Network access method and network equipment

By dividing MAC table entries into temporary and steady-state table entries in BRAS devices, and adding source IP address attributes to RADIUS messages, the aging and security problems of MAC table entries in PPPoE over IPv6 scenarios are solved, and more efficient resource utilization and security improvement are achieved.

CN119996060APending Publication Date: 2025-05-13NEW H3C TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510356414.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-05-13

Smart Images

  • Figure CN119996060A_ABST
    Figure CN119996060A_ABST
Patent Text Reader

Abstract

The invention provides a network access method and network equipment, and the method comprises the steps: receiving a target message sent by a client, packaging an IPv6 source address and an IPv6 destination address of the client in the target message, and when it is determined that the IPv6 destination address points to itself, sending the target message to the client; and acquiring the IPv6 source address in the target message and the MAC (Media Access Control) of the client, establishing a temporary table item, acquiring authentication information from the client according to the temporary table item, performing authentication on an authentication server, changing the temporary table item into a steady-state table item after the authentication is passed, and enabling the client to access a network according to the steady-state table item. Through the method, the network security in a PPPoE over IPv6 (Point-to-Point Protocol over Ethernet over Internet Protocol version 6) scene can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present specification relates to the field of communication technology, and in particular to a method for accessing a network and a network device. Background Art

[0002] BRAS (Broadband Remote Access Server);

[0003] PPPoE (Point-to-Point Protocol over Ethernet, PPP protocol carried on Ethernet); SRv6 (Segment Routing IPv6, segment routing based on IPv6 forwarding plane);

[0004] SID (Segment Identifier);

[0005] RADIUS (Remote Authentication Dial In User Service);

[0006] PPPoE over IPv6 is currently used in scenarios such as rapid activation of access network services. The forwarding behavior of the corresponding SRv6SID on the BRAS is to first record the association between the outer source IP address of the message and the source MAC in the PPPoE message header, generate the <source IP address, PPPoE MAC> table entry, decapsulate the outer IPv6 message header, and then forward the remaining message to the output interface corresponding to the SID. In business scenarios such as PPPoE dial-up access or dedicated line access, the CPE devices on the customer side are usually widely distributed and huge in number. The SRv6 SID of the BRAS is generally sent to the CPE device through the network management system. This SID is used to identify the service from the CPE to the BRAS. The BRAS will serve as a unified export for CPE services. Taking the PPPoE online authentication and service forwarding process as an example, the interaction process between the CPE and BRAS on the customer side is as follows:

[0007] 1) After the CPE goes online, it is authenticated on the BRAS through PPPoE, and the IPv6 header and Ethernet frame header are encapsulated in the outer layer of the PPPoE message to implement PPPoE over IPv6 message encapsulation. Among them, the destination IP address of the IPv6 header is the SRv6 SID of the BRAS, and the source address is the service SID of the CPE itself.

[0008] 2) BRAS authenticates the CPE through the AAA server and allocates the address of the PPPoE service WAN port to the successfully authenticated CPE. At this time, BRAS records the mapping relationship between the PPPoE Session ID and the outer source IP, and generates the <source IP address, PPPoE MAC> table entry based on the SRv6 SID in the outer encapsulation IPv6 header of the PPPoE message.

[0009] 3) After the authentication is completed, the BRAS obtains the relevant authorization information allocated by the AAA server, such as rate limit, etc.

[0010] 4) When the CPE receives the service message sent by the internal network, it will encapsulate the original service message with an IPv6 message header and an Ethernet frame header, where the destination IP address of the IPv6 message header is the SRv6 SID of the BRAS, and the source address is the service SID of the CPE itself. After receiving the service message, the BRAS decapsulates the outer IPv6 message header according to the action corresponding to the SRv6 SID, and then forwards the remaining message to the interface corresponding to the SID, terminating the L2VPN message. The forwarding is performed by looking up the table in the VRF bound to the interface.

