Anti-dhcpv6 lease renewal spoofing transmission method

By defining new types of DHCPv6 messages and adopting a two-way acknowledgement mechanism, the problem of ineffective prevention of DHCPv6 renewal spoofing attacks in the existing technology is solved, and security protection and performance optimization of IPv6 networks are achieved.

WO2025124389A1PCT designated stage expired Publication Date: 2025-06-19CHINA TELECOM CLOUD TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/138194
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-13
Filing Date
2024-12-10
Publication Date
2025-06-19

Smart Images

  • Figure CN2024138194_19062025_PF_FP_ABST
    Figure CN2024138194_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to the field of IPv6 in data communications. Disclosed is an anti-DHCPv6 lease renewal spoofing transmission method, which solves the problem that IPv6 networks are prone to DHCPv6 lease renewal spoofing attacks. The present invention improves interaction processes of DHCPv6Renew, Rebind and Reply messages and processing procedures of device apparatuses, defines DHCPv6 messages of three new types, i.e. S-New, S-Rebind and S-Reply, achieves secure address lease renewal interactions and, by means of fields carried in newly defined interaction messages, checks the security and reliability of the interactions to avoid spoofing attacks of attackers. In addition, the present invention optimizes lease renewal message interaction processes, and additionally confirms the security of the source MAC of clients, solving the problem that IPv6 networks are prone to DHCPv6 lease renewal spoofing attacks.
Need to check novelty before this filing date? Find Prior Art

Description

A transmission method to prevent DHCPv6 lease renewal fraud

[0001] This application claims priority to Chinese patent application number CN202311713627.7, filed on December 13, 2023, entitled “A Transmission Method for Preventing DHCPv6 Lease Renewal Fraud,” the entire text of which is hereby incorporated by reference. Technical Field

[0002] The present invention belongs to the field of IPv6 and DHCPv6 in data communication, and in particular relates to a transmission method for preventing DHCPv6 renewal fraud. Background Art

[0003] The IPv6 protocol features a vast address space. IPv6 addresses can be obtained automatically and statelessly, or they can be uniformly allocated in a stateful manner. DHCPv6 is one of the foundational IPv6 protocols, primarily addressing the manageability issues of stateless address acquisition in IPv6. DHCPv6 is a stateful address autoconfiguration protocol. The address assigned by a DHCPv6 server to a DHCPv6 client is leased. The lease consists of a lifetime (consisting of the address's preferred lifetime and valid lifetime) and renewal times (T1 and T2 for the IA). After the address's valid lifetime expires, the DHCPv6 client can no longer use the address. If the DHCPv6 client wishes to continue using the address before the valid lifetime expires, it must renew the address lease. To extend the valid lifetime and preferred lifetime of the address associated with the IA, the DHCPv6 client sends a Renew message to the server at time T1, containing the IA options. The IA options carry the IA address options for which the lease is to be renewed. If the DHCPv6 client does not receive a response to the renewal message sent at time T1, the DHCPv6 client sends a Rebind message to the DHCPv6 server to renew the address at time T2.

[0004] However, in actual networks, there are many malicious attacks. A typical DHCPv6 renewal attack is shown in Figure 2. The attacker forges a DHCPv6 Renew or Rebind message and sends it to the DHCPv6 server, causing the client to continuously renew the IPv6 address. As a result, the DHCPv6 server cannot release the address, continuously occupying IPv6 resources and preventing the normal recovery of IPv6 addresses.

[0005] Existing methods for preventing DHCPv6 lease renewal attacks mainly involve enabling message snooping on switches in the network, manually configuring DHCPv6 snooping on the switch ports, and generating a snooping binding table on the switch. The binding table mainly binds information such as the source MAC address of the sent DHCPv6 message and the switch port number. DHCPv6 Renew, Rebind, and DHCPv6 Reply messages are then checked for a match. Only messages that successfully match are forwarded by the device; otherwise, they are discarded.

