CN102594939A - Secondary address allocation method and device - Google Patents

Secondary address allocation method and device Download PDF

Info

Publication number
CN102594939A
CN102594939A CN2012100347323A CN201210034732A CN102594939A CN 102594939 A CN102594939 A CN 102594939A CN 2012100347323 A CN2012100347323 A CN 2012100347323A CN 201210034732 A CN201210034732 A CN 201210034732A CN 102594939 A CN102594939 A CN 102594939A
Authority
CN
China
Prior art keywords
address
user
authentication
public network
network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN2012100347323A
Other languages
Chinese (zh)
Other versions
CN102594939B (en
Inventor
张海涛
徐国祥
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
Hangzhou H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou H3C Technologies Co Ltd filed Critical Hangzhou H3C Technologies Co Ltd
Priority to CN201210034732.3A priority Critical patent/CN102594939B/en
Publication of CN102594939A publication Critical patent/CN102594939A/en
Application granted granted Critical
Publication of CN102594939B publication Critical patent/CN102594939B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)
  • Small-Scale Networks (AREA)

Abstract

The invention provides a secondary address allocation method and a secondary address allocation device. The method comprises the following steps of: receiving a public network access request from a user; if the user does not pass authentication, selecting a public network Internet protocol (IP) address from a first address pool, allocating the selected public network IP address to the user, and triggering an authentication server to authenticate the user; if the user passes the authentication after the authentication server is triggered to authenticate the user, selecting an idle public network IP address from a second address pool, and allocating the selected idle public network IP address to the user; and if the user passes the authentication, converting a private network IP address of the user into the public network IP address selected from the second address pool and allocated to the user, so that the user can access a public network by using the public network IP address. Public network IP address waste can be reduced.

