Method system and server for implementing dhcp address security allocation
Abstract
A method and system for implementing DHCP address security allocation and authentication server. The core of the invention is that DHCP client end send the discovery message through access network; when the access network side acquires the identification information such as the port information of said DHCP client end and the like, and authenticates it based on said identification information; finally, DHCP server only allocates the address information for the authorized DHCP client end. Therefore, the invention may perform accessing authentication for user according to the location information, and only allocates the address for the legal user terminals, thereby it enhances the security for allocating address through DHCP manner. Also, in the invention, the address is managed unifiable by the AAA server, or allocates the address after the AAA server authenticates successfully.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
11 claims: 6 independent, 5 dependent
- 1A method for implementing secure allocation of a DHCP address, comprising:权 利 要 求 1、 一种实现 DHCP地址安全分配的方法, 其特征在于, 包括: A. The dynamic host configuration protocol DHCP client sends a DHCP discovery packet through the access network. A、 动态主机配置协议 DHCP客户端通过接入网络发送 DHCP发现 报文; B. The access network side acquires the identification information of the DHCP client, and authenticates the DHCP client based on the identification information;B、接入网絡侧获取所述 DHCP客户端的识别信息, 并基于所述识别 信息对其进行认证; C. For the DHCP client that passes the authentication, the DHCP server assigns an address to it. C、 对于认证通过的 DHCP客户端, 由 DHCP月良务器为其分配地址 §息。
- 66、一种实现 DHCP地址安全分配的 DHCP认证服务器,其特征在于, 包括 DHCP服务器模块、 协议转换模块和 AAA客户端模块; A DHCP authentication server for implementing secure allocation of a DHCP address, comprising:a DHCP server module, a protocol conversion module, and an AAA client module;The DHCP server module is configured to receive a DHCP request message sent by the DHCP client via the access node or the access server, and use the authentication and accounting AAA client module to receive the client that is returned by the AAA server for authentication. The address information allocated by the terminal responds to the DHCP client;所述 DHCP服务器模块用于接收 DHCP客户端经由接入节点或接入 服务器发来的 DHCP请求报文,并以鉴权认证计费 AAA客户端模块接收 的由 AAA服务器返回的为认证通过的客户端分配的地址信息响应所述 DHCP客户端; The protocol conversion module is configured to obtain information required for AAA authentication, and generate an AAA authentication packet from the DHCP discovery packet of the corresponding DHCP client sent by the access node or the access server, and receive the AAA authentication packet according to the AAA client module. Authenticate a response packet, generate a DHCP-provided packet, and send it. 所述协议转换模块用于从接入节点或接入服务器发来的相应的 DHCP客户端的 DHCP发现报文中, 获取 AAA认证需要的信息, 生成 AAA认证报文; 以及根据 AAA客户端模块接收的认证响应报文, 生成 DHCP提供报文并发送;AAA客户端模块: 用于基于 DHCP协议转换模块生成的认证报文与 AAA服务器间进行通信, 获得对所述 DHCP客户端的认证结果, 并交给 协议转换模块和 DHCP服务器模块。 The AAA client module is configured to communicate with the AAA server based on the authentication packet generated by the DHCP protocol conversion module, obtain the authentication result of the DHCP client, and submit the result to the protocol conversion module and the DHCP server module.
