Access control system and method in a network

The access control system modulates MAC addresses and enforces communication policies using ARP packet modulation and a policy server to secure home terminals in apartment complexes, addressing hacking risks and reducing complexity and costs.

JP2025526205APending Publication Date: 2025-08-12VIASCOPE INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025504620
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-03
Filing Date
2022-08-30
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

Existing access control systems in apartment complexes face challenges in managing complex network environments, leading to increased hacking risks and difficulties in blocking direct communication between wall pads within the same building, while also requiring numerous security devices, which increases costs and reduces security policy operation rates.

Method used

An access control system and method that utilizes ARP packet modulation to manage MAC addresses in home terminals, coupled with a policy server for VLAN bandwidth allocation and communication permission policies, allowing the management device to regulate access and block unauthorized communication through L3 switches.

Benefits of technology

Effectively blocks illegal access to in-home terminals by modulating MAC addresses and enforcing communication policies, thereby enhancing security and reducing the complexity and cost associated with traditional access control methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025526205000001_ABST
    Figure 2025526205000001_ABST
Patent Text Reader

Abstract

According to the present disclosure, an access control method in a network including a plurality of home terminals located in different households may include the steps of transmitting an ARP request packet to the plurality of home terminals, analyzing a first ARP response packet received in response to the ARP request packet to acquire address information of the plurality of home terminals, generating a second ARP response packet having a modulated MAC address, and transmitting the second ARP response packet to the plurality of home terminals to modulate the MAC address of each home terminal in the ARP table of the plurality of home terminals. The second ARP response packet is an ARP response packet including, as source address information, the IP address of the home terminal whose MAC address is to be modified in each ARP table and the modulated MAC address, and the modulated MAC address may be a MAC address that cannot be communicated with.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an access control system and method in a network, and more particularly, to an access control system and method for controlling access in a network including a plurality of home terminals located in different households. [Background technology]

[0002] Wall pads installed in each household in an apartment complex are now equipped with a variety of functions. As wall pads are increasingly equipped with cameras and other functions, the leakage of private information through wall pad hacking has recently become a social issue. This has led to a need for a function to control access to wall pads belonging to different households on the apartment complex network. Furthermore, there is a possibility that wall pads may be hacked through major network devices, such as closed circuit television (CCTV) and parking management systems, which are always open to communication with wall pads. This has led to an increasing need to protect these network devices from hacking, such as theft of Internet Protocol (IP) addresses and Media Access Control (MAC) addresses.

[0003] In a typical network within an apartment complex, wall pads in the same building form a subnet, and communication is performed between wall pads within that subnet using direct communication. Wall pads in different buildings can also communicate through inter-subnet communication. Therefore, to protect wall pads from hacking, it is necessary to control access not only within the same subnet within the apartment complex, but also from other subnets.

[0004] In the past, access control lists (ACLs) or firewalls provided by security devices such as switches and routers were used to control access between wall pads in apartment complex networks. ACL technology sets up filters defined by source IP addresses, destination IP addresses, protocols, and application port numbers, and performs comparison tests on inbound or outbound packets to allow or block them. ACL technology unconditionally denies or allows packets to pass through for devices not registered on a whitelist or blacklist, making policy management difficult due to changes in the network environment, such as changes to the network configuration or the registration of new devices. Furthermore, while ACL technology can block communication between subnets in different buildings within an apartment complex, it can be difficult to block direct communication between wall pads in the same building. Communication between wall pads in the same building that belong to the same subnet is carried out through the L2 switch associated with the subnet, not the L3 switch. Therefore, the ACL function configured on the L3 switch cannot block communication between wall pads in the same building.

[0005] In addition, as the number of subnets and nodes that make up the network within an apartment complex increases, i.e., as the number of apartment buildings and households increases, the policy management for access control between wall pads becomes more complex, which increases the probability of failure.In addition, the number of security devices required to configure the access control function also increases, which can lead to problems such as increased costs and reduced security policy operation rates. Summary of the Invention [Problem to be solved by the invention]

[0006] An object of the present disclosure is to provide an access control system and method that can control access to in-home terminals such as wall pads installed in each household in an apartment complex. [Means for solving the problem]

[0007] According to one embodiment, a method for controlling access in a network including multiple home terminals located in different households includes the steps of: a management device transmitting an Address Resolution Protocol (ARP) request packet to the multiple home terminals; the management device analyzing a first ARP response packet received in response to the ARP request packet to acquire address information of the multiple home terminals; the management device generating a second ARP response packet having a modulated Media Access Control (MAC) address; and the management device transmitting the second ARP response packet to the multiple home terminals, thereby modulating the MAC address of each home terminal in the ARP table of the multiple home terminals. The second ARP response packet may be an ARP response packet including, as source address information, the IP address of the home terminal whose MAC address is to be modified in each ARP table and the modulated MAC address. The modulated MAC address may be a MAC address that is not communicable.

[0008] The network may include a policy server that manages access control policies, including a Virtual Local Area Network (VLAN) bandwidth allocation policy and a communication permission policy, for each of a plurality of subnets to which different network devices are connected, and a plurality of network devices including the plurality of home terminals. The access control method may further include the steps of: the management device transmitting a third ARP response packet, in which a MAC address is modulated, to the plurality of network devices, and modulating a MAC address of a gateway to the MAC address of the management device in the ARP tables of the plurality of network devices; the management device receiving packets transmitted from the plurality of network devices to the gateway; and the management device forwarding or discarding the received packets to the gateway based on the access control policy.

[0009] The step of transmitting or discarding the received packet to the gateway may include a step of discarding the received packet if the communication permission policy prohibits communication between a VLAN band to which the destination IP address of the received packet belongs and a VLAN band to which the source IP address of the received packet belongs.

[0010] The step of transmitting or discarding the received packet to the gateway may include a step of transmitting the received packet to the gateway if the communication permission policy allows communication between a VLAN band to which the destination IP address of the received packet belongs and a VLAN band to which the source IP address of the received packet belongs.

[0011] The step of delivering or discarding the received packet to the gateway may include delivering the received packet to the gateway if the destination IP address of the received packet belongs to an external network of the network.

[0012] The communication permission policy may be set so that communication is prohibited between subnets to which the plurality of home terminals belong.

[0013] The access control method may further include a step in which the management device acquires address information of the network device that transmitted the packet from the received packet, and a step in which the management device compares the address information acquired from the received packet with address information managed by the policy server to detect a new network device.

[0014] The access control policy may further include a policy for determining whether the new network device needs to be authorized. The access control method may further include a step of the policy server determining whether the new network device needs to be authorized based on the access control policy or a control input from an administrator, and a step of the management device transmitting a fourth ARP request packet to the new network device to modify the MAC address of another network device in the ARP table of the new network device to a MAC address that cannot be communicated with.