Description

A kind of second level address distribution method and device
Technical field
The present invention relates to communication technical field, particularly a kind of second level address distribution method and device.
Background technology
In carrier network, when the user connects online, can carry out authentication (for example web authentication) through certificate server usually, just be allowed to visit public network behind the authentication success.Because certificate server is positioned at public network, need be just for the user distributes public network IP address before authentification of user, so that the user can carry out authentication by the access registrar server.Yet, because the finiteness of public network IP address if just distribute public network IP address before the authentification of user success, will cause the waste of a large amount of public network IP address.Be that example describes below with the wireless lan (wlan).
Referring to Fig. 1, Fig. 1 is operator's networking sketch map, and wherein, BAS Broadband Access Server (BAS) is the authenticating device that is deployed in the city-level network, can communicate with the certificate server that is deployed in the provincial network; Wireless controller (AC) is other hang or under hang on the BAS, can control a plurality of WAPs (AP).As shown in Figure 1, AP1-AP3, AP4-AP6, AP7-AP9 form the hot spot region respectively.Because the finiteness of public network IP address can be reserved one group of public IP addresses for one or more hot spot regions usually.
When above-mentioned hot spot region has the user to need accesses network; The user needs to obtain earlier the IP public network address, sends authentication request to BAS then, and BAS is according to user's the authentication request triggering authentication server verification process to the user; If authentication success then allows customer access network.As everyone knows, in wlan network, the user's flowability in the hot spot region is very big; Many users have in fact unconsciously inserted network automatically; The demand of accesses network can not sent authentication request to authenticating device yet, if distribute public network IP address for this part user; A lot of public network IP address will be wasted, also the user that the accesses network demand is arranged can be influenced simultaneously.
Summary of the invention
In view of this; The object of the present invention is to provide a kind of second level address distribution method; This method offers unverified successful user with a spot of public network IP address, and a large amount of public network IP address is offered the user of authentication success, thereby can reduce the waste of public network IP address.
In order to achieve the above object, the invention provides a kind of second level address distribution method, this method comprises:
Receive the user's in the private network visit public network request;
If said user not through authentication, then selects a public network IP address to distribute to said user in first address pool, the triggering authentication server is to said user's authentication; After of the authentication of triggering authentication server, if the authentification of user success then selects the public network IP address of a free time to distribute to said user in second address pool to said user;
If said user is through authentication, then with said user's private network IP address transition in second address pool, selecting and distribute to said user's public network IP address, with so that said user uses this public network IP address to visit public network.
The present invention also provides a kind of second level address distributor, is applied in the authenticating device, and this device comprises: receiving element, allocation units, authentication ' unit, NAT converting unit;
Said receiving element is used to receive user's visit public network request;
Said allocation units are used for after receiving element receives user's visit public network request, if said user not through authentication, then selects a public network IP address to distribute to said user in first address pool, and send authentication notification to authentication ' unit; After sending authentication notification,, then in second address pool, select the public network IP address of a free time to distribute to said user if receive the authentication success notice of authentication ' unit to authentication ' unit; If said user through authentication, then sends second address transition notice to the NAT converting unit;
Said authentication ' unit, after being used to receive the authentication notification of allocation units, the triggering authentication server is to said user's authentication, if the success of said authentification of user is then sent the authentication success notice to allocation units;
Said NAT converting unit; After being used to receive second address transition notice of allocation units; With said user's private network IP address transition is allocation units selected and distributed to said user in second address pool public network IP address, with so that said user uses this public network IP address visit public network.
Can know by top technical scheme, among the present invention, before authentification of user success,,, carry out authentication so that the user can the access registrar server for the user distributes the public network IP address in first address pool; After the authentification of user success, select public network IP address idle in second address pool to distribute to the user, thereby make the user can use unique public network IP address visit public network; Distribute through the user being carried out the second level address, can reduce the waste of public network IP address.
Description of drawings
Fig. 1 prior art operator networking sketch map;
Fig. 2 is the schematic flow sheet of embodiment of the invention second level address distribution method;
Fig. 3 is the structural representation of embodiment of the invention second level address distributor.
Embodiment
In order to make the object of the invention, technical scheme and advantage clearer,, technical scheme of the present invention is elaborated below in conjunction with the accompanying drawing embodiment that develops simultaneously.
Referring to Fig. 2, Fig. 2 is the schematic flow sheet of embodiment of the invention second level address distribution method, may further comprise the steps:
User's in step 201, the reception private network visit public network request.
When the user in the private network connects online, can at first obtain a private network IP address, use this private network IP address, the user can't visit the certificate server that is arranged in public network, but can use this private network IP address to send the request of visit public network to authenticating device.
