A method and apparatus for obtaining an address prefix
Patent Information
- Application Number
- CN202011644039.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-30
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2040-12-30
AI Technical Summary
然而ND认证存在很多局限性,在一些应用场景下,如地址请求设备为机顶盒时,ND协议报文无法携带有效认证信息,导致未经授权的用户可以直接采用ND协议获取的IPv6地址访问网络,存在安全隐患
Smart Images

Figure CN114765601B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method and apparatus for obtaining address prefixes. Background Technology
[0002] Internet Protocol over Ethernet (IPoE) is a common broadband access authentication method. It primarily uses bound authentication to authenticate hosts, meaning that authentication is performed using the physical information of the host connection. In other words, when using IPoE to access the internet, users do not need to enter a username and password. The access device generates a username based on information such as the options field and MAC layer information in the internet access request, and combines this with its own default password for authentication. Authorized users are then assigned an IP address.
[0003] In IPoE access scenarios, Internet Protocol version 6 (IPv6) addresses correspond to two address allocation methods: stateless address allocation, which uses the Neighbor Discovery (ND) protocol to allocate the IPv6 address prefix; and stateful address allocation, which uses the Dynamic Host Configuration Protocol version 6 (DHCPv6) protocol to allocate the IPv6 address and address prefix. When an address-requesting device requests an address via DHCPv6, the address allocation device, upon receiving the DHCPv6 request message, can authenticate the device based on the option fields in the request message, such as option18 / option37. If authentication is successful, the address allocation device allocates an IPv6 prefix to the address-requesting device.
[0004] However, in some application scenarios, such as when an address requesting device uses the ND+PD method to request an address, the device obtains the IPv6 address prefix via the DHCPv6 protocol and assigns an IPv6 address to the host on the (local area network, LAN) side based on this prefix. Additionally, the device can also obtain an IPv6 address prefix via the ND protocol to obtain an address on the (wide area network, WAN) side, i.e., its own address. However, ND authentication has many limitations. In some application scenarios, such as when the address requesting device is a set-top box, the ND protocol message cannot carry valid authentication information, allowing unauthorized users to directly access the network using the IPv6 address obtained via the ND protocol, posing a security risk. Summary of the Invention
[0005] This application provides an address prefix acquisition method and apparatus, which can effectively authenticate when allocating address prefixes to address requesting devices, prevent unauthorized user logins, and improve network security.
[0006] In a first aspect of this application, an address prefix acquisition method is provided. The method includes: an address requesting device sending a first request message to an address allocation device to request first prefix information in order to obtain an IPv6 address. Upon receiving the first request message, the address allocation device allocates the first prefix information to the address requesting device and sends a first response message to the address requesting device. The first response message includes the first prefix information and a first time-to-live (TTL). The first TTL indicates the validity period of the first prefix information. After receiving the first response message, the address requesting device generates a second request message and sends it to the address allocation device. The second request message includes authentication information used by the address allocation device to authenticate the legitimacy of the address requesting device. The address allocation device verifies the legitimacy of the address requesting device based on the second request message. After successful authentication, the address allocation device sends a second response message to the address requesting device. The second response message includes a second TTL, which indicates the validity period of the first prefix information, and the second TTL is greater than the first TTL.
[0007] In this implementation, when the address requesting device requests the first prefix information, the address allocation device first allocates temporarily valid first prefix information to the address requesting device before authenticating the address requesting device's legitimacy. After the address allocation device successfully authenticates the address requesting device through a second request message including authentication information sent by the address requesting device, it then allocates a second lifetime to the address requesting device. This second lifetime is the normal lifetime.
[0008] In one specific implementation, the first prefix information is used by the address requesting device to generate a first IPv6 address, which is the address of the address requesting device. In this implementation, after receiving the first response message, the address requesting device can generate the first IPv6 address based on the first prefix information included in the first response message and its corresponding interface identifier, so as to access the network using the first IPv6 address.
[0009] In one specific implementation, the second request message is used to request second prefix information. The method further includes: after the address allocation device authenticates the address requesting device, the address allocation device sends a third response message to the address requesting device, the third response message including the second prefix information. In this implementation, the address requesting device requests the second prefix information through the second request message, and the second prefix information is used by the address requesting device to allocate an IPv6 address for its corresponding user equipment.
[0010] In one specific implementation, the third response message also includes a third time to live, which is used to indicate the validity period of the second prefix information.
[0011] In one specific implementation, the second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device. In this implementation, when the address requesting device obtains the second prefix information, it can assign an address prefix to the connected hosts based on the second prefix information, thereby enabling each host to obtain an IPv6 address based on the assigned address prefix. Alternatively, the address requesting device can generate a second IPv6 address based on the interface identifier corresponding to each host and the second prefix information, and then assign IPv6 addresses to the corresponding hosts.
[0012] In one specific implementation, the second response message further includes third prefix information. This third prefix information is used by the address requesting device to replace the first prefix information with the third prefix information, and the second time-to-live (TTL) indicates the validity period of the third prefix information. In this implementation, after the address requesting device is authenticated, the address allocation device can also reallocate new prefix information, i.e., the third prefix information, to the address requesting device, enabling the device to generate its own corresponding IPv6 address based on the third prefix information and the interface identifier.
[0013] In one specific implementation, the address requesting device and the address allocating device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the address allocating device send the second request message using the Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
[0014] In one specific implementation, the address requesting device is an Ethernet-bearer Internet Protocol (IPoE) device.
[0015] In one specific implementation, the address requesting device is a client device (CPE), and the address allocation device is a broadband access server (BRAS) or a DHCPv6 server.
[0016] In a second aspect of this application, an address prefix acquisition method is provided. The method includes: an address allocation device receiving a first request message sent by an address requesting device, the first request message being used to request first prefix information; the address allocation device sending a first response message to the address requesting device, the first response message including indication information, wherein the indication information is used to instruct the address requesting device to send a second request message; the address allocation device receiving the second request message sent by the address requesting device, the second request message including authentication information, wherein the authentication information is used by the address allocation device to authenticate the legitimacy of the address requesting device; and after the address allocation device successfully authenticates the address requesting device, the address allocation device sending a second response message to the address requesting device, the second response message including the first prefix information.
[0017] In this implementation, after receiving the first request message from the address requesting device requesting first prefix information, the address allocation device does not send a first response message including the first prefix information. Instead, it sends a first response message including indication information. This indication information instructs the address requesting device to send a second request message, so that the address allocation device can authenticate the legitimacy of the address requesting device based on the authentication information carried in the second request message. Once the authentication is successful, the address allocation device allocates the first prefix information to the address requesting device, thereby enabling the address requesting device to generate an IPv6 address based on the first prefix information. This allows the address requesting device to access the network using the IPv6 address, improving network security.
[0018] In one specific implementation, the second response message may further include a second time-to-live (TTL), which is used to indicate the validity period of the first prefix information.
[0019] In one specific implementation, the first response message is a router response RA message, and the indication information is carried in the extended community attribute field newly added to the RA message.
[0020] In one specific implementation, before the address allocation device sends a second response message to the address requesting device, the method further includes: the address allocation device receiving a third request message sent by the address requesting device, the third request message being used to request the first prefix information. In this implementation, since the address allocation device has not allocated the first prefix information to the address requesting device when it sends the first request message, the address requesting device can repeatedly send request messages, such as the third request message, to the address allocation device before obtaining the first prefix information, so that the address allocation device sends a second response message including the first prefix information to the address allocation device based on the third request message.
[0021] In one specific implementation, the first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
[0022] In one specific implementation, the second request message is used to request second prefix information. The method further includes: after the address allocation device authenticates the address requesting device, the address allocation device sends a third response message to the address requesting device, the third response message including the second prefix information. In this implementation, the second request message can be used not only for authenticating the address requesting device but also for requesting the second prefix information.
[0023] In one specific implementation, the second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
[0024] In one specific implementation, the address requesting device and the address allocating device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the address allocating device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
[0025] In one specific implementation, the address requesting device is an Ethernet-bearer Internet Protocol (IPoE) device.
[0026] In one specific implementation, the address requesting device is a client device CPE, and the address allocation device is a broadband access server (BRAS) or a DHCPv6 server.
[0027] In a third aspect of this application, an address prefix acquisition method is provided. The method includes: an address allocation device receiving a first request message sent by an address requesting device, the first request message being used to request first prefix information; the address allocation device configuring the access permission of the address requesting device to a first permission, the first permission representing the first access permission possessed by the address requesting device when accessing the network using the first prefix information; the address allocation device sending a first response message to the address requesting device, the first response message including the first prefix information; the address allocation device receiving a second request message sent by the address requesting device, the second request message including authentication information, the authentication information being used by the address allocation device to authenticate the legitimacy of the address requesting device; after the address allocation device successfully authenticates the address requesting device, the address allocation device configuring the access permission of the address requesting device to a second permission, the second permission representing the second access permission possessed by the address requesting device when accessing the network using the first prefix information, the second access permission being higher than the first access permission.