- 77、一种实现 DHCP地址安全分配的 DHCP认证服务器,其特征在于, 包括认证处理模块和 DHCP服务器; A DHCP authentication server for implementing secure allocation of a DHCP address, comprising:an authentication processing module and a DHCP server;The authentication processing module is configured to obtain the identification information of the client that initiates the DHCP process, and perform the legality authentication on the client according to the saved identification information of the legal user, and send the DHCP discovery packet of the DHCP client that has passed the authentication to the DHCP. server;所述认证处理模块用于获取发起 DHCP过程的客户端的识别信息, 并根据保存的合法用户的识别信息对所述客户端进行合法性认证, 将认 证通过的 DHCP客户端的 DHCP发现报文发送给 DHCP服务器; The DHCP server is configured to receive a DHCP discovery message sent by the authentication processing module, and send a DHCP provisioning message to the DHCP client. When the DHCP client sends a DHCP request message, it is corresponding in the address pool. The DHCP client assigns an address. 所述 DHCP服务器用于接收认证处理模块发来的 DHCP发现报文, 并向所述 DHCP客户端发送 DHCP提供报文;在 DHCP客户端发来 DHCP 请求报文时 , 在其地址池中为相应的 DHCP客户端分配地址。
- 88、一种实现 DHCP地址安全分配的系统,其特征在于, 包括: DHCP 客户端, 接入网络和 DHCP认证服务器; 所述 DHCP客户端通过接入网 络与 DHCP认证服务器通信获取地址信息; 所述 DHCP认证服务器用于 对接入网络获取的 DHCP客户端的 DHCP发现报文进行合法性认证, 并 对认证通过的 DHCP客户端进行地址分配。 A system for implementing secure allocation of a DHCP address, comprising:a DHCP client, an access network, and a DHCP authentication server;wherein the DHCP client obtains address information by communicating with a DHCP authentication server through the access network;The DHCP authentication server is used to authenticate the DHCP discovery packets of the DHCP client that is obtained by the access network, and assign addresses to the DHCP clients that pass the authentication.
- 99、 一种实现 DHCP地址安全分配的方法, 其特征在于, 包括: C、 接入节点或接入服务器接收 DHCP客户端发来的 DHCP发现报 文, 并将所述客户端的识别信息插入所述报文中发送给 DHCP认证服务 器; A method for implementing secure allocation of a DHCP address, comprising:C. an access node or an access server receives a DHCP discovery message sent by a DHCP client, and inserts the identification information of the client into the The packet is sent to the DHCP authentication server. D. The DHCP authentication server obtains the identification information of the client from the packet. D、 DHCP认证服务器从所述报文中获取所述客户端的识别信息; E. The DHCP authentication server authenticates the legality of the client by using the identification information, and performs address allocation processing only on the client that passes the authentication. E、 DHCP认证服务器利用所述的识别信息对所述客户端的合法性进 行认证, 并仅对认证通过的客户端进行地址分配处理。
- 1111、 一种实现 DHCP地址安全分配的方法, 其特征在于, 包括: A method for implementing secure allocation of a DHCP address, comprising:F、接入节点或接入服务器接收 DHCP客户端发来的 DHCP发现报文, 并将所述客户端的识别信息插入所述报文中发送给 DHCP认证服务器; G、 DHCP认证服务器从所述报文中获取所述客户端的识别信息; The access node or the access server receives the DHCP discovery packet sent by the DHCP client, and inserts the identification information of the client into the packet and sends the packet to the DHCP authentication server. G. The DHCP authentication server receives the packet from the DHCP server. Obtaining the identification information of the client in the text;H. The DHCP authentication server sends the authentication request message to the AAA server by using the identification information, and the AAA server authenticates the identification information of the client, and allocates address information to the client that passes the authentication;H、 DHCP认证服务器利用所述的识别信息向 AAA服务器发送认证 请求报文, 由 AAA服务器对所述客户端的识别信息进行认证, 并为认证 通过的客户端分配地址信息; Alternatively, the DHCP authentication server sends the authentication request message to the AAA server by using the identification information, and the AAA server authenticates the identification information of the client;after receiving the authentication pass information, the DHCP authentication server allocates the client for authentication. Address information. 或者, DHCP认证服务器利用所述的识别信息向 AAA服务器发送认证请求 报文, 由 AAA服务器对所述客户端的识别信息进行认证; DHCP认证服 务器接收到认证通过信息后, 为认证通过的客户端分配地址信息。
Independent claims6
115 paragraphs, as filed
The present invention relates to the field of network communication technologies, and in particular, to a method, system, and server for implementing DHCP (Dynamic Host Configuration Protocol) address security allocation.
Background technique
With the maturity of access technologies such as ADSL (Asymmetric Digital Subscriber Line) and Ethernet, broadband access is becoming more and more popular, and at the same time, IPTV (Internet Protocol Television) is being implemented on the broadband access network. , IP TV) Video and VoIP (voice over Internet protocol) services are also growing. The implementation of each service needs to be implemented by a dedicated terminal. For example, the video service needs to use STB (Set Top Box), the voice service needs to use IAD (Integrated Access Device), and so on. Each dedicated terminal needs to obtain the address information of the local end before starting the service. After that, the local terminal can use the address information of the local end to carry out various services.
