authentication of the DHCP client based on the location information and identification information saved for a valid subscriber locally;and send a DHCP message with address information that is assigned to the DHCP client which has passed the authentication via the access server.
Independent claims3
63 paragraphs, as filed
Field of the Invention
0001The present invention relates to the technical field of network communications, in particular, to a method, a system and a server for realizing a secure assignment of a Dynamic Host Configuration Protocol (DHCP) address.
Background of the Invention
0002As access technologies such as ADSL (Asymmetrical Digital Subscriber Line), Ethernet become more and more mature, broadband access becomes more and more popular; and IPTV (Internet Protocol Television) video and VolP (Voice over Internet protocol) services developed based on broadband access network become more and more abundant. The development of each service needs to employ a dedicated terminal; for example, video service needs to use STB (Set Top Box), voice service needs to use IAD (Integrated Access Device). Each dedicated terminal needs to obtain a local address before a service is carried out, and then each service may be carried out using the local address.
0003In a communication network, each terminal usually obtains an IP (Internet Protocol) address based on DHCP protocol. However, in a traditional online service, PPPoE (Point-to-Point Protocol over Ethernet) is usually employed, and an AAA (Authentication, Authorization and Accounting) server is needed to authenticate an access subscriber and assign the IP address. Usually, The AAA server may be an RADIUS (Remote Authentication Dial In User Service) server or other authentication servers.
0004<figref idref="f0001">Figure 1</figref> shows a structure of a network communication system in which an authentication is performed by an RADIUS server and the IP address is obtained via a DHCP server.
0005DHCP server is a server for managing IP addresses and is adapted to respond to an address assignment request from a computer and assign an appropriate IP address to the computer.
0006DHCP client is a terminal adapted to obtain network parameters such as the IP address using DHCP protocol, including computer, STB and IAD.
0007RADIUS server is adapted to manage the account and password of a subscriber and perform an authentication of an access subscriber.
0008BRAS (Broadband Remote Access Server) is adapted to manage the access of a broadband subscriber; for a PPPoE subscriber, the BRAS acts as an RADIUS client and initiates an authentication request to the RADIUS server; and for a DHCP subscriber, the BRAS implements the DHCP relay function
0009Access Network is an intermediate network between the subscriber household and the BRAS.
0010Access Node is a device connecting with a subscriber line directly in an access network, such as ADSL access device DSLAM (Digital Subscriber Line Access Multiplexer).
0011OSS (Operations Support Systems) is a system for the operator to release and manage a service.
0012In <figref idref="f0001">Figure 1</figref>, a DHCP client such as STB and IAD may be assigned with a corresponding IP address using DHCP protocol by a DHCP server disposed in the network.
0013The specific process in which each DHCP client of <figref idref="f0001">Figure 1</figref> obtains the address is as shown in <figref idref="f0001">Figure 2</figref>, including the following steps.
0014Step 21: A DHCP client switches on, sends a DHCP Discovery message to search a server capable of providing the DHCP service.
0015Step 22: As a DHCP relay, a BRAS relays the DHCP Discovery message to the designated DHCP server.
0016Step 23: The DHCP server returns a DHCP Offer message to indicate that the DHCP server is capable of assigning an IP address to the client.
0017Step 24: The DHCP client sends a DHCP Request message and the BRAS relays the DHCP request message to the DHCP server.
0018Step 25: The DHCP server assigns an appropriate IP address and returns a DHCP Reply message.
0019Therefore, the DHCP client may obtain the IP address, and thus access the network and obtain the network service.
0020It can be seen from the above DHCP address assignment process that: during the process in which the DHCP client obtains the IP address in a DHCP mode, an invalid subscriber may easily obtain the corresponding IP address and thus obtain the network service. Therefore, the problem that a hacker maliciously uses up the IP address resources and attacks a network is easy to occur. Moreover, after the hacker attacks the network, the hacker cannot be traced.