[0028] In this implementation, when an address requesting device requests first prefix information from an address allocating device, the address allocating device assigns the first prefix information to the requesting device, but sets its access permission to the first level, meaning it can only access a limited network. After the address allocating device authenticates the address requesting device based on the authentication information in the second request message, it updates the access permission of the address requesting device from the first level to the second level, thus granting the address requesting device normal network access permissions. In other words, before authenticating the legitimacy of the address device, the address allocating device only grants the address requesting device limited network access permissions; after successful authentication, it grants the address requesting device broader network access permissions, thereby ensuring network security through permission settings.
[0029] In one specific implementation, the address allocation device configures the access permission of the address requesting device as a first permission, including: the address allocation device configures the user group corresponding to the address requesting device as a first user group, wherein the access permission of the first user group is the first permission.
[0030] In one specific implementation, the address allocation device configures the access permission of the address requesting device to a second permission, including: the address allocation device changes the user group corresponding to the address requesting device from a first user group to a second user group, wherein the access permission of the second user group is the second permission.
[0031] In this implementation, the address allocation device can locally configure user groups with different network access permissions, namely, a first user group and a second user group. Before authenticating the address requesting device, the device is configured as the first user group, allowing it to access only a limited network using the first prefix information. After successful authentication, the device is updated to the second user group, enabling it to access the network normally using the first prefix information. This enhances network security by granting different permissions.
[0032] In one specific implementation, the first response message may further include a second time-to-live (TTL), which is used to indicate the validity period of the first prefix information.
[0033] In one specific implementation, the first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
[0034] In one specific implementation, the second request message is used to request second prefix information, and the method further includes: after the address allocation device authenticates the address requesting device, the address allocation device sends a second response message to the address requesting device, the second response message including the second prefix information.
[0035] In one specific implementation, the second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
[0036] In one specific implementation, the address requesting device and the address allocating device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the address allocating device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
[0037] In one specific implementation, the address requesting device is an Ethernet-bearer Internet Protocol (IPoE) device.
[0038] In one specific implementation, the address requesting device is a client device CPE, and the address allocation device is a broadband access server (BRAS) or a DHCPv6 server.
[0039] In a fourth aspect of this application, an address prefix acquisition apparatus is provided. The apparatus includes: a receiving unit, configured to receive a first request message sent by an address requesting device, the first request message being used to request first prefix information; a sending unit, configured to send a first response message to the address requesting device, the first response message including the first prefix information and a first time-to-live (TTL), the first TTL being used to indicate the validity duration of the first prefix information; the receiving unit is further configured to receive a second request message sent by the address requesting device, the second request message including authentication information, the authentication information being used by the address allocation device to authenticate the legitimacy of the address requesting device; the sending unit is further configured to send a second response message to the address requesting device after the address requesting device has passed authentication, the second response message including a second TTL, the second TTL being used to indicate the validity duration of the first prefix information, the second TTL being greater than the first TTL.
[0040] In one specific implementation, the first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
[0041] In one specific implementation, the second request message is used to request second prefix information, and the sending unit is further used to send a third response message to the address requesting device after the address requesting device has been authenticated, the third response message including the second prefix information.
[0042] In one specific implementation, the second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
[0043] In one specific implementation, the second response message further includes third prefix information, which is used by the address requesting device to replace the first prefix information with the third prefix information, and the second time to live is used to indicate the validity period of the third prefix information.
[0044] In one specific implementation, the address requesting device and the device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
[0045] In one specific implementation, the address requesting device is an Ethernet-bearer Internet Protocol (IPoE) device.
[0046] In one specific implementation, the address requesting device is a client device (CPE), and the device is a broadband access server (BRAS) or a DHCPv6 server.
[0047] In a fifth aspect of this application, an address prefix acquisition apparatus is provided. The apparatus includes: a receiving unit, configured to receive a first request message sent by an address requesting device, the first request message being used to request first prefix information; a sending unit, configured to send a first response message to the address requesting device, the first response message including indication information used to instruct the address requesting device to send a second request message; the receiving unit is further configured to receive the second request message sent by the address requesting device, the second request message including authentication information used by the address allocation device to authenticate the legitimacy of the address requesting device; the sending unit is further configured to send a second response message to the address requesting device after the address requesting device has passed authentication, the second response message including the first prefix information.
[0048] In one specific implementation, the first response message is a router response RA message, and the indication information is carried in the extended community attribute field newly added to the RA message.
[0049] In one specific implementation, the receiving unit is further configured to receive a third request message sent by the address requesting device before the sending unit sends a second response message to the address requesting device, the third request message being used to request the first prefix information.
[0050] In one specific implementation, the first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
[0051] In one specific implementation, the second request message is used to request second prefix information, and the sending unit is further used to send a third response message to the address requesting device after the address requesting device has been authenticated, the third response message including the second prefix information.
[0052] In one specific implementation, the second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
[0053] In one specific implementation, the address requesting device and the device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
[0054] In one specific implementation, the address requesting device is an Ethernet-bearer Internet Protocol (IPoE) device.
[0055] In one specific implementation, the address request device is a client device (CPE), and the device is a broadband access server (BRAS) or a DHCPv6 server.
[0056] In a sixth aspect of this application, an address prefix acquisition apparatus is provided. The apparatus includes: a receiving unit for receiving a first request message sent by an address requesting device, the first request message being used to request first prefix information; a processing unit for configuring the access permission of the address requesting device to a first permission, the first permission representing a first access permission possessed by the address requesting device when accessing the network using the first prefix information; a sending unit for sending a first response message to the address requesting device, the first response message including the first prefix information; the receiving unit is further configured to receive a second request message sent by the address requesting device, the second request message including authentication information, the authentication information being used by the address allocation device to authenticate the legitimacy of the address requesting device; the processing unit is further configured to, after the address requesting device passes authentication, configure the access permission of the address requesting device to a second permission, the second permission representing a second access permission possessed by the address requesting device when accessing the network using the first prefix information, the second access permission being higher than the first access permission.
[0057] In one specific implementation, the processing unit is specifically configured to configure the user group corresponding to the address request device as a first user group, and the access permissions of the first user group are the first permissions.
[0058] In one specific implementation, the processing unit is specifically used to change the user group corresponding to the address requesting device from the first user group to the second user group, and the access permissions of the second user group are the second permissions.
[0059] In one specific implementation, the first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
[0060] In one specific implementation, the second request message is used to request second prefix information, and the sending unit is further used to send a second response message to the address requesting device after the address requesting device has been authenticated, the second response message including the second prefix information.
[0061] In one specific implementation, the second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
[0062] In one specific implementation, the address requesting device and the device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
[0063] In one specific implementation, the address requesting device is an Ethernet-bearer Internet Protocol (IPoE) device.
[0064] In one specific implementation, the address request device is a client device (CPE), and the device is a broadband access server (BRAS) or a DHCPv6 server.
[0065] In a seventh aspect of this application, a communication device is provided, the device comprising: a processor and a memory; the memory for storing instructions or computer programs; the processor for executing the instructions or computer programs in the memory to cause the communication device to perform the methods described in the first aspect, the second aspect, or the third aspect.
[0066] In an eighth aspect of this application, a computer-readable storage medium is provided, including instructions that, when executed on a computer, cause the computer to perform the methods described in the first, second, or third aspects above. Attached Figure Description
[0067] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0068] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application;
[0069] Figure 2 A flowchart of an address prefix acquisition method provided in this application embodiment;
[0070] Figure 3a A schematic diagram of an RA message structure provided in an embodiment of this application;
[0071] Figure 3b This is a schematic diagram of an extended community attribute structure provided in an embodiment of this application;
[0072] Figure 4 Flowchart of another address prefix acquisition method provided in this application embodiment;
[0073] Figure 5 A flowchart illustrating another address prefix acquisition method provided in this application embodiment;
[0074] Figure 6 A structural diagram of an address prefix acquisition device provided in an embodiment of this application;
[0075] Figure 7 Another address prefix acquisition device structure diagram provided in the embodiments of this application;
[0076] Figure 8 A structural diagram of another address prefix acquisition device provided in the embodiments of this application;
[0077] Figure 9 A structural diagram of a communication device provided in an embodiment of this application;
[0078] Figure 10 This is another structural diagram of a communication device provided in an embodiment of this application. Detailed Implementation
[0079] To enable those skilled in the art to better understand the solutions in this invention, the technical solutions in the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this invention, and not all embodiments.
[0080] To facilitate understanding of the specific implementation of the embodiments of this application, the technologies and network elements involved in the embodiments of this application will be described below.
