发明名称 Secure DHCP server
摘要 A preferred embodiment of the present invention includes a method and apparatus for allocating and using IP addresses in a network of client systems. More specifically, the present invention includes a DHCP server that leases IP addresses to the client systems. The DHCP server works in combination with a secure DHCP relay agent and a secure IP relay agent. Broadcast DHCPREQUEST messages are forwarded to the DHCP server by the secure DHCP relay agent. Before forwarding, the secure DHCP relay agent embeds in each DHCPREQUEST message. The trusted identifier is an unforgeable object specifically associated with the client system sending the DHCPREQUEST message. When the DHCP server receives a DHCPREQUEST message, the DHCP server extracts the trusted identifier. The trusted identifier is then used by the DHCP server to prevent client systems from accessing the IP address leases of other client systems. The DHCP server also counts the number of IP addresses leases assigned to each trusted identifier. In this way, each client system is prevented from leasing more than a predetermined number of IP addresses. Unicast DHCPREQUEST messages received by the DHCP server include a source address that corresponds to the client system sending the unicast DHCPREQUEST message. The validity of the source address is ensured by the secure IP relay agent. The DHCP server uses the source address to prevent client systems from accessing the IP address leases of other client systems.
申请公布号 US5884024(A) 申请公布日期 1999.03.16
申请号 US19960763068 申请日期 1996.12.09
申请人 SUN MICROSYSTEMS, INC. 发明人 LIM, SWEE B.;RADIA, SANJAY R.;WONG, THOMAS K.;TSIRIGOTIS, PANAGIOTIS;GOEDMAN, ROBERT J.
分类号 H04L29/06;H04L29/12;(IPC1-7):G06F11/00 主分类号 H04L29/06
代理机构 代理人
主权项
地址