0021Additionally, the operator needs to use a DHCP server to manage the IP address of the user of the DHCP client and use an RADIUS server to manage the IP address of the user of the PPPoE client. As a result, there exists two sets of IP address resource management mechanisms, the data is decentralized, and the management cost is high. In addition, <patcit id="pcit0001" dnum="WO9916266A"><text>WO 99/16266 A</text></patcit> discloses the following contents. Applications running on a mobile station or an external network entity such as an Internet service provider may specify on an individual application flow basis a requested quality of service. From that requested quality of service, an optimal type of bearer to transfer the application flow through the mobile communications network is determined. For example, a circuit-switched bearer may be allocated if the request is for a real-time service, and a packet-switched bearer may be allocated if the request is for a non-real time type of service. Various other decision making criteria may be employed. A mobile station and a mobile network gateway node each include a mapper for mapping an individual application flow to one of a circuit-switched network and a packet-switched network bearers depending on the quality of service requested for the individual application flow. The network layer quality of service parameters corresponding to an individual application flow are mapped to circuit-switched bearer parameters if the application flow is mapped to the circuit-switched network and to packet-switched bearer parameters if the application flow is mapped to the packet-switched network. The gateway node includes a common access server which permits a mobile station initially establishing a communications session with an external network entity to perform only a single, common access procedure for subsequent communications using one of the circuit-switched and packet-switched networks. After that common access procedure is completed, subsequent application flows between the mobile station and the external network entity are established using abbreviated procedures without having to access the external network entity. Further, IETF STANDARD "DHCP Relay Agent Information Option; rfc 3046.txt" discloses technical contents in connection with DHCP Relay Agent. Further, a patent application (<patcit id="pcit0002" dnum="WO2004006503A"><text>WO/2004/006503</text></patcit>) provides an arrangement and a method with dynamic port configuration of network equipment for communication in a broadband network. A central managing database in connection with a Dynamic Host Configuration Protocol server is keeping templates with recordings of network equipment parameters for their physical port settings and deployed services. Hence, enabling dynamic updating of port settings by conveying parameter recordings from the Dynamic Host Configuration Protocol server. The parameter settings are updated in the intermediate means. However, in the technical solution of D3, because the database is located out of the DHCP server, the data management cost is high and the security for data transmission is low.
Summary of the Invention
0022In view of the above problems in the prior art, an object of the present invention is to provide a method, a system and a server for realizing a secure assignment of a DHCP address. And therefore the security of the address assignment process of the DHCP server may be effectively guaranteed and the data management cost is low.
0023The object of the present invention is realized by the following technical solutions. A method for realizing a secure assignment of a DHCP address, comprising: <ul id="ul0001" list-style="none" compact="compact"><li>receiving, by an access server, a DHCP Discovery message;</li><li>inserting, by the access server, location information of the DHCP client into the DHCP Discovery message;</li><li>sending, by the access server, the DHCP Discovery message with the location information of the DHCP client to a DHCP authentication server;</li><li>receiving, by the DHCP authentication server, the DHCP Discovery message with the location information of the DHCP client, wherein the DHCP authentication server is a DHCP server having an authentication function configured locally, the DHCP authentication server comprises a local database comprising identification information saved for a valid subscriber locally;</li><li>performing an authentication of the DHCP client based on the location information and the identification information saved for the valid subscriber locally by the DHCP authentication server; and</li><li>sending, by the DHCP authentication server, a DHCP message with address information that is assigned to the DHCP client which has passed the authentication via the access server, after the authentication of the DHCP client is passed.</li></ul> A DHCP authentication server for realizing a secure assignment of a DHCP address, the DHCP authentication server having an authentication function configured locally, and comprising an authentication processing module, a DHCP server for assigning an IP address to a DHCP client which requests for an IP address, and a local database comprising identification information saved for a valid subscriber locally, wherein: the authentication processing module is adapted to obtain location information of a client initiating a DHCP process, perform a validity authentication of the client according to the location information and the identification information saved for the valid subscriber, and send a DHCP Discovery message of a DHCP client which has passed the validity authentication to the DHCP server; and the DHCP server is adapted to receive the DHCP Discovery message sent by the authentication processing module and send a DHCP Offer message to the DHCP client, and assign an IP address to a corresponding DHCP client in an address pool of the DHCP server when the DHCP client sends a DHCP request message. A system for realizing a secure assignment of a DHCP address, comprising an access server and a DHCP authentication server; wherein the access server is adapted to receive the DHCP Discovery message sent from the DHCP client, insert location information of the DHCP client into the DHCP Discovery message and send the DHCP Discovery message with the location information to the DHCP authentication server; and the DHCP authentication server has an authentication function configured locally, and is adapted to receive the DHCP Discovery message with the location information of the DHCP client and perform an authentication of the DHCP client based on the location information and identification information saved for a valid subscriber locally; and send a DHCP message with address information that is assigned to the DHCP client which has passed the authentication via the access server.
