Method system and server for implementing dhcp address security allocation
Abstract
A method and system for implementing DHCP address security allocation and authentication server. The core of the invention is that DHCP client end send the discovery message through access network; when the access network side acquires the identification information such as the port information of said DHCP client end and the like, and authenticates it based on said identification information; finally, DHCP server only allocates the address information for the authorized DHCP client end. Therefore, the invention may perform accessing authentication for user according to the location information, and only allocates the address for the legal user terminals, thereby it enhances the security for allocating address through DHCP manner. Also, in the invention, the address is managed unifiable by the AAA server, or allocates the address after the AAA server authenticates successfully.

Term
Term ended
Projected expiry passed 28 April 2026, 0.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
1 claim: 1 independent, 0 dependent
- 1Claims Zastrzeżenia patentowe 1. A method of performing a secure assignment of a DHCP address, including:1. Sposób wykonywania bezpiecznego przypisania adresu DHCP, obejmujący: odbiór, przez serwer dostępu, komunikatu DHCP Discovery (91);receiving, via the access server, the DHCP Discovery message (91);inserting DHCP location information into the DHCP Discovery message via the access server (93);wstawianie do komunikatu DHCP Discovery, przez serwer dostępu, informacji o położeniu klienta DHCP (93);sending to the DHCP authentication server, via the access server, a DHCP Discovery message with location information of the DHCP client (93);receiving, by the DHCP authentication server, a DHCP Discovery message with location information of the DHCP client (93), characterized in that: wysyłanie do serwera uwierzytelniającego DHCP, przez serwer dostępu, komunikatu DHCP Discovery z informacjami o położeniu klienta DHCP (93);odbiór, przez serwer uwierzytelniający DHCP, komunikatu DHCP Discovery z informacjami o położeniu klienta DHCP (93), znamienny tym, że: serwer uwierzytelniający DHCP jest serwerem DHCP wyposażonym w funkcję uwierzytelniania skonfigurowaną lokalnie, przy czym serwer uwierzytelniający DHCP zawiera lokalną bazę danych, zawierającą zapisane lokalnie informacje identyfikujące dla uprawnionego abonenta;the DHCP authentication server is a DHCP server equipped with a locally configured authentication function, wherein the DHCP authentication server comprises a local database containing locally stored identification information for the authorized subscriber;przy czym sposób obejmuje także: the method also includes: realizing, by the DHCP authentication server, DHCP client authentication based on location information and identifying information stored locally for the authorized subscriber and sending, by the DHCP authentication server, a DHCP message with address information that has been assigned to a DHCP client that has successfully authenticated via an access server after DHCP client authentication (96). realizowanie, przez serwer uwierzytelniający DHCP, uwierzytelniania klienta DHCP na podstawie informacji o położeniu i informacji identyfikujących, zapisanych lokalnie dla uprawnionego abonenta i wysyłanie, przez serwer uwierzytelniający DHCP, komunikatu DHCP z informacjami o adresie, który został przypisany do klienta DHCP, który przeszedł pomyślnie uwierzytelnianie przez serwer dostępu, po przejściu uwierzytelniania klienta DHCP (96). 2. A method of making a secure assignment of a DHCP address, according to claim 1, wherein the location information comprises: 2. Sposób wykonania bezpiecznego przypisania adresu DHCP, według zastrzeżenia 1, w którym informacje o położeniu zawierają: numer portu, numer obwodu i numer połączenia klienta DHCP. port number, circuit number and DHCP client connection number. 3. A method of making a secure DHCP address assignment, according to claim 1 or 2, wherein receiving a DHCP discovery message with DHCP client location information by a DHCP authentication server and performing DHCP client authentication based on location information and identifying information stored locally for an authorized subscriber. by the DHCP authentication server, includes: 3. Sposób wykonywania bezpiecznego przypisania adresu DHCP, według zastrzeżenia 1 albo 2, w którym odbiór komunikatu DHCP Discovery z informacjami o położeniu klienta DHCP przez serwer uwierzytelniający DHCP i realizowanie uwierzytelniania klienta DHCP na podstawie informacji o położeniu i informacji identyfikujących, zapisanych lokalnie dla uprawnionego abonenta przez serwer uwierzytelniający DHCP, obejmuje: odbiór, przez serwer uwierzytelniający DHCP, komunikatu DHCP Discovery z informacjami o położeniu klienta DHCP i realizowanie uwierzytelniania uprawnienia klienta DHCP na podstawie informacji o położeniu i informacji identyfikujących, zapisanych lokalnie dla uprawnionego abonenta. receiving, by the DHCP authentication server, a DHCP Discovery message with the location information of the DHCP client and performing the authentication of the DHCP client entitlement based on location information and identification information stored locally for the authorized subscriber. 