Method for secure allocation of addresses for fttr systems, storage medium, electronic device and computer program product

By cooperating with the master gateway and slave gateway in the FTTR system and carrying service identification information and location information for verification, the security risks of service plane division based on VLAN information in the FTTR system are resolved, and the security of address allocation and service exclusivity are improved.

CN120263773BActive Publication Date: 2025-10-10ZTE CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510728901.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-10-10
Estimated Expiration
2045-06-03

AI Technical Summary

Technical Problem

There are security risks in the service plane division based on VLAN information in the FTTR system. Unauthorized devices may enter the system by carrying specific VLAN information and consume address resources, affecting the address allocation of normal user terminal devices. There is no guarantee that specific services are only carried on designated user-side ports.

Method used

In the FTTR system, the master gateway and the slave gateway work together. By carrying service identification information and location information in the address request message, the master gateway performs verification to ensure that only legitimate terminal devices can obtain the corresponding VLAN service domain address, preventing illegal devices from occupying address resources and ensuring service exclusivity.

Benefits of technology

It improves the security of address allocation, prevents illegal devices from obtaining addresses, ensures that specific services can only be accessed through designated ports, and optimizes resource allocation and network management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263773B_ABST
    Figure CN120263773B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a method for securely allocating an address of an FTTR system, a storage medium, an electronic device and a computer program product. The method comprises: applying to a master gateway, receiving a first message sent from a slave gateway; the first message carrying location information and service identification information of a user-side terminal device of the slave gateway; checking the location information and the service identification information in the first message; and allocating an address for the user-side terminal device according to a checking result. By carrying the service identification information and the location information in the message for requesting the address and checking at the master gateway, the security of address allocation is effectively improved, and the problem of security risks in service plane division based on VLAN information in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communications, and in particular, to a method for securely allocating addresses for an FTTR system, a storage medium, an electronic device, and a computer program product. Background Art

[0002] In a fiber-to-the-room (FTTR) system, both the master and slave gateways can connect to terminal devices. When the master and slave gateways are networked, the address information of these terminal devices is assigned by the server on the master gateway's local area network (LAN). By default, the V4 addresses obtained by each connected terminal device are within the same network segment, and the V6 addresses all use the same 64-bit prefix. However, as the application scope of FTTR systems becomes wider, the scenarios become more complex, and the number of complex functions increases, each terminal device within the same FTTR system may carry different services. To achieve data isolation and traffic management between services, different virtual local area networks (VLANs) are usually designed to carry different service types (such as IPTV, internet access, smart home devices, etc.), and different service planes are divided by VLAN information.

[0003] However, this service plane division based on VLAN information has security risks, that is, it cannot effectively prevent malicious devices from entering the system by carrying specific VLAN information from the gateway and consuming address resources. Summary of the Invention

[0004] The embodiments of the present application provide a method for securely allocating addresses for an FTTR system, a storage medium, an electronic device, and a computer program product, to at least address the security risks associated with service plane division based on VLAN information in related technologies.

[0005] According to one embodiment of the present application, a method for securely allocating addresses for an FTTR system is provided, which is applied to a primary gateway and includes:

[0006] Receive a first message sent from a gateway; the first message carries the location information and service identification information of a user-side terminal device from the gateway; verify the location information and service identification information in the first message; and assign an address to the user-side terminal device based on the verification result.

[0007] According to another embodiment of the present application, a secure address allocation method for an FTTR system is provided, which is applied to a slave gateway and includes:

[0008] In response to a second message sent from the user-side terminal device of the gateway, the location information and service identification information of the user-side terminal device are obtained; the location information and service identification information are added to the second message to generate a first message; the first message is sent to the main gateway so that the main gateway verifies the location information and service identification information and allocates an address to the user-side terminal device.

[0009] According to another embodiment of the present application, a computer-readable storage medium is provided, in which a computer program is stored. The computer program is configured to execute the steps of any one of the above method embodiments when run.

[0010] According to another embodiment of the present application, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any one of the above method embodiments.

[0011] According to another embodiment of the present application, a computer program product is provided, including a computer program, which implements the steps of any of the above method embodiments when executed by a processor.

[0012] In an embodiment of the present application, the master gateway receives a first message from a slave gateway; the first message carries the location information and service identification information of the slave gateway's user-side terminal device; verifies the location information and service identification information in the first message; and allocates an address to the user-side terminal device based on the verification result. By carrying the service identification information and location information in the message used to request an address and performing the verification at the master gateway, the security of address allocation is effectively improved, and the security risks of service plane division based on VLAN information in related technologies are resolved. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 This is a hardware structure diagram of a mobile terminal running an embodiment of the method of the present application;

[0014] Figure 2 is a schematic diagram of an FTTR home networking architecture according to an embodiment of the present application;

[0015] Figure 3 is a flowchart of secure address allocation for an FTTR system according to an embodiment of the present application;

[0016] Figure 4 is a flowchart of secure address allocation for an FTTR system according to an embodiment of the present application;

[0017] Figure 5 This is a schematic diagram of the DHCPv4 Option 60 format according to an embodiment of the present application;

[0018] Figure 6 is a schematic diagram of a DHCPv4 Option 82 format according to an embodiment of the present application;

[0019] Figure 7 is a timing diagram of a user-side terminal device requesting an address according to an embodiment of the present application;

[0020] Figure 8 is a structural block diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0021] Hereinafter, embodiments of the present application will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.

[0022] It should be noted that the terms “first”, “second”, and the like in the specification and claims of the present application and in the above-described drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence.

[0023] In the FTTR system, the master gateway and the slave gateway are networked, different service planes can be divided according to VLAN information to realize data isolation and traffic management among multiple services. For example, by adding VLAN labels or binding VLAN information on the ports of each gateway, the messages of the devices connected below are carried into the FTTR system with specific VLAN information, and are further classified and aggregated into different service domains. The user-side terminal device obtains the corresponding v4 and v6 addresses in the service domain through protocol interaction, and finally realizes the classification and aggregation of multi-layer service data in different VLAN domains based on VLAN information, message interaction, and data service processing.