In a communication network, the manner in which each terminal obtains an IP (Internet Protocol) address is usually based on the DHCP protocol. The traditional Internet access service usually uses PPPoE (Point-to-Point Protocol over Ethernet). The point-to-point protocol is implemented, and the AAA (Authentication Authorization, Accounting, Authentication, and Accounting) server needs to complete authentication for the access user and assign an IP address. The AAA server is generally a RADIUS (Remote Authentication Dial In User Service) or other authentication server.
The structure of the network communication system that is authenticated by the RADIUS server and obtains the IP address information through the DHCP server is as shown in FIG. 1 , where:
DHCP server: A server for managing an IP address, responding to a computer's address allocation request, and assigning a suitable IP address to the computer;
DHCP client: A terminal that obtains network parameters such as an IP address using a DHCP protocol, including a computer, an STB, an IAD, and the like;
RADIUS server: The remote dial-in user authentication server is used to manage the user's account and password and complete the authentication of the access user.
BRAS: Broadband remote access server for access management of broadband users. For PPPoE users, BRAS acts as a RADIUS client and initiates an authentication request to the RADIUS server. For DHCP users, the BRAS completes the DHCP relay function.
Access network: from the user's home to the network in the middle of the BRAS;
Access node: A device directly connected to a subscriber line in an access network, such as an ADSL access device DSLAM (Digital Subscriber Line Access Multiplexer);
OSS (Operations Support Systems) System: A system for carrier service delivery and business management.
In FIG. 1, as a DHCP client STB, IAD, etc., a DHCP server can be deployed through a network to assign a corresponding IP address using a DHCP protocol.
Figure 2 shows the process of obtaining the address of each DHCP client as shown in Figure 2: Step 21: The DHCP client is powered on, sends a DHCP discovery packet, and finds a server that can provide DHCP service.
Step 22: The BRAS acts as a DHCP relay and relays the DHCP discovery message to the designated DHCP server.
Step 23: The DHCP server returns a DHCP-provided message, indicating that it can assign an IP address to the client.
Step 24: The DHCP client sends a DHCP request message, and the BRAS relays the DHCP request message to the DHCP server.
Step 25: The DHCP server allocates an appropriate IP address and returns a DHCP response message. In this way, the DHCP client obtains an IP address and can access the network to obtain network services.
From the above DHCP address allocation process, it can be seen that during the process of obtaining the IP address by the DHCP client through the DHCP method, the illegal user can easily obtain the corresponding IP address and obtain the network service. In this way, it is easy for a hacker to maliciously exhaust the IP address resource and attack the network. Moreover, after the hacker attacks the network, it cannot be tracked.
In addition, the operator needs to use a DHCP server to manage the IP address of the DHCP client user, and the RADIUS server manages the IP address of the PPPoE client user. There are two sets of IP address resource management mechanisms, data is dispersed, and management costs are high.
Summary of the invention
In view of the above problems in the prior art, an object of the present invention is to provide a method, system and server for implementing secure allocation of a DHCP address, so that the security of the process of address allocation by the DHCP server can be effectively ensured.
The object of the invention is achieved by the following technical solutions:
The present invention provides a method for implementing secure allocation of a DHCP address, including:
A. The dynamic host configuration protocol DHCP client sends a DHCP discovery message through the access network;
B. The access network side acquires the identification information of the DHCP client, and authenticates the DHCP client based on the identification information;
C. For the DHCP client that passes the authentication, the DHCP server assigns address information to it.
The identification information includes:
Port number, circuit number, and connection number of the DHCP client.
The step B described includes:
The access node or the access server in the access network determines its identification information according to the ingress port/circuit/connection information of the DHCP discovery message.
The step B described includes:
The client's legality authentication is performed by the access node or the access server in the access network according to the identification information of the DHCP client and the identification information of the pre-configured legal user.
The step B described includes:
Bl. The access node or the access server in the access network initiates an authentication request to the authentication server by using the identification information of the client;
B2. The authentication server authenticates the legality of the client according to the saved identification information of the legal user.