4. A method of making a secure assignment of a DHCP address, as claimed in claim 3, also comprising: 4. Sposób wykonywania bezpiecznego przypisania adresu DHCP, według zastrzeżenia 3 obejmujący także: - 10 przypisanie, przez serwer uwierzytelniający DHCP, informacji o adresie do klienta - assigning, by the DHCP authentication server, the address information to the client DHCP that successfully passed authentication after receiving information about the authentication pass. DHCP, który pomyślnie przeszedł uwierzytelnianie, po odbiorze informacji o przejściu uwierzytelniania. 5. A DHCP authentication server for performing a secure DHCP address assignment containing a DHCP server for assigning an IP address to a DHCP client that requests an IP address, characterized by the following: 5. Serwer uwierzytelniający DHCP do wykonywania bezpiecznego przypisania adresu DHCP, zawierający serwer DHCP do przypisywania adresu IP do klienta DHCP, który żąda adresu IP znamienny tym, że: serwer uwierzytelniający DHCP ma funkcję uwierzytelniania skonfigurowaną lokalnie i serwer uwierzytelniający DHCP zawiera także: moduł przetwarzający uwierzytelnianie, a lokalna baza danych zawiera informacje identyfikujące, zapisane lokalnie dla uprawnionego abonenta, przy czym: the DHCP authentication server has a locally configured authentication function and the DHCP authentication server also includes: an authentication processing module, and the local database contains identifying information stored locally for the authorized subscriber, wherein: moduł przetwarzający uwierzytelnianie jest przystosowany do uzyskiwania informacji o położeniu klienta inicjującego proces DHCP, realizowania uwierzytelniania uprawnienia klienta na podstawie informacji o położeniu i informacji identyfikujących, zapisanych dla uprawnionego abonenta oraz wysyłania do serwera DHCP komunikatu DHCP Discovery klienta DHCP, który pomyślnie przeszedł uwierzytelnianie uprawnienia i serwer DHCP jest przystosowany do odbioru komunikatu DHCP Discovery wysyłanego przez moduł przetwarzający uwierzytelnianie i wysyłania do klienta DHCP komunikatu DHCP Offer i przypisywania adresu IP do odpowiedniego klienta DHCP w puli adresów serwera DHCP, gdy klient DHCP wyśle komunikat DHCP Request. the authentication processing module is adapted to obtain information about the location of the client initiating the DHCP process, implementing the client's entitlement authentication based on location information and identifying information stored for the authorized subscriber and sending the DHCP Discovery DHCP client message to the DHCP server that has successfully passed the authorization and server authentication DHCP is configured to receive a DHCP Discovery message sent by the authentication processing module and send a DHCP Offer message to the DHCP client and assign an IP address to the appropriate DHCP client in the DHCP server pool, when the DHCP client sends a DHCP Request message. 6. Serwer uwierzytelniający DHCP, według zastrzeżenia 5, w którym informacje o położeniu zawierają: 6. The DHCP authentication server, according to claim 5, wherein the location information comprises: numer portu, numer obwodu i numer połączenia klienta DHCP. port number, circuit number and DHCP client connection number. 7. A system to perform secure assignment of a DHCP address, including an access server and a DHCP authentication server in which the access server is adapted to receive a DHCP Discovery message sent by a DHCP client, insert the DHCP client location information into a DHCP Discovery message, and send to a DHCP authentication server DHCP Discovery message with location information;7. System do wykonywania bezpiecznego przypisywania adresu DHCP, zawierający serwer dostępu i serwer uwierzytelniający DHCP, w którym serwer dostępu jest przystosowany do odbioru komunikatu DHCP Discovery wysłanego przez klienta DHCP, wstawiania informacji o położeniu klienta DHCP do komunikatu DHCP Discovery oraz wysyłania do serwera uwierzytelniającego DHCP komunikatu