[0024] However, the above process has at least the following two problems:

[0025] First, its security cannot be guaranteed. When FTTR systems divide multiple service planes based on VLAN information, there are security risks. Unauthorized devices could enter the system with specific VLAN information to request addresses, maliciously consuming address resources and affecting the address allocation of legitimate user terminal devices. For example, when slave gateway devices manufactured by other manufacturers are connected to the FTTR system, these slave gateway devices also have VLAN tagging capabilities, adding specific VLAN tags to network traffic passing through them. This capability enables downstream terminal devices, even in a mixed-manufacturer environment, to send data packets to the FTTR system's internal network by carrying specific VLAN tags, thereby communicating with the master gateway or other slave gateway devices and obtaining the address corresponding to the service domain. However, if this is a malicious attack, intentionally consuming all addresses in the address pool corresponding to the service domain, legitimate user terminal devices will no longer be able to obtain corresponding addresses, thus affecting home users' normal Internet access and other services.

[0026] Second, the exclusivity of services carried by each user-side port cannot be guaranteed. For example, some customized services need to be restricted to specific user-side ports. Under normal circumstances, when a terminal device is connected to a designated user-side port, it enters the system with its specific VLAN and ultimately obtains an address for the service domain corresponding to that VLAN. However, if the terminal device is moved to another user-side port, it will also eventually obtain an address because it enters the system with the same VLAN. In this case, the specific VLAN domain is exposed on non-designated user-side ports, making it impossible to meet the user's special service needs.

[0027] Therefore, how to securely allocate addresses when dividing multiple service planes based on VLAN information, prevent illegal devices from occupying address resources, and ensure that specific services can only be accessed through designated user-side ports to avoid service security risks remains to be solved.

[0028] In response to the above-mentioned technical problems, an embodiment of the present application proposes a method for secure address allocation in an FTTR system. The technical concept is that when a user-side terminal device sends an address request message, the message is parsed from the gateway and service identification information and location information are added to the message. The message carrying the service identification information and location information is then forwarded to the main gateway. The main gateway verifies the legitimacy of the message based on the preset service identification information and location information, and decides whether to allocate an address. Only user-side terminal devices carrying correct service identification information and location information can obtain address resources within the corresponding VLAN service domain, thereby solving the security risk problem of service plane division based on VLAN information in related technologies and ensuring the exclusivity of the service carried by the user-side port.

[0029] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 This is a hardware block diagram of the mobile terminal running the method embodiment of this application. Figure 1 As shown, the mobile terminal may include one or more ( Figure 1 Only one is shown) a processor 102 (the processor 102 may include but is not limited to a microprocessor MCU or a programmable logic device FPGA and other processing devices) and a memory 104 for storing data. The mobile terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the mobile terminal. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.

[0030] Memory 104 can be used to store computer programs, such as application software programs and modules, such as the computer program corresponding to the secure address allocation method for the FTTR system described in the embodiments of the present application. Processor 102 executes the computer programs stored in memory 104 to perform various functional applications and data processing, thereby implementing the aforementioned methods. Memory 104 may include high-speed random access memory (RAM) and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, memory 104 may further include memory located remotely from processor 102, which can be connected to the mobile terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0031] Transmission device 106 is used to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the mobile terminal's communications provider. In one embodiment, transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0032] Figure 2 This is a schematic diagram of the FTTR home networking architecture according to an embodiment of the present application. The embodiment of the present application can be run on Figure 2 In the network architecture shown in Figure 2 As shown, the network architecture includes:

[0033] Network server: It can be the data center or network center of the Internet Service Provider (ISP), providing source services for Internet access and is the upstream of the home network connection.

[0034] Fiber to the home: This refers to the access point where the Internet service provider (ISP) directly or indirectly connects to the user's home through an optical fiber line. This link may include equipment such as the optical network unit (ONU) and the optical line terminal (OLT).

[0035] Master Gateway: The core device of the FTTR system, responsible for the management, routing, and address allocation of the entire home network. The master gateway connects to the ISP via fiber and establishes connections with each slave gateway device or user-side terminal device, forming the network hub within the home.

[0036] Slave Gateway 1, Slave Gateway 2, and Slave Gateway 3: These are slave gateway devices that connect to the master gateway via fiber, Wi-Fi, or Ethernet cables, extending network signals to every corner of the home. Each slave gateway can connect to multiple user devices and, depending on its configuration, can support different service domains (also called service planes), such as internet access, IPTV, and VOIP.

[0037] Set-Top Box (STB): A terminal device connected to a master or slave gateway (i.e., a user-side terminal device). It can be connected to the master or slave gateway via a network cable and is used to receive and decode IPTV signals so that online TV programs can be played on a TV.

[0038] Mobile terminal (Phone): A terminal device connected to the master or slave gateway (i.e., a user-side terminal device), which can access various mobile devices on the home network, including smartphones. These devices can connect to the master or slave gateway via Wi-Fi or wired connections.

[0039] The master and slave gateways can be networked together via fiber, Wi-Fi, or Ethernet cables. Various user terminals can access the system through user-side ports via Ethernet cables or Wi-Fi, with addresses assigned uniformly by the master gateway's address allocation module. The master gateway's upper layer is ultimately connected to various servers on the operator's side via fiber, enabling downstream terminals to access the internet, stream videos, play cloud games, and other network services.

[0040] in, Figure 2The user-side terminal devices, such as set-top boxes and mobile terminals, are merely examples of terminal devices connected to the master or slave gateway. These devices (i.e., user-side terminal devices) can include a variety of home electronic devices, such as personal computers, smart TVs, mobile phones, printers, and smart home controllers. These devices connect to the user-side port of the slave gateway via network cables or wireless connections. User-side terminal devices are the service targets of the FTTR home network system and must correctly access the network and obtain an IP address for data communication.

[0041] Service Domain: In an FTTR system, a service domain refers to a logical network area divided to meet different network service requirements. For example, each service type, such as IPTV, VOIP, internet access, and smart home control, can be assigned to its own service domain. Different service domains can be identified by different VLAN IDs. Service domains enable network administrators to provide independent network environments for different types of services, isolate and optimize data flows, and ensure service quality.