The present invention also provides a DHCP authentication server for implementing secure allocation of a DHCP address, including:
The DHCP server module: receives a DHCP request message sent by the DHCP client via the access node or the access server, and allocates the client that is authenticated by the AAA server and is returned by the authentication and accounting AAA client module. The address information is responsive to the DHCP client;
The protocol conversion module is configured to obtain the information required for AAA authentication, generate an AAA authentication packet, and perform authentication according to the AAA client module in the DHCP discovery packet of the corresponding DHCP client sent from the access node or the access server. Responding to the packet, generating a DHCP-provided packet, and sending the packet;
AAA client module: used for authentication packets generated by the DHCP protocol conversion module
The AAA server communicates with the authentication result of the DHCP client, and submits the result to the protocol conversion module and the DHCP server module.
The present invention also provides a DHCP authentication server for implementing secure allocation of a DHCP address, including:
The authentication processing module is configured to obtain the identification information of the client that initiates the DHCP process, and perform legality authentication on the client according to the saved identification information of the legal user, and the authentication is performed.
The DHCP server receives the DHCP discovery packet sent by the authentication processing module, and sends a DHCP provisioning packet to the DHCP client. When the DHCP client sends a DHCP request packet, it is the corresponding DHCP client in the address pool. The end assigns an address.
The invention also provides a system for implementing secure allocation of a DHCP address, comprising: a DHCP client, an access network and a DHCP authentication server, and the DHCP client communicates with the DHCP authentication server to obtain address information through the access network, and at the same time, the DHCP authentication server It is used to authenticate the DHCP discovery packets of the DHCP client that is obtained by the access network, and assign the DHCP client to the address.
The present invention also provides a method for implementing DHCP address security allocation based on the foregoing system, including:
C. The access node or the access server receives the DHCP discovery packet sent by the DHCP client, and inserts the identification information of the client into the packet and sends it to the DHCP authentication service to cry.
D. The DHCP authentication server obtains the identification information of the client from the packet.
E. The DHCP authentication server authenticates the legality of the client by using the identification information, and performs address allocation processing only on the client that passes the authentication.
The step E described includes:
The DHCP authentication server authenticates the DHCP client according to the saved identification information of the legal user, and sends the DHCP discovery packet of the client that has passed the authentication to the DHCP server. The DHCP server performs address allocation processing.
The present invention also provides a method for implementing secure allocation of a DHCP address, including:
The access node or the access server receives the DHCP discovery packet sent by the DHCP client, and inserts the identification information of the client into the packet and sends the packet to the DHCP authentication server.
G. The DHCP authentication server acquires the identification information of the client from the packet.
H. The DHCP authentication server sends the authentication request message to the AAA server by using the identification information, and the AAA server authenticates the identification information of the client, and allocates address information to the client that passes the authentication;
By,
The DHCP authentication server sends the authentication request message to the AAA server by using the identification information, and the AAA server authenticates the identification information of the client. After receiving the authentication pass information, the DHCP authentication server allocates address information for the authenticated client. .
It can be seen from the technical solution provided by the present invention that the present invention can perform access authentication on the user according to the location information, and only assign an IP address to the legal user and the terminal, thereby greatly enhancing the security of assigning the address through the DHCP method. Sex
Moreover, in the present invention, the address can be uniformly managed by the RADIUS server, that is, the DHCP server and the RADIUS server uniformly manage the IP address, thereby reducing the cost of network management; and the original security measures of the RADIUS server can be utilized to control the number of IP addresses obtained by the user. Effectively prevent malicious exhaustion of address attacks; even if a network attack or other network security problem occurs, the physical location of the user can be tracked according to the IP address, and the hacker attack behavior can be effectively shocked!
At the same time, the present invention has good compatibility, that is, in the implementation process, no new interfaces and commands are added to the OSS system, and the service management process of the DHCP client user and the service delivery management process of the original PPPoE client are completely completed. Consistent, protecting the investment of operators.