[0081] In an IPv6 network, IPoE terminal devices can obtain IPv6 addresses in two ways: stateless address allocation and stateful address allocation. In stateless address allocation, the terminal device and router exchange Router Solicitation (RS) and Router Advertisement (RA) messages via the ND protocol to obtain prefix information from the RA messages. The terminal device then obtains an IPv6 address based on the prefix information and its own interface identifier. Stateful address allocation involves the terminal device and router exchanging DHCPv6 messages using the DHCPv6 protocol. These DHCPv6 messages can include authentication information, which the router uses to authenticate the terminal device's legitimacy. Upon successful authentication, the router assigns the terminal device an IPv6 address / prefix and other network configuration parameters. It's important to note that stateful and stateless address allocation are not independent; they can coexist. That is, a terminal device can have both an IPv6 address generated via RA and an IPv6 address obtained via DHCPv6.
[0082] The stateless address allocation and stateful address allocation processes are as follows:
[0083] 1) After startup, the terminal device uses a local link prefix, such as FE80::0, and a local interface identifier to generate a local link address. The local interface identifier is an identifier automatically generated by the terminal device according to preset rules, and the generated local interface identifier may be the same as the interface identifier of other terminal devices.
[0084] 2) The terminal device performs duplicate address detection (DAD) on the local link address, i.e., it sends a neighbor solicitation (NS) message in the broadcast domain. If the terminal device can receive a neighbor advertisement (NA) message sent by a neighbor device, it indicates a local link address conflict. The terminal device needs to regenerate the interface identifier and generate a local link address based on the interface identifier and the local link prefix, and then perform DAD detection again until the local link addresses are no longer conflicting.
[0085] 3) The terminal device sends a router solicitation (RS) message to the router. This RS message is used to request prefix information. The source media access control (MAC) address in this RS message is the local link address.
[0086] 4) The router sends a router advertisement (RA) message to the terminal device based on the RS message. The RA message may carry prefix information.
[0087] 5) After receiving the RA message, if the RA message specifies the use of a stateless method to obtain an IPv6 address, the terminal device generates a global unicast address using the prefix information and local interface identifier in the RA message. After obtaining the global unicast address, the terminal device performs DAD (Dual Adaptive Detection) on the global unicast address to ensure that the global unicast address is unique on the link.
[0088] 6) If the RA message specifies that a stateful method should be used to obtain an IPv6 address, the terminal device sends a DHCPv6 request message to the router.
[0089] 7) The router sends a DHCPv6 response message to the terminal device. This response message may include the IPv6 address, prefix, and other configuration information.
[0090] In practical applications, routers can configure the flag field of the RA (Real Estate Address) message to instruct terminal devices to obtain IPv6 addresses either in a stateless or stateful manner. Specifically, the RA includes an autonomous flag (A) field, a managed flag (M) field, and other flags (O) fields. The A flag field indicates whether stateless IP is configured. When the A flag field is on (corresponding bit is 1), it means the terminal device should automatically generate an IPv6 address based on the prefix in the RA message (the terminal device ensures the generated IPv6 address is usable through DAD); when the A flag field is off (corresponding bit is 0), it means the terminal device should not automatically generate an IPv6 address based on the prefix in the RA message. The M flag field indicates whether stateful IP is configured; this field is a global parameter in the RA message. When the M flag field is on (corresponding bit is 1), it indicates that the terminal device has started stateful address allocation traffic after completing the stateless address allocation process, meaning the terminal device can obtain an IPv6 address via the DHCPv6 protocol. When the M flag field is off (corresponding bit is 0), it indicates that the terminal device cannot obtain an IPv6 address via the DHCPv6 protocol. The O flag field indicates whether to obtain parameters other than an IPv6 address via the DHCPv6 protocol; this field is a global parameter in the RA message. It should be noted that this field is only read when the M flag field is off.
[0091] DHCPv6 prefix delegation (DHCPv6-PD) is a prefix allocation mechanism standardized in RFC 3633. With DHCPv6-PD, terminal devices do not need to specify IPv6 address prefixes for user-side hosts; they only need to submit a prefix allocation request to the router, which can then allocate address prefixes to the terminal device. After obtaining the address prefix, the terminal device allocates address prefixes to user-side hosts based on this prefix, thereby enabling the hosts to generate IPv6 addresses according to the allocated address prefix.
[0092] In some application scenarios, terminal devices need to access the network via ND+PD. The traditional ND+PD method is as follows:
[0093] 1) When the terminal device interface starts, it generates a valid local link address based on the local link prefix and interface identifier.
[0094] 2) The terminal device sends an RS message, which includes the local link address and is used to request prefix information.
[0095] 3) After receiving the RS message, the router sends an RA message to the terminal device. The RA message includes prefix information and time to live.
[0096] 4) The terminal device generates an IPv6 address based on the prefix information in the RA message.
[0097] 5) The terminal device sends a DHCPv6 request message to the router.
[0098] 6) The router sends a DHCPv6 response message to the terminal device. This response message includes the IPv6 address and prefix information.
[0099] As the above process demonstrates, when a terminal device obtains an IPv6 address in a stateless manner, the RS message cannot carry valid authentication information, causing the router to directly assign prefix information to the unauthenticated terminal device. This allows the unauthenticated terminal device to directly access the network using the generated IPv6 address, posing a security risk.
[0100] Based on this, this application provides an address prefix acquisition method. When an address requesting device obtains first prefix information via the ND method, an address allocation device can allocate the first prefix information to the address requesting device. However, the lifetime of this first prefix information is temporary, meaning the address requesting device can obtain a short-lived valid IPv6 address through the first prefix information. After the address requesting device is authenticated via the PD method, the address allocation device allocates a normal lifetime to the address requesting device. Alternatively, the address allocation device may temporarily not respond to the address requesting device's request for the first prefix information. After the address allocation device authenticates the address requesting device via the PD method, it sends the first prefix information to the address requesting device, enabling the address requesting device to obtain a valid IPv6 address. Alternatively, the address allocation device allocates the first prefix information to the address requesting device and simultaneously configures the address requesting device's access permissions to a first access permission, meaning the IPv6 address generated by the address requesting device using the first prefix information can only access a limited network. After the address allocation device authenticates the address requesting device via the PD method, it configures the address requesting device's access permissions to a second access permission, thereby enabling the address requesting device to access the network normally using the IPv6 address generated by the first prefix information.
[0101] See Figure 1 The figure is a schematic diagram of an application scenario provided by an embodiment of this application. The network system is illustrated by taking five network devices as an example, namely a personal computer (PC), customer-premises equipment (CPE), a broadband remote access server (BRAS), an authentication, authorization, accounting (AAA) server, and a DHCPv6 server.
[0102] In this context, the address requesting device can be a CPE device, and the address allocation device can be a BRAS device. When the BRAS device has authentication capabilities, it can perform local authentication upon receiving a message containing authentication information from the CPE device. When the BRAS device does not have authentication capabilities, it can parse the authentication information sent by the CPE device and send it to the AAA server to obtain the authentication result.
[0103] Furthermore, when a CPE device requests an IPv6 address prefix via the ND protocol, the BRAS device can allocate prefix information for the CPE device from its locally stored prefix pool. When a CPE device requests an IPv6 address prefix via the DHCPv6-PD protocol, if the BRAS device has address allocation capabilities, it can allocate prefix information for the CPE device from its locally stored prefix pool upon receiving the request message from the CPE device; if the BRAS device does not have address allocation capabilities, it will send a request message to the DHCPv6 server upon receiving the request message from the CPE device, so that the DHCPv6 server can allocate prefix information for the CPE device.
[0104] It should be noted that, Figure 1 The application scenarios shown are only illustrated as one possible embodiment and do not constitute a limitation on the embodiments of this application. For example, the address request device can be a set-top box or other network device with Internet access requirements.
[0105] To facilitate understanding of the specific implementation of the embodiments of this application, the following description will be provided in conjunction with the accompanying drawings.
[0106] See Figure 2 The figure is a flowchart of an address prefix acquisition method provided in an embodiment of this application, as shown below. Figure 2 As shown, the method may include:
[0107] S201: The address request device generates the first request message.
[0108] In this embodiment, after the address requesting device starts up, it can generate a local link address using the local link prefix and interface identifier. If the local link address does not conflict, a first request message can be generated. This first request message is used to request first prefix information. Specifically, the address requesting device uses the ND protocol to generate the first request message, which can be an RS message. The address requesting device can be an IPoE device.
[0109] When multiple address requesting devices exist in a network system, the address allocation device can identify the address requesting device using a device unique identifier (DUID). Specifically, each address requesting device corresponds to a DUID to uniquely identify itself. In this case, the first request message may include the device unique identifier.
[0110] S202: The address requesting device sends a first request message to the address allocating device.
[0111] S203: The address allocation device generates a first response message based on the first request message.
[0112] After receiving the first request message, the address allocation device parses the message to determine that it requests first prefix information. The device then allocates the first prefix information to the address requesting device and generates a first response message including the first prefix information. Furthermore, the first response message may include a first time-to-live (TTL), which is a short TTL indicating the validity period of the first prefix information. For example, a first TTL of 50 seconds ensures that the address requesting device can utilize the allocated first prefix information for subsequent interactions.