[0042] VLAN Configuration: Each user-side port on a slave gateway can be assigned to a different VLAN based on actual service requirements. That is, when a user-side terminal device accesses a specific slave gateway port, its network traffic is automatically tagged with the VLAN to which that port belongs. This allows the slave gateway to ensure that different terminal devices are categorized and routed along the correct network path based on the service domain to which their access port belongs. For example, if the IPTV service domain corresponds to VLAN 100, and a user-side port is assigned to VLAN 100, all devices connected to that port will be considered to be within the IPTV service domain.

[0043] Exemplarily, the IP address (e.g., IPv4 address and IPv6 address) obtained by the user-side terminal device depends on the service domain configured for the slave gateway port to which it is connected. Each service domain can have its own independent address pool (the address pool can contain one or more IP addresses available for allocation). When the terminal device sends a message to the slave gateway to initiate an address acquisition request, the slave gateway can parse the message and fill the service identification information and location information corresponding to the service domain to which the terminal device belongs into the optional option field of the message, generate a new message, and send it to the master gateway. The master gateway can decide whether to allocate an address to the downstream terminal device and which service domain to allocate the address based on a pre-configured checklist and the service identification information and location information carried in the new message.

[0044] The FTTR home networking system can realize network coverage in the home, provide high-speed and stable network connection through the cooperation of the master gateway and the slave gateway. The user terminal device can access the slave gateway through wired or wireless mode, and then access the network of the ISP through the connection between the slave gateway and the master gateway, and enjoy various Internet services. In addition, through the VLAN technology, the system can provide data isolation and traffic management for different service types to ensure the quality and security of network services.

[0045] In the embodiment, a method for securely allocating an address for a FTTR system running on the mobile terminal or the networking architecture is provided, which is applied to a master gateway, Figure 3 is a flowchart of the method for securely allocating an address for the FTTR system according to the embodiment of the application, as shown in the figure, the flow includes the following steps: Figure 3

[0046] Step S301, receiving a first message sent by a slave gateway; the first message carries location information and service identification information of a user-side terminal device of the slave gateway.

[0047] The master gateway in the embodiment can be responsible for the connection with an Internet service provider (ISP), and can manage the VLAN configuration and address allocation strategy of the entire system.

[0048] The user-side terminal device (such as a personal computer, a smart TV, a mobile phone, etc.) needs to obtain an IP address in the network to communicate. In the FTTR system, the IP address (including but not limited to IPv4 and IPv6) of the user-side terminal device can be allocated by the dynamic host configuration protocol (DHCP) server of the master gateway. When the user-side terminal device under the slave gateway accesses the network (for example, accesses the network for the first time), the user-side terminal device of the slave gateway can send an address request message (for example, a DHCP Discover message or a DHCPv6 Solicit message) to the slave gateway, and the slave gateway can forward the message to the master gateway. The master gateway can determine whether to allocate an address for the user-side terminal device of the slave gateway according to a preset rule.

[0049] In an exemplary embodiment, the first message is obtained by the slave gateway adding the location information and the service identification information to a second message, and the second message is an address request message sent by the user-side terminal of the slave gateway.

[0050] ​As an example, when / after the slave gateway receives the address request message (i.e., the second message) sent by the user-side terminal device, it can obtain the location information of the user-side terminal device in the network and the service identification information corresponding to the user-side terminal device, add the location information and service identification information to the address request message (i.e., the second message), generate a first message, and send the first message carrying the location information and service identification information to the main gateway.

[0051] In an exemplary embodiment, the location information includes a slave gateway ID and user-side port information corresponding to the slave gateway ID; the service identification information includes a unique service identification code corresponding to a VLAN service domain to which the user-side terminal device belongs.

[0052] As an example, location information may refer to access information when a user-side terminal device accesses a network through a slave gateway. For example, the location information of the user-side terminal device may include the slave gateway number / slave gateway ID, the port number of the slave gateway accessed by the user-side terminal device, etc. The location information can be used to locate the relative position of the user-side terminal device in the network, as well as the slave gateway service used by the user-side terminal device, to assist the master gateway in performing secure address allocation.

[0053] As an example, service identification information can refer to the identification information corresponding to the VLAN service domain to which the user-side terminal device belongs, which can be used to distinguish and manage different service domains. During the address allocation process, the primary gateway can accurately identify the service domain to which the received message belongs based on the service identification information, and then decide whether to allocate an address and which service domain to allocate the address. The service identification information can be a unique service identification code for the VLAN service domain, and each service domain can correspond to a unique service identification code.

[0054] For example, a service domain can refer to a logical network area divided for different types of network services, such as IPTV, VOIP, and Internet access. In FTTR systems, these service domains are implemented using VLAN (Virtual Local Area Network) technology. Each service domain can be associated with one or more VLAN IDs, which identify a specific virtual network. VLAN technology can create multiple logical networks on the same physical network, enabling the isolation and management of service data.

[0055] Step S302: verifying the location information and the service identification information in the first message;

[0056] As an example, the master gateway may be preset with a checklist, which may record the location information and service identification information of all user-side terminal devices of the slave gateways, as well as the mapping relationship between the location information and the service identification information.

[0057] As an example, when / after receiving the first message, the main gateway can verify whether the location information and service identification information in the first message match or are consistent with the location information and service identification information of the user-side terminal device of the slave gateway recorded in the check table.

[0058] Step S303: Allocate an address to the user-side terminal according to the verification result.

[0059] As an example, when a terminal device accesses the network through a slave gateway, the slave gateway can obtain the location information of the terminal device's access and send the location information to the main gateway. The main gateway can confirm whether the device initiates a request from the expected access point based on the location information, so as to reject requests initiated by illegal access points.

[0060] As an example, if the verification passes, that is, the verification result is a match or consistency, the main gateway can assign an address within the corresponding service domain to the user-side terminal device; if the verification fails, that is, the verification result is a mismatch or inconsistency, the main gateway does not assign an address to the user-side terminal device, thereby ensuring the security of the network and the exclusivity of the service.

[0061] As an example, each user-side port of the slave gateway can be configured to a different VLAN service domain. The master gateway can allocate addresses under different service domains according to the different user-side ports of the slave gateway to which the user-side terminal devices of the slave gateway are connected.