[0015] The access control method may further include a step in which, if the new network device is an unauthorized device, the management device transmits a fifth ARP request packet to the new network device to modify the MAC address of the gateway in the ARP table of the new network device to a MAC address that cannot be communicated with or the MAC address of the management device.

[0016] The access management policy may further include a blocking policy for address theft devices. The access control method may further include the steps of: detecting the address theft device that has stolen the address of another network device registered on the network by comparing address information acquired from the received packet with address information managed by the policy server; and blocking the address theft device from the network based on the blocking policy.

[0017] In the access control method, the management device can be connected to an 802.1Q tagged port of an L3 switch.

[0018] According to one embodiment, an access control system in a network including a plurality of home terminals located in different households may include a management device that transmits Address Resolution Protocol (ARP) request packets to the plurality of home terminals, analyzes first ARP response packets received in response to the ARP request packets to acquire address information of the plurality of home terminals, and transmits second ARP response packets with modulated Media Access Control (MAC) addresses to the plurality of home terminals to modulate the MAC addresses of each home terminal registered in the ARP tables of the plurality of home terminals, thereby blocking communication between the plurality of home terminals. The second ARP response packets may be ARP response packets that include, as source address information, the IP addresses of the home terminals whose MAC addresses are to be modified in each ARP table and the modulated MAC addresses. The modulated MAC addresses may be MAC addresses that are not communicable.

[0019] The access control system may further include a policy server that manages access management policies, including a Virtual Local Area Network (VLAN) bandwidth allocation policy and a communication permission policy, for each of a plurality of subnets constituting the network. The management device transmits a third ARP response packet, in which a MAC address is modulated, to a plurality of network devices registered in the network, modulating the MAC addresses of gateways registered in the ARP tables of the plurality of network devices to the MAC address of the management device. When a packet is received from the plurality of network devices, the management device delivers the received packet to the gateway or discards the received packet based on the access management policy, and the plurality of network devices may include the plurality of home terminals.

[0020] The management device can discard the received packet if the communication permission policy prohibits communication between the VLAN band to which the destination IP address of the received packet belongs and the VLAN band to which the source IP address of the received packet belongs.

[0021] The management device may allow communication between the VLAN band to which the destination IP address of the received packet belongs and the VLAN band to which the source IP address of the received packet belongs in the communication permission policy, or may transmit the received packet to the gateway if the destination IP address of the received packet belongs to an external network of the network.

[0022] The communication permission policy may be set so that communication is prohibited between different subnetworks to which the plurality of home terminals belong.

[0023] The policy server manages address information of the plurality of network devices, and the management device can obtain address information of the network device that transmitted the packet from the received packet and detect a new network device by comparing the address information obtained from the received packet with address information managed by the policy server.

[0024] The access control policy may further include a policy for determining whether the new network device needs to be authorized. The policy server may determine whether the new network device needs to be authorized based on the access control policy or a control input from an administrator. If the new network device is an unauthorized device, the management device may transmit a fourth ARP request packet to the new network device to modify the MAC address of another network device in the ARP table of the new network device to a MAC address that cannot be communicated with.

[0025] If the new network device is an unauthorized device, the management device can transmit a fifth ARP request packet to the new network device to modify the MAC address of the gateway in the ARP table of the new network device to a MAC address that cannot be communicated with or the MAC address of the management device.

[0026] The access management policy may further include a blocking policy for address theft devices. The management device may compare address information acquired from the received packet with address information managed by the policy server to detect the address theft device that has stolen the address of another network device registered on the network, and block the address theft device from the network based on the blocking policy.

[0027] The management device may be connected to an 802.1Q tagged port of an L3 switch. [Effects of the Invention]

[0028] According to the present disclosure, it is possible to effectively block illegal access to in-home terminals such as wall pads installed in each household in an apartment complex. [Brief explanation of the drawings]

[0029] [Figure 1] 1 illustrates a schematic diagram of a network in an apartment complex according to one embodiment; [Figure 2] 1 illustrates a schematic diagram of an access control system according to one embodiment. [Figure 3] 1 illustrates a schematic diagram of a method for controlling access in a network according to an embodiment; [Figure 4] 1 illustrates a method for blocking access of address-stealing devices in a network according to one embodiment; DETAILED DESCRIPTION OF THE INVENTION

[0030] Hereinafter, the embodiments disclosed herein will be described in detail with reference to the accompanying drawings. Identical or similar components will be designated by identical or similar reference numerals, and redundant description thereof will be omitted. The suffixes "module" and "unit" used in the following description are assigned or used interchangeably for the sake of ease of description, and do not have any distinct meanings or functions. Furthermore, when describing the embodiments disclosed herein, if it is determined that a detailed description of related publicly known technology may obscure the gist of the embodiments disclosed herein, such a detailed description will be omitted. Furthermore, the accompanying drawings are intended to facilitate understanding of the embodiments disclosed herein, and should not be construed as limiting the technical concepts disclosed herein, and should be understood to include all modifications, equivalents, and alternatives within the concept and technical scope of the present invention.

[0031] Terms including ordinal numbers such as "first," "second," etc. may be used to describe various components, but the components are not limited by these terms. The terms are used only to distinguish one component from another.

[0032] The singular expression includes the plural expression unless the context clearly indicates otherwise.

[0033] In this application, the use of terms such as "comprise" or "have" is intended to specify the presence of any feature, number, step, operation, component, part, or combination thereof stated in the specification, and should be understood as not precluding the possible presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0034] FIG. 1 illustrates a schematic diagram of a network within an apartment complex according to one embodiment.

[0035] Referring to Figure 1, in network 1 within an apartment complex, packets sent to and from an external network (the Internet) pass through firewall 11 and L3 switch 12. Firewall 11 is responsible for the security of network 1 and can block harmful traffic entering or leaving the network. L3 switch 12 can operate as a backbone switch located at the center of nodes in network 1 that wish to connect to the Internet. In this case, all packets sent and received between network 1 and the Internet pass through L3 switch 12. L3 switch 12 can also operate as a gateway for network 1. The gateway can transmit packets between the Internet and network 1 or between subnets that make up network 1 based on the destination IP address contained in each packet.

[0036] The network 1 may include at least one subnet 20 .

