Distribution method of DHCP (Dynamic Host Configuration Protocol) fixed address

By introducing a dynamic credential management module and a status detection module into the DHCP protocol, the problems of high maintenance cost, lack of flexibility and insufficient security in the traditional DHCP protocol are solved. Terminals can apply for fixed IP addresses independently, reducing operation and maintenance costs and improving security and address pool utilization.

CN120812031APending Publication Date: 2025-10-17INTERNET DOMAIN NAME SYST BEIJING ENG RES CENT
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511035232.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-25
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

The allocation of fixed IP addresses in the traditional DHCP protocol relies on administrators to pre-configure a MAC-IP static binding table, resulting in high maintenance costs, lack of flexibility, insufficient security, and rigid policies.

Method used

A dynamic credential management module is introduced to generate and verify dynamic credentials through the extended option field in the DHCP Offer message. Terminal devices apply for fixed IP addresses within the temporary IP lease period. The binding relationship is dynamically adjusted in conjunction with the status detection module, and a secure hash algorithm is used to prevent forged MAC attacks.

Benefits of technology

It enables terminals to independently apply for fixed IP addresses, reduces operation and maintenance costs by 94%, improves security against MAC forgery attacks, dynamically adjusts address allocation strategies, and increases address pool utilization to 89%.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120812031A_ABST
    Figure CN120812031A_ABST
Patent Text Reader

Abstract

The invention discloses a DHCP (Dynamic Host Configuration Protocol) fixed address allocation method, which solves the problems of high maintenance cost, lack of flexibility, insufficient security and strategy stiffness in the prior art. The method comprises the following steps: receiving a DHCP Discover message which is sent by terminal equipment and carries an expansion option field null mark; a dynamic voucher management module is utilized to generate a dynamic voucher in response to the DHCP Discover message, a DHCP Offer message is sent to the terminal, and the DHCP Offer message comprises the dynamic voucher and a short-tenancy temporary IP; wherein the dynamic voucher management module is preset in a DHCP (Dynamic Host Configuration Protocol) server; the dynamic voucher is contained in an extended option field of the DHCP Offer message, is generated through a security mechanism, contains a unique identifier of the terminal equipment, and has a security attribute.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of DHCP server, in particular to a method for allocating fixed address of DHCP. BACKGROUND

[0002] The inventor realizes that in the traditional DHCP protocol, the allocation of fixed IP address depends on the pre-configuration of MAC-IP static binding table by the administrator, and has the following defects:

[0003] 1. High maintenance cost: new or replacement equipment needs manual update of the binding table.

[0004] 2. Lack of flexibility: the terminal cannot actively apply or change the fixed IP, and must be operated by the administrator.

[0005] 3. Insufficient security: only relying on MAC address authentication, a fake MAC can maliciously seize the IP.

[0006] Rigid policy: the binding relationship is strongly coupled with the device, and the address allocation strategy cannot be dynamically adjusted according to the network state (such as load balancing). Although the DHCPv6 IA_NA mechanism supports dynamic fixed address allocation, it is only applicable to IPv6 environment and cannot cover the mainstream IPv4 enterprise network. In addition, the terminal needs to implement a complex DHCPv6 state machine, and the support rate of embedded devices is less than 15%. SUMMARY

[0007] The present application provides a method for allocating fixed address of DHCP, which aims to solve the problems of high maintenance cost, lack of flexibility, insufficient security and rigid policy of the prior art mentioned in the background.

[0008] In a first aspect, a method for allocating fixed address of DHCP is provided, comprising:

[0009] receiving a DHCP Discover message carrying an empty flag of an extended option field sent by a terminal device;

[0010] In response to the DHCP Discover message, a dynamic credential is generated by a dynamic credential management module, and a DHCP Offer message is sent to the terminal, wherein the DHCP Offer message contains the dynamic credential and a short-term temporary IP; wherein the dynamic credential management module is pre-set in the DHCP server; the dynamic credential is contained in the extended option field of the DHCP Offer message, is generated by a security mechanism, contains a unique identifier of the terminal device, and has a security attribute.

[0011] The receiving terminal device sends a DHCP Request message in a temporary IP lease period, the DHCP Request message carrying a fixed IP address expected by the terminal device and a dynamic credential extracted from a DHCP Offer message;

[0012] The dynamic credential management module verifies the validity of the dynamic credential, and if the dynamic credential is valid and the target IP address is idle, the dynamic credential management module establishes a binding relationship between the dynamic credential and the target IP address, and then sends a DHCP Ack message to the terminal device to allocate the fixed IP address; if the dynamic credential is invalid or the target IP address is occupied, a DHCP Nck message and a rejection reason code are sent to the terminal device.