DHCP Discovery z informacjami o położeniu;characterized in that: znamienny tym, że: serwer uwierzytelniający DHCP ma funkcję uwierzytelniającą, skonfigurowaną lokalnie i jest przystosowany do odbioru komunikatu DHCP Discovery z informacjami o położeniu klienta DHCP i wykonywania uwierzytelniania klienta DHCP na podstawie informacji o położeniu i informacje identyfikujących, zapisanych lokalnie dla uprawnionego abonenta oraz wysyłania komunikatu DHCP z informacjami o adresie, który został przypisany do klienta DHCP, który przeszedł pomyślnie uwierzytelnianie przez serwer dostępu. the DHCP authentication server has an authentication function configured locally and is adapted to receive a DHCP discovery message with the location of the DHCP client and perform DHCP client authentication based on location information and identifying information stored locally for the authorized subscriber and sending a DHCP message with address information that has been assigned to a DHCP client that has successfully authenticated by the access server. - 11 8. System według zastrzeżenia 7, w którym serwer uwierzytelniający DHCP jest serwerem uwierzytelniającym DHCP jak określony w zastrzeżeniu 5. 8. The system according to claim 7, wherein the DHCP authentication server is a DHCP authentication server as defined in claim 5. She prepared and verified Sporządziła i zweryfikowała Grażyna Palka Patent attorney Grażyna Palka Rzecznik patentowy Fig. 3 Fig. 3 Fig. 4 Fig. 4 - 14 Customer - 14 Klient DHCP DHCP _L_ _L_ 91: Informacje konfigurujące uwierzytelnianie 91: Information that configures authentication 92;DHCP Discovery message 92;Komunikat DHCP Discovery 93: DHCP Discovery message (carrying information about the location of the subscriber) 93: Komunikat DHCP Discovery (przenoszący informacje o położeniu abonenta) 94;DHCP Provision message 94;Komunikat DHCP Provision 96: DHCP Reply message 96: Komunikat DHCP Reply Fig.5 Figure 5
77 paragraphs, as filed
[0001] The invention relates to the field of network communication technology, in particular to a method, a system and a server for performing secure assignment of a dynamic host configuration (DHCP) protocol address.
Background of the Invention [0002] With the development of access technologies such as ADSL (asymmetric digital subscriber line) or Ethernet, broadband access is becoming increasingly popular; and IPTV video services (IP television) and VoIP (Internet voice transmission protocol), developed on the basis of broadband access to the network, are becoming more and more numerous. The development of such services forces the use of a dedicated terminal, for example video services require the use of STB (STB decoder), voice services require the use of IAD (integrated access devices). Each dedicated terminal must obtain a local address before the service is performed, and then each service can be performed using a local address.
[0003] In a communication network, each terminal obtains an IP address (internet protocol) based on the DHCP protocol. However, in traditional online services the PPPoE protocol is usually used (communication protocol between two stations via Ethernet), and the AAA server (authentication, authorization and check-in) must authenticate the subscriber's access and assign the IP address. Typically, the AAA server may be a RADIUS server (remote address address services using switches) or another authentication server.
[0004] Figure 1 shows the structure of a communication network system in which authentication is performed by a RADIUS server and the IP address is obtained from a DHCP server.
[0005] A DHCP server is a server that manages IP addresses and is adapted to respond to computer requests for address assignment and assign a corresponding IP address to a computer.
[0006] A DHCP client is a terminal adapted to obtain network parameters, such as an IP address, using DHCP, including a computer, STB and IAD.
[0007] A RADIUS server is adapted to manage the subscriber's account and password as well as to implement subscriber access authentication.
[0008] The BRAS server (remote broadband access server) is adapted to manage access of a broadband subscriber and in the case of a PPPoE subscriber.
- 2 the BRAS server behaves like a RADIUS client and initiates an authentication request for the RADIUS server and in the case of a DHCP subscriber, the BRAS server performs the DHCP forwarding function.
[0009] The access network is an intermediate network between the subscriber's house and the BRAS server.
[0010] An access node is a device that connects to a subscriber line directly in an access network, such as a DSLAM access device (digital subscriber access multiplexer).
