WO2006116926A1

Method system and server for implementing dhcp address security allocation

Abstract

A method and system for implementing DHCP address security allocation and authentication server. The core of the invention is that DHCP client end send the discovery message through access network; when the access network side acquires the identification information such as the port information of said DHCP client end and the like, and authenticates it based on said identification information; finally, DHCP server only allocates the address information for the authorized DHCP client end. Therefore, the invention may perform accessing authentication for user according to the location information, and only allocates the address for the legal user terminals, thereby it enhances the security for allocating address through DHCP manner. Also, in the invention, the address is managed unifiable by the AAA server, or allocates the address after the AAA server authenticates successfully.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

11 claims: 6 independent, 5 dependent

  1. 1
    A method for implementing secure allocation of a DHCP address, comprising:权 利 要 求 1、 一种实现 DHCP地址安全分配的方法, 其特征在于, 包括: A. The dynamic host configuration protocol DHCP client sends a DHCP discovery packet through the access network. A、 动态主机配置协议 DHCP客户端通过接入网络发送 DHCP发现 报文; B. The access network side acquires the identification information of the DHCP client, and authenticates the DHCP client based on the identification information;B、接入网絡侧获取所述 DHCP客户端的识别信息, 并基于所述识别 信息对其进行认证; C. For the DHCP client that passes the authentication, the DHCP server assigns an address to it. C、 对于认证通过的 DHCP客户端, 由 DHCP月良务器为其分配地址 §息。
  2. 6
    6、一种实现 DHCP地址安全分配的 DHCP认证服务器,其特征在于, 包括 DHCP服务器模块、 协议转换模块和 AAA客户端模块; A DHCP authentication server for implementing secure allocation of a DHCP address, comprising:a DHCP server module, a protocol conversion module, and an AAA client module;The DHCP server module is configured to receive a DHCP request message sent by the DHCP client via the access node or the access server, and use the authentication and accounting AAA client module to receive the client that is returned by the AAA server for authentication. The address information allocated by the terminal responds to the DHCP client;所述 DHCP服务器模块用于接收 DHCP客户端经由接入节点或接入 服务器发来的 DHCP请求报文,并以鉴权认证计费 AAA客户端模块接收 的由 AAA服务器返回的为认证通过的客户端分配的地址信息响应所述 DHCP客户端; The protocol conversion module is configured to obtain information required for AAA authentication, and generate an AAA authentication packet from the DHCP discovery packet of the corresponding DHCP client sent by the access node or the access server, and receive the AAA authentication packet according to the AAA client module. Authenticate a response packet, generate a DHCP-provided packet, and send it. 所述协议转换模块用于从接入节点或接入服务器发来的相应的 DHCP客户端的 DHCP发现报文中, 获取 AAA认证需要的信息, 生成 AAA认证报文; 以及根据 AAA客户端模块接收的认证响应报文, 生成 DHCP提供报文并发送;AAA客户端模块: 用于基于 DHCP协议转换模块生成的认证报文与 AAA服务器间进行通信, 获得对所述 DHCP客户端的认证结果, 并交给 协议转换模块和 DHCP服务器模块。 The AAA client module is configured to communicate with the AAA server based on the authentication packet generated by the DHCP protocol conversion module, obtain the authentication result of the DHCP client, and submit the result to the protocol conversion module and the DHCP server module.
  3. 7