[0011] The current PPPoE over IPv6 mechanism is consistent with the PW connection of static L2VPN established between CPE and BRAS. The aging of <source IP address, PPPoE MAC> entries on the BRAS device depends on the aging of entries dynamically learned by L2VPN. That is, if no message is received to refresh the MAC address entry before the aging timer of the MAC address expires, the MAC address entry is deleted to minimize the occupied MAC address table resources.

[0012] Since the BRAS device will record the source IPv6 address of the message and the source Mac address of the inner PPPoE message after receiving the message with the corresponding service SRv6 SID encapsulation, and the service SID is exposed to the public network, any CPE can obtain the SID address by capturing packets, thereby constructing a large number of attack messages with different source IPv6 addresses and source Mac addresses and sending them to the BRAS device, so that the BRAS device is constantly in the process of learning new MAC table entries, consuming a large number of table entries and CPU resources of the BRAS device. In addition, the aging time of a single MAC table entry is in minutes, and the aging speed is much slower than the speed of new generation. When the table entries on the BRAS device reach the upper limit of the specification, the subsequent normal business development is affected. Summary of the invention

[0013] To overcome the problems existing in the related art, this specification provides a method for accessing a network and a network device.

[0014] According to a first aspect of an embodiment of this specification, a method for accessing a network is provided, the method being applied to a BRAS based on a PPPoE over IPv6 protocol, the method comprising:

[0015] Receive a target message sent by a client, wherein the target message encapsulates an IPv6 source address and an IPv6 destination address of the client;

[0016] When it is determined that the IPv6 destination address points to itself, obtaining the IPv6 source address and the MAC of the client in the target message and establishing a temporary table entry;

[0017] Acquire authentication information from the client according to the temporary table entry and perform authentication on the authentication server, and after the authentication is passed, change the temporary table entry into a stable table entry;

[0018] The client is enabled to access a network according to the steady-state entry.

[0019] The target message is a layer 2 PPPoE message that is again encapsulated with an IPv6 source address and an IPv6 destination address;

[0020] The IPv6 source address is the client address to which the IPv6 source address is added, and the IPv6 destination address is the BRAS address.

[0021] The step of obtaining the IPv6 source address and the MAC address of the client in the target message and establishing a temporary table entry includes:

[0022] The corresponding relationship between the IPv6 source address in the target message and the MAC address of the client is obtained, and a temporary table entry is established according to the corresponding relationship, and a first aging time is set for the temporary entry.

[0023] The first aging time may be selected from 30 milliseconds to 2000 milliseconds.

[0024] The acquiring authentication information from the client according to the temporary entry and performing authentication on the authentication server includes:

[0025] Obtain authentication information through LCP negotiation with the client based on the temporary entry;

[0026] Send an authentication message to the authentication server, where the authentication message carries the authentication information and the IPv6 source address.

[0027] The step of changing the temporary table entry to a stable table entry includes:

[0028] The first aging time of the temporary entry is canceled.

[0029] It can be seen from the above embodiments that, in order to solve the problem of service SRv6 SID being exposed to the public network in the scenario of PPPoE over IPv6, the association between the outer source IP address of the message and the source MAC in the PPPoE message header is recorded, and the generated <source IP address, PPPoE MAC> table item is divided into two parts: a temporary table item and a stable table item, wherein the temporary table item is only valid for a short time. By adding the attribute of the source IP address of the message sent by the CPE in the RADIUS message for verification by the AAA server, the temporary table item is converted into a stable table item, thereby improving the security in the PPPoE over IPv6 scenario.

[0030] According to a second aspect of an embodiment of this specification, a method for accessing a network is provided, the method being applied to a client, the method comprising:

[0031] After the client goes online, it sends a target message to the BRAS, where the target message encapsulates an IPv6 source address and an IPv6 destination address, where the IPv6 source address is the client address and the IPv6 destination address is the BRAS address, so that the BRAS obtains the IPv6 source address and the client's MAC in the target message and establishes a temporary table entry;

[0032] A negotiation message sent by the BRAS is received, and authentication information is sent to the BRAS, so that the BRAS sends the authentication information to the authentication server for authentication, and when the authentication is passed, the BRAS changes the temporary table entry into a stable table entry.