[0013] In the above scheme, optionally, the DHCP server further comprises a state detection module for monitoring network state in real time, and dynamically adjusting IP address binding relationship according to a preset strategy, wherein the state detection module is pre-set in the DHCP server.

[0014] In the above scheme, further optionally, the dynamically adjusting IP address binding relationship according to the preset strategy specifically comprises:

[0015] If the last active time of the IP is monitored to be more than 10 days, the IP is automatically released;

[0016] If the network load is monitored to be more than a preset value, the low-priority device is downgraded to a temporary IP;

[0017] If an ARP spoofing attack is detected, the IP is migrated to an isolated network segment;

[0018] The network state is monitored in real time based on device priority, and the priority of a production line device is set to be higher than that of an office device according to a preset label.

[0019] In the above scheme, optionally, for a terminal device that does not support the extension option field, the extension option field is automatically added or deleted by a proxy gateway when the terminal device interacts with the DHCP server, so as to ensure that the terminal device can work normally.

[0020] For cross-network segment transmission of a relay device, the extension option field is encapsulated by a DHCP relay agent information field.

[0021] In the scheme, the dynamic credential is generated by the security mechanism, specifically, a key for encryption operation is generated in a secure environment, and the encryption operation is performed using the key; the secure environment is a hardware security module (HSM) or a trusted execution environment (TEE); the generation, use and destruction of the key are completed within the physical security boundary of the secure environment, and the key is never exported outside the security boundary of the secure environment.

[0022] In the scheme, further optionally, the method further comprises: automatically rotating the key in the secure environment according to a preset time; the rotation of the key is completed within the physical security boundary of the secure environment, and the key is never exported outside the security boundary of the secure environment.

[0023] In the scheme, optionally, the security attribute of the dynamic credential includes at least one of the following:

[0024] Time effectiveness, the use period of the dynamic credential is limited by a timestamp and a valid period window;

[0025] Uniqueness, the uniqueness of a request at the same time is ensured by a variable-length true random number.

[0026] In the scheme, further optionally, the generation formula of the dynamic credential Token is:

[0027] Token = HMAC-SHA256 (Server_Key, Client_MAC || Timestamp || Nonce).

[0028] In the formula, Server_Key is a 256-bit symmetric key protected by the secure environment and used as the encryption root key of the dynamic credential Token; Client_MAC represents the physical address of the client and is used to bind the Token and the identity of the terminal device to prevent cross-device impersonation; Timestamp represents a UTC timestamp with a valid period window, and the valid window is used to ensure the time effectiveness of the Token and resist replay attacks; Nonce is a fixed 8-byte length true random number, and the length is configured to meet the time effectiveness security requirements of the Token, to make up for the timestamp precision vulnerability and ensure the uniqueness of a request at the same time; HMAC-SHA256 is a secure hash algorithm based on a key-based encryption hash function, which ensures that the Token cannot be forged and tampered with; || represents a data concatenation symbol.

[0029] In the scheme, further optionally, the verification of the validity of the dynamic credential by the dynamic credential management module includes:

[0030] 1) Time window verification of the dynamic credential Token: |current time-generation time|≤valid period window;

[0031] 2) HMAC re-comparison for dynamic credential Token:

[0032] 21) The DHCP server receives the Token carried in the DHCP Request sent by the terminal;

[0033] 22) The DHCP server re-computes the HMAC-SHA256 (Server_Key, Client_MAC||Timestamp||Nonce) with the same Server_Key and the received Client_MAC, Timestamp and Nonce;

[0034] 23) Comparison result: if the re-computed result is the same as the received Token, it means that the Token is not tampered with, and the verification is passed; if it is different, it means that the Token is forged or tampered with, and the verification fails and returns an error code Token invalid error code.

[0035] In the above scheme, optionally, in the rejection reason code, the rejection reason code indicating that the dynamic credential is invalid is a custom special error code, specifically 0x5B, and the RFC standard is adopted; the rejection reason codes in other cases are all RFC standard codes.

[0036] In the above scheme, optionally, the DHCP server persists the binding relationship between the established dynamic credential and the target IP address into an IP binding table.