BRIEF DESCRIPTION OF DRAWINGS FIG. 1 is a schematic structural diagram of a broadband access system;
2 is a schematic diagram of a process of obtaining an address through a DHCP server;
3 is a schematic structural diagram of a DHCP authentication server according to the present invention; FIG. 4 is another schematic structural diagram of a DHCP authentication server according to the present invention; FIG. 5 is a schematic structural diagram of a system according to the present invention;
6 is a schematic diagram of a DHCP address allocation process based on the system shown in FIG. 5. FIG. 7 is a schematic diagram of another DHCP address allocation process based on the system shown in FIG. 5. FIG. 8 is another schematic diagram of the system according to the present invention. Schematic;
FIG. 9 is a schematic diagram of a DHCP address allocation process based on the system shown in FIG.
Detailed ways
The core of the present invention is to increase the process of authenticating the authenticity of the DHCP client in the process of obtaining the address information from the DHCP client, so as to prevent the attack of the DHCP server by the illegal user. In addition, based on the above core ideas, The address management of the DHCP server and the authentication server are unified to facilitate address management. The authentication server includes an AAA server such as a RADIUS server. Of course, other authentication functions may be used for other functions.
The present invention provides a method for implementing secure allocation of a DHCP address, which mainly includes:
(1) The DHCP client sends a DHCP Discovery message through the access network;
(2) The access server (such as the BRAS, the access node, etc.) on the network side determines the identification information of the DHCP client according to the ingress port information of the DHCP discovery message, such as the port number of the DHCP client, VPI (Virtual path) Identifiers, virtual channel identifiers, virtual channel identifiers, virtual local area network IDs, etc., based on the identification information and pre-configured identification of legitimate users The information is authenticated by the DHCP client;
Taking the RADIUS server as the authentication server as an example, the access node or the access server in the access network may use the identification information of the client to initiate an authentication request to the remote dial-up authentication RADIUS server, and the RADIUS server saves the legitimate user according to the The identification information authenticates the legality of the client;
Of course, it is also possible to set a gateway dedicated to authentication, which performs corresponding authentication processing according to the configured information.
(3) DHCP discovery of the DHCP client that passes authentication ^ <sup>1</sup>The message is sent to the DHCP server, and the DHCP server assigns address information to it. The specific address allocation process is the same as the existing address allocation process, so it is not detailed.
In addition, a corresponding DHCP server with an authentication function can be set in the network, so that after receiving the DHCP discovery message sent by the DHCP client, the authentication process can be performed first. After the authentication is passed, the corresponding authentication is performed. Address information.
The present invention provides two DHCP authentication servers having authentication functions, which will be separately described below with reference to the accompanying drawings.
The first DHCP authentication server with authentication function needs to authenticate the DHCP client through an authentication server, such as a RADIUS server. The specific structure is shown in Figure 3. The RADIUS server is used as the authentication server as an example, including the DHCP server module. , protocol conversion module and RADIUS client module:
The DHCP server module is configured to allocate an IP address to the DHCP client that passes the authentication, specifically to receive a DHCP request message sent by the DHCP client via the access node or the access server, and allocate corresponding IP address information to the DHCP client. The IP address information is the IP address information returned by the RADIUS client module and returned by the RADIUS server for authentication.
The protocol conversion module is configured to obtain the information required for the RADIUS authentication in the DHCP discovery packet of the corresponding DHCP client sent from the access node or the access server, and generate a RADIUS authentication packet for authenticating the DHCP client. At the same time, the protocol conversion module needs to respond to the DHCP client according to the authentication response message received by the RADIUS client module. Specifically, the protocol conversion module needs to generate a corresponding DHCP provisioning packet and send the response packet to the DHCP client that passes the authentication. The corresponding DHCP client is configured to be assigned a corresponding IP address. The RADIUS client module is configured to communicate with the RADIUS server based on the authentication packet generated by the DHCP protocol conversion module, thereby implementing authentication for the DHCP client. The specific authentication rule can be authenticated according to the rules set in the RADIUS server, and then the authentication result of the DHCP client is obtained. The authentication result includes the IP address assigned by the RADIUS server to the client, and the IP address. Need to be handed over to the DHCP server module; By DHCP client terminal response packet processed by the protocol converting module needs subsequent processing, ie DHCP client sends a DHCP offer message.
At this time, the DHCP authentication server works in the gateway mode, and the DHCP authentication server supports the DHCP protocol and the RADIUS protocol. From the perspective of the DHCP client and the BRAS, the DHCP authentication server is a DHCP server; from the perspective of the RADIUS server, DHCP The authentication server is a RADIUS client.