[0113] The first response message can be a RA message, with the first time-to-live (TTL) carrying the valid lifetime within the RA message. The RA message structure is as follows: Figure 3a As shown, the RA message may include a type field, a length field, a prefix length field, a time-to-live (TTL) field, a priority time field, a reserved field, and a prefix field. The prefix field carries first prefix information, the TTL field indicates the validity period of the first prefix information, and the priority time indicates the duration for which the IPv6 address generated from the stateless address is in a priority state. The address requesting device can be a client device (CPE), and the address allocation device can be a BRAS or a DHCPv6 server.
[0114] S204: The address allocation device sends a first response message to the address requesting device.
[0115] S205: The address requesting device generates a second request message based on the first response message.
[0116] In this embodiment, after the address requesting device receives the first response message sent by the address allocating device, it can obtain the first prefix information by parsing the first response message, and generate a first IPv6 address based on the first prefix information and the interface identifier. The first IPv6 address is the address of the address requesting device itself. Simultaneously, the address requesting device generates a second request message, which includes authentication information used by the address allocating device to authenticate the legitimacy of the address requesting device. Specifically, the address requesting device can generate the second request message according to the DHCPv6 protocol. This second request message is a Solicit message, and the authentication information is carried in the option field of the Solicit message.
[0117] S206: The address requesting device sends a second request message to the address allocating device.
[0118] S207: The address allocation device authenticates the address requesting device based on the second request message.
[0119] The second request message includes authentication information. Upon receiving the second request message, the address allocation device parses it to obtain the authentication information, and then uses this information to authenticate the legitimacy of the address requesting device. Specifically, the address allocation device can perform legitimacy authentication locally, or it can send an authentication request to the AAA server based on the authentication information, so that the AAA server can authenticate the legitimacy of the address requesting device and obtain the authentication result.
[0120] S208: After successful authentication, the address allocation device sends a second response message to the address requesting device.
[0121] After the address allocation device successfully authenticates the address requesting device, it can send a second response message to the address requesting device. This second response message includes a second time-to-live (TTL), which indicates the validity period of the first prefix information. The second TTL is longer than the first TTL. That is, after successful authentication, the address allocation device updates the TTL of the first prefix in the address requesting device to the normal TTL. The second response message is an RA (Real Estate Information) message.
[0122] In some implementations, the second response message may also include third prefix information, the time-to-live (TTL) of which is the second TTL. That is, the address allocation device reallocates new prefix information to the address requesting device, so that the address requesting device can generate a new IPv6 address based on the third prefix information and the interface identifier, and use the new IPv6 address to access the network. Simultaneously, the address requesting device releases the first prefix information and the first IPv6 address.
[0123] S209: After successful authentication, the address allocation device sends a third response message to the address requesting device.
[0124] The second request message can also be used to request second prefix information. After the address requesting device is authenticated, the address allocation device sends a third response message to the address requesting device, which includes the second prefix information. After obtaining the second prefix information, the address requesting device can assign address prefixes to the connected hosts based on the second prefix information, thus enabling each host to obtain an IPv6 address based on the assigned address prefix. Alternatively, the address requesting device can generate a second IPv6 address based on the interface identifier corresponding to each host and the second prefix information, and then assign IPv6 addresses to the corresponding hosts. The third response message can be a Reply message from the DHCPv6 protocol.
[0125] According to the technical solution provided in this embodiment, when an address requesting device requests first prefix information, the address allocation device first allocates temporarily valid first prefix information to the address requesting device before performing legitimacy authentication on the address requesting device. After the address allocation device successfully authenticates the address requesting device through a second request message including authentication information sent by the address requesting device, it then allocates a second lifetime to the address requesting device, which is the normal lifetime.
[0126] See Figure 4 The figure is a flowchart of another address prefix acquisition method provided in an embodiment of this application, as shown below. Figure 4 As shown, the method may include:
[0127] S401: The address request device generates the first request message.
[0128] In this embodiment, after the address requesting device starts up, it can generate a local link address using the local link address and interface identifier. If the local link address does not conflict, a first request message is generated to request the first prefix information. Specifically, the address requesting device generates the first request message through the ND protocol, and the first request message is an RS message.
[0129] For a detailed description of the implementation of S401, please refer to the relevant description of S201. This embodiment will not repeat it here.
[0130] S402: The address requesting device sends a first request message to the address allocating device.
[0131] S403: The address allocation device generates a first response message based on the first request message.
[0132] In this embodiment, after receiving the first request message, the address allocation device parses the message to determine that the requesting device requests first prefix information. Since the first request message does not carry authentication information, the address allocation device does not allocate the first prefix information for the requesting device. Instead, it instructs the requesting device to send a second request message first through the indication information in the first response message. That is, when the requesting device requests the first prefix information via the ND protocol, the address allocation device does not allocate the first prefix information immediately. Instead, it instructs the requesting device to send a second request message including authentication via the PD protocol. The address allocation device can then authenticate the legitimacy of the requesting device through the authentication information in the second request message. The first response message can be an RA message, and the indication information can be carried in a newly added extended community attribute field of the RA message. This newly added extended community attribute field can occupy a reserved field in the RA message. This extended community attribute field can be defined using a type-length-value (TLV) field. The Type field indicates the type (indicating message), the Length field indicates the number of bytes included in the Value field (e.g., 8 bytes), and the Value field carries the indicating message. Figure 3b As shown. The address requesting device can be an IPoE device. Specifically, the address requesting device can be a client device (CPE), and the address allocation device can be a BRAS or a DHCPv6 server.
[0133] S404: The address allocation device sends a first response message to the address requesting device.
[0134] S405: The address request device generates a second request message based on the first response message.
[0135] After receiving the first response message, the address requesting device parses the first response message to obtain indication information. Based on this indication information, it generates a second request message. This second request message includes authentication information, which is used by the address allocation device to authenticate the legitimacy of the address requesting device. Specifically, the address requesting device generates the second request message according to the DHCPv6 protocol. This second request message is a Solicit message, and the authentication information is carried in the option field of the Solicit message.
[0136] For details on the specific implementation of S405, please refer to the relevant description of S205. This embodiment will not repeat it here.
[0137] S406: The address requesting device sends a second request message to the address allocating device.
[0138] S407: The address allocation device authenticates the address requesting device based on the second request message.
[0139] For details on the implementation of S407, please refer to the relevant description of S207. This embodiment will not repeat them here.
[0140] S408: After successful authentication, the address allocation device sends a second response message to the address requesting device.
[0141] After the address requesting device is successfully authenticated, indicating its legitimacy, the address allocation device assigns first prefix information to the address requesting device and sends a second response message including the first prefix information to the address requesting device. The address requesting device can generate a first IPv6 address based on the first prefix information, which is its own corresponding IPv6 address. Optionally, the second response message also includes a second time-to-live (TTL), which indicates the validity period of the first prefix information. In other words, the address allocation device assigns first prefix information to the address requesting device only after successful authentication, thereby improving network security. The second response message can be an RA (Range Access Message) message.
[0142] In one specific implementation, before sending a second response message to the address requesting device, the address allocation device resends a request message, namely a third request message, to the address allocation device. This third request message is used to request the first prefix information. The third request message can be an RS message.
[0143] S409: The address allocation device sends a third response message to the address requesting device.
[0144] The second request message can be used to request second prefix information. After the address requesting device is authenticated, indicating its legitimacy, the address allocation device can send a third response message to the address requesting device. This third response message includes the second prefix information. After obtaining this second prefix information, the address requesting device can allocate address prefixes to the user hosts it connects to, enabling each host to generate an IPv6 address based on its assigned address prefix. Alternatively, the address requesting device can generate a second IPv6 address based on the interface identifier corresponding to each host and the second prefix information, and then allocate IPv6 addresses to its corresponding hosts. The third response message can be a Reply message from the DHCPv6 protocol.
[0145] According to the technical solution provided in this embodiment, after receiving a first request message from an address requesting device requesting first prefix information, the address allocation device does not send a first response message including the first prefix information to the address requesting device. Instead, it sends a first response message including indication information. This indication information is used to instruct the address requesting device to send a second request message, so that the address allocation device can authenticate the legitimacy of the address requesting device based on the authentication information carried in the second request message. After successful authentication, the address allocation device allocates the first prefix information to the address requesting device, thereby enabling the address requesting device to generate an IPv6 address based on the first prefix information. This allows the address requesting device to access the network using the IPv6 address, thereby improving network security.
[0146] See Figure 5 This figure is a flowchart of another address prefix acquisition method provided in an embodiment of this application, as shown below. Figure 5 As shown, the method may include:
[0147] S501: The address request device generates the first request message.