[0037] Compared with the prior art, the present application has at least the following beneficial effects:

[0038] The present application is based on further analysis and research on the problems of the prior art, and realizes that the prior art has high maintenance cost, lack of flexibility, insufficient security, and rigid policy. By embedding a dynamic credential management module in the DHCP server, the terminal can automatically complete the "credential-fixed IP" binding when it first goes online, without the need for manual maintenance of the MAC-IP static table. An extensible dynamic credential (including terminal unique identifier and security attributes) is introduced, allowing the terminal to independently apply for or replace the desired fixed IP within the lease period, realizing "self-service" address management. A credential verification and rejection reason code is added in the DHCP Offer / Request / Ack / Nck interaction process, replacing single MAC authentication with cryptographic means to prevent address grabbing by fake MAC. The binding relationship is decoupled from "static MAC-IP" to "dynamic credential-IP", and combined with real-time address occupation monitoring, so that the server can dynamically decide the allocation result based on network load, address pool balance, and other strategies, achieving the comprehensive effect of continuously updating fixed address allocation without human intervention, terminals self-help obtaining or changing fixed IP, fake terminals being rejected due to failed credential verification, and real-time adjustment of address allocation strategy according to network state, thereby solving the defects of high maintenance cost, lack of flexibility, insufficient security, and rigid policy in the prior art.

[0039] The present application also has at least the following effects:

[0040] 1. Improved operation and maintenance efficiency: terminals independently apply for fixed IP, reducing network maintenance cost by 94% (from 8 person-days to 0.5 person-days), and completely liberating administrators.

[0041] 2. Security capability leap: dynamic credentials resist MAC spoofing attacks, with a 100% success rate of resisting spoofing (10 million attacks with zero breakthrough), meeting the requirements of the third level of Cybersecurity 2.0.

[0042] 3. Intelligent resource scheduling: dynamically recycling IP based on traffic / activity, improving address pool utilization from 51% to 89%, and ensuring 99.99% SLA for core business. BRIEF DESCRIPTION OF DRAWINGS

[0043] Figure 1 An application flow diagram of a DHCP fixed address allocation method provided by an embodiment of the present application;

[0044] Figure 2 A system architecture diagram of a DHCP fixed address allocation method provided by an embodiment of the present application;

[0045] Figure 3 A timing logic diagram of a DHCP fixed address allocation method provided by an embodiment of the present application;

[0046] Figure 4 A protocol compatibility solution schematic diagram is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0047] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application is further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0048] In the description of the present application: unless otherwise specified, the expressions such as "include", "contain", "have" and the like also mean "not limited to" (some units, components, materials, steps, etc.).

[0049] The present application aims to provide a fixed address allocation method and system based on dynamic credentials and DHCP protocol extension, to solve the problems of high operation and maintenance cost, terminal lack of autonomy, weak security mechanism and rigid policy in the traditional static MAC-IP binding scheme. The specific implementation is as follows:

[0050] 1. Replace MAC address authentication with dynamic credentials (Token) to solve the risk of forgery.

[0051] 2. Extend the DHCP Option 188 interaction mechanism, so that the terminal can apply for a fixed address autonomously after obtaining a temporary IP.

[0052] 3. Establish an address binding state real-time monitoring module to support dynamic adjustment of binding relationship according to network policy.

[0053] 4. Finally achieve the four technical effects of terminal configuration-free application, administrator zero intervention, anti-forgery attack and flexible policy adjustment.

[0054] In one embodiment, referring to Figure 1 and Figure 3 , a DHCP fixed address allocation method is provided, comprising:

[0055] receiving a DHCP Discover message carrying an empty flag of an extended option field sent by a terminal device;

[0056] in response to the DHCP Discover message, generating a dynamic credential by using a dynamic credential management module, and sending a DHCP Offer message to the terminal, wherein the DHCP Offer message contains the dynamic credential and a short-term temporary IP; wherein the dynamic credential management module is pre-set in the DHCP server; the dynamic credential is contained in the extended option field of the DHCP Offer message, is generated by a security mechanism, contains a unique identifier of the terminal device, and has a security attribute;

[0057] The receiving terminal device sends a DHCP Request message in a temporary IP lease period, and the DHCP Request message carries a fixed IP address expected by the terminal device and a dynamic credential extracted from a DHCP Offer message;

[0058] The dynamic credential management module verifies the validity of the dynamic credential. If the dynamic credential is valid and the target IP address is idle, the dynamic credential management module establishes a binding relationship between the dynamic credential and the target IP address, and then sends a DHCP Ack message to the terminal device to allocate the fixed IP address. If the dynamic credential is invalid or the target IP address is occupied, a DHCP Nck message and a rejection reason code are sent to the terminal device.