[0037] In the network 1 within the apartment complex, each subnet 20 may include at least one L2 switch 21 supporting communication between the home terminals 22 located in the same building. Communication between home terminals 22 belonging to the same subnet 20, i.e., home terminals 22 belonging to the same building, may correspond to direct communication through the L2 switch 21. Communication between home terminals 22 belonging to different subnets 20, i.e., home terminals 22 belonging to different buildings, may correspond to communication between subnets 20 through the gateway of the L3 switch 12. The home terminal 22 is a network device located in each household and can perform various functions such as providing information within the apartment complex / household, controlling equipment within the apartment complex / household, and making calls. The home terminal 22 may include, for example, a video phone, a door phone, a wall pad, etc.

[0038] In addition to the in-home terminal 22, the network 1 may include various shared systems (e.g., CCTV 31, parking management system 32, complex entrance door 33, shared entrance door 34, etc.) managed within the apartment complex through the network 1. The network 1 may further include various servers located within the apartment complex, such as a complex server 41 and a call server 42.

[0039] In the network 1, shared systems (e.g., CCTV 31, parking management system 32, apartment complex entrance door 33, shared entrance door 34, etc.) and various servers (e.g., apartment complex server 41, call server 42, etc.) may constitute at least one subnet 30, 40. In the network 1, each subnet 20, 30, 40 may be divided into virtual local area network (VLAN) bands. That is, different VLAN bands may be assigned to the subnets 20, 30, 40.

[0040] For ease of explanation, the in-home terminal 22, shared systems (CCTV 31, parking management system 32, housing complex entrance door 33, shared entrance door 34, etc.), and servers (housing complex server 41, call server 42, etc.) belonging to network 1 may also be referred to as "network devices."

[0041] The network 1 may further include a policy server 43 and a management device 13 to block illegal access to network devices belonging to the network 1 .

[0042] FIG. 2 illustrates a schematic diagram of an access control system for controlling access to network devices in a network 1 within an apartment complex according to one embodiment.

[0043] Referring to FIG. 2, the access control system 100 may include the L3 switch 12, the management device 13, and the policy server 43 shown in FIG.

[0044] The management device 13 and the policy server 43 are connected to the L3 switch 12 and can communicate with each other through the L3 switch 12 .

[0045] The policy server 43 can perform the function of setting and managing a policy for network access (access control policy) and device information of network devices in the network 1.

[0046] The policy server 43 may include a database 431 and a policy manager 432 .

[0047] The database 431 can store policy (access control policy) information for connection authentication, authorization, accounting, etc. for network access in the network 1. The access control policy can include a VLAN band (or subnet band) allocation policy and a communication permission policy (a communication permission policy for each VLAN band, and a communication permission policy between VLAN bands) for each subnet 20, 30, 40 constituting the network 1. For example, the communication permission policy can be set so that communication is blocked between different subnets 20 to which the home terminal 22 belongs, and communication is allowed between the subnet 20 to which the home terminal 22 belongs and the subnet 30 to which the parking management system 32 belongs. The access control policy can further include a policy for determining whether to authorize a network device attempting to newly connect to the network 1, a blocking policy for devices that are unauthorized by the network 1 or that have stolen the address of another network device, etc.

[0048] The database 431 may further include device information for each network device registered in the network 1. The device information may include address information (IP address and MAC address) of each network device, status information (online / offline), authentication information (authorized / unauthorized), whether or not it needs to be blocked, etc.

[0049] The policy management unit 432 can set and manage policy information stored in the database 431. The policy management unit 432 can set and manage policy information based on control inputs received from an administrator.

[0050] The policy management unit 432 can also set and manage device information stored in the database 431. The policy management unit 432 can receive address information, status information, etc. of each network device from the management device 13, and set and manage the device information based on the received information.

[0051] When the policy management unit 432 is notified by the management device 13 that a new network device has been detected, it can determine whether or not to authorize the new network device based on the information about the new network device received from the management device 13. The policy management unit 432 can determine whether or not to authorize the new network device based on the policy information stored in the database 431. The policy management unit 432 can also notify the administrator of the detection of a new network device, and then determine whether or not to authorize the network device based on a control input received from the administrator.

[0052] The policy management unit 432 can also transmit corresponding authorization information to the management device 13 when it determines whether authorization is required for the new network device.

[0053] The management device 13 can regulate access to the network 1 using ARP (Address Resolution Protocol) packet modulation and packet forwarding.

[0054] The management device 13 may include a storage unit 131 , a transmission / reception unit 132 , and a control unit 133 .

[0055] The storage unit 131 can store various information, data, etc. processed by the management device 13. The storage unit 131 can store information (policy information, device information, etc.) received from the policy server 43. The storage unit 131 can also store address information, status information, etc. of each network device acquired by the control unit 133 (to be described later). The storage unit 131 can also temporarily store packets transmitted and received through the transmission / reception unit 132.

[0056] The transmitting / receiving unit 132 can transmit and receive information, packets, etc. between the management device 13 and other devices belonging to the network 1 .

[0057] The transceiver 132 can receive policy information, device information, etc. from the policy server 43. The transceiver 132 can notify the policy server 43 of the occurrence of an event and transmit status information, address information, etc. of the network device acquired by the management device 13 to the policy server 43.

[0058] The transceiver 132 may collect packets (e.g., ARP packets, User Datagram Protocol (UDP) packets, and Transmission Control Protocol (TCP) packets) transmitted through the L3 switch 12 within the network 1. The transceiver 132 may be connected to an 802.1Q tagged port (or trunk port) of the L3 switch 12. The 802.1Q tagged port of the L3 switch 12 is a port through which traffic of multiple VLAN bands passes. As described above, different VLAN bands may be assigned to the subnets 20, 30, and 40 of the network 1. Therefore, in order for the management device 13 to collect packets of all the subnets 20, 30, and 40 transmitted through the L3 switch 12, it must be able to access all the VLAN bands assigned to the subnets 20, 30, and 40. For this purpose, the transceiver 132 may be connected to an 802.1Q tagged port of the L3 switch 12.

[0059] The transmitting / receiving unit 132 can also transmit and receive ARP packets (ARP request packets, ARP response packets, etc.) to and from each network device connected to the network 1 (for example, the in-home terminal 22).

[0060] The transmitting / receiving unit 132 can also forward packets received from other network devices to a gateway (for example, the L3 switch 12 that performs a gateway function).

[0061] The control unit 133 can control the overall operation of the management device 13 .

[0062] When the operation of the management device 13 is started, the control unit 133 can receive policy information, device information of the network devices, etc. from the policy server 43 and store them in the storage unit 131 .

[0063] In addition, the control unit 133 can transmit an ARP request packet for each VLAN band (subnet band) to acquire information (address information, status information, etc.) of the network devices connected to each VLAN band (subnet band).