The specific processing procedure includes: the DHCP authentication server processes the DHCP message forwarded by the DHCP relay, and generates a RADIUS packet to the RADIUS server according to the identification information of the client carried in the packet, and the RADIUS server determines according to the user data configured in advance. The user's legality is completed, and the user is assigned an IP address. After receiving the authentication response packet from the RADIUS server, the DHCP authentication server returns a DHCP packet to the DHCP client, carrying the IP address assigned by the RADIUS server, and finally the DHCP client. Get the IP address.
The second DHCP authentication server with authentication function sets the authentication function locally and implements authentication processing. The specific structure is shown in Figure 4, including the authentication processing module and the DHCP server module:
The authentication processing module is configured to obtain the identification information of the DHCP client that initiates the DHCP process, and perform legality authentication on the client according to the identification information of the legal user that is saved, and then send the authentication result to the DHCP server module. The identification information of the legitimate user can be saved by the corresponding storage module (not shown);
The DHCP server module: obtains the authentication result of the DHCP client by the authentication processing module, and sends a DHCP-provided packet to the DHCP client that passes the authentication result, indicating that the DHCP server can assign a corresponding IP address to it, and can send the DHCP client. When a DHCP request packet is sent, it is assigned a corresponding IP address, which implements the function of the DHCP server. At this time, the DHCP authentication server works in the server mode, which is equivalent to a DHCP server with security authentication function, and can independently perform authentication and address allocation for the client.
The above two authentication authentication DHCP authentication servers can be set in any network that needs to apply the DHCP server to implement the corresponding address allocation function.
The present invention also provides a system for implementing DHCP address security allocation with a DHCP address allocation authentication function. The structure of the system is as shown in FIG. 5 and FIG. 8 respectively, and specifically includes: a DHCP client, an access network, and a DHCP. The authentication server is configured to perform legality authentication on the DHCP client's DHCP discovery packet obtained by the access network, and perform address allocation processing on the authenticated DHCP client.
In the system of the present invention, the DHCP authentication server can authenticate the DHCP client in the following two ways, and allocate the corresponding IP address, specifically:
As shown in Figure 5, the identification information of the DHCP client is sent to the RADIUS server through the authentication request packet, and is authenticated by the RADIUS server, and the RADIUS server allocates the corresponding IP address, or the RADIUS server only performs the authentication. The authentication process is performed, and the corresponding IP address is still allocated by the DHCP server; here, only the RADIUS server is used as the authentication server to describe a specific application example of the present invention, and is not limited thereto;
As shown in FIG. 8, the identification information of the DHCP client is authenticated according to the identification information of the legal user saved locally, and the DHCP server allocates a corresponding IP address for the DHCP client that passes the authentication.
In the system, the access node and the BRAS support the capture of the DHCP message, and the Qption 82 option is inserted, so that the DHCP authentication server can obtain the identification information of the corresponding DHCP client after receiving the DHCP message. The Option 82 option identifies the location information of the user as the identification information, including port information, VPI/VCI information, and VLAN ID. The Option 82 option can be inserted into the DHCP packet at the access node. Insert the Option82 option.
Based on the above system, the present invention also provides a corresponding method for implementing DHCP address security allocation, which will be described in detail below.
First, the DHCP authentication server works in gateway mode, and the authentication server is 33.
-10-
The RADIUS server is used as an example to describe the method. As shown in Figure 5, Figure 6, and Figure 7, the detailed description is as follows:
As shown in FIG. 5 and FIG. 6, when the method is specifically implemented, the method includes the following steps:
Step 61: When the user opens the account, the operator adds a user data to the ADIUS server, and the account is the location information of the user. The coding mode is the same as the Option 82 option inserted by the access node and the BRAS, and the recording terminal (STB, IAD) can be selected. MAC (Media Access Control) address.
Step 62: When the DHCP client needs to obtain the IP address information, the DHCP client needs to send a DHCP discovery packet to the BRAS.
Step 63: The BRAS acts as a DHCP relay, captures the DHCP message, and inserts the Option 82 option in the packet, and then sends the DHCP discovery packet carrying the user location information to the DHCP authentication server, where the Option 82 option identifies the location of the user. Information, such as port information, VPI/VCI, VLAN ID, etc.