[0011] The OSS (operational support system) is a system for the operator to enter and manage the service.
[0012] Na <sup>f</sup>and<sup>g</sup>. 1<sup>kli</sup>en<sup>t</sup> DHCP - this is me<sup>k ST</sup>B <sup>and</sup> IiAD, mo<sup>with</sup>e <sup>be p</sup>government<sup>YPI</sup>san<sup>yp</sup>through the server <sup>DHCP </sup>placed on the network to the corresponding IP address using the DHCP protocol.
[0013] A specific process in which each DHCP client in Fig. 1 obtains an address is shown in Fig. 2 and comprises the following steps. Step 21: The DHCP client is enabled, sends a DHCP Discovery message to search for a server capable of delivering the service DHCP.
[0015] Step 22: As a DHCP relay, the BRAS server transmits a DHCP Discovery message to the designated DHCP server.
[0016] Step 23: the DHCP server returns a DHCP Offer message to indicate that the DHCP server is able to assign an IP address to the client.
[0017] Step 24: the DHCP client sends a DHCP Request message and the BRAS server forwards the DHCP Request message to the DHCP server.
[0018] Step 25: the DHCP server assigns the corresponding IP address and returns the DHCP Reply message.
[0019] In this way, the DHCP client can obtain the IP address and thus gain access to the network and the network service.
[0020] In the above process of address assignment by DHCP, it can be seen that: during a process during which a DHCP client obtains an IP address in DHCP mode, the wrong subscriber can easily obtain the corresponding IP address and thus obtain a network service. Thus, a problem can easily arise when a hacker maliciously uses IP address resources and attacks the network. In addition, after the hacker attacks the network, he can not be targeted.
[0021] In addition, the operator must use a DHCP server to manage the IP addresses of the DHCP client and RADIUS server to manage the IP addresses of the PPPoE client user. As a result, there are resource management mechanisms of two pools of IP addresses, data is decentralized and management costs are high.
In addition, document WO 99/16266 A discloses the following content. Applications launched in a mobile station or in an external network unit, such as an internet service provider, can determine the desired quality of service based on individual applications. Based
- 3 such a quality of service request is determined an optimal type of transmission for transmitting application data via a mobile communication network. For example, circuit switched communication can be used if the request is for a real-time service and packet switched transmissions can be used if the request is for a non-real-time service. Many other decision-making criteria can be used. Both the mobile station and the gateway of the mobile network gateway contain a mapping unit for mapping the traffic of a given application for transmission of circuit switched networks or packet switched networks, depending on the requested quality of service for the traffic of the given application. The network layer service quality parameters corresponding to the application's traffic are mapped to the circuit switched communication parameters, if the application traffic is mapped to the circuit switched network, and to the packet switched communication parameters, if the application traffic is mapped to the packet switched network. The gateway node comprises a shared access server that allows the mobile station to initially establish communication sessions with an external network entity to perform only a single common access procedure for subsequent communication links, using circuit switched networks and packet switched. After completing this common access procedure, the traffic of subsequent applications between the mobile station and the outdoor network unit is set using shortened procedures, without having to access the outside network unit. if the application traffic is mapped to the packet switched network. The gateway node comprises a shared access server that allows the mobile station to initially establish communication sessions with an external network entity to perform only a single common access procedure for subsequent communication links, using circuit switched networks and packet switched. After completing this common access procedure, the traffic of subsequent applications between the mobile station and the outdoor network unit is set using shortened procedures, without having to access the outside network unit. if the application traffic is mapped to the packet switched network. The gateway node comprises a shared access server that allows the mobile station to initially establish communication sessions with an external network entity to perform only a single common access procedure for subsequent communication links, using circuit switched networks and packet switched. After completing this common access procedure, the traffic of subsequent applications between the mobile station and the outdoor network unit is set using shortened procedures, without having to access the outside network unit. which allows the mobile station to initially establish communication sessions with the external network unit to perform only a single common access procedure for subsequent communication connections, using circuit switched networks and packet switching. After completing this common access procedure, the traffic of subsequent applications between the mobile station and the outdoor network unit is set using shortened procedures, without having to access the outside network unit. which allows the mobile station to initially establish communication sessions with the external network unit to perform only a single common access procedure for subsequent communication connections, using circuit switched networks and packet switching. After completing this common access procedure, the traffic of subsequent applications between the mobile station and the outdoor network unit is set using shortened procedures, without having to access the outside network unit.