Whether step 202, judges through authentication, if then execution in step 204, otherwise, execution in step 203.
When authenticating device receives the visit public network request of user's transmission, at first need judges whether through authentication, whether confirm subsequent action through authentication success according to the user.
Step 203, in first address pool, select a public network IP address to distribute to said user, the triggering authentication server is to said user's authentication; After of the authentication of triggering authentication server, if the authentification of user success then selects the public network IP address of a free time to distribute to said user in second address pool to said user.
In the present embodiment,, available public network IP address is divided into two parts, leaves in respectively in first address pool and second address pool based on the finiteness of public network IP address.Wherein, the public network IP address in first address pool mainly offers not through user's use of authentication, and each public network IP address can be simultaneously shared by a plurality of users.The user that public network IP address in second address pool mainly offers through authentication uses, and each public network IP address only can be assigned to a user and use.Generally speaking, the public network IP address quantity in first address pool is less than the public network IP address quantity in second address pool, but is not necessary.
In this step; During the user to access public net through authentication,, then not need not in first address pool, to select public network IP address to distribute to the user again if in first address pool, selected public network IP address to distribute to the user; Directly the triggering authentication server is to user's verification process; If still unallocated, then need from first address pool, to select a public network IP address to distribute to said user earlier, and then the triggering authentication server is to user's authentication.
In the present embodiment; Each public network IP address in first address pool maybe be shared by a plurality of users; Shared mode is for adopting the many-one conversion of NAT; The shared public network IP address of private network IP address transition with the user in first address pool, selecting; Each user's through will having distributed same public network IP address port mapping is carried out distinguish to different port, thereby realizes the target network resource in the shared public network IP address visit of a plurality of users public network, reduces the waste of public network IP address.Each public network IP address in second address pool only supplies a user to use; Occupation mode is for adopting the conversion one to one of NAT; With user's private network IP address transition is in second address pool, to select and distribute to user's public network IP address, thereby makes the user can use the target network resource in this public network IP address visit public network.
For not through the user of authentication, be of the NAT conversion of a plurality of private network IP address owing to what adopt to a public network IP address, therefore, the user will be limited to the visit of Internet resources; In addition, authenticating device generally also can limit the visit of public network the user through authentication not, only allows the limited Internet resources on the user to access public net, for example, only allows the certificate server on the user to access public net, to carry out authentification of user.
In addition; If the target network resource that the user not through authentication need visit is to allow to use the public network IP address in first address pool to conduct interviews; Then not the triggering authentication server to user's authentication; And directly user's private network IP address transition is to make the user can visit this target network resource by the public network IP address in first address pool of having distributed to the user.
Therefore; Before of the authentication of triggering authentication server, can further include said user: judge whether to allow to use the public network IP address of in first address pool, selecting and distribute to said user to visit the target network resource of said visit public network request, if; Then the private network IP address transition with the user is this public network IP address; With so that said user uses this public network IP address to visit said target network resource, otherwise the triggering authentication server is to said user's authentication.
The permission access list can be set in advance, comprise the all-network resource in the public network of the public network IP address visit of allow using in first address pool in the said permission access list.If there is the target network resource of user's visit public network request in the permission access list; Then explanation allows the user to use this target network resource of public network IP address visit in first address pool; Otherwise, explain not allow the user to use this target network resource of public network IP address visit in first address pool.
In addition, after the authentication of triggering authentication server to the user, certificate server can return the authentication result to the user, and said authentication result comprises authentication success and authentification failure.If the authentication result that certificate server returns is this user authentication failure, then when the user sent the request of visit public network once more, the triggering authentication server was to user's authentication once more.If the authentication result that certificate server returns is this authentification of user success, then can implement address assignment for the second time, also promptly: the public network IP address of in second address pool, selecting a free time to this user; And public network IP address that should the free time is assigned as the user; Like this, this user just taken should the free time public network IP address, before this user offline; Can again this public network IP address not distributed to other user, this public network IP address visit public network can be used in this family.In this case, because user's private network IP address can be transformed into in second address pool, selecting and distribute to this user's public network IP address uniquely, therefore, the user is generally unrestricted to the visit of Internet resources in the public network.
In addition, when the public network IP address of a free time of selection is distributed to said user in second address pool, also need further be released in the public network IP address of selecting and distribute to said user in first address pool.After the authentification of user success, use the public network IP address visit public network of in second address pool, selecting and distributing.