[0033] According to a third aspect of an embodiment of this specification, a network device is provided, the network device enabling a BRAS function, the network device comprising:

[0034] A receiving module, used to receive a target message sent by a client, wherein the target message encapsulates an IPv6 source address and an IPv6 destination address of the client;

[0035] An acquisition module, configured to acquire the IPv6 source address and the client's MAC in the target message and establish a temporary table entry when it is determined that the IPv6 destination address points to itself;

[0036] a processing module, configured to obtain authentication information from the client according to the temporary table entry and perform authentication on the authentication server, and after the authentication is passed, change the temporary table entry into a stable table entry, and

[0037] The client is enabled to access a network according to the steady-state entry.

[0038] The processing module is specifically used to obtain authentication information through LCP negotiation with the client based on the temporary table entry, and send an authentication message to the authentication server, where the authentication message carries the authentication information and the IPv6 source address.

[0039] According to a fourth aspect of an embodiment of this specification, a network device is provided, the network device enabling a client function, the network device comprising:

[0040] A sending module, configured to send a target message to a BRAS, wherein the target message encapsulates an IPv6 source address and an IPv6 destination address, wherein the IPv6 source address is a client address and the IPv6 destination address is a BRAS address, so that the BRAS obtains the IPv6 source address and the client MAC in the target message and establishes a temporary table entry;

[0041] The receiving module is used to receive the negotiation message sent by the BRAS and send authentication information to the BRAS, so that the BRAS sends the authentication information to the authentication server for authentication, and when the authentication is passed, the BRAS changes the temporary table entry into a stable table entry.

[0042] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the specification and, together with the description, serve to explain the principles of the specification.

[0044] Figure 1 It is a flowchart of a method for accessing a network according to an exemplary embodiment of this specification.

[0045] Figure 2 It is a flowchart of a method for accessing a network according to an exemplary embodiment of this specification. DETAILED DESCRIPTION

[0046] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with this specification. Instead, they are merely examples of devices and methods consistent with some aspects of this specification as detailed in the appended claims.

[0047] The terms used in this specification are for the purpose of describing specific embodiments only and are not intended to limit this specification. The singular forms "a", "the" and "the" used in this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0048] It should be understood that although the terms first, second, third, etc. may be used in this specification to describe various information, this information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0049] PPPoE (Point-to-Point Protocol over Ethernet) itself is not a protocol specific to IPv4 or IPv6. It encapsulates PPP frames on Ethernet and can be used to transmit IPv4 or IPv6 traffic. PPPoE over IPv6 refers to the process of using PPPoE to transmit IPv6 packets.

[0050] PPPoE over IPv6 is mainly used in broadband access scenarios, especially in DSL (Digital Subscriber Line) and other Ethernet-based access technologies, where it allows ISPs to provide independent connections for multiple users on a shared network infrastructure.

[0051] In order to solve the problem of SID address being exposed in the public network environment in the prior art, the embodiment of the present disclosure provides a method for accessing the network, which is applied to the BRAS based on the PPPoE over IPv6 protocol, such as Figure 1 As shown, the method includes:

[0052] S101 receives a target message sent by a client, wherein the target message encapsulates an IPv6 source address and an IPv6 destination address of the client;

[0053] S102: when it is determined that the IPv6 destination address points to itself, obtain the IPv6 source address and the client's MAC in the target message and create a temporary table entry;

[0054] S103, obtaining authentication information from the client according to the temporary entry and performing authentication on an authentication server, and after the authentication is passed, changing the temporary entry to a stable entry;

[0055] S104 enables the client to access the network according to the steady-state entry.

[0056] In this embodiment, when the client sends a PPPoE over IPv6 message, a PPPoE over IPv6 message encapsulation format is provided. Specifically, a new Ethernet header and an IPv6 basic header are added to the front of the original Layer 2 PPPoE message. The IPv6 header contains an IPv6 source address (i.e., the router node address to which the IPv6 encapsulation is added) and an IPv6 destination address (the node SID address of the BRAS device in the network).