0024Moreover, in the present invention, addresses may be managed by an RADIUS server unitedly, in other words, the DHCP server and the RADIUS server unitedly manages the IP addresses, thus the cost of network management may be towered. In addition, the original security measures of the RADIUS server may be used to control the number of IP addresses to be obtained by a subscriber, so that the attack of malicious address use-up may be effectively prevented. Even if the network attack or other network security problems occur, the physical location of the subscriber may be traced according to the IP address, so that a hacker may be effectively deterred from carrying out an attack activity.
0025The present invention has good compatibility, in other words, during the implementation of the present invention, no extra interface and command is added to the OSS system, and the service management process on the user of the DHCP client is consistent with the original service release management process on the PPPoE client. As a result, the investment of the operator may be protected.
Brief Description of the Drawings
0026<figref idref="f0001">Figure 1</figref> is a structural representation of a broadband access system;
0027<figref idref="f0001">Figure 2</figref> is a schematic diagram showing a process in which a DHCP server obtains an address;
0028<figref idref="f0002">Figure 3</figref> is a structural representation of the DHCP authentication server according to the present invention;
0029<figref idref="f0002">Figure 4</figref> is another structural representation system according to the present invention; and
0030<figref idref="f0003">Figure 5</figref> is a schematic diagram of a DHCP address assignment process based on the system shown in <figref idref="f0002">Figure 4</figref>.
Detailed Description of the Embodiments
0031The main concept of the present invention lies in that: during the process in which a DHCP client obtains an address from a DHCP server, a validity authentication process on the DHCP client is added, so that an invalid subscriber may be prevented from attacking the DHCP server. In addition, based on the above concept, the address management of the DHCP server and the authentication server may be united, thus it is easy to perform address management. The authentication server includes an AAA server such as a RADIUS server. Optionally, the authentication server may be other authentication servers with the similar function.
0032One embodiment of the present invention provides a method for realizing a secure assignment of a DHCP address, mainly including the following.
0033(1) A DHCP client sends a DHCP Discovery message via an access network.
0034(2) The access server on the network side (such as BRAS and access node) determines identification information of the DHCP client, such as the port number, VPI (Virtual path identifiers)NCI (Virtual channel identifiers) and VLAN ID (Virtual Local Area Network ID), according to ingress port information of the DHCP Discovery message, and performs an authentication of the DHCP client based on the identification information of the DHCP client and preconfigured identification information for a valid subscriber.
0035(3) The DHCP Discovery message of the DHCP client having passed the authentication is sent to the DHCP server, and the address is assigned to the DHCP client via the DHCP server. The specific address assignment process is the same as a conventional address assignment process, and the repeat description thereof is omitted.
0036Moreover, a corresponding DHCP server with an authentication function may be configured in the network, so that the DHCP server may first perform an authentication process after receiving a DHCP Discovery message sent from a DHCP client, and the corresponding address will only be assigned after the authentication is passed.
0037The present invention provides a DHCP authentication server with the authentication function. Descriptions of the DHCP authentication server will now be illustrated in conjunction with the drawings respectively.
0038For the DHCP authentication server with the authentication function, the authentication function is configured and implemented locally. The specific structure of the DHCP authentication server is as shown in <figref idref="f0002">Figure 3</figref>, including an authentication processing module and a DHCP server module.
0039The authentication processing module is adapted to obtain the identification information of the DHCP client during initiating the DHCP process, perform a validity authentication of the client according to the identification information saved for valid subscribers, and then send an authentication result to the DHCP server module, wherein the identification information of the valid subscriber is saved in a corresponding storage module (not shown).
0040The DHCP server module is adapted to obtain the authentication result on the DHCP client from the authentication processing module, send a DHCP Offer message to the DHCP client with the authentication result of PASSED to indicate that the DHCP server may assign a corresponding IP address to the DHCP client, and then assign the corresponding IP address to the DHCP client after the DHCP client sends a DHCP request message. Thus, the function of the DHCP server is implemented.