    7、一种实现 DHCP地址安全分配的 DHCP认证服务器,其特征在于, 包括认证处理模块和 DHCP服务器; A DHCP authentication server for implementing secure allocation of a DHCP address, comprising:an authentication processing module and a DHCP server;The authentication processing module is configured to obtain the identification information of the client that initiates the DHCP process, and perform the legality authentication on the client according to the saved identification information of the legal user, and send the DHCP discovery packet of the DHCP client that has passed the authentication to the DHCP. server;所述认证处理模块用于获取发起 DHCP过程的客户端的识别信息, 并根据保存的合法用户的识别信息对所述客户端进行合法性认证, 将认 证通过的 DHCP客户端的 DHCP发现报文发送给 DHCP服务器; The DHCP server is configured to receive a DHCP discovery message sent by the authentication processing module, and send a DHCP provisioning message to the DHCP client. When the DHCP client sends a DHCP request message, it is corresponding in the address pool. The DHCP client assigns an address. 所述 DHCP服务器用于接收认证处理模块发来的 DHCP发现报文, 并向所述 DHCP客户端发送 DHCP提供报文;在 DHCP客户端发来 DHCP 请求报文时 , 在其地址池中为相应的 DHCP客户端分配地址。
  4. 8
    8、一种实现 DHCP地址安全分配的系统,其特征在于, 包括: DHCP 客户端, 接入网络和 DHCP认证服务器; 所述 DHCP客户端通过接入网 络与 DHCP认证服务器通信获取地址信息; 所述 DHCP认证服务器用于 对接入网络获取的 DHCP客户端的 DHCP发现报文进行合法性认证, 并 对认证通过的 DHCP客户端进行地址分配。 A system for implementing secure allocation of a DHCP address, comprising:a DHCP client, an access network, and a DHCP authentication server;wherein the DHCP client obtains address information by communicating with a DHCP authentication server through the access network;The DHCP authentication server is used to authenticate the DHCP discovery packets of the DHCP client that is obtained by the access network, and assign addresses to the DHCP clients that pass the authentication.
  5. 9
    9、 一种实现 DHCP地址安全分配的方法, 其特征在于, 包括: C、 接入节点或接入服务器接收 DHCP客户端发来的 DHCP发现报 文, 并将所述客户端的识别信息插入所述报文中发送给 DHCP认证服务 器; A method for implementing secure allocation of a DHCP address, comprising:C. an access node or an access server receives a DHCP discovery message sent by a DHCP client, and inserts the identification information of the client into the The packet is sent to the DHCP authentication server. D. The DHCP authentication server obtains the identification information of the client from the packet. D、 DHCP认证服务器从所述报文中获取所述客户端的识别信息; E. The DHCP authentication server authenticates the legality of the client by using the identification information, and performs address allocation processing only on the client that passes the authentication. E、 DHCP认证服务器利用所述的识别信息对所述客户端的合法性进 行认证, 并仅对认证通过的客户端进行地址分配处理。
  6. 11
    11、 一种实现 DHCP地址安全分配的方法, 其特征在于, 包括: A method for implementing secure allocation of a DHCP address, comprising:F、接入节点或接入服务器接收 DHCP客户端发来的 DHCP发现报文, 并将所述客户端的识别信息插入所述报文中发送给 DHCP认证服务器; G、 DHCP认证服务器从所述报文中获取所述客户端的识别信息; The access node or the access server receives the DHCP discovery packet sent by the DHCP client, and inserts the identification information of the client into the packet and sends the packet to the DHCP authentication server. G. The DHCP authentication server receives the packet from the DHCP server. Obtaining the identification information of the client in the text;H. The DHCP authentication server sends the authentication request message to the AAA server by using the identification information, and the AAA server authenticates the identification information of the client, and allocates address information to the client that passes the authentication;H、 DHCP认证服务器利用所述的识别信息向 AAA服务器发送认证 请求报文, 由 AAA服务器对所述客户端的识别信息进行认证, 并为认证 通过的客户端分配地址信息; Alternatively, the DHCP authentication server sends the authentication request message to the AAA server by using the identification information, and the AAA server authenticates the identification information of the client;after receiving the authentication pass information, the DHCP authentication server allocates the client for authentication. Address information. 或者, DHCP认证服务器利用所述的识别信息向 AAA服务器发送认证请求 报文, 由 AAA服务器对所述客户端的识别信息进行认证; DHCP认证服 务器接收到认证通过信息后, 为认证通过的客户端分配地址信息。
Independent claims6