Step 64: The DHCP authentication server receives the DHCP message from the BRAS, and then extracts the Option 82 option and the MAC address of the terminal, generates a RADIUS protocol packet, and sends the packet to the RADIUS server. The account number in the packet is the content of option 82. Calling- The Station-ID (call site identity) attribute is the MAC address of the terminal;
The RADIUS server receives the authentication request, performs authentication based on the information in the database, determines the validity of the user based on the account, and determines the legality of the terminal based on the MAC address. If the authentication succeeds, the IP address is assigned to the user, and the authentication response is returned. Text, see step 65;
Step 65: After the authentication is passed, the RADIUS server returns an authentication response packet to the DHCP authentication server, and the packet carries an IP address assigned to the client.
After receiving the authentication response packet, the DHCP authentication server extracts the IP address assigned by the RADIUS server and assigns an IP address to the DHCP client using the standard DHCP procedure. See the following steps:
Step 66: After receiving the response packet, the DHCP authentication server sends a DHCP provisioning packet to the DHCP client.
Step 67: After receiving the DHCP provisioning message, the DHCP client sends a DHCP request message to the DHCP authentication server.
Step 68: The DHCP authentication server sends the IP address information sent from the RADIUS server to the DHCP client through the DHCP response packet.
In the foregoing step 63, the BRAS is inserted into the Option 82 option. In the actual application process, as shown in FIG. 7, the DSLAM can also be inserted into the Option 82 option by the access node, and the BRAS only performs DHCP relay, and other processing procedures are performed. It is exactly the same as the process described above.
In the above process, if the RADIUS server performs only the authentication process and the corresponding IP address is still assigned by the DHCP server, the process of steps 65 to 68 is as follows: When the RADIUS server returns the authentication pass message to the DHCP server, the DHCP server sends the message to the DHCP server. The DHCP client sends a DHCP-provided message and assigns the corresponding IP address to the DHCP client through subsequent processing identical to the existing address allocation process.
After that, the DHCP authentication server works in the server mode as an example, and the method is described. As shown in FIG. 8 and FIG. 9, the specific description is as follows:
Step 91: When the user opens the account, the operator adds a piece of data to the DHCP authentication server, and records the location information of the user. The coding mode is the same as the Option 82 option inserted by the access node and the BRAS, and the MAC of the recording terminal (STB, IAD) can be selected. address.
Step 92: When the DHCP client needs to obtain the IP address information, the DHCP client needs to send a DHCP discovery packet to the BRAS.
Step 93: The BRAS acts as a DHCP relay, captures the DHCP message, and inserts the Option 82 option in the message, and then sends the DHCP discovery message carrying the user location information to the DHCP authentication server. The Option 82 option identifies the user. Location information, such as port information, VPI/VCI, VLAN ID, etc.
The DHCP authentication server receives the DHCP message from the BRAS, extracts the Option 82 option as the identification information and the MAC address of the terminal, and queries the local database to authenticate the identification information of the DHCP client according to the identification information of the legal user saved locally. If the authentication succeeds, the DHCP client sends a DHCP-provided packet to the DHCP client. Step 94: The DHCP authentication server sends a DHCP-provided packet to the DHCP client. Step 95: After receiving the DHCP-provided packet, the DHCP client receives the DHCP-provided packet. Sending a DHCP request message to the DHCP authentication server;
Step 96: The DHCP authentication server allocates IP address information to the DHCP client, and sends the DHCP response message to the DHCP client.
Similarly, in step 93 of FIG. 9, the BRAS is inserted into the Option 82 option. In the actual application process, the Option 82 option can also be inserted by the access node DSLAM, and the BRAS is only used as a DHCP relay. The other processes are identical.
In summary, the present invention greatly enhances the security of the address allocation in the DHCP mode, and can perform access authentication on the user according to the location information, and only assigns an IP address to the legal user and the legal terminal, so as to effectively prevent maliciousness. Exhausted address attack. Moreover, in the event of a network attack or other network security problem, the physical location of the user can also be tracked according to the IP address, and the hacker attack behavior can be effectively shocked.