[0006] Problems with existing technologies:

[0007] 1. The security and reliability of DHCPv6 messages cannot be verified bidirectionally:

[0008] DHCPv6 message snooping is configured manually. This requires manual configuration, which is inefficient, inflexible, and lacks applicability, and cannot be automatically verified. Manually configuring mapping relationships is a tedious and laborious task, especially for large-scale networks.

[0009] 2. DHCPv6 message snooping requires switches to maintain monitoring entries, which increases the switch burden and reduces forwarding performance. DHCPv6 snooping technology takes effect only when monitoring entries are generated on the switch and messages are compared and monitored. This increases the switch burden and reduces forwarding performance, leading to reduced overall network performance. Summary of the Invention

[0010] The technical problem to be solved by the present invention is to provide a transmission method for preventing DHCPv6 renewal spoofing in response to the shortcomings of the background technology; the security and reliability of the interaction are verified by using the fields carried in the newly defined interaction message to prevent attackers from carrying out spoofing attacks; the renewal message interaction process is optimized, the security confirmation of the client source MAC is added, and the problem that the IPv6 network is easily susceptible to DHCPv6 renewal spoofing attacks is solved.

[0011] The present invention adopts the following technical solutions to solve the above technical problems:

[0012] A transmission method for preventing DHCPv6 lease renewal fraud specifically comprises the following steps:

[0013] Step 1: Use the newly defined Message Type = 14, 15, and 16 DHCPv6 messages for secure communication.

[0014] Step 2: Use the fields carried in the message to perform hash verification;

[0015] Step 3: Optimize the interaction process and implement a two-way confirmation mechanism. The server verifies the client's MAC address. During the original DHCPv6 message exchange, the NS and NA messages with the Option field added are used to perform two-way identity authentication between the DHCPv6 client and server.

[0016] NS stands for neighbor solicitation, and NA stands for neighbor advertisement.

[0017] As a further preferred solution of the transmission method for preventing DHCPv6 renewal fraud of the present invention, in step 1, a secure address renewal DHCPv6 message S-Renew at time T1 is defined.

[0018] As a further preferred solution of the transmission method for preventing DHCPv6 renewal fraud of the present invention, in step 1, the byte Message Type=14 is defined, and 4 bytes are newly added to the original DHCPv6 message to carry the DHCPv6 random number; and a secure address renewal DHCPv6 message S-Rebind at time T2 is defined.

[0019] As a further preferred solution of the transmission method for preventing DHCPv6 renewal fraud of the present invention, in step 1, Message Type=15 is defined, and 4 bytes are added to the original DHCPv6 message to carry the DHCPv6 random number; a secure DHCPv6 reply message S-Reply is defined.

[0020] As a further preferred solution of the transmission method for preventing DHCPv6 lease renewal fraud of the present invention, the byte Message Type=16 is defined, and 4 bytes are added to the original DHCPv6 message to carry the DHCPv6 hash value; the IPv6 NS and NA messages are modified:

[0021] Four bytes are added to the original NS message to carry the DHCPv6 random number.

[0022] Four bytes are added to the original NA message to carry the DHCPv6 hash value.

[0023] As a further preferred solution of the transmission method for preventing DHCPv6 renewal fraud of the present invention, the interaction process of the address renewal DHCPv6 message S-Renew, the address renewal DHCPv6 message S-Rebind and the address renewal DHCPv6 message S-Reply is as follows:

[0024] In step 3.1, the client sends a DHCPv6 S-Renew message to the server at time T1 to notify it to renew its address lease, or sends a DHCPv6 S-Rebind message to the server at time T2 to notify it to renew its address lease.

[0025] In step 3.2, after receiving the S-Renew or S-Rebind message, the server confirms the source of the message and sends an S-NS message to request the source IPv6 MAC address of the message. The server then hashes the source MAC address, source IPv6 address, unicast IPv6 address corresponding to the destination IPv6 address, destination address, and random number of the NS message as input variables to the hash function to generate a 32-bit hash value, which is then recorded in the local table. NS stands for neighbor solicitation.