[0059] In the embodiment, the extension option field is exemplarily described by taking Option 188 as an example for the convenience of description; it should be understood by those skilled in the art that any extension option field conforming to the DHCP protocol extension specification and capable of realizing the functions described in the application should fall within the protection scope of the application.

[0060] In the embodiment, the dynamic credential management module has the following functions.

[0061] Credential generation and verification process:

[0062] Phase one: dynamic credential generation phase.

[0063] 1) Terminal: send a DHCP Discover message carrying an Option 188 empty mark;

[0064] 2) Server: respond to the DHCP Offer message, including:

[0065] Short lease temporary IP (lease period ≤ 5 minutes).

[0066] Generate a dynamic credential Token.

[0067] Phase two: fixed address application phase

[0068] 1) Terminal: send a DHCP Request message in a temporary IP lease period, carrying:

[0069] Requested IP Address field: fill in the expected fixed IP (such as 192.168.1.100).

[0070] Option 188 field: fill in the received Token.

[0071] 2) Server:

[0072] Verify Token:

[0073] a. Time window verification (|current time - generation time|≤5 seconds).

[0074] b. HMAC recalculation comparison.

[0075] Perform binding:

[0076] a. If IP is idle and Token is valid → establish Token-IP binding (not MAC!).

[0077] b. Return DHCP Ack to allocate fixed IP (lease period≥1 year).

[0078] In one embodiment, the protocol extension is implemented: the DHCP Option 188 data structure is shown in Table 1 as follows.

[0079] Table 1

[0080] Message Type Option 188 structure Length Description Discover

[188] [0] 2 bytes Null marker (length = 0) Offer

[188]

[32] [Token...] 34 bytes Carries 32 byte Token Request

[188]

[32] [Token...] 34 bytes Submit Token application for fixed IP

[0081] In one embodiment, further comprising: the DHCP server monitors the network state in real time through the state detection module, and dynamically adjusts the IP address binding relationship according to the preset strategy, wherein the state detection module is pre-set in the DHCP server.

[0082] In one embodiment, the dynamically adjusting IP address binding relationship according to the preset strategy specifically includes:

[0083] If the last active time of the IP is monitored to be more than 10 days, the IP is automatically released;

[0084] If the network load is monitored to be more than the preset value, the low-priority device is downgraded to a temporary IP;

[0085] If an ARP spoofing attack is detected, the IP is migrated to an isolated network segment;

[0086] Based on real-time monitoring of the network state according to the device priority, the priority of the production line device is set to be greater than the priority of the office device.

[0087] In this embodiment, the state detection and strategy execution engine has the following functions:

[0088] (1) Real-time detection latitude reference Table 2.

[0089] Table 2

[0090]

[0091] (2) Strategy execution logic:

[0092] High load releases low-priority IP.

[0093] Security event triggers isolation.

[0094] (3) Dynamic adjustment rule library reference Table 3.

[0095] Table 3

[0096]

[0097] Reference Figure 2 , this application introduces a newly designed dynamic credential management module and state detection module. The dynamic credential management module of the server generates a dynamic credential Token to establish a Token→IP binding relationship when the terminal applies for an IP. The state detection module can dynamically adjust the IP according to the strategy by detecting the IP activity or network traffic in real time.

[0098] In one embodiment, for terminal devices that do not support the extension option field, the extension option field is automatically added or deleted by a proxy gateway when it interacts with the DHCP server, thereby ensuring that the terminal device can work normally;

[0099] For cross-segment transmission of relay devices, the extension option field is encapsulated through the DHCP relay agent information field.

[0100] In this embodiment, the specific protocol compatibility scheme is referred to Figure 4 and Table 4.

[0101] Table 4

[0102]

[0103] Scenario 1: Cisco switch enables Option 188 transparent transmission, example code as follows.

[0104] interface GigabitEthernet0 / 1.

[0105] ip dhcp relay information option-insert # enable relay support.

[0106] Scenario 2: Linux proxy gateway deployment (compatible with old devices), example code as follows:

[0107] # Install proxy tools.