[0148] In this embodiment, after the address requesting device starts up, it can generate a local link address using the local link prefix and interface identifier. If the local link address does not conflict, a first request message can be generated. This first request message is used to request first prefix information. Specifically, the address requesting device uses the ND protocol to generate the first request message, which can be an RS message. The address requesting device can be an IPoE device.
[0149] For details on the specific implementation of S501, please refer to the relevant descriptions of S201 and S401, which will not be repeated here in this embodiment.
[0150] S502: The address requesting device sends a first request message to the address allocating device.
[0151] S503: The address allocation device configures the access permission of the address requesting device as the first permission.
[0152] In this embodiment, when the address allocation device receives the first request message, it finds through parsing that the first request message does not include authentication information that can be used for legitimacy authentication. Then, the address allocation device sets the access permission of the address requesting device to the first permission. The first permission is used to represent the first access permission that the address requesting device has when accessing the network using the first prefix information. For example, the first permission means that the address requesting device can access the limited network using the allocated prefix information.
[0153] Specifically, the address allocation device can locally configure two user groups, each with different access permissions. Network devices in one user group can only access the limited network, while network devices in the other user group can access the network normally. When the address allocation device has not yet verified the legitimacy of the address requesting device, it adds the address requesting device to the user group that accesses the limited network. For example, if the address allocation device configures two user groups, user-group1 and user-group2, where user-group1 can only access the limited network and user-group2 can access the network normally, then the address allocation device sets the user group corresponding to the address requesting device to user-group1, i.e., adds the address requesting device to user-group1. Here, the address requesting device is the client device (CPE), and the address allocation device is the Broadband Access Server (BRAS) or DHCPv6 server.
[0154] S504: The address allocation device generates the first response message.
[0155] After receiving the first request message, the address allocation device parses the message to determine that the address requesting device requests first prefix information. If so, it allocates the first prefix information to the address requesting device and generates a first response message including the first prefix information. Optionally, the first response message may also include a second time-to-live (TTL), which represents the validity period of the first prefix information, indicating that the TTL of the first prefix information is a normal TTL. The first response message can be an RA (Range Access Message) message.
[0156] S505: The address allocation device sends a first response message to the address requesting device.
[0157] The address allocation device sends a first response message, including first prefix information, to the address requesting device, enabling the address requesting device to generate a first IPv6 address based on the first prefix information. This first IPv6 address is the address of the address requesting device itself, allowing the address requesting device to use this IPv6 address for limited network access. The first response message can be an RA message.
[0158] It should be noted that the execution order of S503-S505 is not limited to the above process. In specific implementation, the address allocation device can execute S504 and S505 first, and then execute S503; or, the address allocation device can execute S503-S505 simultaneously.
[0159] S506: The address requesting device generates a second request message based on the first response message.
[0160] The second request message includes authentication information, which is used by the address allocation device to authenticate the legitimacy of the address requesting device. For a detailed implementation of S506, please refer to the descriptions of S205 or S405; these details will not be repeated here. The second request message can be a Solicit message from the DHCPv6 protocol.
[0161] S507: The address requesting device sends a second request message to the address allocating device.
[0162] S508: The address allocation device authenticates the address requesting device based on the second request message.
[0163] Upon receiving a second request message, the address allocation device parses the message to obtain authentication information, and then uses this information to authenticate the legitimacy of the address requesting device. Specifically, the address allocation device can perform legitimacy authentication locally, or it can send an authentication request to the AAA server based on the authentication information, allowing the AAA server to authenticate the legitimacy of the address requesting device and obtain the authentication result.
[0164] S509: After successful authentication, the address allocation device will configure the access permissions of the address requesting device to the second permission.
[0165] After the address requesting device is successfully authenticated, indicating that it is a legitimate device, the address allocation device configures its access permissions to the second level. This second level of access permission represents the second level of access the address requesting device has when accessing the network using the first prefix information, and it is superior to the first level of access permission. For example, the second level of access permission means that the address requesting device can access the network normally. Specifically, the address allocation device changes the user group corresponding to the address requesting device from the first user group to the second user group, and the access permission of the second user group is the second level of access permission. In other words, the address allocation device moves the address requesting device from the first user group to the second user group, thereby changing the access permissions of the address requesting device.
[0166] S510: The address allocation device sends a second response message to the address requesting device.
[0167] The second request message can also be used to request second prefix information. After the address requesting device is authenticated, the address allocation device sends a second response message to the address requesting device, which includes the second prefix information. After obtaining the second prefix information, the address requesting device can allocate an address prefix to the connected hosts based on the second prefix information, thereby enabling each host to obtain an IPv6 address based on the allocated address prefix. Alternatively, the address requesting device can generate a second IPv6 address based on the interface identifier corresponding to each host and the second prefix information, and allocate an IPv6 address to its corresponding hosts. The second response message can be a Reply message from the DHCPv6 protocol.
[0168] The technical solution provided in this embodiment allows the address allocation device to assign first prefix information to an address requesting device when the address requesting device requests such information. However, the address allocation device sets the access permission of the requesting device to a first-level permission, meaning it can only access a limited network. After the address allocation device authenticates the address requesting device based on the authentication information in the second request message, it updates the access permission of the requesting device from the first-level permission to the second-level permission, thus granting the address requesting device normal network access. In other words, before authenticating the legitimacy of the address device, the address allocation device only grants the requesting device limited network access. Once authentication is successful, it grants the requesting device a larger network access permission, thereby ensuring network security through permission settings.
[0169] Based on the above method embodiments, this application also provides an address prefix acquisition device and apparatus, which will be described below in conjunction with the accompanying drawings.
[0170] See Figure 6 This figure is a structural diagram of an address prefix acquisition device provided in an embodiment of this application. This device 600 can be applied to an address allocation device to perform... Figure 2 The address allocation device in the illustrated embodiment may include a receiving unit 601 and a sending unit 602.
[0171] The receiving unit 601 is configured to receive a first request message sent by the address requesting device, wherein the first request message is used to request first prefix information. For details on the implementation of the receiving unit 601, please refer to [link to relevant documentation]. Figure 2 Detailed description of S202 in the illustrated embodiment.
[0172] Sending unit 602 is configured to send a first response message to the address requesting device. The first response message includes the first prefix information and a first time-to-live (TTL), wherein the first TTL indicates the validity period of the first prefix information. For implementation details of sending unit 602, please refer to [link to relevant documentation]. Figure 2Detailed description of S203 and S204 in the illustrated embodiment.
[0173] The receiving unit 601 is further configured to receive a second request message sent by the address requesting device, the second request message including authentication information, which is used by the address allocation device to authenticate the legitimacy of the address requesting device. For an implementation of the receiving unit 601, please refer to [link to relevant documentation]. Figure 2 Detailed description of S205 and S206 in the illustrated embodiment.
[0174] The sending unit 602 is further configured to send a second response message to the address requesting device after the address requesting device has passed authentication. The second response message includes a second time-to-live (TTL), which indicates the validity period of the first prefix information. The second TTL is longer than the first TTL. For details on the implementation of the sending unit 602, please refer to [link to relevant documentation]. Figure 2 Detailed description of S208 in the illustrated embodiment.
[0175] In one possible implementation, the first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
[0176] In one possible implementation, the second request message is used to request second prefix information, and the sending unit 602 is further configured to send a third response message to the address requesting device after the address requesting device has been authenticated, the third response message including the second prefix information. For details on the implementation of the sending unit 602 sending the third response message, please refer to [link to relevant documentation]. Figure 2 Detailed description of S209 in the illustrated embodiment.
[0177] In one possible implementation, the second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
[0178] In one possible implementation, the second response message further includes third prefix information, which is used by the address requesting device to replace the first prefix information with the third prefix information, and the second time-to-live is used to indicate the validity period of the third prefix information.
[0179] In one possible implementation, the address requesting device and the device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
[0180] In one possible implementation, the address requesting device is an Ethernet-bearer Internet Protocol (IPoE) device.
[0181] In one possible implementation, the address requesting device is a client device (CPE), and the device is a broadband access server (BRAS) or a DHCPv6 server.
[0182] For details on the specific executable functions and implementation of device 600, please refer to [link / reference]. Figure 2 The corresponding descriptions of the address allocation device in the illustrated embodiments will not be repeated here.
[0183] See Figure 7 The figure shows another address prefix acquisition device provided in an embodiment of this application. Device 700 can be applied to address allocation devices to perform... Figure 4 The address allocation device in the illustrated embodiment may include a receiving unit 701 and a sending unit 702.
[0184] The receiving unit 701 is configured to receive a first request message sent by the address requesting device, wherein the first request message is used to request first prefix information. For details on the implementation of the receiving unit 701 receiving the first request message, please refer to [link to relevant documentation]. Figure 4 Detailed description of S401 and S402 in the illustrated embodiment.