[0026] In step 3.3, after receiving the NS message, the client performs NA to reply with its own MAC address. The random number, the destination MAC address, the source IPv6 address, the destination IPv6 address, and the destination address are used as input variables of the hash function to hash the 32-bit hash value, which is then filled into the Option 2 field of the message. Option 2 is the optional field 2.

[0027] In step 3.4, after receiving the NA message, the server confirms that the MAC address matches the source MAC address of the received S-Renew or S-Rebind message. It compares the hash value carried in the received NA message with the locally stored hash value. If the comparison is consistent, it will send a DHCP reply message in response to the DHCPv6 message with Message Type = 16. The server uses the destination MAC address, Client Identifier, Server Identifier, IA Address, and the random number in the S-Renew or S-Rebind message to create a 32-bit hash value and fill it into the DHCPv6 Hash Value field of the message.

[0028] The S-Renew or S-Rebind message is a DHCP message. The S stands for Security. The MAC address stands for Media Access Control Address, a basic concept in network communications.

[0029] Client Identifier and Server Identifier are parameters in the DHCP message, client identification numbers;

[0030] IA Address is a parameter in the DHCP message, Identity Association, identity alliance.

[0031] As a further preferred embodiment of the transmission method for preventing DHCPv6 renewal fraud of the present invention, in step 3.1, a 4-byte DHCPv6 random number is added to the S-Renew message. The client generates a 32-bit hash value based on the generated random number, source MAC address, Client Identifier, and Server Identifier and saves it to the local table.

[0032] As a further preferred solution of the transmission method for preventing DHCPv6 renewal fraud of the present invention, in step 3.1, a 4-byte DHCPv6 random number is newly added to the S-Rebind message. The client will hash a 32-bit hash value based on the generated random number, source MAC address, and Client Identifier and save it in the local table entry.

[0033] As a further preferred solution of the transmission method for preventing DHCPv6 renewal fraud of the present invention, the processing flow of IPv6 address renewal of a client device supporting the address renewal security mechanism is as follows:

[0034] The client initiates the IPv6 address lease renewal process and sends a DHCPv6 message with Message Type = 14.

[0035] The 32-bit hash value is generated by hashing the random number, source MAC address, client identifier, and server identifier in the packet and saved in the local table.

[0036] Check whether an NS request is received. If not, the DHCPv6 server is not notified and the address is not renewed. The address renewal process is executed again.

[0037] If received, the DHCPv6 server responds to the NA message with its own MAC address. It then checks whether it has received the DHCPv6 Reply message from the server. If not, it determines that the DHCPv6 server has not been notified, does not renew the address lease, and executes the address release process again.

[0038] If received, the DHCPv6 hash value in the reply message is extracted and the hash value in the message is determined to be consistent with the locally saved hash value:

[0039] If they match, the DHCPv6 Reply message is deemed secure and authentic, and the address lease is renewed.

[0040] If they are inconsistent, the received message is determined to be an attack message, discarded, logged, and reported to the administrator.

[0041] As a further preferred solution of the transmission method for preventing DHCPv6 renewal fraud of the present invention, the processing flow of renewing the IPv6 address of a server-side device supporting the address renewal security mechanism is as follows:

[0042] When the server receives a DHCPv6 Renew or Rebind message, it checks whether the DHCPv6 address renewal security mechanism is configured. If not, it responds with a normal Reply message with Message Type = 7.

[0043] If configured, parse the received DHCPv6 message with Message Type = 14 or 15 and perform an NS request for its source address; check whether an NA reply message is received. If not, respond with a normal Message Type = 7 Reply message; if received, determine whether the reply MAC in the NA message is consistent with the source MAC in the S-Renew or S-Rebind message; if they are consistent, respond with a DHCPv6 message with Message Type = 16; and use the destination MAC address, Client Identifier, Server Identifier, and the random number in the S-Renew or S-Rebind message to hash a 32-bit hash value to fill the DHCPv6 Hash Value field in the message; if they are inconsistent, determine that the received Renew or Rebind message is an attack message, discard the message, record the attack log, and report it to the administrator.