[0064] The control unit 133 may broadcast an ARP request packet including the IP address of a network device whose information is to be confirmed as destination address information to a subnet to which the network device belongs. Thereafter, the control unit 133 may determine status information of a corresponding network device based on whether an ARP response packet is received in response to the transmitted ARP request packet. That is, if the control unit 133 transmits an ARP request packet at least once within a predetermined time and then does not receive an ARP response packet from the corresponding network device within a predetermined time, the control unit 133 may determine that the network device is in an offline state. If the control unit 133 receives an ARP response packet from the corresponding network device within a predetermined time after transmitting an ARP request packet, the control unit 133 may determine that the network device is in an online state. When the control unit 133 determines that the state of each network device is online or offline, the control unit 133 may set status information of each network device based on the determined state and store the set status information in the storage unit 131. Here, the online state may indicate that a connection between the network device and the network 1 is activated, and the offline state may indicate that a connection between the network device and the network 1 is deactivated.

[0065] When the control unit 133 acquires state information, it can compare the acquired state information with previous state information of the network device to detect a state change event. Here, the previous state information of the network device can be acquired from device information of the network device received from the policy server 43 or from previous state information of the network device stored in the storage unit 131. When the control unit 133 detects a network device whose state has changed from an offline state to an online state or from an online state to an offline state, it can determine that a state change event has occurred for the network device. When the control unit 133 detects the occurrence of a state change event in at least one network device, it can notify the policy server 43 of the occurrence of the state change event. In addition, the control unit 133 can transmit updated state information to the policy server 43 to update the device information stored in the policy server 43.

[0066] After transmitting an ARP request packet to a network device, the control unit 133 can, when it receives an ARP response packet in response to the ARP request packet, analyze the received ARP response packet to acquire address information (IP address and MAC address) of each network device. A network device that has confirmed its own IP address from the destination address information in the ARP request packet transmitted from the management device 13 can transmit an ARP response packet containing its own IP address and MAC address as source address information. Therefore, when the control unit 133 receives an ARP response packet, it can acquire address information (IP address and MAC address) of the corresponding network device from the source address information (source IP address and source MAC address) contained in the response packet.

[0067] The control unit 133 can collect status information and address information of the home terminals 22 installed in each household in the apartment complex using the method described above, and can also confirm which subnet 20 (VLAN band) each home terminal 22 belongs to.

[0068] The control unit 133 can identify the home terminals 22 connected to each subnet 20 based on the information collected in the above-mentioned manner, and can block communication between the home terminals 22 of different households belonging to the same subnet 20 using ARP packet modulation.

[0069] The control unit 133 can generate modulated ARP response packets for modulating the MAC address in the ARP table of each indoor terminal 22 based on the address information of each indoor terminal 22. Each modulated ARP response packet can include the IP address of the indoor terminal 22 that is the target of MAC address modulation and the modulated MAC address as source address information. The modulated MAC address can be a meaningless MAC address that is not suitable for communication.

[0070] When the control unit 133 generates the modulated ARP response packet, it can transmit it to the subnetwork 20 to which the indoor terminal 22, the MAC address of which is to be modulated, belongs. As a result, other indoor terminals 22 in the same subnetwork 20 that have received the modulated ARP response packet can update their own stored ARP tables based on the source address information included in the received ARP response packet. In other words, each indoor terminal 22 that has received the modulated ARP response packet can acquire the source IP address and source MAC address from the received ARP response packet and change the MAC address corresponding to the source IP address to the source MAC address in its own ARP table.

[0071] The ARP table of each network device can include address information (IP addresses and MAC addresses) of network devices belonging to the same broadcast domain (e.g., subnet) as the network device, and address information (IP addresses and MAC addresses) of gateways to which the network device is connected. Each home terminal 22 references the address information of the opposite home terminal 22 stored in this ARP table to communicate with other home terminals 22 belonging to the same subnet 20. Therefore, if the MAC address in the ARP table that an home terminal 22 belonging to the same subnet 20 references to communicate with another home terminal 22 is modified to a MAC address that does not allow communication, the home terminal 22 will not know the correct MAC address of the other home terminal 22 belonging to the same subnet 20, and will not be able to communicate directly with the other home terminal 22.

[0072] The control unit 133 can also regulate access between network devices belonging to different subnets using ARP packet modulation and packet forwarding.

[0073] The control unit 133 can generate a modulated ARP response packet for each subnet requiring access control, modulating the MAC address of the gateway (e.g., L3 switch 12) to the MAC address of the management device 13, and transmit the modulated ARP response packet to each subnet. The modulated ARP response packet can include the IP address of the gateway (L3 switch 12) and the MAC address of the management device 13 as source address information. Each network device that receives the modulated ARP response packet can update the MAC address of the gateway to the MAC address of the management device 13 in its stored ARP table. As a result, when a specific network device transmits a packet destined for an outside subnet (another subnet or an external network of network 1), the packet can be delivered to the management device 13 instead of the gateway of the L3 switch 12. In other words, when each network device transmits a packet destined for an outside subnet (the Internet or another subnet), the control unit 133 can receive the transmitted packet on behalf of the gateway.

[0074] When the control unit 133 receives a packet on behalf of the gateway, it can check the source subnet and destination subnet of the received packet based on the source IP address and destination IP address of the received packet. Furthermore, the control unit 133 can check whether access from the source subnet to the destination subnet is permitted based on policy information (communication permission policy between VLAN bands (or subnet bands)) received from the policy server 43. If the communication permission policy prohibits access from the source subnet to the destination subnet, the control unit 133 can discard the packet without forwarding it, thereby blocking the access. For example, this case applies when an indoor terminal 22 transmits a packet to connect to an indoor terminal 22 belonging to another building (another subnet 20). In this case, the packet transmitted from the indoor terminal 22 can be discarded and its transmission can be blocked. If the communication permission policy permits access from the source subnet to the destination subnet, the control unit 133 can forward the packet to the gateway (L3 switch 12) so that the packet can be successfully transmitted to the destination. For example, this case applies when the in-home terminal 22 transmits a packet to connect to a commonly used network device in an apartment complex (e.g., CCTV 31, parking management system 32, complex entrance door 33, shared entrance door 34, etc.), in which case the packet transmitted from the in-home terminal 22 is forwarded to the gateway to be delivered successfully to the destination.

[0075] Even if the received packet is a packet to be transmitted to an external network of the network 1, the control unit 133 can forward the packet to the gateway (L3 switch 12) so that the packet can be transmitted normally.

[0076] When a packet is forwarded from the management device 13, the gateway (L3 switch 12) can check the destination address of the forwarded packet and transmit the packet to the destination subnet or external network.