Like this, for not through all users of authentication,, make the shared a spot of public network IP address of all users through adopting the method for NAT conversion; , then distribute public network IP address separately, thereby can save a large amount of public network IP address through the user of authentication for.
Step 204, with said user's private network IP address transition in second address pool, selecting and distribute to said user's public network IP address, with so that said user uses this public network IP address to visit public network.
In this step; Authenticating device confirms that the user is through authentication; Explain before this and in second address pool, to select and the public network IP address of a free time of having distributed to this user, therefore, can adopt the NAT technology; Directly the private network IP address transition with the user is in second address pool, to select and distribute to this user's public network IP address, thereby makes the user can use this public network IP address visit public network.
In the embodiment of the invention shown in Figure 2; When the user reaches the standard grade and visit public network; Need the triggering authentication server that the user is carried out authentication, and be that the user distributes the public network IP address that is not used by other user after certificate server is to the authentification of user success in second address pool, thereby make the user when the subsequent access public network; All can user's private network IP address be transformed into uniquely the public network IP address of this distribution so that the user can be not accesses network limitedly.When user offline; Can send the request of rolling off the production line to authenticating device, in order to utilize public network IP address fully, then authenticating device is after the request of rolling off the production line that receives the user; Can discharge the public network IP address of in second address pool, selecting and distribute to this user before this; This public network IP address again as public network IP address idle in second address pool, so that can continue to distribute to user's use of other new authentication success, is realized making full use of of public network IP address.
In addition; In being released in second address pool, select and when distributing to said user's public network IP address; Can also further in first address pool, select a public network IP address to distribute to said user; Also can be earlier not for this user of rolling off the production line distribute the public network IP address in first address pool, but when this user of rolling off the production line sends the request of visit public network once more, in first address pool, select a public network IP address to distribute to said user again.
In the embodiment of the invention shown in Figure 2, described authentication can be the web authentication, and described certificate server can be the web certificate server.
In this case, authenticating device triggering authentication server specifically can comprise user's authentication:
The web certification page is sent to said user;
Receive said user and receive the web authentication request that generates behind the said web certification page, said user's web authentication request is sent to the web certificate server, in addition, also need write down the said user's who carries in the said web authentication request port information;
Receive said web certificate server authentication result to said user after receiving said web authentication request.
User capture web certificate server carries out in the process of authentication; It is the public network IP address of from first address pool, selecting; And be this public network IP address of from first address pool, selecting with user's private network IP address transition; And visit the web certificate server through this public network IP address of from first address pool, selecting and carry out authentication, therefore, the user's IP address that writes down in the web certificate server is this public network IP address of from first address pool, selecting.And after the authentification of user success; From second address pool, selected the public network IP address of a free time to distribute to this user; During customer access network; Be that user's private network IP address transition is this public network IP address of from second address pool, selecting, through this public network IP address accesses network of from second address pool, selecting.The public network IP address that has used when this has just caused authentification of user and during the actual access network is inconsistent; Therefore; Need notify the web server for the public network IP address that the user distributes with authentification of user success back, thereby the address information when making user's addresses information and the user's actual access network in the certificate server is consistent.
Therefore; After the public network IP address that will in second address pool, select distributes this user; The public network IP address that also need will in second address pool, select and the user's of record port information notice web certificate server; In addition, also need notify certificate server, thereby make certificate server to search and to revise user's IP address and port information according to ID with ID to web.Here, can use the public network IP address distributed in the web verification process in first address pool that the user uses and port information ID as this user.
In addition, when receiving the request of rolling off the production line of authenticated, also need notify the web certificate server this user offline, so that the web certificate server can in time be deleted this user related information, for example IP address and port information.
In the present embodiment; In fact really the user not being carried out the second level address distributes; But according to user's authentication scenario, be different public network IP address through adopting the NAT technology with user's private network IP address transition, thereby can reach the user is carried out the effect that the second level address is distributed.And according to authentication result; Unverified successful user is adopted many-to-one NAT conversion; The user of authentication success is then adopted man-to-man NAT conversion, make the shared a spot of public network IP address of unverified all successful users, thereby can save a large amount of public network IP address.