[0062] For example, the VLAN service domain configured for one port of the slave gateway is VLAN 100, which is specifically used for Internet access. The main gateway can assign addresses under VLAN 100 to user-side terminal devices connected to this port; another port of the slave gateway is configured as VLAN 200, which is used for VOIP services. The main gateway can assign addresses under VLAN 200 to user-side terminal devices connected to this port.

[0063] In the embodiments of the present application, a first message sent from the gateway is received; the first message carries location information and service identification information of a user-side terminal device of the gateway; the location information and the service identification information in the first message are checked; and an address is allocated to the user-side terminal device according to a checking result. By carrying the service identification information and the location information in the message for requesting the address and checking at the master gateway, the security of address allocation is effectively improved, the problem of security hidden danger in service plane division based on VLAN information in the related art is solved, and the exclusivity of user-side ports carrying services is ensured, and unauthorized devices are prevented from obtaining addresses of a specific service domain.

[0064] In an exemplary embodiment, before receiving the first address request message sent from the gateway, the method further comprises:

[0065] VLAN service domain information and location information of each of the slave gateways are obtained; the location information of the slave gateway includes a slave gateway ID and user-side port information of the slave gateway; corresponding service identification information is configured for different VLAN service domains according to the VLAN service domain information; the VLAN service domain to which the user-side port information of each of the slave gateways belongs is determined according to the location information and the VLAN service domain information, and a mapping relationship between the user-side port information and the service identification information is determined, and a master gateway address allocation checking table is generated.

[0066] As an example, the VLAN service domain information can refer to a series of pre-defined VLAN IDs and service types represented by the VLAN IDs, for example, VLAN 100 represents an Internet service plane, VLAN 200 represents a Voice over IP (VoIP) service plane, and the like.

[0067] As an example, the master gateway can determine the VLAN service domain to which the user-side port of each of the slave gateways should be allocated by medium configuration or preset information when the system is initialized or configured. Each user-side port of the slave gateway can be allocated to a corresponding VLAN service domain, so that different user-side ports can carry different service types, or some user-side ports are configured to carry the same type of VLAN service.

[0068] As an example, in an FTTR system, the main gateway can pre-divide multiple service planes (i.e., service domains) based on VLAN information. For example, different VLAN IDs can be used to carry services such as IPTV (Internet Protocol Television), VOIP (Voice over Internet Protocol), and Internet access. VLAN service domain information can include VLAN IDs (such as VLAN 100, VLAN 200, and so on), meaning each service domain has its own corresponding VLAN ID. While the main gateway can divide logical networks based on VLAN service domain information, it does not directly link security authentication information for specific services, nor does it include information about the physical access location of terminal devices. Therefore, in scenarios with high security requirements, relying solely on VLAN IDs may not be sufficient to fully control and verify the legitimacy of network access.

[0069] Based on the above-mentioned technical problems, in an embodiment of the present application, when / after the FTTR system is divided into multiple service planes based on VLAN information, the main gateway can configure corresponding service identification information for different VLAN service domains according to the VLAN service domain information, for example, configure a corresponding unique service identification code for each VLAN service domain.

[0070] For example, a VLAN ID can be used to divide logical networks and identify different network subsets. A service identifier, on the other hand, focuses more on security authentication and service access control, ensuring the exclusivity and security of a specific service.

[0071] VLAN IDs are unique within a specific scope (such as the entire FTTR system), but they can be used for multiple services. Service identifiers are designed specifically for each VLAN service domain. Not only are they unique within the system, but they are also directly associated with a specific service type, providing a more granular control method.

[0072] VLAN IDs can be easily identified and utilized by devices on the network, and the addition of service identification codes adds a software-based verification mechanism to the system, improving the security level of the address allocation process so that only legitimate and predicted service identification code requests can pass verification.

[0073] The unique service identification code configured in this embodiment provides an additional layer of authentication for each VLAN service domain. Combining the service identification code with the VLAN ID ensures that only devices carrying the specified service identification code can access the corresponding service domain. This effectively prevents unauthorized access, avoiding illegal resource occupation and potential security threats.

[0074] Furthermore, service identification codes can be used to restrict access to specific services, ensuring that certain services (such as customized services) are only available on designated user-side ports. Even if the VLAN information is the same, if a terminal device accesses from a non-designated port, the system will not assign it an address in the corresponding service domain due to the lack or mismatch of the service identification code, thus protecting the exclusivity of the service.

[0075] In this embodiment, the service identification code can be used as part of the address allocation decision, allowing the master gateway to accurately allocate addresses based on the service type and access location requested by the terminal device. This allows the master gateway to more meticulously control and manage the address allocation process, ensuring that only legitimate terminal devices can obtain the corresponding network access rights within their service domain. This control mechanism can optimize resource allocation and ensure efficient use of network bandwidth and address resources.

[0076] As an example, the master gateway can determine the service identification code for each user-side port based on the service identification information corresponding to the user-side port information and VLAN service domain information of the slave gateway, and establish a mapping relationship between the user-side port information and the service identification code. The mapping relationship indicates the service type carried by each user-side port and is encrypted or protected by the service identification code. This ensures that even if the VLAN information is known, it cannot be legally identified by the system without the correct service identification code.

[0077] Based on the above mapping relationship, the main gateway can create a checklist for address allocation (i.e., main gateway address allocation checklist), for example, as shown in Table 1:

[0078] Table 1

[0079]

[0080] As an example, the primary gateway address allocation checklist may include at least the following information:

[0081] Slave gateway number: identifies the specific slave gateway device in the network.

[0082] User-side port number: identifies the specific physical port on the slave gateway.

[0083] VLAN service domain: defines the service type and VLAN ID assigned to the port.

[0084] Service identification code: An identifier bound to the VLAN service domain, used for identity authentication and service exclusivity control.

[0085] In an exemplary embodiment, the method further includes:

[0086] According to the slave gateway ID, the mapping relationship between the user-side port information and the service identification information is synchronized to the corresponding slave gateway.