[0185] Sending unit 702 is configured to send a first response message to the address requesting device. The first response message includes indication information, which instructs the address requesting device to send a second request message. For details on the implementation of sending unit 702 sending the first response message, please refer to [link to relevant documentation]. Figure 4 Detailed description of S403 and S404 in the illustrated embodiment.
[0186] The receiving unit 701 is further configured to receive the second request message sent by the address requesting device, the second request message including authentication information, which is used by the address allocation device to authenticate the legitimacy of the address requesting device. For details on the implementation of the receiving unit 702 receiving the second request message, please refer to [link to relevant documentation]. Figure 4 Detailed description of S405 and S406 in the illustrated embodiment.
[0187] The sending unit 702 is further configured to send a second response message to the address requesting device after the address requesting device has passed authentication, the second response message including the first prefix information. For a detailed description of how the sending unit 702 sends the second response message, please refer to S408.
[0188] In one possible implementation, the first response message is a router response RA message, and the indication information is carried in the extended community attribute field newly added to the RA message.
[0189] In one possible implementation, the receiving unit 701 is further configured to receive a third request message sent by the address requesting device before the sending unit sends the second response message to the address requesting device, the third request message being used to request the first prefix information.
[0190] In one possible implementation, the first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
[0191] In one possible implementation, the second request message is used to request second prefix information, and the sending unit 702 is further configured to send a third response message to the address requesting device after successful authentication, the third response message including the second prefix information. For a detailed description of the implementation of the sending unit 702 sending the third response message, please refer to S409.
[0192] In one possible implementation, the second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
[0193] In one possible implementation, the address requesting device and the device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
[0194] In one possible implementation, the address requesting device is an Ethernet-bearer Internet Protocol (IPoE) device.
[0195] In one possible implementation, the address requesting device is a client device (CPE), and the apparatus is a broadband access server (BRAS) or a DHCPv6 server.
[0196] For details on the specific executable functions and implementation of device 700, please refer to [link / reference]. Figure 4 The corresponding descriptions of the address allocation device in the illustrated embodiments will not be repeated here.
[0197] See Figure 8 This figure is a structural diagram of an address prefix acquisition device provided in an embodiment of this application. This device 800 can be applied to an address allocation device to perform... Figure 5The address allocation device in the illustrated embodiment includes a receiving unit 801, a processing unit 802, and a sending unit 803.
[0198] The receiving unit 801 is configured to receive a first request message sent by the address requesting device, wherein the first request message is used to request first prefix information. For details on the implementation of the receiving unit 801 receiving the first request message, please refer to the detailed description of S501 or S502.
[0199] Processing unit 802 is configured to set the access permission of the address requesting device to a first permission, wherein the first permission represents the first access permission that the address requesting device possesses when accessing the network using the first prefix information. For a detailed description of the implementation of processing unit 802, please refer to S503.
[0200] The sending unit 803 is configured to send a first response message to the address requesting device, the first response message including the first prefix information. For a detailed description of the implementation of the sending unit 803, please refer to S504 and S505.
[0201] The receiving unit 801 is further configured to receive a second request message sent by the address requesting device, the second request message including authentication information, which is used by the address allocation device to authenticate the legitimacy of the address requesting device. For a detailed description of the implementation of the receiving unit 801, please refer to S506 and S507.
[0202] The processing unit 802 is further configured to, after the address requesting device has been authenticated, configure the access permission of the address requesting device to a second permission, wherein the second permission represents the second access permission that the address requesting device possesses when accessing the network using the first prefix information, and the second access permission is superior to the first access permission. For a detailed description of the implementation of the processing unit 802, please refer to S508 and S509.
[0203] In one possible implementation, the processing unit 802 is specifically configured to configure the user group corresponding to the address requesting device as a first user group, and the access permissions of the first user group are the first permissions. For a detailed description of the implementation of the processing unit 802, please refer to S503.
[0204] In one possible implementation, the processing unit 802 is specifically configured to change the user group corresponding to the address requesting device from the first user group to a second user group, and the access permissions of the second user group are the second permissions. For a detailed description of the implementation of the processing unit 802, please refer to S509.
[0205] In one possible implementation, the first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
[0206] In one possible implementation, the second request message is used to request second prefix information, and the sending unit 803 is further used to send a second response message to the address requesting device after the address requesting device has been authenticated, the second response message including the second prefix information.
[0207] In one possible implementation, the second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
[0208] In one possible implementation, the address requesting device and the device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
[0209] In one possible implementation, the address requesting device is an Ethernet-bearer Internet Protocol (IPoE) device.
[0210] In one possible implementation, the address requesting device is a client device (CPE), and the apparatus is a broadband access server (BRAS) or a DHCPv6 server.
[0211] For details on the specific executable functions and implementation of device 800, please refer to [link / reference]. Figure 5 The corresponding descriptions of the address allocation device in the illustrated embodiments will not be repeated here.
[0212] Figure 9 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application. The communication device may be, for example, […]. Figure 2 The address request device and address allocation device in the illustrated embodiment may also be... Figure 6 Device 600 in the illustrated embodiment Figure 7 The device implementation of apparatus 700 in the illustrated embodiment, Figure 8 Device 800 in the illustrated embodiment.
[0213] Please see Figure 9 As shown, the communication device 900 includes at least a processor 910. The communication device 900 may also include a communication interface 920 and a memory 930. The number of processors 910 in the communication device 900 can be one or more. Figure 9Taking a processor as an example. In this embodiment, the processor 910, communication interface 920, and memory 930 can be connected via a bus system or other means. Figure 9 Taking the connection between China and Israel via the 940 bus system as an example.
[0214] Processor 910 may be a CPU, an NP, or a combination of a CPU and an NP. Processor 910 may further include hardware chips. These hardware chips may be application-specific integrated circuits (ASICs), programmable logic devices (PLDs), or combinations thereof. The PLDs may be complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), generic array logic (GALs), or any combination thereof.
[0215] When the communication device is an address allocation device, the processor 910 can perform functions such as verifying the legitimacy of the address requesting device as described in the above method examples. When the communication device is an address requesting device, the processor 910 can perform functions such as generating request messages as described in the above method embodiments.
[0216] The communication interface 920 is used to receive and send messages. Specifically, the communication interface 920 may include a receiving interface and a sending interface. The receiving interface is used to receive messages, and the sending interface is used to send messages. There may be one or more communication interfaces 920.
[0217] The memory 930 may include volatile memory, such as random-access memory (RAM); the memory 930 may also include non-volatile memory, such as flash memory, hard disk drive (HDD), or solid-state drive (SSD); the memory 930 may also include a combination of the above types of memory.
[0218] Optionally, the memory 930 stores an operating system and programs, executable modules, or data structures, or subsets thereof, or extended sets thereof. The programs may include various operation instructions for implementing various operations. The operating system may include various system programs for implementing various basic services and handling hardware-based tasks. The processor 910 can read the programs in the memory 930 to implement the address prefix acquisition method provided in this embodiment.
[0219] The memory 930 can be a storage device in the communication device 900, or it can be a storage device independent of the communication device 900.
[0220] The bus system 940 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus system 940 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 9 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0221] Figure 10 This is a schematic diagram of another communication device 1000 provided in this application embodiment. The communication device 1000 can be configured as the address request device and address allocation device in the foregoing embodiments, or it can also be... Figure 6 Device 600 in the illustrated embodiment Figure 7 Device 700 in the illustrated embodiment Figure 8 The device implementation of apparatus 800 in the illustrated embodiment.
[0222] The communication equipment 1000 includes: a main control board 1010 and an interface board 1030.
[0223] The main control board 1010, also known as the main processing unit (MPU) or route processor card, controls and manages the various components in the network device 1000, including route calculation, device management, device maintenance, and protocol processing functions. The main control board 1010 includes a central processing unit 1011 and a memory 1012.
[0224] Interface board 1030 is also known as a line processing unit (LPU), linecard, or service board. Interface board 1030 provides various service interfaces and implements packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces, POS (Packet over SONET / SDH) interfaces, etc., with Ethernet interfaces including, for example, Flexible Ethernet Clients (FlexE Clients). Interface board 1030 includes: a central processing unit 1031, a network processor 1032, a forwarding table entry memory 1034, and a physical interface card (PIC) 1033.
[0225] The central processing unit 1031 on the interface board 1030 is used to control and manage the interface board 1030 and communicate with the central processing unit 1011 on the main control board 1010.
[0226] The network processor 1032 is used to implement packet forwarding processing. The network processor 1032 can be in the form of a forwarding chip. Specifically, uplink packet processing includes: packet ingress interface processing, forwarding table lookup; downlink packet processing includes: forwarding table lookup, etc.