[0057] In step S101, when the BRAS receives a PPPoE over IPv6 message sent by the client, it parses the IPv6 basic header and determines whether the IPv6 destination address points to itself. If so, it determines that the message is a message of the local service SRv6 SID.

[0058] At this time, the BRAS device records the IPv6 source address in the PPPoE over IPv6 message and the PPPoE MAC of the client carried in the message (ie, the MAC address of the client), and establishes a corresponding relationship between the IPv6 source address and the PPPoE MAC.

[0059] In this embodiment, a temporary table entry <source IP address, PPPoE MAC> is generated according to the corresponding relationship. The temporary table entry is characterized by a short aging time. The aging time of the temporary table entry can be selected from 30 milliseconds to 2000 milliseconds. For example, the aging time of the temporary table entry is set to 1000 milliseconds, that is, when it reaches 1000 milliseconds, the table entry will age. In this embodiment, by setting a temporary table entry with a shorter time, it is possible to effectively prevent attackers from intercepting SID addresses and constructing attack messages to attack. In other embodiments, the aging time of the temporary table entry can be defined according to network characteristics. For example, when the network delay is small and / or there are few devices, the aging time can also be set to 30 milliseconds, or when the network delay is large and / or the network is more complex, the aging time can be set to 2000 milliseconds.

[0060] In step S102, the BRAS device completes the PPPoE discovery phase and the LCP negotiation phase with the client (e.g., CPE device) based on the temporary table entry, thereby obtaining the client's authentication information, which includes: basic authentication information and the client's IPv6 source address, wherein the basic information may include: user name, user password and other information.

[0061] In this embodiment, the BRAS device sends the authentication information to the authentication server for authentication.

[0062] In this embodiment, the authentication server may pre-record the IPv6 source addresses of each legal client. For example, when the client opens an account, the operator records the IPv6 source addresses of each legal client and the corresponding basic authentication information in the authentication server. When the authentication server receives the authentication information sent by the BRAS, only the user name, password and source IPv6 address that are consistent with those on the AAA server can pass the authentication, thereby effectively preventing the attacker from simulating the client to initiate authentication after intercepting the basic information of the client, causing the authentication server to make a wrong authentication result.

[0063] At this time, when the authentication server authenticates the client's authentication information, it will notify the BRAS. After receiving the authentication from the authentication server, the BRAS will add the temporary table entry to the steady-state table entry, that is, change the temporary table entry to the steady-state table entry. The steady-state table entry may not age over time (that is, cancel the aging time) and will only be deleted when the user goes offline.

[0064] It can be seen from the above embodiments that, on the one hand, during the authentication process, the authentication server will not only authenticate the basic information of the client, but also authenticate the IPv6 source address of the client, to prevent attackers from intercepting the basic information of the client and disguising themselves as the client to initiate authentication to the authentication server, causing the authentication server to make an erroneous authentication result. At the same time, by setting temporary table entries, the effective time of the table entries can be controlled to further prevent attackers from obtaining the authentication information of the client.

[0065] Based on the above method embodiment, the present disclosure embodiment also provides a method for accessing a network, the method is applied to a client, such as Figure 2 As shown, the method includes:

[0066] S201: After the client goes online, it sends a target message to the BRAS, where the target message encapsulates an IPv6 source address and an IPv6 destination address, where the IPv6 source address is the client address and the IPv6 destination address is the BRAS address, so that the BRAS obtains the IPv6 source address and the client's MAC in the target message and creates a temporary table entry;

[0067] S202 receives the negotiation message sent by the BRAS, and sends authentication information to the BRAS, so that the BRAS sends the authentication information to the authentication server for authentication, and when the authentication is passed, the BRAS changes the temporary table entry into a stable table entry.