[0108] apt install dhcp-option-proxy.

[0109] # Configure rules: automatically add Option 188 to DHCP packets.

[0110] echo "ADD_OPTION_188=true" > / etc / dhcp-proxy.conf.

[0111] In one embodiment, the dynamic credential is generated by the security mechanism specifically as follows: a key for encryption operation is generated in a secure environment, and an encryption operation is performed using the key; the secure environment is a hardware security module (HSM) or a trusted execution environment (TEE); the generation, use and destruction of the key are all completed within the physical security boundary of the secure environment, and the key is never exported outside the security boundary of the secure environment.

[0112] In one embodiment, the method further comprises: automatically rotating the key in the secure environment according to a preset time; the rotation of the key is completed within the physical security boundary of the secure environment, and the key is never exported outside the security boundary of the secure environment.

[0113] In one embodiment, the security attribute of the dynamic credential includes at least one of the following:

[0114] Time effectiveness, limiting the use period of the dynamic credential by a timestamp and a valid period window;

[0115] One-time use, ensuring the uniqueness of a request at the same time by a variable-length true random number.

[0116] In one embodiment, the generation formula of the dynamic credential Token is:

[0117] Token = HMAC-SHA256 (Server_Key, Client_MAC || Timestamp || Nonce).

[0118] In the formula, Server_Key is a 256-bit symmetric key protected by the secure environment and serves as an encryption root key of the dynamic credential Token; Client_MAC represents the physical address of the client and is used to bind the Token and the identity of the terminal device to prevent cross-device impersonation; Timestamp represents a UTC timestamp with a valid period window, and the valid window is used to ensure the time effectiveness of the Token and resist replay attacks; Nonce is a fixed 8-byte length true random number, and its length is configured to meet the time effectiveness security requirements of the Token, to make up for the timestamp precision vulnerability and ensure the uniqueness of a request at the same time; HMAC-SHA256 is a secure hash algorithm based on a key-based encryption hash function, to ensure that the Token is not counterfeit and tamper-proof; || represents a data concatenation symbol.

[0119] In the embodiment, the core algorithm formula is:

[0120] Token = HMAC-SHA256 (Server_Key, Client_MAC || Timestamp || Nonce).

[0121] The parameters in the core algorithm formula are explained as follows:

[0122] Server_Key: 256-bit symmetric key, protected by the server hardware security module (HSM).

[0123] 1) Function: Encryption root key of Token, determines the security of the entire system.

[0124] 2) Implementation specification:

[0125] Storage location: Hardware security module (HSM) or trusted execution environment (TEE).

[0126] Lifetime: The key lifetime of Server_Key implements hardware-level closed management:

[0127] a) Generate a true random key inside the HSM / TEE and never export the physical security boundary;

[0128] b) All encryption operations dependent on the key are performed inside the secure environment;

[0129] c) Automatically rotate the key at a predetermined period and securely destroy the old key.

[0130] The complete life cycle description includes the following mandatory stages:

[0131] 1) Generation stage.

[0132] Generate a 256-bit key inside the HSM / TEE using a true random number generator (TRNG) that meets the NIST SP 800-90A standard, and the key is never exported from the physical security boundary after generation.

[0133] 2) Usage stage.

[0134] All encryption operations (including Token generation / validation) are completed inside the HSM / TEE, and external systems can only call encryption services (such as HSM_GenerateToken(Client_MAC)) through secure APIs.

[0135] 3) Rotation stage.

[0136] Automatically trigger key rotation at a predetermined time (default 90 days), the parallel period of new and old keys ≤24 hours (old key only used for decrypting historical Token).

[0137] 4) Destruction stage.

[0138] The expired key is subjected to cryptographic erasure by the HSM / TEE, and zeroization by the storage medium layer to ensure that the key cannot be recovered.

[0139] Client_MAC: Physical address of the client.

[0140] Function: Bind Token with terminal device identity, prevent cross-device impersonation.

[0141] Format specification: Standard IEEE 802 MAC address (6 bytes).

[0142] Processing logic: Remove delimiters, convert to binary, 00:1A:2B:3C:4D:5E → 0x001A2B3C4D5E.

[0143] Security boundary: Only used for Token generation, not directly bound to IP (to avoid MAC spoofing risk).

[0144] Timestamp: UTC timestamp, precision ±1ms (ISO 8601 format), valid period window ±5s, provides Token timeliness, resists replay attacks.