0041At this point, the DHCP authentication server operates in a server mode, corresponds to a DHCP server with a secure authentication function, and may implement the authentication and address assignment for a client independently.
0042The above DHCP authentication server with the authentication function may be configured in any network in need of a DHCP server to realize the corresponding function of address assignment.
0043The present invention further provides a corresponding system with a DHCP address assignment and authentication function for realizing a secure assignment of a DHCP address. The structure of the system is shown in <figref idref="f0002">Figure 4</figref>, specifically including a DHCP client, an access network and a DHCP authentication server. The DHCP authentication server is adapted to perform a validity authentication of a DHCP Discovery message of the DHCP client obtained by the access network, and perform an address assignment to the DHCP client which has passed the authentication.
0044In the system according to the present invention, the DHCP authentication server may perform the authentication of the DHCP client and assign a corresponding IP address in the following mode.
0045As shown in <figref idref="f0003">Figure 5</figref>, the validity authentication is performed on the identification information of the DHCP client according to the identification information of the valid subscriber saved locally, and the DHCP server may assign the corresponding IP address to the DHCP client which has passed the authentication.
0046Specifically, in the system, the access node and BRAS support the capture of a DHCP message and insert an option Option82 into the DHCP message, so that the DHCP authentication server may obtain the corresponding identification information of the DHCP client after receiving the DHCP message. In the option Option82, subscriber location information, acting as the identification information, is identified. Specifically, the subscriber location information includes port information, VPI/VCI information and VLAN ID. The option Option82 may be inserted into the DHCP message on the access node, or the option Option82 may be inserted into the DHCP message on the BRAS.
0047The present invention further provides a corresponding method for realizing a secure assignment of a DHCP address based on the above system. A detail description will now be illustrated below.
0048For example, the method is described in the case that the DHCP authentication server operates in a server mode, as shown in <figref idref="f0002">Figure 4</figref> and <figref idref="f0003">Figure 5</figref>.
0049Step 91: When a subscriber opens an account, the operator adds a piece of data to a DHCP authentication server and records the subscriber location information, the encoding mode is consistent with the option Option82 inserted by the access node or the BRAS, and the MAC address of a terminal (STB, IAD) may be selectively recorded.
0050Step 92: When a DHCP client needs to obtain the IP address, the DHCP client needs to send a DHCP Discovery message to the BRAS.
0051Step 93: As a DHCP relay, the BRAS captures the DHCP message and inserts option Option82 into the message, and then sends the DHCP Discovery message carrying the subscriber location information to the DHCP authentication server. The subscriber location information, such as port information, VPI/VCI and VLAN ID, is identified in the option Option82.
0052The DHCP authentication server receives the DHCP message relayed by the BRAS, extracts the option Option82 and the MAC address of the terminal as the identification information, queries a local database, and performs an authentication of the identification information of the DHCP client according to the identification information saved for a valid subscriber locally. If the authentication is passed, the DHCP authentication server returns a DHCP Offer message to the DHCP client, as described in Step 94.
0053Step 94: The DHCP authentication server sends a DHCP Offer message to the DHCP client.
0054Step 95: After receiving the DHCP Offer message, the DHCP client sends a DHCP request message to the DHCP authentication server.
0055Step 96: The DHCP authentication server assigns the IP address to the DHCP client, and sends the IP address to the DHCP client via a DHCP Reply message.
0056Similarly, as described in Step 93 of <figref idref="f0003">Figure 5</figref>, the BRAS inserts the option Option82. In practical application, the option Option82 may also be inserted by an access node like DSLAM, while the BRAS only acts as the DHCP relay. Other processes are the same as those described above.
0057In conclusion, the present invention may enhance the security of the address assignment in DHCP mode greatly, and may perform an access authentication of a subscriber according to location information, and may only assign an IP address to a valid subscriber or a valid terminal. Therefore, the attack of malicious address use-up may be effectively prevented. Moreover, when the network attack or other network security problems occur, the physical location of the subscriber may be traced according to the IP address, so that a hacker may be effectively deterred from carrying out an attack activity.