[0227] The physical interface card 1033 is used to implement physical layer interfacing functions. Raw traffic enters the interface board 1030 through this card, and processed packets are sent out from the physical interface card 1033. The physical interface card 1033 includes at least one physical interface, also called a physical port. The physical interface card 1033 corresponds to the FlexE physical interface 204 in the system architecture. The physical interface card 1033, also called a daughter card, can be installed on the interface board 1030. It is responsible for converting photoelectric signals into packets, performing validity checks on the packets, and forwarding them to the network processor 1032 for processing. In some embodiments, the central processing unit 1031 of the interface board 1003 can also perform the functions of the network processor 1032, such as implementing software forwarding based on a general-purpose CPU, thus eliminating the need for the network processor 1032 in the physical interface card 1033.
[0228] Optionally, the communication device 1000 includes multiple interface boards. For example, the communication device 1000 also includes an interface board 1040, which includes a central processing unit 1041, a network processor 1042, a forwarding table entry memory 1044, and a physical interface card 1043.
[0229] Optionally, the communication device 1000 also includes a switching fabric board 1020. The switching fabric board 1020 can also be referred to as a switch fabric unit (SFU). In cases where the network device has multiple interface boards 1030, the switching fabric board 1020 is used to complete data exchange between the interface boards. For example, interface boards 1030 and 1040 can communicate via the switching fabric board 1020.
[0230] The main control board 1010 and the interface board 1030 are coupled. For example, the main control board 1010, interface boards 1030 and 1040, and the switching network board 1020 communicate with each other via a system bus connected to the system backplane. In one possible implementation, an inter-process communication (IPC) channel is established between the main control board 1010 and the interface board 1030, and the main control board 1010 and the interface board 1030 communicate with each other through the IPC channel.
[0231] Logically, the communication device 1000 includes a control plane and a forwarding plane. The control plane includes a main control board 1010 and a central processing unit 1031, while the forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 1034, a physical interface card 1033, and a network processor 1032. The control plane performs functions such as router operation, generating forwarding tables, processing signaling and protocol messages, and configuring and maintaining the device's status. The control plane distributes the generated forwarding table to the forwarding plane. In the forwarding plane, the network processor 1032 uses the forwarding table distributed by the control plane to look up and forward messages received by the physical interface card 1033. The forwarding table distributed by the control plane can be stored in the forwarding table entry memory 1034. In some embodiments, the control plane and the forwarding plane can be completely separated and not on the same device.
[0232] It should be understood that Figures 6-8 In each embodiment, the transmitting unit and the receiving unit can be different physical interface cards. For example, the receiving unit 601 is equivalent to physical interface card 1033, and the transmitting unit 602 is equivalent to physical interface card 1034. The processing unit 802, etc. in the device 800 can be equivalent to one or more of the central processing unit 1011, central processing unit 1031, and central processing unit 1041 in the communication device 1000.
[0233] It should be understood that the operation on interface board 1040 in this embodiment is consistent with the operation on interface board 1030, and will not be described again for the sake of simplicity. It should be understood that the communication device 1000 in this embodiment can correspond to the address request device or address allocation in the above-described method embodiments. The main control board 1010, interface board 1030 and / or interface board 1040 in the communication device 1000 can implement the functions and / or various steps implemented by the address request device or address allocation device in the above-described method embodiments, and will not be described again for the sake of simplicity.
[0234] It should be understood that a network device may have one or more main control boards, including a primary and a backup main control board. Similarly, it may have one or more interface boards; the more powerful the network device's data processing capabilities, the more interface boards it provides. Each interface board may also have one or more physical interface cards. A switching board may or may not exist; multiple switching boards can share the load and provide redundancy. In a centralized forwarding architecture, network devices may not need a switching board, as the interface boards handle the entire system's business data processing. In a distributed forwarding architecture, a network device can have at least one switching board, enabling data exchange between multiple interface boards and providing high-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of a distributed architecture network device are greater than those of a centralized architecture device. Alternatively, network devices can also consist of a single board, without a switching board. The functions of the interface board and the main control board are integrated on this one board. In this case, the central processing unit (CPU) on the interface board and the CPU on the main control board can be combined into a single CPU to perform the combined functions. This type of device has lower data exchange and processing capabilities (e.g., low-end switches or routers). The specific architecture adopted depends on the specific network deployment scenario.
[0235] In some possible embodiments, the address request device, relay device, or address allocation device described above can be implemented as a virtualized device. For example, a virtualized device can be a virtual machine (VM) running a program for sending messages, deployed on a hardware device (e.g., a physical server). A virtual machine refers to a complete computer system with full hardware system functionality simulated by software, running in a completely isolated environment. A virtual machine can be configured as an address request device, relay device, or address allocation device. For example, an address request device or address allocation device can be implemented based on a general-purpose physical server combined with Network Functions Virtualization (NFV) technology. The address request device or address allocation device can be a virtual host, virtual router, or virtual switch. Those skilled in the art can virtualize an address request device or address allocation device with the above functions on a general-purpose physical server using NFV technology by reading this application; further details are omitted here.
[0236] It should be understood that the communication devices of the various product forms described above each have any of the functions of the address request device or the address allocation device in the above method embodiments, which will not be elaborated here.
[0237] This application also provides a chip, including a processor and an interface circuit. The interface circuit is used to receive instructions and transmit them to the processor. The processor may be, for example, a... Figure 7 One specific implementation of the illustrated apparatus 700 can be used to execute the address prefix acquisition method described above. The processor is coupled to a memory used to store programs or instructions, which, when executed by the processor, cause the chip system to implement the method in any of the above method embodiments.
[0238] Optionally, the chip system may contain one or more processors. These processors can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor, implemented by reading software code stored in memory.
[0239] Optionally, the chip system may contain one or more memories. The memory may be integrated with the processor or disposed separately from it; this application does not limit this. For example, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or disposed separately on different chips. This application does not specifically limit the type of memory or the arrangement of the memory and processor.
[0240] For example, the chip system may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD), or other integrated chips.
[0241] This application also provides a computer-readable storage medium, including instructions or a computer program, which, when run on a computer, causes the computer to execute the address prefix acquisition method provided in the above embodiments.
[0242] This application also provides a computer program product containing instructions or computer programs, which, when run on a computer, causes the computer to execute the address prefix acquisition method provided in the above embodiments.
[0243] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0244] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0245] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical business division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.
[0246] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0247] Furthermore, the various business units in the embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software business unit.
[0248] If the integrated unit is implemented as a software business unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0249] Those skilled in the art will recognize that, in one or more of the examples above, the services described in this invention can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these services can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of computer programs from one place to another. Storage media can be any available medium accessible to general-purpose or special-purpose computers.
[0250] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are merely specific embodiments of the present invention.
[0251] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A method for obtaining an address prefix, characterized in that, The method includes: The address allocation device receives a first request message sent by the address request device, the first request message being used to request first prefix information; The address allocation device sends a first response message to the address request device. The first response message includes the first prefix information and a first time to live. The first time to live is used to indicate the validity period of the first prefix information. The address allocation device receives a second request message sent by the address requesting device. The second request message includes authentication information, which is used by the address allocation device to authenticate the legitimacy of the address requesting device. After the address allocation device authenticates the address requesting device, the address allocation device sends a second response message to the address requesting device. The second response message includes a second time-to-live (TTL), which indicates the validity period of the first prefix information. The second TTL is longer than the first TTL.
2. The method according to claim 1, characterized in that, The first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
3. The method according to claim 1, characterized in that, The second request message is used to request second prefix information, and the method further includes: After successfully authenticating the address requesting device, the address allocation device sends a third response message to the address requesting device, the third response message including the second prefix information.
4. The method according to claim 3, characterized in that, The second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
5. The method according to any one of claims 1-4, characterized in that, The second response message also includes third prefix information, which is used by the address requesting device to replace the first prefix information with the third prefix information, and the second time to live is used to indicate the validity period of the third prefix information.
6. The method according to any one of claims 1-4, characterized in that, The address requesting device and the address allocation device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the address allocation device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
7. The method according to any one of claims 1-4, characterized in that, The address requesting device is an Ethernet-based Internet Protocol (IPoE) device.
8. The method according to any one of claims 1-4, characterized in that, The address requesting device is a client device CPE, and the address allocation device is a broadband access server (BRAS) or a DHCPv6 server.
9. A method for obtaining an address prefix, characterized in that, The method includes: The address allocation device receives a first request message sent by the address request device, the first request message being used to request first prefix information; The address allocation device sends a first response message to the address requesting device. The first response message includes indication information, which is used to instruct the address requesting device to send a second request message. The address allocation device receives the second request message sent by the address requesting device. The second request message includes authentication information, which is used by the address allocation device to authenticate the legitimacy of the address requesting device. After the address allocation device authenticates the address requesting device, the address allocation device sends a second response message to the address requesting device, the second response message including the first prefix information.
10. The method according to claim 9, characterized in that, The first response message is a router response RA message, and the indication information is carried in the extended community attribute field newly added to the RA message.
11. The method according to claim 9, characterized in that, Before the address allocation device sends a second response message to the address requesting device, the method further includes: The address allocation device receives a third request message sent by the address request device, the third request message being used to request the first prefix information.
