Unlock instant, AI-driven research and patent intelligence for your innovation.

Access control method and system based on physical port and mac address of intelligent switch

A MAC address, intelligent switch technology, applied in the field of terminal access, can solve the problems of network bottleneck, control failure, high cost, etc., to achieve the effect of not changing the network topology, eliminating access trailing, and reliable admission control

Inactive Publication Date: 2017-05-31
刘建兵 +1
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] These four technologies have their own problems and defects. ①It relies on switches supporting the 802.1x protocol, which cannot be implemented on ordinary switches, and the cost is high; there is a problem of access tailing; ②The terminal is required to use DHCP to assign IP addresses. The terminal is invalid; ③Depending on the capability of the gateway device itself, there is a risk of network bottleneck and single point of failure; changing the network structure, the control range is affected by the network topology; there is no access control function for the LAN below the gateway, only access can be controlled; ④ Yes Pure soft means are actually ARP spoofing. There are many ways to change the gateway address assigned to the terminal by this method, resulting in control failure; its characteristics similar to ARP attacks will be blocked by many personal firewall software and cannot play a role

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Access control method and system based on physical port and mac address of intelligent switch
  • Access control method and system based on physical port and mac address of intelligent switch
  • Access control method and system based on physical port and mac address of intelligent switch

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0014] In order to make the object, technical solution and advantages of the present invention clearer, the present invention will be described in further detail below in conjunction with specific embodiments and with reference to the accompanying drawings.

[0015] For devices connected at the network border, only the management and control based on the switch port is the most thorough management and control, and only the authentication based on the MAC address of the access device can identify the physical device. Access authentication methods based on client software, VLAN, and 802.1X protocol, which are popular in the industry, essentially fail to achieve access control on the access boundary. Access devices that fail authentication are actually connected to the network access switch. , data communication can still be realized at the access switch or the access layer, which is an incomplete access control method.

[0016] The MAC address of the access device is used as the...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention discloses an access control method and system based on a physical interface and MAC addresses of an intelligent exchanger. The method comprises the following steps that 1, MAC table data are read from the exchanger establishing SNMP protocol connection; 2, acquired data are sent to a data merging module; 3, merging and processing are conducted on the data acquired through SNMP via the data merging module, and the data are sent to a filter A; 4, the merged data are sent to a filter B through the data merging module; 5, the filter A determines a newly added MAC address and sends an MAC-PORT corresponding to the newly added MAC address to an MAC identification module; 6, the reduced MAC addresses are determined, the off-line state is written into an MAC identification base; 7, the filer A updates an MAC / PORT cache according to the received data; 8, the MAC identification module searches whether the received MAC addresses are already in the MAC identification base to determine whether the device is legal.

Description

technical field [0001] The invention relates to the technical field of terminal access, in particular to an access control method and system based on a physical port and a MAC address of an intelligent switch. Background technique [0002] There are four main types of existing access control technologies: ①802.1x access control, ②DHCP-based access control, ③Gateway-based access control, ④ARP-based mandatory technology, different technologies use different access control points Enables and disables access. ①The control point is on the protocol port of the switch, and the access is closed. Except for the EAP protocol, all the protocol ports are closed. The client can only complete the access authentication process through the EAP protocol and the authentication server communication, and the access is open. Then all switch protocol ports are opened, and the terminal accesses the network; the access control point of ② is on the gateway address of the network segment, that is, o...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L12/911H04L12/947H04L12/24H04L29/06
Inventor 刘建兵薛锋
Owner 刘建兵