[0087] As an example, the master gateway can filter out the mapping relationship related to the slave gateway from the master gateway address allocation check table based on the slave gateway ID. For example, the master gateway can search for all entries involving the user-side port and service identifier corresponding to each slave gateway ID. The master gateway can package the mapping relationship between the user-side port information and the service identification information of each filtered slave gateway ID and send it to the corresponding slave gateway. The information received by each slave gateway only contains the service identification information related to its own user-side port, so that the slave gateway can establish and maintain a streamlined mapping table locally to ensure that it knows which user-side ports should be matched with which service identification codes.

[0088] As an example, the mapping relationship received from the gateway will be used to update its local user-side port and service identifier mapping table. This enables the gateway to quickly find the corresponding service identifier code when receiving the address request of the terminal device and fill in this information in the message as needed.

[0089] For example, the master gateway can filter out the mapping relationship related to each slave gateway according to the slave gateway ID in Table 1, as shown in Table 2, Table 3, and Table 4:

[0090] Table 2

[0091]

[0092] Table 3

[0093]

[0094] Table 4

[0095]

[0096] In an exemplary embodiment, step S302 may specifically include:

[0097] The location information and the service identification information in the first message are verified according to the location information indicated in the preset main gateway address allocation check table and the service identification information corresponding to the location information.

[0098] In an exemplary embodiment, when the location information in the first message matches the location information indicated in the main gateway address allocation check table, and the service identification information in the first message matches the service identification information corresponding to the location information indicated in the main gateway address allocation check table, the address of the virtual local area network VLAN service domain corresponding to the service identification information is allocated to the user-side terminal device.

[0099] In an exemplary embodiment, when the location information in the first message does not match the location information indicated in the main gateway address allocation check table, or the service identification information in the first message does not match the service identification information corresponding to the location information indicated in the main gateway address allocation check table, the address of the corresponding VLAN service domain is not allocated.

[0100] Through the method of the above embodiment, if the terminal device does not carry the corresponding service identification information, even if its message enters the FTTR system, the main gateway will not allocate the address corresponding to the VLAN domain to it, thereby avoiding the malicious consumption of addresses in the address pool corresponding to the VLAN service domain, and improving the security of address allocation; ensuring that the address request message of a specific VLAN can only enter the FTTR system through a specific user-side port and obtain the address of the corresponding VLAN domain. If other user-side ports are forced to be switched for access, the address of the specific VLAN domain will ultimately not be obtained. This can avoid the specific VLAN domain being exposed to other non-designated user-side ports, and ensure the exclusivity of the services carried by the user-side ports.

[0101] In this embodiment, a secure address allocation method for an FTTR system running on the above mobile terminal or networking architecture is provided, which is applied from a gateway, Figure 4 FIG. 1 is a flowchart of secure address allocation for an FTTR system according to an embodiment of the present application. Figure 4 As shown, the process includes the following steps:

[0102] Step S401: In response to a second message sent by a user-side terminal device from a gateway, obtain location information and service identification information of the user-side terminal device.

[0103] Step S402: Add location information and service identification information to the second message to generate a first message.

[0104] Step S403: Send the first message to the main gateway, so that the main gateway verifies the location information and the service identification information and allocates an address to the user-side terminal device.

[0105] In an embodiment of the present application, the slave gateway obtains the location information and service identification information of the user-side terminal device by responding to the second message sent by the user-side terminal device of the slave gateway, adds the location information and service identification information to the second address request message, generates a first message, and sends the first message to the main gateway, so that the main gateway verifies the location information and service identification information and assigns an address to the user-side terminal device. By adding the location information and service identification information to the message, the main gateway can verify the user-side terminal device and assign an address based on the verification result, which solves the security risk problem of service plane division based on VLAN information in the related technology, and also ensures the exclusivity of the service carried by the user-side port, preventing unauthorized devices from obtaining the address of a specific service domain.

[0106] In an exemplary embodiment, the location information includes a slave gateway ID and user-side port information corresponding to the slave gateway; the service identification information includes a unique service identification code corresponding to the VLAN service domain to which the user-side terminal device belongs.

[0107] In an exemplary embodiment, the acquiring, in response to the second message sent by the user-side terminal device from the gateway, the location information and service identification information of the user-side terminal device includes:

[0108] In response to a second message sent by the user-side terminal device of the slave gateway, the user-side port information of the user-side terminal device accessing the slave gateway and the slave gateway ID of the slave gateway are obtained; and the service identification information corresponding to the user-side port information is determined according to the mapping relationship between the user-side port information, the user-side port information indicated in the preset slave gateway lookup table, and the service identification information.

[0109] For example, the second message is a message sent by the user-side terminal device requesting to obtain a network address. When the second message arrives at the slave gateway, the slave gateway can identify which physical port (ie, the user-side port) has received the second message.

[0110] For example, each slave gateway has a unique identifier in the FTTR system, namely, a slave gateway ID, which is used to distinguish different slave gateway devices in the network. When the second message arrives, the slave gateway ID can help the system locate the specific slave gateway.

[0111] In an exemplary embodiment, before adding the location information and the service identification information to the second address request message, the method further includes:

[0112] Receive the mapping relationship between the user-side port information and the service identification information synchronized by the master gateway, and generate the slave gateway lookup table.

[0113] In an exemplary embodiment, the location information and the service identification information are added to the second address request message to generate a first message, including:

[0114] It is determined that the optional item field does not exist in the second message, an optional item field is added to the second address request message, and the location information and the service identification information are encapsulated in the optional item field to obtain the first message; or

[0115] It is determined that the optional item field exists in the second message, and the location information and the service identification information are encapsulated in the optional item field to obtain the first message.

[0116] Exemplarily, the second message sent by the user-side terminal device can include an optional item field or can not include the optional item field. The gateway can analyze the second message after receiving the second message to identify whether the optional item field exists in the second message.

[0117] In the DHCP or DHCPv6 protocol, the Options field can be used to carry additional information to enhance the functionality and flexibility of the protocol. The Options field can carry various types of information, such as DNS server address, lease time, host name, etc., and the location information and the service identification information in the embodiments of the present application.

[0118] For example, Figure 5 is a schematic diagram of the DHCPv4 Option 60 format according to the embodiments of the present application. The DHCPv4 Option 60, which can also be referred to as the "Vendor Class Identifier" option, can be used to identify the vendor or hardware type to which the client belongs in the DHCPv4 request message to support vendor-specific functions or configurations. As shown in Figure 5 ,

[0119] Code (60): indicates that the code of this option is 60, that is, Option 60.