12. The method according to any one of claims 9-11, characterized in that, The first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
13. The method according to any one of claims 9-11, characterized in that, The second request message is used to request second prefix information, and the method further includes: After successfully authenticating the address requesting device, the address allocation device sends a third response message to the address requesting device, the third response message including the second prefix information.
14. The method according to claim 13, characterized in that, The second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
15. The method according to any one of claims 9-11, characterized in that, The address requesting device and the address allocation device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the address allocation device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
16. The method according to any one of claims 9-11, characterized in that, The address requesting device is an Ethernet-based Internet Protocol (IPoE) device.
17. The method according to any one of claims 9-11, characterized in that, The address requesting device is a client device CPE, and the address allocation device is a broadband access server (BRAS) or a DHCPv6 server.
18. A method for obtaining an address prefix, characterized in that, The method includes: The address allocation device receives a first request message sent by the address request device, the first request message being used to request first prefix information; The address allocation device configures the access permission of the address requesting device to a first permission, which represents the first access permission that the address requesting device has when accessing the network using the first prefix information; The address allocation device sends a first response message to the address requesting device, the first response message including the first prefix information; The address allocation device receives a second request message sent by the address requesting device. The second request message includes authentication information, which is used by the address allocation device to authenticate the legitimacy of the address requesting device. After the address allocation device authenticates the address requesting device, the address allocation device configures the address requesting device's access permission to a second permission. The second permission represents the second access permission that the address requesting device has when accessing the network using the first prefix information, and the second access permission is higher than the first access permission.
19. The method according to claim 18, characterized in that, The address allocation device configures the access permissions of the address requesting device to the first permission, including: The address allocation device configures the user group corresponding to the address request device as a first user group, and the access permissions of the first user group are the first permissions.
20. The method according to claim 19, characterized in that, The address allocation device configures the access permissions of the address requesting device to a second permission, including: The address allocation device changes the user group corresponding to the address requesting device from the first user group to the second user group, and the access permissions of the second user group are the second permissions.
21. The method according to any one of claims 18-20, characterized in that, The first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
22. The method according to any one of claims 18-20, characterized in that, The second request message is used to request second prefix information, and the method further includes: After successfully authenticating the address requesting device, the address allocation device sends a second response message to the address requesting device, the second response message including the second prefix information.
23. The method according to claim 22, characterized in that, The second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
24. The method according to any one of claims 18-20, characterized in that, The address requesting device and the address allocation device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the address allocation device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
25. The method according to any one of claims 18-20, characterized in that, The address requesting device is an Ethernet-based Internet Protocol (IPoE) device.
26. The method according to any one of claims 18-20, characterized in that, The address requesting device is a client device CPE, and the address allocation device is a broadband access server (BRAS) or a DHCPv6 server.
27. An address prefix acquisition device, characterized in that, The device includes: The receiving unit is configured to receive a first request message sent by the address requesting device, wherein the first request message is used to request first prefix information; The sending unit is configured to send a first response message to the address requesting device. The first response message includes the first prefix information and a first time-to-live (TTL). The first TTL is used to indicate the validity period of the first prefix information. The receiving unit is further configured to receive a second request message sent by the address requesting device, the second request message including authentication information, the authentication information being used to authenticate the legitimacy of the address requesting device; The sending unit is further configured to send a second response message to the address requesting device after the address requesting device has been authenticated, the second response message including a second time-to-live (TTL), the second TTL being used to indicate the validity period of the first prefix information, and the second TTL being greater than the first TTL.
28. The apparatus according to claim 27, characterized in that, The first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
29. The apparatus according to claim 27, characterized in that, The second request message is used to request the second prefix information. The sending unit is further configured to send a third response message to the address requesting device after the address requesting device has been authenticated, the third response message including the second prefix information.
30. The apparatus according to claim 29, characterized in that, The second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
31. The apparatus according to any one of claims 27-30, characterized in that, The second response message also includes third prefix information, which is used by the address requesting device to replace the first prefix information with the third prefix information, and the second time to live is used to indicate the validity period of the third prefix information.
32. The apparatus according to any one of claims 27-30, characterized in that, The address requesting device and the device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
33. The apparatus according to any one of claims 27-30, characterized in that, The address requesting device is an Ethernet-based Internet Protocol (IPoE) device.
34. The apparatus according to any one of claims 27-30, characterized in that, The address request device is a client device (CPE), and the device is a broadband access server (BRAS) or a DHCPv6 server.
35. An address prefix acquisition device, characterized in that, The device includes: The receiving unit is configured to receive a first request message sent by the address requesting device, wherein the first request message is used to request first prefix information; A sending unit is configured to send a first response message to the address requesting device, the first response message including indication information, the indication information being used to instruct the address requesting device to send a second request message; The receiving unit is further configured to receive the second request message sent by the address requesting device, the second request message including authentication information, the authentication information being used to authenticate the legitimacy of the address requesting device; The sending unit is further configured to send a second response message to the address requesting device after the address requesting device has been authenticated, the second response message including the first prefix information.
36. The apparatus according to claim 35, characterized in that, The first response message is a router response RA message, and the indication information is carried in the extended community attribute field newly added to the RA message.
37. The apparatus according to claim 35, characterized in that, The receiving unit is further configured to receive a third request message sent by the address requesting device before the sending unit sends a second response message to the address requesting device, the third request message being used to request the first prefix information.
38. The apparatus according to any one of claims 35-37, characterized in that, The first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
39. The apparatus according to any one of claims 35-37, characterized in that, The second request message is used to request the second prefix information. The sending unit is further used to send a third response message to the address requesting device after the address requesting device has been authenticated. The third response message includes the second prefix information.
40. The apparatus according to claim 39, characterized in that, The second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
41. The apparatus according to any one of claims 35-37, characterized in that, The address requesting device and the device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
42. The apparatus according to any one of claims 35-37, characterized in that, The address requesting device is an Ethernet-based Internet Protocol (IPoE) device.
43. The apparatus according to any one of claims 35-37, characterized in that, The address request device is a client device (CPE), and the device is a broadband access server (BRAS) or a DHCPv6 server.
44. An address prefix acquisition device, characterized in that, The device includes: The receiving unit is configured to receive a first request message sent by the address requesting device, wherein the first request message is used to request first prefix information; The processing unit is configured to configure the access permission of the address requesting device to a first permission, wherein the first permission represents the first access permission that the address requesting device has when accessing the network using the first prefix information; The sending unit is configured to send a first response message to the address request device, the first response message including the first prefix information; The receiving unit is further configured to receive a second request message sent by the address requesting device, the second request message including authentication information, the authentication information being used to authenticate the legitimacy of the address requesting device; The processing unit is further configured to configure the access permission of the address requesting device to a second permission after the address requesting device is authenticated. The second permission represents the second access permission that the address requesting device has when accessing the network using the first prefix information, and the second access permission is higher than the first access permission.
45. The apparatus according to claim 44, characterized in that, The processing unit is specifically configured to configure the user group corresponding to the address request device as a first user group, and the access permissions of the first user group are the first permissions.
46. The apparatus according to claim 45, characterized in that, The processing unit is specifically used to change the user group corresponding to the address request device from the first user group to the second user group, and the access permissions of the second user group are the second permissions.
47. The apparatus according to any one of claims 44-46, characterized in that, The first prefix information is used by the address requesting device to generate a first IPv6 address based on the first prefix information, and the first IPv6 address is the address of the address requesting device.
48. The apparatus according to any one of claims 44-46, characterized in that, The second request message is used to request the second prefix information. The sending unit is further used to send a second response message to the address requesting device after the address requesting device has been authenticated. The second response message includes the second prefix information.
49. The apparatus according to claim 48, characterized in that, The second prefix information is used to generate a second IPv6 address, which is the address of the user equipment corresponding to the address requesting device.
50. The apparatus according to any one of claims 44-46, characterized in that, The address requesting device and the device send the first request message using the Neighbor Discovery (ND) protocol, and the address requesting device and the device send the second request message using Internet Protocol version 6 Dynamic Host Configuration Protocol (DHCPv6).
51. The apparatus according to any one of claims 44-46, characterized in that, The address requesting device is an Ethernet-based Internet Protocol (IPoE) device.
52. The apparatus according to any one of claims 44-46, characterized in that, The address request device is a client device (CPE), and the device is a broadband access server (BRAS) or a DHCPv6 server.
53. A communication device, the device comprising: Processor and memory; The memory is used to store instructions or computer programs; The processor is configured to execute the instructions or computer program in the memory to cause the communication device to perform the method according to any one of claims 1-26.
54. A computer-readable storage medium comprising instructions which, when executed on a computer, cause the computer to perform the method described in any one of claims 1-26.
Citation Information
Patent Citations
System and method for Diameter prefix authorization
CN102017563A
Access control method and device
CN108123857A