[0068] In this embodiment, the client defines a new PPPoE over IPv6 message encapsulation format, that is, a new Ethernet header and an IPv6 basic header are added to the original Layer 2 PPPoE message. The IPv6 header contains the IPv6 source address (that is, the router node address to which the IPv6 encapsulation is added) and the IPv6 destination address (the node SID address of the BRAS device in the network).

[0069] In this embodiment, after the BRAS device receives a message whose destination IP is the local service SRv6 SID, it records the association between the outer source IP address of the message and the source MAC in the PPPoE message header, and generates a temporary table entry of <source IP address, PPPoE MAC>. The temporary table entry is valid only for a short time and will be immediately aged and deleted after the validity period expires. The length of the validity period is determined by the performance of the current device and the number of temporary table entries.

[0070] After the BRAS device completes the PPPoE discovery phase and the LCP negotiation phase interaction with the CPE according to the temporary table entry, it enters the authentication phase. In the RADIUS message sent to the AAA server, the BRAS device not only carries the most basic user name and password, but also extracts the source IPv6 address from the CPE message, adds it as an attribute in the RADIUS message, and sends it to the AAA server for verification.

[0071] When a CPE user opens an account, the operator stores the source IPv6 address and user name in the AAA server for verification by the BRAS device. Only when the user name, password and source IPv6 address are consistent with those on the AAA server can the authentication be passed. Only after the BRAS device receives the response message of the AAA server, the <source IP address, PPPoE MAC> table item of this user will be added to the steady-state table item area. This table item is consistent with the online status of the user, will not age over time, and will only be deleted when the user goes offline.

[0072] It can be seen from the above embodiments that the <source IP address, PPPoE MAC> table item is divided into two parts: a temporary table item and a stable table item. The temporary table item is only valid for a short time and ages quickly. By adding the attribute of the source IP address of the CPE message sent in the RADIUS message to the AAA server for verification, the temporary table item is converted into a stable table item, thereby improving the security in the PPPoE over IPv6 scenario.

[0073] Based on the above method embodiments, the embodiment of the present disclosure further provides a network device, wherein the network device enables a BRAS function, and the network device includes:

[0074] A receiving module, used to receive a target message sent by a client, wherein the target message encapsulates an IPv6 source address and an IPv6 destination address of the client;

[0075] An acquisition module, configured to acquire the IPv6 source address and the client's MAC in the target message and establish a temporary table entry when it is determined that the IPv6 destination address points to itself;

[0076] a processing module, configured to obtain authentication information from the client according to the temporary table entry and perform authentication on the authentication server, and after the authentication is passed, change the temporary table entry into a stable table entry, and

[0077] The client is enabled to access a network according to the steady-state entry.

[0078] The processing module is specifically used to obtain authentication information through LCP negotiation with the client based on the temporary table entry, and send an authentication message to the authentication server, where the authentication message carries the authentication information and the IPv6 source address.

[0079] On the other hand, an embodiment of the present disclosure further provides a network device, wherein the network device enables a client function, and the network device includes:

[0080] A sending module, configured to send a target message to a BRAS, wherein the target message encapsulates an IPv6 source address and an IPv6 destination address, wherein the IPv6 source address is a client address and the IPv6 destination address is a BRAS address, so that the BRAS obtains the IPv6 source address and the client MAC in the target message and establishes a temporary table entry;

[0081] The receiving module is used to receive the negotiation message sent by the BRAS and send authentication information to the BRAS, so that the BRAS sends the authentication information to the authentication server for authentication, and when the authentication is passed, the BRAS changes the temporary table entry into a stable table entry.

[0082] For the device embodiment, since it basically corresponds to the method embodiment, the relevant parts can refer to the partial description of the method embodiment. The device embodiment described above is only schematic, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place, or they may be distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this specification. A person of ordinary skill in the art can understand and implement it without paying creative labor.

[0083] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0084] Those skilled in the art will readily appreciate other embodiments of the specification after considering the specification and practicing the invention claimed herein. The specification is intended to cover any variations, uses or adaptations of the specification that follow the general principles of the specification and include common knowledge or customary techniques in the art that are not claimed in the specification. The specification and examples are to be considered exemplary only, and the true scope and spirit of the specification are indicated by the following claims.