[0044] Compared with the prior art, the present invention adopts the above technical solution and has the following technical effects:

[0045] This invention improves the interaction process of DHCPv6 Renew, Rebind, and Reply messages and the processing flow of equipment. It defines three new types of DHCPv6 messages: S-Renew, S-Rebind, and S-Reply, achieving secure address renewal. The security and reliability of the interaction are verified using fields carried in the newly defined interaction messages, preventing spoofing attacks. Furthermore, the renewal message interaction process is optimized, and secure verification of the client's source MAC address is added, addressing the vulnerability of IPv6 networks to DHCPv6 renewal spoofing attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.

[0047] FIG1 is a schematic diagram of a DHCPv6 lease renewal attack network in FIG1 IPv6 of the present invention;

[0048] FIG2 is a DHCPv6 message structure of the present invention;

[0049] FIG3 is an S-Renew message structure of the present invention;

[0050] FIG4 is an S-Rebind message structure of the present invention;

[0051] FIG5 is an S-Reply message structure of the present invention;

[0052] FIG6 is an S-NS message structure of the present invention;

[0053] FIG7 is a S-NA message structure of the present invention;

[0054] FIG8 is an interaction process of the original IPv6 address renewal T1 moment of the present invention;

[0055] 9 is the original IPv6 address renewal T2 moment interaction process of the present invention;

[0056] 10 is an improved IPv6 address renewal T1 moment interaction process of the present invention (agree to renew);

[0057] 11 is an improved IPv6 address renewal T1 moment interaction process of the present invention (do not agree to renew);

[0058] 12 is an improved IPv6 address renewal T2 moment interaction process of the present invention (agree to renew);

[0059] 13 is an improved IPv6 address renewal T2 moment interaction process of the present invention (do not agree to renew);

[0060] 14 is a process of renewing a Pv6 address lease by a client supporting a secure DHCPv6 mechanism according to the present invention;

[0061] FIG. 15 is a diagram showing the process of the improved DHCPv6 server processing an address renewal request according to the present invention. DETAILED DESCRIPTION

[0062] The technical solution of the present invention is further described in detail below with reference to the accompanying drawings:

[0063] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. The present invention is described in detail below based on the drawings and preferred embodiments. The purpose and effect of the present invention will become more clear. It should be understood that the specific embodiments described here are only used to explain the present invention and are not used to limit the present invention.

[0064] Based on the above-mentioned problems, this paper proposes a transmission method and device to prevent DHCPv6 renewal spoofing. It mainly defines three DHCPv6 messages: the DHCPv6 secure address renewal message S-Renew (Security Renew), S-Rebind (Security Rebind), and the DHCPv6 secure reply message S-Reply (Security Reply). The newly defined fields carried in the interaction message are used to verify the security and reliability of the interaction, preventing attackers from carrying out spoofing attacks. At the same time, the renewal message interaction process is optimized, and the security confirmation of the client source MAC is added, solving the problem of IPv6 networks being vulnerable to DHCPV6 renewal spoofing attacks.

[0065] A transmission method for preventing DHCPv6 lease renewal fraud, as shown in FIG1 , specifically comprises the following steps:

[0066] (1) When the DHCPv6 client has anti-lease renewal spoofing enabled, it uses the newly defined Message Types 14, 15, and 16 for secure communication. Hash verification is performed using the fields carried in the message. Referring to Figure 2, the first few fields are Msg-Type, also known as the Message Type. Different values ​​indicate different message types.

[0067] Refer to Figure 2 for Message Type. The first few fields are Msg-Type, which is also the Message Type. Different values ​​indicate different message types.