[0077] The control unit 133 may continuously analyze packets received from the network devices and update the status information of each network device. When the control unit 133 receives a packet, it may determine whether the network device that transmitted the packet is already registered in the policy server 43 based on the source address information of the received packet. If the network device that transmitted the packet is already registered, the control unit 133 may determine that the network device is online. Furthermore, when the control unit 133 determines that a network device that has not transmitted a packet for a predetermined period of time is identified among the network devices registered in the policy server 43 (i.e., a network device whose address information is registered in the device information of the policy server 43), it may determine the status of the network device using an ARP packet as described above. That is, the control unit 133 may transmit an ARP request packet to determine the status of the network device and determine the status of the network device based on whether an ARP response packet is received in response to the ARP request packet.

[0078] The control unit 133 can also continuously analyze packets received from network devices to detect new network devices attempting to newly connect to the network 1. When the control unit 133 receives a packet from a network device, it acquires source address information (source IP address and source MAC address) from the received packet and compares it with address information of previously registered network devices to determine whether the network device that transmitted the packet is a new device. If the control unit 133 does not find address information identical to the source address information acquired from the received packet among the address information of previously registered network devices, it can determine that the network device that transmitted the packet is a new device that has newly connected to the network 1. When the control unit 133 determines that the network device that transmitted the packet is a new device, it can notify the policy server 43 of the occurrence of a new device detection event and transmit address information (IP address and MAC address) of the network device to the policy server 43.

[0079] When the policy server 43 is notified by the management device 13 that a new network device has been detected, the policy server 43 can determine whether or not to authorize the new network device based on the access management policy or a control input received from the administrator. When the new network device is authorized, the policy server 43 can register the new network device in the network 1 and include the address information of the new network device in the device information in the database 431. The policy server 43 can also transmit information indicating whether or not the new network device is authorized to the management device 13.

[0080] When the control unit 133 receives authorization information (authorized / unauthorized) for a new network device from the policy server 43, it can block the new network device's access to the network 1 depending on whether the new network device is authorized. If the new network device is an unauthorized device, the control unit 133 can use the modulated ARP response packet to modulate the MAC addresses of network devices belonging to the same subnet as the unauthorized network device into meaningless MAC addresses that cannot be communicated with in the ARP table of the unauthorized network device. That is, the control unit 133 can generate a modulated ARP response packet to modulate the MAC addresses of network devices belonging to the same subnet as the unauthorized network device into meaningless addresses and transmit the modulated ARP response packet to the subnet to which the unauthorized network device belongs. Upon receiving the modulated ARP response packet, the unauthorized network device updates its ARP table based on the address information acquired from the modulated ARP response packet, thereby preventing the unauthorized network device from identifying the correct MAC address of the network device.

[0081] The control unit 133 can also block unauthorized network devices from accessing network devices outside the subnetwork to which the unauthorized network devices belong by modifying the MAC address of the gateway to a meaningless address in the ARP table of the unauthorized network devices. That is, the control unit 133 transmits an ARP response packet for modifying the MAC address of the gateway (e.g., L3 switch 12) to a meaningless MAC address, thereby modifying the MAC address of the gateway to a meaningless MAC address in the ARP table of the unauthorized network devices. This can block communications between the unauthorized network devices and not only other network devices in the subnetwork to which the unauthorized network devices belong, but also network devices in other subnetworks that the unauthorized network devices should access through the gateway.

[0082] The control unit 133 can also block unauthorized network devices from accessing other network devices using the packet forwarding method described above. When an unauthorized network device is detected, the control unit 133 can transmit an ARP response packet to the subnet to which the unauthorized network device belongs, in order to change the MAC address of the gateway in the ARP table of the unauthorized network device to the MAC address of the management device 13. As a result, the MAC address of the gateway in the ARP table of the unauthorized network device is changed to the MAC address of the management device 13, and packets transmitted by the unauthorized network device can be delivered to the management device 13 instead of the gateway. Since the management device 13 already knows that the network device is an unauthorized device, when a packet is received from the unauthorized network device, it can discard the packet and block communication of the unauthorized network device.

[0083] The control unit 133 can also analyze the received packets to check whether or not the address of the network device has been stolen (IP address theft, MAC address theft, or IP address and MAC address theft).

[0084] When a packet is received, the control unit 133 can detect a network device that has stolen an IP address or MAC address by comparing the source address information of the received packet with the address information of devices registered in the policy server 43. If the source address information extracted from the collected packet has the same IP address but a different MAC address as a network device already registered in the policy server 43, the control unit 133 can determine that the network device that transmitted the packet has stolen an IP address. Furthermore, if the source address information extracted from the collected packet has the same MAC address but a different IP address as a network device already registered in the policy server 43, the control unit 133 can determine that the network device that transmitted the packet has stolen a MAC address.

[0085] The control unit 133 can also analyze ARP probe packets transmitted from each network device to detect a network device that has stolen IP and MAC addresses.

[0086] RFC 5227, the proposed standard for IPv4 Address Conflict Detection, specifies ARP probe packets. In ACD, ARP probe packets are used by hosts to check whether their IP addresses are already in use within their own network and to prevent IP conflicts. A host broadcasts an ARP probe packet with an ARP Opcode set to 1 as an ARP request within its own network and waits for a response packet (a packet with an ARP Opcode set to 2). When transmitting an ARP probe packet (ARP request), a host can set the source MAC address in the header to its own MAC address and the source IP address to 0.0.0.0. A host can also set the destination MAC address in the ARP probe packet header to 00:00:00:00:00:00 and the destination IP address to its own IP address. To prevent IP address conflicts, such ARP probe packets do not update the ARP tables of other hosts on the same network.

[0087] Each network device (host) in network 1 repeatedly broadcasts an ARP probe packet whenever its IP address changes. Therefore, a stealing device that copies the address data of another network device and changes its own IP address and MAC address broadcasts the ARP probe packet within the network to which the cloned IP address belongs. As described above, an ARP probe packet (ARP request) transmitted from each network device (host) can include the IP address and MAC address of the network device that transmitted it. Therefore, when the control unit 133 receives an ARP probe packet transmitted as an ARP request from a network device, it can detect the IP address and MAC address of the corresponding network device from the received ARP probe packet. The control unit 133 can also compare the detected IP address and MAC address with the address information registered in the policy server 43 to determine whether the device is a stealing device that copies and uses the IP address and MAC address of another network device.

[0088] In addition to when an IP address is changed, each network device can also transmit ARP probe packets when a network interface changes from an inactive state to an active state, when a network device returns from a power-saving mode to a normal mode, when a change occurs in the link status with the network 1 (e.g., the connection status of an Ethernet cable), when an 802.11 wireless interface is associated with a new base station, etc. In other words, even a normal network device, not a pirating device, can repeatedly broadcast ARP probe packets when its connection to the network changes from an offline state to an online state.