[0120] Length: length field, usually in bytes.

[0121] Enterprise Code field: in Option 60, the Enterprise Code field can be used to identify a specific vendor or enterprise. As Figure 5As shown in the figure, the Enterprise Code field is further subdivided and can contain multiple subfields, namely the sub-option type Field Type, the sub-option length Field Length, and the sub-option value Field Value. It can be used to carry more detailed information, such as the gateway ID, user-side port information, and service identification code.

[0122] Option 60 enables the slave gateway to convey detailed information about the source of the address request message (i.e., the second message) to the master gateway, including the slave gateway ID, user-side port information, and the service identifier corresponding to the user-side port information. This helps the master gateway perform more refined address allocation control and security checks.

[0123] For example, Figure 6 This is a diagram of the format of DHCPv4 Option 82 according to an embodiment of the present application. DHCPv4 Option 82, also known as the "Relay Agent Information" option, can be used in a DHCPv4 relay agent scenario to convey client location information or information about the relay agent itself to a DHCP server. In this embodiment of the present application, Option 82 can be used to carry the location information and service identification information of the user-side terminal device, enabling the primary gateway to verify and determine address allocation based on this information.

[0124] like Figure 6 As shown, Code: 82 can represent Option 82.

[0125] Length Len: Indicates the total length of this option, including the length of all sub-options.

[0126] Agent Information Field of the sub-option: can contain one or more sub-options to convey different information.

[0127] Sub-option SubOpt: can include multiple types, such as relay agent circuit Circuit ID, remote ID, etc. In the embodiment of the present application, these sub-options can be used to carry service identification code, slave gateway ID and user side port information, etc.

[0128] Sub-option Value: The specific value of each sub-option can be filled in to provide the location information and service identification information of the terminal device.

[0129] Figure 5 and Figure 6It is shown how to use Option 60 and Option 82 in the DHCP protocol to carry additional service identification information and location information, thereby improving the accuracy and security of address allocation in the FTTR system. By embedding service identification information and location information in the address request message, the main gateway can verify whether the terminal device is located in the expected service plane and whether it carries the correct service identification code, thereby making a decision on whether to allocate an address within the corresponding VLAN domain. This mechanism avoids unauthorized devices accessing specific network resources while ensuring fine-grained control of address allocation, meeting the security and management needs of multiple service planes in home networks.

[0130] As an example, when receiving the second message sent by the user-side terminal device from the gateway, it can be checked whether the optional field (such as Option 60 and Option 82 in DHCPv4, or Option 16 and Option 18 in DHCPv6) already exists in the second message. If no optional field is found in the message, the gateway can add an optional field to the second message. For example, this can be achieved by inserting a specific Option code in the header of the second message, each Option code corresponding to a specific field type. Then, the gateway encapsulates the location information and service identification information into the newly added optional field. The location information and service identification information can be formatted as specific field values to ensure that the main gateway can correctly parse them.

[0131] As an example, if the second message already contains an Option field, the gateway can directly encapsulate the location information and service identification information into the optional field to obtain the first message.

[0132] It should be noted that since the message sent by the user-side terminal device as a client can carry VLAN service domain information or not, the embodiments of the present application can achieve that messages carrying VLAN service domain information and messages not carrying VLAN service domain information can both carry specified VLAN service domain information into the FTTR system by configuring the corresponding VLAN service domain information of the user-side port or binding the VLAN.

[0133] As an example, the second message carries VLAN service domain information. When passing through the slave gateway, the service identification information and location information are filled in the optional option field to obtain the first message carrying the service identification information and location information, and then send it to the master gateway. The master gateway can parse the first message to extract the service identification information and location information, and then query the master gateway address allocation check table maintained by the master gateway based on the service identification information and location information. If a match is found in the entry in the master gateway address allocation check table, the address corresponding to the VLAN service domain is determined to be allocated; otherwise, no address is allocated.

[0134] The following further explains the secure address allocation method of the FTTR system of this application in combination with actual scenarios:

[0135] Example 1 Under normal circumstances, the business identification information and location information are correct, the verification is passed and the address is successfully obtained.

[0136] For example, Figure 7 This is a timing diagram of a user-side terminal device requesting an address according to an embodiment of the present application. Figure 7 As shown, the following steps may be included:

[0137] Step 701a: The master gateway address check table may be configured through media configuration or pre-set, and the mapping relationship between the user-side port information and the service identification information may be synchronized to the corresponding slave gateway.

[0138] For example, multiple service planes can be divided based on VLAN service information. For example, as shown in Table 1, there are currently four services: Internet access, Internet phone (VOIP), Internet television (IPTV), and telecommunications management services (ITMS). VLANs 100, 200, 300, and 400 are used to carry these four service planes, respectively. Each service plane is assigned a unique service identification code, such as AAA, BBB, CCC, or DDD. Furthermore, address pools with different network segments and prefixes can be configured for each of the four service planes to subsequently allocate V4 and V6 addresses to terminal devices on the four service pages.

[0139] For example, depending on actual network deployment requirements, each user-side port of a slave gateway can be assigned to a different VLAN domain, or multiple or all user-side ports of a slave gateway can be assigned to the same VLAN domain. For example, as shown in Table 1, each port of slave gateway #1 is assigned to a different VLAN service domain, all four ports of slave gateway #2 are assigned to the INTERNET service domain, i.e., VLAN 100, and none of the four ports of slave gateway #3 are assigned to a service domain.

[0140] Exemplarily, the user side port and service identification code mapping relationship in the master gateway address allocation check table is mapped to converge the service identification codes corresponding to each user side port of the slave gateway from the gateway and synchronously to the corresponding slave gateway. For example, as shown in Table 2, the mapping relationship of the user side port and service identification code of the No. 1 slave gateway; as shown in Table 3, the mapping relationship of the user side port and service identification code of the No. 2 slave gateway; as shown in Table 4, the mapping relationship of the user side port and service identification code of the No. 3 slave gateway.