[0068] (2) Optimize the interaction process and implement a two-way confirmation mechanism. The server actively authenticates the client's MAC address. During the original DHCPv6 message exchange, the NS and NA messages with the added option field are used to perform two-way authentication between the DHCPv6 client and server. Referring to Figure 2, the option field is located below the IANA field, which means that an optional field is added below the regular message.

[0069] Add DHCPv6 message: Currently, the DHCPv6 protocol defines 13 types of messages, and the client and server interact through these 13 messages. The DHCPv6 message format is shown in Figure 2, where the first byte is Message-Type, which is used to identify different types of DHCPv6 messages. Currently, the value of this field only uses 13. Bytes 2 to 4 are the ID for message interaction. Bytes 5 to 8 are the client's DUID (unique identifier of the DHCP device). Bytes 9 to 12 are the server's DUID (unique identifier of the DHCP device). Bytes 13 to 16 are IA_NA (Identity Association for Non-temporary Address), which is used to transfer the allocated IPv6 address or the IPv6 address to be released when the address is released.

[0070] The original address renewal interaction messages are Renew (Message Type=5) sent at time T1 and Rebind (Message Type=6) sent at time T2, as well as the reply message Reply (Message Type=7). There is a lack of mutual verification, which makes it easy for fraud to occur.

[0071] Now, we define a secure address renewal DHCPv6 message, S-Renew (Security Renew), at time T1, as shown in Figure 3. Its Message Type is defined as 14, and 4 bytes are added to the original DHCPv6 message to carry the DHCPv6 nonce. We define a secure address renewal DHCPv6 message, S-Rebind (Security Rebind), at time T2, as shown in Figure 4. Its Message Type is defined as 15, and 4 bytes are added to the original DHCPv6 message to carry the DHCPv6 nonce. We define a secure DHCPv6 reply message, S-Reply (Security Reply), as shown in Figure 5. Its Message Type is defined as 16, and 4 bytes are added to the original DHCPv6 message to carry the DHCPv6 hash value. Simultaneously, the IPv6 NS and NA messages are modified. 4 bytes are added to the original NS message to carry the DHCPv6 nonce, as shown in Figure 6. 4 bytes are added to the original NA message to carry the DHCPv6 hash value, as shown in Figure 7.

[0072] Original message exchange process: Without DHCPv6 security configuration, the client and server interact using the original process, as shown in Figure 8. At time T1, the client sends a DHCPv6 Renew message to notify the server to renew the IPv6 address. The source MAC address in the message is the client interface MAC_A, the destination MAC address is the multicast MAC address, the source IP address is the link-local address, the destination IP address is the multicast address, the source port number is 546, the destination port number is 547, the protocol is UDP, the message type is 8, the client identifier is its own DUID, the server identifier is the server's DUID, and the IA address carries the IPv6 address to be renewed. T1 is agreed to be 0.5 times the priority lifetime, and T2 is 0.8 times the priority lifetime. If the client does not receive a reply message from the DHCPv6 server, it will send a Rebind message at time T2. The exchange process is shown in Figure 9.

[0073] S-Renew, S-Rebind and S-Reply message interaction process: When the client configures the security mechanism, the interaction between the client and the server, as shown in Figures 10, 11, 12 and 13, mainly consists of four steps:

[0074] (1) The client sends a DHCPv6 S-Renew message at time T1 to notify the server of address renewal, or sends a DHCPv6 S-Rebind message at time T2 to notify the server of address renewal. The difference from the original process is that a 4-byte DHCPv6 random number is added to the S-Renew message. The client will hash the generated random number, source MAC address, Client Identifier, and Server Identifier to generate a 32-bit hash value and save it to the local table. The S-Rebind message also adds a 4-byte DHCPv6 random number. The client will hash the generated random number, source MAC address, and Client Identifier to generate a 32-bit hash value and save it to the local table.