In addition, the IETF standard "DHCP Relay Agent Information Option; rfc 3046.txt "reveals the technical content pertaining to the DHCP Relay Agent element.
Additionally, the patent application (WO / 2004/006503) provides a system and method for dynamic configuration of network equipment ports for communication in a broadband network. The central management database in conjunction with the dynamic node configuration protocol server stores templates with stored network equipment parameters for physical port settings and services used. Therefore, it enables dynamic update of port settings by transferring saved parameters from the host dynamic configuration protocol server. Parameter settings are updated via intermediates. However, in the technical solution with D3, due to the fact that the database is placed outside the DHCP server, the costs of data management are high, and the security of data transmission is small.
Brief description of the invention [0022] Given the above problems in the prior art, it is an object of the invention to provide a method, a system and a server for performing a secure assignment of a DHCP address. Then the security of how to assign DHCP server addresses can be ensured efficiently, and the data management costs are low.
[0023] The object of the invention is implemented by means of the following technical solutions. How to perform a secure DHCP address assignment, including:
receiving, through the access server, the DHCP Discovery message;
- 4 inserting DHCP location information into the DHCP Discovery message, by the access server;
sending to the DHCP authentication server, via the access server, a message
DHCP Discovery with information about the location of the DHCP client;
receiving, by the DHCP authentication server, the DHCP Discovery message with the location information of the DHCP client, wherein the DHCP authentication server is a DHCP server with authentication function configured locally, the DHCP authentication server includes a local database containing locally stored identification information for the authorized subscriber;
realizing, by the DHCP authentication server, DHCP client authentication based on location information and identifying information stored locally for the authorized subscriber and sending, by the DHCP authentication server, a DHCP message with address information that has been assigned to a DHCP client that has successfully authenticated via an access server after DHCP client authentication.
DHCP authentication server for performing a secure DHCP address assignment, a DHCP authentication server with a locally configured authentication function and containing an authentication processing module, a DHCP server for assigning IP addresses to DHCP clients that request IP addresses and a local database containing identifying information stored locally for an authorized subscriber , wherein:
the authentication processing module is adapted to obtain information about the location of the client initiating the DHCP process, realize the credentials of the client based on the location information and identifying information stored for the authorized subscriber and sending DHCP Discovery DHCP client to the DHCP server, which has successfully passed the authorization of the authorization and server DHCP is configured to receive a DHCP Discovery message sent by the authentication processing module and send a DHCP Offer message to the DHCP client and assign an IP address to the appropriate DHCP client from the DHCP server pool, when the DHCP client sends the DHCP Request message.
A system for performing a secure DHCP address assignment, including an access server and a DHCP authentication server, in which the access server is adapted to receive a DHCP Discovery message sent by a DHCP client, inserting the DHCP client location information into a DHCP Discovery message, and sending a DHCP message to the DHCP authentication server. Discovery with location information and the DHCP authentication server has a locally configured authentication function and is adapted to receive a DHCP discovery message with the location information of the DHCP client and perform DHCP client authentication based on location information and identifying information stored locally for the authorized subscriber; and sending a DHCP message with the address information that has been assigned to the DHCP client,
[0024] Furthermore, in this invention, addresses can be managed together by a RADIUS server, i.e. in other words a DHCP server and a RADIUS server jointly manage IP addresses, thus network management costs can be combined. In addition, the original security measures of the RADIUS server can be used to control the number of IP addresses that can be obtained by the subscriber so that an attack can be effectively prevented using malicious addresses. Even if there is a network attack or other network security issue, the physical location of the subscriber can be found based on the IP address, so that the hacker can be effectively prevented from performing the attack.
[0025] This invention has good compatibility, in other words in the implementation of the present invention, no additional interface and commands are added to the OSS system, and the service management process for the DHCP client user is consistent with the service management process originally issued to the PPPoE client. As a result, the operator's investment can be protected.
Brief Description of the Drawings [0026] Figure 1 shows the structure of a broadband access system;
[0027] Figure 2 is a diagram representing a process in which a DHCP server obtains an address;
[0028] Figure 3 shows the structure of a DHCP authentication server according to the invention;
[0029] Figure 4 shows another structure of the system according to the invention and [0030] Figure 5 is a diagram representing the process of assigning a DHCP address based on the system shown in Figure 4.