[0145] Nonce: 8-byte true random number (NIST SP 800-90A), compensates for timestamp precision vulnerabilities, ensures uniqueness of requests at the same time.

[0146] HMAC-SHA256: Secure Hash Algorithm, key-based cryptographic hash function, ensures Token cannot be forged or tampered with. Implementation specification: conforms to FIPS 198-1 standard, output length is 256 bits (32 bytes).

[0147] ||: Indicates data splicing.

[0148] In one embodiment, the use of the dynamic credential management module to verify the validity of the dynamic credential includes:

[0149] 1) Time window verification of dynamic credential Token: |current time - generation time| ≤ valid period window;

[0150] 2) Recalculation of dynamic credential Token HMAC:

[0151] 21) The DHCP server receives the Token carried in the DHCP Request sent by the terminal.

[0152] 22) The DHCP server recalculates the HMAC-SHA256 (Server_Key, Client_MAC||Timestamp||Nonce) with the same Server_Key and the received Client_MAC, Timestamp, Nonce.

[0153] 23) Comparison result: if the recalculated result is the same as the received Token, it means that the Token is not tampered with, and the verification is passed; if it is different, it means that the Token is forged or tampered with, and the verification fails and returns an error code Token invalid error code.

[0154] In one embodiment, in the rejection reason code, the rejection reason code indicating that the dynamic credential is invalid is a custom special error code, specifically 0x5B, using the RFC standard; the rejection reason codes in other cases are all RFC standard codes.

[0155] In one embodiment, the DHCP server persists the binding relationship between the established dynamic credential and the target IP address in the IP binding table; wherein "persisting" means saving data through a non-volatile storage medium (such as a disk or a database) to ensure that the server can recover the binding relationship after power failure and restart.

[0156] In this embodiment, the database design: IP binding table (dhcp_binding) is shown in Table 5.

[0157] Table 5

[0158]

[0159] The technical key points of the present application are:

[0160] 1. Dynamic credential security mechanism:

[0161] Time-limited Token generated by the HSM-protected key (Server_Key)

[0162] (HMAC-SHA256 (Client_MAC||Timestamp||Nonce)), replacing the traditional MAC authentication, to solve the IP forgery risk.

[0163] 2. Two-stage protocol extension:

[0164] Through the DHCP Option 188, the terminal autonomously applies, and the terminal autonomously submits a Token application for a fixed address after obtaining a temporary IP, realizing zero administrator intervention, which is different from the existing protocol: DHCPv6 IA_NA requires a complete state machine, and this scheme only requires two interactions (IPv4 / IPv6 universal).

[0165] First interaction is to declare the capability (Discover with empty Option 188).

[0166] Temporary address transition period (≤5 minutes short lease) → Leave a safety window for fixed applications.

[0167] Special error code (0x5B means Token invalid) → Compatible with RFC standard while expanding semantics.

[0168] 3. State-driven policy engine:

[0169] Based on IP activity / network traffic real-time monitoring, automatically release idle IP or migrate high-priority devices, existing DHCP server (such as ISC DHCP) has no real-time policy execution capability.

[0170] Dynamic adjustment rule base (example):

[0171]

[0172]

[0173] The technical features of the above embodiments can be combined in any manner. In order to make the description simple, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present disclosure.

Claims

1. A method for allocating a DHCP fixed address, characterized in that: include: Receive a DHCP Discover message from a terminal device that carries an empty flag for the extended option field. In response to the DHCP Discover message, a dynamic credential is generated using a dynamic credential management module, and a DHCP Offer message is sent to the terminal, wherein the DHCP Offer message includes the dynamic credential and a short-lease temporary IP address; wherein the dynamic credential management module is pre-installed in the DHCP server; the dynamic credential is included in an extended option field of the DHCP Offer message, is generated through a security mechanism, includes a unique identifier of the terminal device, and has security attributes; The receiving terminal device sends a DHCP Request message during the temporary IP lease period, wherein the DHCP Request message carries the fixed IP address desired by the terminal device and the dynamic credentials extracted from the DHCP Offer message; The dynamic credential management module is used to verify the validity of the dynamic credential. If the dynamic credential is valid and the target IP address is idle, the dynamic credential management module is used to establish a binding relationship between the dynamic credential and the target IP address, and then a DHCP Ack message is sent to the terminal device to allocate a fixed IP address. If the dynamic credential is invalid or the target IP address is occupied, a DHCP Nck message and a rejection reason code are sent to the terminal device.