[0075] (2) After receiving the S-Renew or S-Rebind message, the server confirms the source of the message. It sends an S-NS message to request the source IPv6 MAC address of the message. At the same time, the source MAC address, source IPv6 address, unicast IPv6 address corresponding to the destination IPv6 address, destination address, and random number of the NS message are hashed as input variables of the hash function to generate a 32-bit hash value, which is recorded in the local table. S-NS stands for neighbor request.

[0076] (3) After receiving the NS message, the client performs a NA to reply with its own MAC address. At the same time, the random number, the destination MAC address of the message, the source IPv6 address, the destination IPv6 address, and the destination address are used as input variables of the hash function to hash the resulting 32-bit hash value, which is then filled into the Option 2 field at the end of the message. Option 2 is the optional field 2.

[0077] After receiving the NA message, the server confirms that the MAC address matches the source MAC address of the received S-Renew or S-Rebind message. It also compares the hash value carried in the received NA message with the locally stored hash value. If the comparison is consistent, it sends an S-Reply message in response to the DHCPv6 message with Message Type = 16. It also uses the destination MAC address, Client Identifier, Server Identifier, IA Address, and the random number in the S-Renew or S-Rebind message to create a 32-bit hash value, which is then used to populate the DHCPv6 Hash Value field in the message. This makes the entire interaction more secure, with bidirectional verification and confirmation.

[0078] T-Renew or S-Rebind messages are DHCP messages. S stands for Security. MAC address stands for Media Access Control Address, a basic concept in network communications.

[0079] Client Identifier and Server Identifier are parameters in the DHCP message, client identification numbers;

[0080] IA Address is a parameter in the DHCP message, Identity Association, identity alliance.

[0081] (4) Processing flow for IPv6 address renewal by a client device that supports the address renewal security mechanism: The client initiates the IPv6 address renewal process. The entire process is shown in Figure 13. The client sends a DHCPv6 message with Message Type = 14. The client uses the random number, source MAC address, Client Identifier, and Server Identifier in the message to hash a 32-bit hash value and save it in the local table. It determines whether an NS request has been received. If not, it determines that the DHCPv6 server has not been notified and the address will not be renewed. After a period of time, the address renewal process is re-executed. If received, it responds to the NA message with its own MAC address. It determines whether a DHCPv6 Reply message has been received from the server. If not, it determines that the DHCPv6 server has not been notified and the address will not be renewed. After a period of time, the address release process is re-executed. If received, the client extracts the DHCPv6 hash value in the Reply message and determines whether the hash value in the message is consistent with the hash value saved locally. If they are consistent, it is determined that the received DHCPv6 Reply message is secure and reliable, and the address is renewed. If they are inconsistent, the received message is determined to be an attack message, discarded, logged, and reported to the administrator.

[0082] The process of renewing an IPv6 address for a server device that supports the address renewal security mechanism is as follows: When the server receives a DHCPv6 Renew or Rebind message, the entire process is shown in Figure 15. The server checks whether the DHCPv6 address renewal security mechanism is configured. If not, it responds with a normal Reply message with Message Type = 7. If configured, it parses the received DHCPv6 message with Message Type = 14 or 15 and performs an NS request on its source address. It checks whether an NA reply message is received. If not, it responds with a normal Reply message with Message Type = 7. If received, it determines whether the reply MAC in the NA message is consistent with the source MAC in the S-Renew or S-Rebind message. If they are consistent, it responds with a DHCPv6 message with Message Type = 16. At the same time, it uses the destination MAC address, Client Identifier, Server Identifier, and random number in the S-Renew or S-Rebind message to hash a 32-bit hash value to fill in the DHCPv6 Hash Value field of the message. If the two messages are inconsistent, the system determines that the received Renew or Rebind message is an attack message, discards the message, records the attack log, and reports it to the administrator.

[0083] The present invention relates to a transmission method for preventing DHCPv6 lease renewal fraud. The method mainly improves the interaction process of DHCPv6 Renew, Rebind and Reply messages and the processing flow of equipment devices, defines three new types of DHCPv6 messages: S-Renew, S-Rebind and S-Reply, realizes secure address lease renewal interaction, and solves the problem that IPv6 is easily susceptible to DHCPv6 lease renewal fraud attacks.