[0089] Therefore, the control unit 133 may additionally check the status information of the network device that transmitted the ARP probe packet to prevent erroneous identification of a normal network device as a stolen device. If the same address information as the address information newly collected through the ARP probe packet has already been registered in the policy server 43, the control unit 133 may additionally check the status information of the corresponding network device before receiving the ARP probe packet to finally determine whether the address has been stolen. That is, if the status information of the corresponding network device before receiving the ARP probe packet indicates an offline state, the control unit 133 may determine that the received ARP probe packet was received from a normal device whose connection state with the network 1 has changed to an online state, and may finally determine that the corresponding network device is a normal network device and not a stolen device.

[0090] When a device that has stolen address information of another network device is confirmed as described above, the control unit 133 can notify the policy server 43 of the occurrence of an address theft event. Furthermore, based on the policy information received from the policy server 43, the control unit 133 can block the detected theft device's access to the network 1. For example, when a theft device is detected, the control unit 133 can transmit a network use blocking packet (a response packet to an ARP probe packet (ARP Probe Reply packet)) to block the theft device's use of the network.

[0091] Shared systems such as CCTV 31 and parking management systems 32 are typically kept online 24 hours a day, 365 days a year, allowing constant communication with the in-home terminal 22 and the apartment complex server. Therefore, if someone steals the address of such a shared system for malicious purposes, they may be able to illegally access other network devices. In network 1, management device 13 detects such illegal address theft and blocks the stolen device from accessing other network devices in advance, thereby blocking attempts to infiltrate network 1 by stealing the address of the shared system.

[0092] Hereinafter, the access control method in the network 1 in the apartment complex will be described with reference to FIGS.

[0093] 3 illustrates a method for controlling access between network devices in a network 1 according to one embodiment. The method of FIG. 3 can be performed by the access control system 100 described with reference to FIG.

[0094] Referring to FIG. 3, when the management device 13 starts its operation, it can obtain status information and address information of each network device registered in the network 1 (S11).

[0095] In step S11, the management device 13 can transmit an ARP request packet to acquire status information and address information of each network device. The management device 13 can generate an ARP request packet for each network device, including the IP address of the network device as destination address information, and transmit the packet to the subnet to which the network device belongs. The control unit 133 can then determine status information of the corresponding network device based on whether an ARP response packet is received in response to the transmitted ARP request packet. Furthermore, after transmitting the ARP request packet to a network device, if the management device 13 receives an ARP response packet in response to the ARP request packet, it can acquire address information (IP address and MAC address) of each network device from the source address information of the received ARP response packet.

[0096] When the management device 13 confirms the status information and address information of each network device, it can use an ARP packet to modulate the MAC addresses of the network devices and gateways that require access control in the ARP table of each network device (S12).

[0097] In step S12, the management device 13 modulates the MAC addresses of other on-premise terminals 22 to meaningless addresses in the ARP tables of each on-premise terminal 22 in order to block communications between the on-premise terminals 22. To this end, the management device 13 can generate modulated ARP response packets for modulating the MAC addresses of each on-premise terminal 22 in the ARP table. Each modulated ARP response packet can include the IP address of the corresponding on-premise terminal 22 and a modulated MAC address (a MAC address unsuitable for communication) as source address information. The management device 13 can transmit the ARP response packets generated in this manner to the subnetwork 20 to which the corresponding on-premise terminal 22 belongs. As a result, the corresponding MAC address in the ARP table of the on-premise terminal 22 belonging to the subnetwork 20 is modulated to a MAC address that does not allow communication, thereby blocking access of other on-premise terminals to the corresponding on-premise terminal 22. In this manner, the management device 13 can block all direct communication between the on-premises terminals 22 by changing the MAC addresses of all other on-premises terminals in the ARP table of each on-premises terminal 22 to addresses that do not allow communication.

[0098] In step S12, the management device 13 can modify the MAC address of the gateway to the MAC address of the management device 13 in the ARP table of each network device 22 to restrict access between different subnets 20, 30, and 40. To this end, the management device 13 can transmit a modified ARP response packet including the IP address of the actual gateway (the IP address of the L3 switch 12) and the MAC address of the management device 13 as source address information to the subnet to which each network device belongs. As a result, the MAC address of the gateway can be modified to the MAC address of the management device 13 in the ARP table of each network device. Therefore, when each network device attempts to transmit a packet outside its own subnetwork, it transmits the packet by referring to the MAC address of the management device 13 rather than the gateway, and the transmitted packet can be received by the management device 13 instead of the gateway.

[0099] After registering the MAC address of the gateway in the ARP table, the management device 13 can receive packets transmitted by network devices belonging to each subnet to other networks (e.g., other subnets) on behalf of the gateway (S13).

[0100] When the management device 13 receives the packet, it analyzes the packet and can check whether the network device that transmitted the packet, that is, the source of the packet, is a new network device (S14).

[0101] In step S14, the management device 13 acquires source address information (source IP address and source MAC address) from the received packet and can compare it with address information of network devices already registered in the policy server 43. If the management device 13 does not find address information identical to the source address information acquired from the received packet among the address information of already registered network devices, it can determine that the source of the packet is a new device that has just been connected to the network 1. If the management device 13 finds address information identical to the source address information acquired from the received packet among the address information of already registered network devices, it can determine that the source of the packet is a network device already registered in the network 1.

[0102] When the management device 13 confirms through step S14 that the packet sender is a network device already registered in the network 1, it can determine whether or not to block the received packet based on the access management policy received from the policy server 43 (S15).

[0103] In step S15, the management device 13 extracts the source IP address and the destination IP address from the received packet, and can check whether the communication permission policy between VLAN bands (or subnet bands) is set to allow communication between the subnet to which the source IP address belongs and the subnet to which the destination IP address belongs. If the communication permission policy prohibits communication between the VLAN band (subnet band) to which the source IP address belongs and the VLAN band (subnet band) to which the destination IP address belongs (for example, when an in-home terminal 22 attempts to connect to an in-home terminal 22 that belongs to another building (another subnet 20)), the management device 13 can determine that it is necessary to block the packet. On the other hand, if the communication permission policy allows communication between the VLAN band (subnet band) to which the source IP address belongs and the VLAN band (subnet band) to which the destination IP address belongs (for example, if the in-home terminal 22 attempts to connect to a network device commonly used within an apartment complex (for example, CCTV 31, parking management system 32, complex entrance door 33, shared entrance door 34, etc.)), the management device 13 can determine that there is no need to block the packet.