[0085] It should be understood that the present description is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present description is limited only by the appended claims.

[0086] The above description is only a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this specification should be included in the scope of protection of this specification.

Claims

1. A method for accessing a network, characterized in that: The method is applied to a BRAS based on the PPPoE over IPv6 protocol, and the method comprises: Receive a target message sent by a client, wherein the target message encapsulates an IPv6 source address and an IPv6 destination address of the client; When it is determined that the IPv6 destination address points to itself, obtaining the IPv6 source address and the MAC of the client in the target message and establishing a temporary table entry; Acquire authentication information from the client according to the temporary table entry and perform authentication on the authentication server, and after the authentication is passed, change the temporary table entry into a stable table entry; The client is enabled to access a network according to the steady-state entry.

2. The method according to claim 1, characterized in that The target message is a layer 2 PPPoE message that re-encapsulates an IPv6 source address and an IPv6 destination address; The IPv6 source address is the client address to which the IPv6 source address is added, and the IPv6 destination address is the BRAS address.

3. The method according to claim 1, characterized in that The obtaining the IPv6 source address and the MAC address of the client in the target message and establishing a temporary table entry includes: The corresponding relationship between the IPv6 source address in the target message and the MAC address of the client is obtained, and a temporary table entry is established according to the corresponding relationship, and a first aging time is set for the temporary entry.

4. The method according to claim 3, characterized in that: The first aging time may be selected from 30 milliseconds to 2000 milliseconds.

5. The method according to claim 1, characterized in that The acquiring authentication information from the client according to the temporary table entry and performing authentication on the authentication server includes: Obtain authentication information through LCP negotiation with the client based on the temporary entry; Send an authentication message to the authentication server, where the authentication message carries the authentication information and the IPv6 source address.

6. The method according to claim 3, characterized in that The changing the temporary table entry into a stable table entry includes: The first aging time of the temporary entry is canceled.

7. A method for accessing a network, characterized in that: The method is applied to a client, and the method comprises: After the client goes online, it sends a target message to the BRAS, where the target message encapsulates an IPv6 source address and an IPv6 destination address, where the IPv6 source address is the client address and the IPv6 destination address is the BRAS address, so that the BRAS obtains the IPv6 source address and the client's MAC in the target message and establishes a temporary table entry; A negotiation message sent by the BRAS is received, and authentication information is sent to the BRAS, so that the BRAS sends the authentication information to the authentication server for authentication, and when the authentication is passed, the BRAS changes the temporary table entry into a stable table entry.

8. A network device, characterized in that: The network device enables a BRAS function, and the network device includes: A receiving module, used to receive a target message sent by a client, wherein the target message encapsulates an IPv6 source address and an IPv6 destination address of the client; An acquisition module, configured to acquire the IPv6 source address and the client's MAC in the target message and establish a temporary table entry when it is determined that the IPv6 destination address points to itself; a processing module, configured to obtain authentication information from the client according to the temporary table entry and perform authentication on the authentication server, and after the authentication is passed, change the temporary table entry into a stable table entry, and The client is enabled to access a network according to the steady-state entry.

9. The network device according to claim 8, characterized in that: The processing module is specifically used to obtain authentication information through LCP negotiation with the client based on the temporary table entry, and send an authentication message to the authentication server, where the authentication message carries the authentication information and the IPv6 source address.

10. A network device, characterized in that: The network device enables a client function, and the network device includes: A sending module, configured to send a target message to a BRAS, wherein the target message encapsulates an IPv6 source address and an IPv6 destination address, wherein the IPv6 source address is a client address and the IPv6 destination address is a BRAS address, so that the BRAS obtains the IPv6 source address and the client MAC in the target message and establishes a temporary table entry; The receiving module is used to receive the negotiation message sent by the BRAS and send authentication information to the BRAS, so that the BRAS sends the authentication information to the authentication server for authentication, and when the authentication is passed, the BRAS changes the temporary table entry into a stable table entry.