[0084] Existing implementations primarily prevent address renewal spoofing attacks by manually configuring DHCP message snooping. This present invention proposes a new implementation, involving a transmission method and device for preventing DHCPv6 renewal spoofing. This optimizes the IPv6 address renewal process, bidirectionally verifying the identities of both the client and server, ensuring that Renew or Rebind messages are not sent by unknown attackers.

[0085] Those skilled in the art will understand that the above description is merely a preferred embodiment of the invention and is not intended to limit the invention. Although the invention has been described in detail with reference to the above examples, those skilled in the art can still modify the technical solutions described in the above examples or replace some of the technical features therein with equivalents. Any modifications, equivalent replacements, etc. made within the spirit and principles of the invention shall be included in the scope of protection of the invention. All technical features in this embodiment can be freely combined according to actual needs.

[0086] Finally, it should be noted that the above is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments or make equivalent substitutions for some of the technical features therein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A transmission method for preventing DHCPv6 renewal fraud, characterized in that: The specific steps include: Step 1: Use the newly defined Message Type = 14, 15, 16 three DHCPv6 messages for secure interaction; Step 2: Perform hash verification using the fields carried in the message; Step 3: Optimize the interaction process, implement a two-way confirmation mechanism, and the server performs MAC address authentication verification on the client; In the middle of the original DHCPv6 message exchange, the NS and NA messages with the option field added are used to perform bidirectional identity authentication between the DHCPv6 client and the server. Among them, NS is neighbor solicitation and NA is neighbor advertisement.

2. A transmission method for preventing DHCPv6 renewal fraud according to claim 1, characterized in that: In step 1, a secure address renewal DHCPv6 message S-Renew at time T1 is defined.

3. A transmission method for preventing DHCPv6 renewal fraud according to claim 1, characterized in that: In step 1, define the byte Message Type=14, and add 4 bytes to the original DHCPv6 message to carry the DHCPv6 random number; define a secure address renewal DHCPv6 message S-Rebind at time T2.

4. A transmission method for preventing DHCPv6 renewal fraud according to claim 1, characterized in that: In step 1, define Message Type = 15, and add 4 bytes to the original DHCPv6 message to carry the DHCPv6 random number; define a secure DHCPv6 reply message S-Reply.

5. A transmission method for preventing DHCPv6 renewal fraud according to claim 1, characterized in that: Define the byte Message Type = 16, and add 4 bytes to the original DHCPv6 message to carry the DHCPv6 hash value; modify the IPv6 NS and NA messages: Four bytes are added to the original NS message to carry the DHCPv6 random number. Four bytes are added to the original NA message to carry the DHCPv6 hash value.

6. A transmission method for preventing DHCPv6 renewal fraud according to claim 1, characterized in that: The exchange process of the address renewal DHCPv6 message S-Renew, the address renewal DHCPv6 message S-Rebind and the address renewal DHCPv6 message S-Reply is as follows: Step 3.1: The client sends a DHCPv6 S-Renew message to notify the server to renew the address at time T1, or sends a DHCPv6 S-Rebind message to notify the server to renew the address at time T2. Step 3.2: After receiving the S-Renew or S-Rebind message, the server will confirm the source of the message. Send an S-NS message to request the source IPv6 MAC address of the message; hash the source MAC address, source IPv6 address, unicast IPv6 address corresponding to the destination IPv6 address, destination address, and random number of the NS message as input variables of the hash function, hash out a 32-bit hash value, and record the hash value in the local table; NS is a neighbor request; Step 3.3: After receiving the NS message, the client performs NA to reply with its own MAC address; The random number, the destination MAC address, source IPv6 address, destination IPv6 address, and target address of the message are used as input variables of the hash function to hash a 32-bit hash value and fill it into the option 2 field of the message; option 2 is the optional field 2; Step 3.4: After receiving the NA message, the server confirms that the MAC is consistent with the source MAC of the received S-Renew or S-Rebind message; compares the hash value carried in the received NA message with the locally stored hash value. If the comparison is consistent, it will send a DHCP reply message to reply to the DHCPv6 message with Message Type = 16; use the destination MAC address, Client Identifier, Server Identifier, IA Address of the message and the random number in the S-Renew or S-Rebind message to hash a 32-bit hash value to fill in the DHCPv6 Hash Value field of the message; T-Renew or S-Rebind messages are DHCP messages. S is for added security features. MAC address is Media Access Control Address, a basic concept in network communications. Client Identifier and Server Identifier are parameters in the DHCP message, client identification numbers; IA Address is a parameter in the DHCP message, Identity Association, identity alliance.