Detailed description of embodiments The main idea of the invention is that: during a process in which a DHCP client obtains an address from a DHCP server, the authorization authentication process is added on the client side, so that an unauthorized subscriber can be deterred from attacking the DHCP server. In addition, based on the above idea, the management of DHCP server addresses and authentication server can be combined, making it easy to implement address management. The authentication server includes an AAA server, such as a RADIUS server. Optionally, the authentication server may be another authentication server with a similar function.
[0032] One embodiment of the present invention provides a method for performing a secure assignment of a DHCP address, mainly including the following.
[0033] (1) The DHCP client sends a DHCP Discovery message over the access network.
[0034] (2) A network-side access server (such as BRAS and access node) based on information about the input port of the DHCP Discovery message identifies DHCP client identification information, such as port number, VPI (virtual path identifiers), NCI (channel identifiers) virtual) and VLAN ID (virtual network ID
- local) and performs DHCP client authentication based on the identification information of the DHCP client and pre-configured identification information for the authorized subscriber.
[0035] (3) The DHCP Discovery message of the DHCP client that has successfully passed the authentication is sent to the DHCP server and the address is assigned by the DHCP server to the DHCP client. The actual process of address assignment is the same as the standard address assignment process, and its re-description is omitted for this reason.
Furthermore, a proper DHCP server with an authentication function may be configured on the network so that after receiving the DHCP Discovery message sent from the DHCP client, the DHCP server can first perform the authentication process and the appropriate address will be assigned after the authentication is successful.
[0037] This invention provides a DHCP authentication server with an authentication function. In this part there is a description of the DHCP authentication server with reference to the respective drawings.
[0038] For a DHCP authentication server with an authentication function, the authentication function is configured and implemented locally. The specific structure of the DHCP authentication server, including the authentication processing module and the DHCP server module, is illustrated in FIG. 3.
[0039] The authentication processing module is adapted to obtain information identifying the DHCP client during the initiation of the DHCP process, performing authenticated client authentication based on the identifying information stored for the authorized subscriber and then sending the authentication result to the DHCP server module in which the identifying information of the authorized subscriber they are stored in the appropriate data storage module (not shown).
The DHCP server module is adapted to obtain an authentication result for the DHCP client from an authentication processing module, sending a DHCP Offer message with the PASSED authentication result to the DHCP client, to indicate that the DHCP server can assign the appropriate IP address to the DHCP client and then assign the corresponding IP address to the DHCP client after the DHCP client sends the DHCP Request message. Thus, the DHCP server function is implemented.
[0041] At this point, the DHCP authentication server operates in a server mode corresponding to a DHCP server with a secure authentication function and may perform independent authentication and address assignment for the client.
[0042] The above DHCP authentication server with an authentication function may be configured on any network that requires a DHCP server to perform the corresponding address assignment function.
[0043] This invention also provides an appropriate system with the assignment of a DHCP address and an authentication function for performing secure assignment of the DHCP address.
The system structure is shown in FIG. 4 and in particular includes a DHCP client, an access network and a DHCP authentication server. The DHCP authentication server is capable of performing the authentication of the DHCP Discovery message of the DHCP client obtained by the access network and performing the address assignment to the client
DHCP that successfully passed authentication.
[0044] In a system according to the invention, the DHCP authentication server can perform DHCP client authentication and assign a corresponding IP address in the following mode.
[0045] As shown in Fig. 5, the entitlement authentication is performed for the DHCP client identification information based on the identifying identifier of the authorized subscriber, stored locally, and the DHCP server may assign the corresponding IP address to the DHCP client that has successfully passed the authentication.
[0046] In particular, on the access node system, the BRAS server supports capturing a DHCP message and insert Option82 into a DHCP message so that the DHCP authentication server can obtain the appropriate information identifying the DHCP client after receiving the DHCP message. In Option82, subscriber location information is identified as the identifying information. In particular, the subscriber location information includes port information, VPI / VCI information, and VLAN ID information. The option Option82 can be inserted into the DHCP message on the access node or Option Option can be inserted into the DHCP message in the BRAS server.
