Local Network Address Management via DHCP Invalidation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access gateway systems face significant processing loads when implementing parental control by inspecting all packets to enforce time-based access restrictions, which is inefficient and does not effectively cut off connections established before the control start time.
Innovation Solution
The method involves sending a DHCP or ICMPv6 message to devices in a local network, indicating that their address is no longer valid at a specified start time, thereby preventing communication until an end time, reducing the need for packet inspection and allowing only authorized access during designated periods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the access gateway inspects all packets to enforce parental control rules, then access control effectiveness is improved, but processing load increases significantly
Solution Approach 1:
The patent applies preliminary action by invalidating the device address at the start time of the parental control rule before any packet inspection is needed. The DHCP server sends a DHCP message to invalidate the address at the predetermined start time, preventing the device from obtaining a valid address before the block period begins. This eliminates the need to inspect packets during the block period while ensuring access control effectiveness is maintained.
2Reliability
If packet inspection is performed to block access after start time, then access control is enforced, but connections established before start time are not cut off
Solution Approach 1:
The patent uses preliminary action by pre-invalidating the device address at the start time through DHCP message transmission. When the start time is reached, the DHCP server sends a message indicating the address is no longer valid, which immediately terminates any existing connections before they can continue. This ensures both access control enforcement and immediate connection termination without delay.
Solution Approach 2:
The patent implements feedback by having the DHCP server continuously monitor the current time against the parental control rule start time and end time. When the current time reaches the start time, the server sends a feedback message to invalidate the address. This feedback mechanism ensures that address invalidation occurs precisely at the intended moment, cutting off connections immediately when the block period begins.
3Reliability
If continuous packet inspection is performed to maintain parental control, then access restrictions are maintained, but processing resources are consumed continuously
Solution Approach 1:
The patent applies periodic action by having the DHCP server check the current time periodically against the parental control rule parameters (start time and end time) and only take action when the current time reaches the start time or end time. Instead of continuously inspecting packets, the server performs time-based checks at intervals and sends DHCP messages only when needed. This maintains access restrictions while significantly reducing continuous processing resource consumption.
Data Source
Figure 1~3
Figure 2a~2b
Figure 2c
AI summary
The invention relates to a technique for managing an address in a local area network (3) using an access device (30) allowing access to an extended communication network. An address allows a device (31-34) of the local area network to communicate with other devices by means of the access device. The access device obtains an access control rule to be applied, said rule aiming to block communication of data packets from at least one start time and until an end time. The access device then sends, to at least one device of the local area network, a message relating to an address in the local area network associated with said device. The message carries an item of information indicating to the device that said address is no longer valid from said start time. The access device implements at least one action leading to an absence of a valid address for said device of the local area network, as long as the end time of the access control rule is not exceeded. Said technique enables, in particular, the implementation of a parental control application.