0058Additional advantages and modifications will readily occur to those skilled in the art. Therefore, the present invention in its broader aspects is not limited to the specific details and representative embodiments shown and described herein. Accordingly, various modifications and variations may be made without departing from the scope of the present invention as defined by the appended claims and their equivalents.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| WO9916266A | Cites | World Intellectual Property Organization (WIPO) |
| WO2004006503A | Cites | World Intellectual Property Organization (WIPO) |
| CN1450766A | Cites | China |
| CN1458761A | Cites | China |
| JP2004228799A | Cites | Japan |
| KR2003055695A | Cites | Republic of Korea |
| PATRICK MOTOROLA BCS M: "DHCP Relay Agent Information Option; rfc3046.txt" IETF STANDARD, INTERNET ENGINEERING TASK FORCE, IETF, CH, 1 January 2001 (2001-01-01), XP015008829 ISSN: 0000-0003 | Non-patent | – |
| REN F. ET AL.: 'DHCP and Relative Secure Problem' COMPUTER ENGINEERING vol. 30, no. 17, September 2004, pages 127 - 129, XP008096602 | Non-patent | – |
13 members in 9 offices; this record represents the family
Members13
| Document | Office | Kind | |
|---|---|---|---|
| CN1855926A | China | A | |
| WO2006116926A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1876754A1 | European Patent Office (EPO) | A1 | |
| US2008092213A1 | United States of America | A1 | |
| CN100388739C | China | C | |
| EP1876754A4 | European Patent Office (EPO) | A4 | |
| EP1876754B1This record | European Patent Office (EPO) | B1 | |
| AT546914T | Austria | T | |
| ATE546914T1 | Austria | T1 | |
| PT1876754E | Portugal | E | |
| DK1876754T3 | Denmark | T3 | |
| ES2381857T3 | Spain | T3 | |
| PL1876754T3 | Poland | T3 |
78 legal events, as 17 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| ExpiryMK07 | MK07 | AT | |
| Patent expired because of reaching the maximum lifetime of a patentExpiredMK | MK | BE | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Ep patent expiredExpiredEUP | EUP | DK | |
| Patent expired because of reaching the maximum lifetime of a patentExpiredMK | MK | NL | |
| Ip right expiredExpiredST27 STATUS EVENT CODE: U-0-0-H10-H14 (AS PROVIDED BY THE NATIONAL OFFICE)H14 | H14 | CH | |
| Expiry of rightR071 | R071 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Amendment of ipc main classPREVIOUS MAIN CLASS: H04L0012240000R079 | R079 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Filing of the translation of the text of european patentsAG4A | AG4A | HU | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Translation of ep patentT3 | T3 | PL | |
| Lt: invalidation of european patent or patent extensionLTIE | LTIE | EP | |
| Ep patent validated in greeceEP | EP | GR | |
| Definitive protectionFG2A | FG2A | ES | |
| Ep patent with danish claimsT3 | T3 | DK | |
| Translation filed for an european patent granted for nl, confirming art. 52 par. 1 or 6 of the patents act 1995GrantedT3 | T3 | NL | |
| Translation of granted ep patentGrantedTRGR | TRGR | SE | |
| Translation is availableAVAILABILITY OF NATIONAL TRANSLATIONSC4A | SC4A | PT | |
| Ep patent valid in romaniaEPE | EPE | RO | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Supplementary search report drawn up and despatchedA4 | A4 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1876754
- Application
- 67417519
Titles3
- German
- VERFAHREN, SYSTEM AND SERVER ZUR IMPLEMENTIERUNG VON DHCP-ADRESSEN-SICHERHEITS-ZUTEILUNG
- English
- METHOD SYSTEM AND SERVER FOR IMPLEMENTING DHCP ADDRESS SECURITY ALLOCATION
- French
- PROCEDE, SYSTEME ET SERVEUR POUR METTRE EN OEUVRE L'ATTRIBUTION DE SECURITE D'ADRESSE DHCP
Classification
- CPC, 3
- H04L63/08
- H04L63/0892
- H04L61/5014
- IPC, 2
- H04L12 24
- H04L29 12
Designated states31
- Contracting states, 31
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
- Netherlands (Kingdom of the)
and 7 moreShow fewer
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