7. A transmission method for preventing DHCPv6 renewal fraud according to claim 1, characterized in that: In step 3.1, a 4-byte DHCPv6 random number is added to the S-Renew message. The client generates a 32-bit hash value based on the generated random number, source MAC address, Client Identifier, and Server Identifier and saves it in the local table.

8. A transmission method for preventing DHCPv6 renewal fraud according to claim 1, characterized in that: In step 3.1, a 4-byte DHCPv6 random number is added to the S-Rebind message. The client generates a 32-bit hash value based on the generated random number, source MAC address, and Client Identifier and saves it in the local table.

9. A transmission method for preventing DHCPv6 renewal fraud according to claim 1, characterized in that: Support Address Continued The process of renewing the IPv6 address lease of a client device with a lease security mechanism is as follows: The client starts the IPv6 address renewal process and sends a DHCPv6 message with Message Type = 14. The random number, source MAC address, Client Identifier, and Server Identifier in the message are used to hash a 32-bit hash value and save it in the local table. Determine whether the NS request is received. If not, it is determined that the DHCPv6 server has not been notified, the address is not renewed, and the address renewal process is re-executed; If received, the MAC address is replied to the NA message; if the DHCPv6 Reply message from the server is received, it is determined that the DHCPv6 server has not been notified, the address is not renewed, and the address release process is executed again; If received, extract the DHCPv6 hash value in the Reply message and determine whether the hash value in the message is consistent with the hash value saved locally: If they are consistent, the received DHCPv6 Reply message is considered safe and credible, and the address is renewed; If they are inconsistent, the received message is determined to be an attack message, the message is discarded, a log is recorded, and the administrator is reported.

10. A transmission method for preventing DHCPv6 renewal fraud according to claim 1, characterized in that: The process of renewing the IPv6 address of a server device that supports the address renewal security mechanism is as follows: When the server receives a DHCPv6 Renew or Rebind message, it checks whether the DHCPv6 address renewal security mechanism is configured. If not, it responds with a normal Reply message with Message Type = 7. If configured, parse the received DHCPv6 message with Message Type = 14 or 15, and make an NS request for its source address; check whether an NA reply message is received: if not, respond with a normal Reply message with Message Type = 7; If received, determine whether the response MAC in the NA message is consistent with the source MAC of the S-Renew or S-Rebind message; if they are consistent, reply to the DHCPv6 message with Message Type = 16; at the same time, use the destination MAC address, Client Identifier, Server Identifier and the random number in the S-Renew or S-Rebind message to hash a 32-bit hash value to fill the DHCPv6 Hash Value field of the message; if they are inconsistent, determine that the received Renew or Rebind message is an attack message, discard the message, record the attack log and report it to the administrator.

Citation Information

Patent Citations

  • Method of controlling multiple DHCP Server dynamic distribution host addresses

    CN106302854A

  • System and method capable of reducing address renewing frequency of user terminal

    CN114745359A

  • Rental renewing information management method, equipment and medium

    CN115277642A

  • DHCPv6 security authentication method

    CN116743453A

  • Transmission method for preventing DHCPv6 lease renewing deception

    CN117880246A