[0104] If blocking of the packet is required by policy (S16), the management device 13 can discard the packet and block communication (S17). On the other hand, if blocking of the packet is not required (S16), the management device 13 can forward the packet to a real gateway (e.g., L3 switch 12) (S18) so that the packet can be normally delivered to the destination.

[0105] If the management device 13 determines in step S14 that the sender of the received packet is a new network device, it can transmit the address information of the new network device to the policy server 43 to notify the detection of the new network device. The policy server 43, which has been notified of the detection of the new network device by the management device 13, can determine whether or not to authorize the new network device based on a policy or a control input entered from the administrator (S19). If the new network device is an authorized device (S20), the policy server 43 can register the new network device in the network 1 (S21) and include the address information of the new network device in the device information of the database 431.

[0106] When the policy server 43 determines whether the new network device needs to be authorized, it can transmit information regarding whether authorization is necessary to the management device 13. Upon receiving this information, the management device 13 can block the unauthorized device's access to the network 1 if the new network device is an unauthorized device (S20) (S22).

[0107] In step S22, the management device 13 can use the modulated ARP response packet to modulate the MAC addresses of network devices that belong to the same subnet as the unauthorized network device in the ARP table of the unauthorized network device to meaningless MAC addresses that cannot be used for communication, thereby preventing the unauthorized network device from confirming the correct MAC addresses of other network devices that belong to the same subnet as itself, and blocking communication with the other network devices.

[0108] In step S22, the management device 13 can also use the modulated ARP response packet to modulate the MAC address of the gateway to a meaningless address in the ARP table of the unauthorized network device, thereby blocking the unauthorized network device from communicating with not only other network devices in its own subnet but also network devices in other subnets that it must access through the gateway.

[0109] In step S22, the management device 13 can also use an ARP packet modulation and packet forwarding method to block unauthorized network devices from accessing other network devices. When an unauthorized network device is detected, the management device 13 can transmit an ARP response packet to the subnet to which the unauthorized network device belongs, for modulating the MAC address of the gateway to the MAC address of the management device 13 in the ARP table of the unauthorized network device. In this way, packets transmitted by the unauthorized network device are delivered to the management device 13 instead of the gateway, and since the management device 13 already knows that the network device is an unauthorized device, it can discard packets received from the unauthorized network device.

[0110] 4 is a schematic diagram illustrating a method for blocking access of an address stealing device in a network 1 according to one embodiment. The method of FIG. 4 can be performed by the access control system 100 described with reference to FIG.

[0111] Referring to FIG. 4, when the management device 13 collects packets from the network devices (S31), it analyzes each packet and determines whether the address of the network device that transmitted the packet has been stolen (S32).

[0112] In step S32, the management device 13 can detect a network device that has stolen an IP address or MAC address by comparing the source address information of the collected packets with the address information of devices registered in the policy server 43. If the source address information extracted from the collected packets has the same IP address but a different MAC address as a network device already registered in the policy server 43, the management device 13 can determine that the network device that transmitted the packet has stolen an IP address. Furthermore, if the source address information extracted from the collected packets has the same MAC address but a different IP address as a network device already registered in the policy server 43, the management device 13 can also determine that the network device that transmitted the packet has stolen a MAC address.

[0113] In step S32, the management device 13 can also detect a network device that has stolen its IP and MAC addresses by analyzing the ARP probe packets transmitted from each network device. The management device 13 can detect the IP address and MAC address of the corresponding network device from the ARP probe packet transmitted as an ARP request from the network device. The management device 13 then compares the detected IP address and MAC address with the address information registered in the policy server 43 to determine whether the device is a stealing device that duplicates and uses the IP address and MAC address of another network device. At this time, the management device 13 can additionally check the status information of the network device that transmitted the ARP probe packet to prevent it from mistakenly identifying a normal network device as a stolen device. If the status information of the corresponding network device indicates an offline state before receiving the ARP probe packet, the management device 13 can determine that the received ARP probe packet was received from a normal device whose connection status with the network 1 has changed to an online state, and can finally determine that the corresponding network device is a normal network device and not a stolen device.

[0114] If the management device 13 determines in step S32 that the network device is an address theft device (S33), it can notify the policy server 43 that an address theft device has been detected (S34). Furthermore, it can block the detected address theft device's access to the network 1 based on the policy information received from the policy server 43 (S35). For example, when an address theft device is detected, the control unit 133 can transmit a network use blocking packet (a response packet to the ARP probe packet) to block the theft device's use of the network.

[0115] If the management device 13 determines in step S32 that the network device is not an address stealing device (S33), it can process the packet received from the network device according to the set policy (S36). For example, it can process the packet through steps S14 to S22 of FIG. 3.

[0116] According to the above-described embodiment, the access control system 100 can effectively block direct communication between on-premises terminals 22 registered in the same subnet 20 by using modulated ARP packets to modulate the MAC addresses of other on-premises terminals 22 held by each on-premises terminal 22 into addresses that do not allow communication.

[0117] In addition, the access control system 100 modulates the MAC address of the gateway held by each network device to the MAC address of the management device 13, and after the management device 13 receives the packet on behalf of the gateway, it discards or forwards the packet according to policy, thereby effectively blocking access between subnets that are not allowed to communicate with each other (for example, subnet 20 to which in-house terminals 22 in different buildings are connected).

[0118] In addition, the management device 13 of the access control system 100 can analyze collected packets to detect and block access by unauthorized network devices or address theft devices in advance.

[0119] The above-described embodiments can be implemented as computer-readable code on a medium having a program recorded thereon. Computer-readable media include all types of storage devices that store data readable by a computer system. Examples of computer-readable media include hard disk drives (HDDs), solid-state disks (SSDs), silicon disk drives (SDDs), ROMs, RAMs, CD-ROMs, magnetic tapes, floppy disks, and optical data storage devices, as well as media embodied in the form of carrier waves (e.g., transmissions via the Internet). The computer may also include a terminal control unit. Therefore, the above detailed description should not be construed as limiting in all respects, but should be considered as illustrative. The scope of the present invention should be determined by reasonable interpretation of the appended claims, and all modifications within the scope of the present invention are encompassed within the scope of the present invention.

Claims

1. 1. An access control method in a network including a plurality of home terminals located in different households, comprising: a step in which a management device transmits an ARP (Address Resolution Protocol) request packet to the plurality of home terminals; The management device analyzes a first ARP response packet received in response to the ARP request packet to acquire address information of the plurality of on-premises terminals; the management device generating a second ARP response packet in which a MAC (Media Access Control) address is modulated; and the management device modifies the MAC address of each of the on-premises terminals in the ARP tables of the on-premises terminals by transmitting the second ARP response packet to the on-premises terminals; The second ARP response packet is an ARP response packet including the IP address of the home terminal whose MAC address is to be modified in each ARP table and the modified MAC address as source address information, The access control method, wherein the modulated MAC address is a MAC address with which communication is not possible.