[0047] The invention also provides an appropriate way of performing secure assignment of a DHCP address based on the above system. Below is a detailed description.
[0048] For example, the method is described in the case where the DHCP authentication server is operating in server mode as shown in Figures 4 and 5.
[0049] Step 91: when the subscriber opens the account, the operator adds some data to the DHCP authentication server and records the subscriber's location information, and the coding mode is consistent with Option82 inserted by the access node or BRAS server and the terminal's MAC address (STB, IAD) it can be saved selectively.
[0050] Step 92: When the DHCP client requires obtaining an IP address, the DHCP client must send the DHCP Discovery message to the BRAS server.
[0051] Step 93: as a DHCP relay, the BRAS server intercepts a DHCP message and inserts Option82 into the message and then sends a DHCP Discovery message carrying the subscriber location information to the DHCP authentication server. Subscriber location information, such as port information, VPI / VCI and VLAN ID, is identified in Option82.
[0052] The DHCP authentication server receives the DHCP message forwarded by the BRAS, extracts Option82 and the MAC address of the terminal as identifying information, polls the local database and performs authentication of the DHCP client identification information based on identifying information stored locally for the authorized subscriber.
- 8 If authentication is successful, the DHCP authentication server will return a message
DHCP Offer to the DHCP client, as described in step 94.
[0053] Step 94: The DHCP authentication server sends a DHCP Offer message to the DHCP client.
[0054] Step 95: upon receipt of the DHCP Offer message, the DHCP client sends a DHCP Request message to the DHCP authentication server.
[0055] Step 96: The DHCP authentication server assigns the IP address to the DHCP client and sends the IP address to the DHCP client using the DHCP Reply message.
[0056] Similarly as described in step 93 of Fig. 5, the BRAS server inserts Option82. In practical use, Option82 can also be inserted by an access node, such as DSLAM, and BRAS will only act as a DHCP relay. Other processes are the same as described above.
[0057] Finally, the invention can significantly increase the security of address assignment in DHCP mode and can perform subscriber access authentication based on location information and only assign an IP address to an authorized subscriber or an authorized terminal. Thus, you can effectively prevent an attack using a malicious address. In addition, when a network attack or other network security issue occurs, the physical location of the subscriber can be found based on the IP address, so that the hacker can be effectively prevented from performing the attack.
[0058] Those skilled in the art will readily find additional advantages and modifications. For this reason, the invention in its broader embodiments is not limited to the specific details and representative embodiments set forth and described herein. Accordingly, various modifications and variations may be made without departing from the scope of the invention as defined by the appended claims and their equivalents.
She prepared and verified
Grażyna Palka Patent attorney
3 sheets
Sheet 1 Sheet 2 Sheet 3
12 members in 9 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 200510069417 | China | A | |
| 200510069417 | China | A | |
| 06741751 | European Patent Office (EPO) | A | |
| 2006000833 | China | W | |
| 2006000833 | China | W | |
| CN2005169417 | – | – | – |
| EP20060741751 | – | – | – |
| WO2006CN00833 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| CN1855926A | China | A | |
| WO2006116926A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1876754A1 | European Patent Office (EPO) | A1 | |
| US2008092213A1 | United States of America | A1 | |
| CN100388739C | China | C | |
| EP1876754A4 | European Patent Office (EPO) | A4 | |
| EP1876754B1 | European Patent Office (EPO) | B1 | |
| ATE546914T1 | Austria | T1 | |
| PT1876754E | Portugal | E | |
| DK1876754T3 | Denmark | T3 | |
| ES2381857T3 | Spain | T3 | |
| PL1876754T3This record | Poland | T3 |
Numbers
- Publication, DOCDB
- 1876754
- Publication, EPODOC
- PL1876754T
- Application
- 741751
- Application, DOCDB
- 06741751
- Application, EPODOC
- PL20060741751T
Titles2
- English
- METHOD SYSTEM AND SERVER FOR IMPLEMENTING DHCP ADDRESS SECURITY ALLOCATION
- Polish
- Sposób, system i serwer do wykonywania bezpiecznego przypisania adresu DHCP
Classification
- CPC, 3
- H04L63/08
- H04L63/0892
- H04L61/5014
- IPC, 2
- H04L12 24
- H04L29 12