2. The method for allocating a DHCP fixed address according to claim 1, wherein: Also includes: The DHCP server monitors the network status in real time through a status detection module and dynamically adjusts the IP address binding relationship according to a preset strategy, wherein the status detection module is pre-set in the DHCP server.

3. The method for allocating a DHCP fixed address according to claim 2, wherein: Dynamically adjusting the IP address binding relationship according to the preset strategy specifically includes: If the last active time of the IP is detected to be more than 10 days, the IP will be automatically released; If the network load is detected to exceed the preset value, the low-priority device will be downgraded to a temporary IP; If an ARP spoofing attack is detected, the IP address will be moved to an isolated network segment. Monitor network status in real time based on device priority. Set the priority of production line equipment to be higher than that of office equipment according to preset tags.

4. The method for allocating a DHCP fixed address according to claim 1, wherein: For a terminal device that does not support the extended option field, the extended option field is automatically added or deleted through the proxy gateway when the terminal device interacts with the DHCP server, thereby ensuring that the terminal device can work normally; For cross-segment transmission of a relay device, the extended option field is encapsulated through the DHCP relay agent information field.

5. The method for allocating a DHCP fixed address according to claim 1, wherein: Dynamic credentials are generated through the security mechanism as follows: a key for encryption operations is generated in a secure environment, and the encryption operations are performed using the key; the secure environment is a hardware security module HSM or a trusted execution environment TEE; the entire process of key generation, use, and destruction is completed within the physical security boundary of the secure environment, and the key is never exported outside the security boundary of the secure environment.

6. The method for allocating a DHCP fixed address according to claim 5, wherein: Also includes: The key is automatically rotated in the secure environment at a preset time; the key rotation is completed within the physical security boundary of the secure environment, and the key is never exported outside the security boundary of the secure environment.

7. The method for allocating a DHCP fixed address according to claim 1, wherein: The security attributes of the dynamic credential include at least one of the following: Timeliness: limiting the usage period of dynamic credentials through timestamps and validity windows; One-time, variable-length true random numbers are used to ensure the uniqueness of requests at the same time.

8. The method for allocating a DHCP fixed address according to claim 5 or 7, wherein: The formula for generating the dynamic credential Token is: Token=HMAC-SHA256(Server_Key,Client_MAC||Timestamp||Nonce) Wherein, Server_Key is a 256-bit symmetric key, protected by the secure environment, and serves as the encryption root key of the dynamic credential Token; Client_MAC represents the physical address of the client, which is used to bind the Token to the terminal device identity to prevent cross-device impersonation; Timestamp represents the UTC timestamp with a validity window, which is used to ensure the timeliness of the Token and resist replay attacks; Nonce is a true random number with a fixed length of 8 bytes, whose length is configured to meet the timeliness security requirements of the Token, used to compensate for the timestamp accuracy vulnerability and ensure the uniqueness of requests at the same time; HMAC-SHA256 is a secure hash algorithm, a key-based cryptographic hash function that ensures that the Token is unforgeable and tamper-proof; || represents the data splicing symbol.

9. The method for allocating a DHCP fixed address according to claim 8, wherein: The verifying the validity of the dynamic credential by using the dynamic credential management module includes: 1) Perform time window verification on the dynamic credential token: |current time - generation time| ≤ validity window; 2) Perform HMAC recalculation and comparison on the dynamic credential Token: 21) The DHCP server receives the DHCP Request sent by the terminal containing the token; 22) The DHCP server recalculates HMAC-SHA256(Server_Key, Client_MAC||Timestamp||Nonce) using the same Server_Key and the received Client_MAC, Timestamp, and Nonce. 23) Comparison result: If the recalculated result is the same as the received Token, it means that the Token has not been tampered with and the verification is successful; if they are different, it means that the Token has been forged or tampered with, and the verification fails and returns the error code "Invalid Token".

10. The method for allocating a DHCP fixed address according to claim 1, wherein: Among the rejection reason codes, the rejection reason code indicating that the dynamic credential is invalid is a customized special error code, specifically 0x5B, which adopts the RFC standard; the rejection reason codes for other situations are all RFC standard codes.

11. The method for allocating a DHCP fixed address according to claim 1, wherein: The DHCP server stores the established binding relationship between the dynamic credential and the target IP address in the IP binding table.