[0141] In step 702a, according to the division of the VLAN service domain described above, the VLAN identification or VLAN binding configuration of each user side port is performed, so that the messages carrying VLAN ID and not carrying VLAN ID can carry the specified VLAN into the system, and finally classified and converged into different service domains.

[0142] In step 703a, the slave gateway can obtain and analyze the address request message (i.e. the second message) of the user side terminal device, check whether the option60 or option82 item exists in the second message, if the option60 or option82 item does not exist, the option60 or option82 item can be added first and then filled with content; if the option60 or option82 item exists, the option item content can be directly filled.

[0143] The slave gateway can obtain the user side port information of the user side port receiving the second message, and can query the mapping relationship of the user side port and service identification code (i.e. the slave gateway check table) maintained by the slave gateway according to the user side port information, find the service identification code corresponding to the user side port information, and encapsulate the user side port information, service identification code and slave gateway ID of the slave gateway in the Field Value field of the option60 or the Sub-option Value field of the option82 according to the standard format.

[0144] For example, the user side terminal device sends the address request message of VLAN100, the address request message of VLAN100 comes from the user side port 1 of the No. 1 slave gateway, the No. 1 slave gateway can query Table 2 according to the port information "port 1" to determine that the service identification code of "port 1" is "AAA", and therefore can add the information of "port 1", "AAA" and "slave gateway 1" and the like in the option60 or option82 option.

[0145] In step 704a, the master gateway can check the request message (i.e. the first message) converged in different VLAN service domains, and if the check is passed, the address is allocated.

[0146] Illustratively, the primary gateway may parse the request message and extract the service identification code and location information.

[0147] For example, the master gateway parses a message for VLAN 100 and finds its service identification code is "AAA," the user-side port is "Port 1," and the slave gateway ID is "Slave Gateway 1." The master gateway uses VLAN 100 and the slave gateway ID as keywords to query the master gateway address allocation checklist, as shown in Table 1. It finds the corresponding service identification code is "AAA" and the user-side port is "Port 1," which are consistent with the message parsed. Therefore, the check passes, and the master gateway allows the user-side terminal device to be assigned an address in the VLAN 100 service domain.

[0148] Step 705a: The user-side terminal device successfully obtains the address.

[0149] Example 2: In abnormal circumstances, the service identification information and location information are incorrect, resulting in verification failure and inability to obtain the address process

[0150] Reference Figure 7 , which may include the following steps:

[0151] Step 701b: The master gateway address check table may be configured through media configuration or pre-set, and the mapping relationship between the user-side port information and the service identification information may be synchronized to the corresponding slave gateway.

[0152] Step 702b: Based on the division of the VLAN service domains, VLAN identification or VLAN binding can be configured for each user-side port, so that both messages carrying VLAN IDs and messages without VLAN IDs can carry the specified VLAN to enter the system and are finally classified and aggregated into different service domains.

[0153] Step 703b: The gateway can obtain and parse the address request message (i.e., the second message) of the user-side terminal device, and check whether option 60 or option 82 already exists in the second message. If option 60 or option 82 does not exist, option 60 or option 82 can be added first and then the content can be filled in; if option 60 or option 82 exists, the option content can be directly filled in.

[0154] Step 704b: The primary gateway may verify the request messages (ie, the first messages) aggregated in different VLAN service domains, and will not allocate an address if the verification fails.

[0155] Illustratively, the primary gateway may parse the request message and extract the service identification code and location information.

[0156] For example, the master gateway parses a message for VLAN 100 and finds its service identification code is "BBB," the user-side port is "Port 2," and the slave gateway ID is "Slave Gateway 1." The master gateway uses VLAN 100 and the slave gateway ID as keywords to query the master gateway address allocation checklist, as shown in Table 1. The checklist finds the corresponding service identification code is "AAA" and the user-side port is "Port 1," which are inconsistent with the message parsed. The check fails, and the master gateway disallows allocation of an address in the VLAN 100 service domain to the user-side terminal device.

[0157] Step 705b: The user-side terminal device fails to obtain the address.

[0158] Example 3: Abnormal situation: no service identification information or location information is carried, resulting in verification failure and inability to obtain address process

[0159] Reference Figure 7 , which may include the following steps:

[0160] Step 701c: The master gateway address check table may be configured through media configuration or pre-set, and the mapping relationship between the user-side port information and the service identification information may be synchronized to the corresponding slave gateway.

[0161] Step 702c: Based on the division of the VLAN service domains, VLAN identification or VLAN binding can be configured for each user-side port, so that both packets carrying VLAN IDs and packets without VLAN IDs can enter the system with the specified VLAN and finally be classified and aggregated into different service domains.

[0162] Step 703c: The gateway can obtain and parse the address request message (i.e., the second message) of the user-side terminal device, and check whether option 60 or option 82 already exists in the second message. If option 60 or option 82 does not exist, option 60 or option 82 can be added first and then the content can be filled in; if option 60 or option 82 exists, the option content can be directly filled in.

[0163] For example, the user-side terminal device sends an address request message for VLAN 100, and the address request message for VLAN 100 comes from the user-side port 1 of slave gateway No. 3. Slave gateway No. 3 can query Table 4 based on the user-side port information "Port 1" and determine that the service identification code corresponding to "Port 1" is empty. Therefore, the information of "Port 1", "Empty" and "Slave Gateway 3" can be added to option 60 and option 82.

[0164] Step 704c: The primary gateway verifies the request messages (ie, the first messages) aggregated in different VLAN service domains. If the verification fails, no address is allocated.

[0165] Illustratively, the primary gateway may parse the request message and extract the service identification code and location information.

[0166] For example, the master gateway parses a message for VLAN 100 and finds its service identification code to be "null," the user-side port to be "Port 1," and the slave gateway ID to be "Slave Gateway 3." The master gateway uses VLAN 100 and the slave gateway ID as keywords to query the master gateway address allocation checklist. As shown in Table 1, since the master gateway has not assigned a VLAN domain to each user-side port of slave gateway 3, it cannot find the corresponding information and determines that the check fails. Therefore, the master gateway does not allow the user-side terminal device to be assigned an address in the VLAN 100 service domain.

[0167] Step 705c: The user-side terminal device fails to obtain the address.