The above is only a preferred embodiment of the present invention, but the scope of the present invention is not limited thereto, and any person skilled in the art can easily think of changes or within the technical scope disclosed by the present invention. Alternatives are intended to be covered by the scope of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| CN114915612A | Cited by | China | – | Search report |
| CN1450766A | Cites | China | A | International search |
| CN1458761A | Cites | China | X | International search |
| KR20030055695A | Cites | Republic of Korea | A | International search |
| WO2004006503A1 | Cites | World Intellectual Property Organization (WIPO) | – | Applicant |
| JP2004228799A | Cites | Japan | A | International search |
| WO9916266A1 | Cites | World Intellectual Property Organization (WIPO) | – | Applicant |
12 members in 9 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 200510069417 | China | A | |
| 200510069417 | China | A | |
| 2005100694174 | – | – | – |
| CN2005169417 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| CN1855926A | China | A | |
| WO2006116926A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| EP1876754A1 | European Patent Office (EPO) | A1 | |
| US2008092213A1 | United States of America | A1 | |
| CN100388739C | China | C | |
| EP1876754A4 | European Patent Office (EPO) | A4 | |
| EP1876754B1 | European Patent Office (EPO) | B1 | |
| ATE546914T1 | Austria | T1 | |
| PT1876754E | Portugal | E | |
| DK1876754T3 | Denmark | T3 | |
| ES2381857T3 | Spain | T3 | |
| PL1876754T3 | Poland | T3 |
9 legal events, as 3 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: published in national officeWWP | WWP | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Non-entry into the national phaseNENP | NENP | RU | |
| Wipo information: withdrawn in national officeWithdrawnWWW | WWW | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Wipo information: withdrawn in national officeWithdrawnWWW | WWW | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO |
Numbers
- Publication
- 2006/116926
- Publication, DOCDB
- 2006116926
- Publication, EPODOC
- WO2006116926
- Application
- 833
- Application, DOCDB
- 2006000833
- Application, EPODOC
- WO2006CN00833
Titles2
- English
- METHOD SYSTEM AND SERVER FOR IMPLEMENTING DHCP ADDRESS SECURITY ALLOCATION
- French
- PROCEDE, SYSTEME ET SERVEUR POUR METTRE EN OEVRE L'ATTRIBUTION DE SECURITE D'ADRESSE DHCP
Classification
- CPC, 3
- H04L63/08
- H04L63/0892
- H04L61/5014
- IPC, 2
- H04L9 32
- H04L12 24
Designated states131
- Regional, 74
- African Regional Intellectual Property Organization (ARIPO)
- Botswana
- Ghana
- Gambia
- Kenya
- Lesotho
- Malawi
- Mozambique
- Namibia
- Sudan
- Sierra Leone
- Eswatini
- United Republic of Tanzania
- Uganda
- Zambia
- Zimbabwe
- Eurasian Patent Organization (EAPO)
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Republic of Moldova
- Russian Federation
and 50 moreShow fewer
- Tajikistan
- Turkmenistan
- European Patent Office (EPO)
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Iceland
- Italy
- Lithuania
- Luxembourg
- Latvia
- Monaco
- Netherlands (Kingdom of the)
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
- African Intellectual Property Organization (OAPI)
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Equatorial Guinea
- Guinea-Bissau
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- National, 57
- United Arab Emirates
- Antigua and Barbuda
- Albania
- Australia
- Bosnia and Herzegovina
- Barbados
- Brazil
- Belize
- Canada
- China
- Colombia
- Costa Rica
- Cuba
- Dominica
- Algeria
- Ecuador
- Egypt
- Grenada
- Georgia
- Croatia
- Indonesia
- Israel
- India
- Japan
and 33 moreShow fewer
- Comoros
- Saint Kitts and Nevis
- Democratic People’s Republic of Korea
- Republic of Korea
- Saint Lucia
- Sri Lanka
- Liberia
- Libya
- Morocco
- Madagascar
- North Macedonia
- Mongolia
- Mexico
- Nigeria
- Nicaragua
- Norway
- New Zealand
- Oman
- Papua New Guinea
- Philippines
- Seychelles
- Singapore
- San Marino
- Syrian Arab Republic
- Tunisia
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Saint Vincent and the Grenadines
- Viet Nam
- Yugoslavia, later Serbia and Montenegro (until 2006)
- South Africa