2. The network includes a policy server that manages access management policies, including a Virtual Local Area Network (VLAN) bandwidth allocation policy and a communication permission policy, for each of a plurality of subnets to which different network devices are connected, and a plurality of network devices including the plurality of home terminals; The access control method includes: the management device transmitting a third ARP response packet with a modulated MAC address to the plurality of network devices, so that the MAC address of the gateway in the ARP tables of the plurality of network devices is modulated to the MAC address of the management device; receiving packets transmitted from the plurality of network devices to a gateway by the management device; and The access control method according to claim 1 , further comprising the step of: the management device transmitting or discarding the received packet to the gateway based on the access control policy.

3. The step of transmitting or discarding the received packet to the gateway comprises:

3. The access control method according to claim 2, further comprising a step of discarding the received packet when the communication permission policy prohibits communication between the VLAN band to which the destination IP address of the received packet belongs and the VLAN band to which the source IP address of the received packet belongs.

4. The step of transmitting or discarding the received packet to the gateway comprises:

3. The access control method according to claim 2, further comprising a step of transmitting the received packet to the gateway when the communication permission policy allows communication between a VLAN band to which the destination IP address of the received packet belongs and a VLAN band to which the source IP address of the received packet belongs.

5. The step of transmitting or discarding the received packet to the gateway comprises:

3. The access control method according to claim 2, further comprising the step of transmitting the received packet to the gateway if a destination IP address of the received packet belongs to an external network of the network.

6. 3. The access control method according to claim 2, wherein the communication permission policy is set so that communication is prohibited between subnets to which the plurality of home terminals belong.

7. The management device acquires address information of the network device that transmitted the packet from the received packet; and 3. The access control method according to claim 2, further comprising the step of: said management device detecting a new network device by comparing address information acquired from said received packet with address information managed by said policy server.

8. The access control policy further includes a policy for determining whether the new network device needs to be authorized; The access control method includes: the policy server determining whether to authorize the new network device based on the access management policy or control input from an administrator; and 8. The access control method of claim 7, further comprising the step of the management device transmitting a fourth ARP request packet to the new network device to modify the MAC address of another network device in the ARP table of the new network device to a MAC address with which communication is not possible, if the new network device is an unauthorized device.

9. 9. The access control method of claim 8, further comprising the step of the management device transmitting a fifth ARP request packet to the new network device to modify the MAC address of the gateway in the ARP table of the new network device to a MAC address that cannot be communicated with or the MAC address of the management device, if the new network device is an unauthorized device.

10. The access management policy further includes a blocking policy for an address theft device; The access control method includes: the management device comparing the address information acquired from the received packet with address information managed by the policy server to detect the address theft device that has stolen the address of another network device registered on the network; and 3. The access control method according to claim 2, further comprising the step of: said management device blocking said address stealing device from said network based on said blocking policy.

11. The access control method according to claim 1 , wherein the management device is connected to an 802.1Q tagged port of an L3 switch.

12. An access control system in a network including a plurality of home terminals located in different households, a management device that transmits an ARP (Address Resolution Protocol) request packet to the plurality of on-premises terminals, analyzes a first ARP response packet received in response to the ARP request packet to acquire address information of the plurality of on-premises terminals, and transmits a second ARP response packet, the MAC (Media Access Control) address of which is modulated, to the plurality of on-premises terminals, thereby modulating the MAC address of each on-premises terminal registered in an ARP table of the plurality of on-premises terminals, thereby blocking communication between the plurality of on-premises terminals; The second ARP response packet is an ARP response packet including the IP address of the home terminal whose MAC address is to be modified in each ARP table and the modified MAC address as source address information, An access control system, wherein the modulated MAC address is a MAC address that is not capable of communication.

13. a policy server that manages access management policies, including a Virtual Local Area Network (VLAN) bandwidth allocation policy and a communication permission policy, for each of a plurality of subnets that constitute the network; the management device transmits third ARP response packets, the MAC addresses of which are modulated, to a plurality of network devices registered in the network, modulating the MAC addresses of gateways registered in the ARP tables of the plurality of network devices to the MAC address of the management device; and when a packet is received from the plurality of network devices, delivers the received packet to the gateway or discards the received packet based on the access management policy; The access control system according to claim 12 , wherein the plurality of network devices includes the plurality of home terminals.

14. The access control system of claim 13, wherein the management device discards the received packet if the communication permission policy prohibits communication between the VLAN band to which the destination IP address of the received packet belongs and the VLAN band to which the source IP address of the received packet belongs.

15. The access control system of claim 13, wherein the management device allows communication between a VLAN band to which the destination IP address of the received packet belongs and a VLAN band to which the source IP address of the received packet belongs in the communication permission policy, or transmits the received packet to the gateway if the destination IP address of the received packet belongs to an external network of the network.

16. The access control system according to claim 13, wherein the communication permission policy is set so that communication is prohibited between different subnetworks to which the plurality of home terminals belong.

17. The policy server manages address information of the plurality of network devices; The access control system of claim 13, wherein the management device acquires address information of the network device that transmitted the packet from the received packet, and compares the address information acquired from the received packet with address information managed by the policy server to detect a new network device.

18. The access control policy further includes a policy for determining whether the new network device needs to be authorized; The policy server determines whether to authorize the new network device based on the access management policy or a control input from an administrator; 18. The access control system of claim 17, wherein, if the new network device is an unauthorized device, the management device transmits a fourth ARP request packet to the new network device to modify the MAC address of another network device in the ARP table of the new network device to a MAC address that cannot be communicated with.

19. 19. The access control system of claim 18, wherein the management device transmits a fifth ARP request packet to the new network device to modify the MAC address of the gateway in the ARP table of the new network device to a MAC address that cannot be communicated with or the MAC address of the management device if the new network device is an unauthorized device.

20. The access management policy further includes a blocking policy for an address theft device; 14. The access control system of claim 13, wherein the management device compares the address information acquired from the received packet with address information managed by the policy server to detect the address-stealing device that has stolen the address of another network device registered on the network, and blocks the address-stealing device from the network based on the blocking policy.

21. The access control system according to claim 12, wherein the management device is connected to an 802.1Q tagged port of an L3 switch.

Citation Information

Patent Citations

  • Control method and device for realizing host blocking based on ARP (Address Resolution Protocol), equipment and medium

    CN114598675A

  • Network supervising system, network supervising server, and network supervising program

    JP2011004135A

  • Network isolating method of host using arp

    KR100893935B1