[0168] Through the above embodiments 1-3, if the terminal device does not carry the corresponding service identification information, even if its message enters the FTTR system, the main gateway will not allocate the address corresponding to the VLAN domain for it, thereby avoiding the malicious consumption of addresses in the address pool corresponding to the VLAN service domain, and improving the security of address allocation; ensuring that the address request message of a specific VLAN can only enter the FTTR system through a specific user-side port and obtain the address of the corresponding VLAN domain. If other user-side ports are forced to be switched for access, the address of the specific VLAN domain will ultimately not be obtained. This can avoid the specific VLAN domain from being exposed to other non-designated user-side ports, and ensure the exclusivity of the services carried by the user-side ports.

[0169] It should be noted that the embodiments of the present application can also be used for FTTR to securely obtain the IPv6 address from the gateway. It is only necessary to replace the option options carrying the verification code from option 60 and option 82 of the DHCPv4 request message with option 16 and option 18 of the DHCPv6 request message. The address acquisition process in the above embodiments 1-3 is only an example, and the embodiments of the present application do not limit the type of address obtained.

[0170] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus the necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the existing technology, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0171] It should be noted that the above modules can be implemented through software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.

[0172] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps of any of the above method embodiments when run.

[0173] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.

[0174] Figure 8 is a structural block diagram of an electronic device according to an embodiment of the present application, such as Figure 8 As shown, an embodiment of the present application further provides an electronic device 80, including a memory 801 and a processor 802, wherein the memory 801 stores a computer program, and the processor 802 is configured to run the computer program to execute the steps in any of the above method embodiments.

[0175] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.

[0176] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail here.

[0177] An embodiment of the present application further provides a computer program product, including a computer program, which implements the steps of any of the above method embodiments when executed by a processor.

[0178] Obviously, those skilled in the art should understand that the modules or steps of the present application described above can be implemented using a general-purpose computing device, they can be concentrated on a single computing device, or distributed across a network composed of multiple computing devices, they can be implemented using program code executable by the computing device, and thus, they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be performed in a different order than herein, or they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. Thus, the present application is not limited to any specific combination of hardware and software.

[0179] The above description is merely a preferred embodiment of the present application and is not intended to limit the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the principles of the present application shall be included within the scope of protection of the present application.

Claims

1. A method for securely allocating addresses for an FTTR system, characterized in that: Applied to the main gateway, including: Receive a first message sent from a slave gateway; the first message carries location information and service identification information of a user-side terminal device of the slave gateway; wherein the location information includes a slave gateway ID and user-side port information corresponding to the slave gateway ID; the service identification information includes a unique service identification code of a VLAN service domain to which the user-side terminal device belongs; Verify the location information and the service identification information in the first message based on a preset master gateway address allocation check table, wherein the master gateway address allocation check table records the mapping relationship between the user-side port information of each slave gateway and the unique service identification code; Determine that the verification result is that the main gateway address allocation check table contains user side port information that matches the user side port information in the first message, and the unique service identification code corresponding to the user side port information, and allocate an address for the user side terminal device.

2. The method according to claim 1, characterized in that The first message is obtained by the slave gateway adding the location information and the service identification information to the second message, and the second message is an address request message sent by the user-side terminal of the slave gateway.

3. The method according to claim 1, characterized in that Before receiving the first address request message sent from the gateway, the method further includes: Acquire VLAN service domain information and location information of each of the plurality of slave gateways; the location information of the slave gateway includes a slave gateway ID and user-side port information of the slave gateway; According to the VLAN service domain information, corresponding service identification information is configured for different VLAN service domains respectively; According to the location information and the VLAN service domain information, the VLAN service domain to which the user-side port information of each slave gateway belongs is determined, and then the mapping relationship between the user-side port information and the service identification information is determined, and the master gateway address allocation check table is generated.

4. The method according to claim 3, characterized in that Also includes: According to the slave gateway ID, the mapping relationship between the user-side port information and the service identification information is synchronized to the corresponding slave gateway.

5. A method for secure address allocation in an FTTR system, characterized in that: Applicable to the slave gateway, including: In response to a second message sent by the user-side terminal device of the slave gateway, obtaining location information and service identification information of the user-side terminal device; wherein the location information includes the slave gateway ID of the slave gateway and the user-side port information corresponding to the slave gateway ID; the service identification information includes a unique service identification code of the VLAN service domain to which the user-side terminal device belongs; wherein the unique service identification code is a service identification code obtained from a preset slave gateway lookup table based on the user-side port information; the slave gateway lookup table is obtained by synchronizing the mapping relationship between the user-side port of the slave gateway and the unique service identification code to the slave gateway based on the master gateway address allocation check table and the slave gateway ID; adding the location information and service identification information to the second message to generate a first message; The first message is sent to the main gateway, so that the main gateway verifies the location information and the service identification information in the first message and allocates an address to the user-side terminal device.

6. The method according to claim 5, characterized in that The acquiring, in response to the second message sent by the user-side terminal device from the gateway, the location information and service identification information of the user-side terminal device, includes: In response to a second message sent by a user-side terminal device of the slave gateway, obtaining user-side port information of the user-side terminal device accessing the slave gateway and a slave gateway ID of the slave gateway; The VLAN service domain unique identification code corresponding to the user side port information is determined according to the mapping relationship between the user side port information, the user side port information of the slave gateway recorded in the preset slave gateway lookup table, and the VLAN service domain unique identification code.

7. The method according to claim 5, characterized in that The adding the location information and the service identification information to the second message to generate the first message includes: Determining that no optional field exists in the second message, adding an optional field to the second message, and encapsulating the location information and the service identification information in the optional field to obtain the first message; or Determine whether an optional field exists in the second message, encapsulate the location information and the service identification information in the optional field, and obtain the first message.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 4 are implemented, or the steps of the method described in any one of claims 5 to 7 are implemented.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the processor implements the steps of the method described in any one of claims 1 to 4, or implements the steps of the method described in any one of claims 5 to 7.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 4 are implemented, or the steps of the method described in any one of claims 5 to 7 are implemented.

Citation Information

Patent Citations

  • Address allocation method and device

    CN117914826A

  • Method for safely allocating address for FTTR (Fiber To The Rate) system

    CN118175141A