Need to prove in the embodiment of the invention shown in Figure 2, no matter be in first address pool, to select public network IP address to distribute to the user, and in second address pool, select public network IP address to give the user after the authentification of user success, all can the executive address aging mechanism.After distributing public network IP address to give the user, if the user does not have flow in the preset time, then can public network IP address that distribute to the user is aging; Particularly; When distribute be the public network IP address in first address pool time, can directly discharge this public network IP address, when distribute be the public network IP address in second address pool time; The authentification of user success is described, can be handled according to user offline.
More than embodiment of the invention second level address distribution method is specified, the present invention also provides a kind of second level address distributor, is applied in the authenticating device, this device has the NAT translation function, can reduce the waste of public network IP address.
Referring to Fig. 3, Fig. 3 is the structural representation of embodiment of the invention second level address distributor, and this device comprises: receiving element 301, allocation units 302, authentication ' unit 303, NAT converting unit 304; Wherein,
Receiving element 301 is used to receive user's visit public network request;
Allocation units 302 are used for after receiving element 301 receives user's visit public network request, if said user not through authentication, then selects a public network IP address to distribute to said user in first address pool, and send authentication notification to authentication ' unit 303; After sending authentication notification,, then in second address pool, select the public network IP address of a free time to distribute to said user if receive the authentication success notice of authentication ' unit 303 to authentication ' unit 303; If said user through authentication, then sends second address transition notice to NAT converting unit 304;
Authentication ' unit 303, after being used to receive the authentication notification of allocation units 302, the triggering authentication server is to said user's authentication, if the success of said authentification of user is then sent the authentication success notice to allocation units 302;
NAT converting unit 304; After being used to receive second address transition notice of allocation units 302; With said user's private network IP address transition is allocation units 302 selected and distributed to said user in second address pool public network IP address, with so that said user uses this public network IP address visit public network.
Allocation units 302 are before sending authentication notification to authentication ' unit 303; Be further used for: judge whether to allow to use the public network IP address of in first address pool, selecting and distribute to said user to visit the target network resource of said visit public network request; If; Then send first address transition notice to NAT converting unit 304, otherwise, authentication notification sent to authentication ' unit 303;
Said NAT converting unit 304; After being used to receive first address transition notice of allocation units 302; With said user's private network IP address transition is to convert allocation units 302 selected and distributed to said user in second address pool public network IP address into, with so that said user uses this public network IP address to visit said target network resource.
This device also comprises dispensing unit 305, is used for being provided with in advance the permission access list; Comprise the all-network resource in the public network of the public network IP address visit of allow using in first address pool in the said permission access list;
Said NAT converting unit, be used for adopting many-to-one network address translation NAT will be not user's the public network IP address of private network IP address transition through authentication for selecting and distribute in first address pool; Adopt the user's that man-to-man NAT will be through authentication the public network IP address of private network IP address transition in second address pool, selecting and distribute.
When said allocation units 302 select the public network IP address of one free time to distribute to said user, further be released in the public network IP address of selecting and distribute to said user in first address pool in second address pool;
Said receiving element 301 is further used for receiving said user's the request of rolling off the production line;
Said allocation units 302 if receiving element 301 receives said user's the request of rolling off the production line, then are released in the public network IP address of selecting and distribute to said user in second address pool after said authentification of user success.
Allocation units 302 are selected in being released in second address pool and when distributing to said user's public network IP address, further in first address pool, are selected a public network IP address, and this public network IP address is distributed to said user.
Said authentication is the web authentication, and said certificate server is the web certificate server;
Said authentication ' unit 303, is used for: the web certification page is sent to said user during to said user's authentication at the triggering authentication server; Receive said user and receive the web authentication request that generates behind the said web certification page, said user's web authentication request is sent to the web certificate server, and write down the said user's who carries in the said web authentication request port information; Receive said web certificate server authentication result to said user after receiving said web authentication request; Said authentication result comprises authentication success and authentification failure;
Said receiving element 301; Being used for will be after second address pool selects the public network IP address of a free time to distribute to said user at allocation units 302, with the said user's of this public network IP address and authentication ' unit 303 records port information notice web certificate server.
Said receiving element 301 is further used for after the request of rolling off the production line that receives said user: the said user offline of notice web certificate server.
The above is merely preferred embodiment of the present invention, and is in order to restriction the present invention, not all within spirit of the present invention and principle, any modification of being made, is equal to replacement, improvement etc., all should be included within the scope that the present invention protects.

Claims (12)

1. a second level address distribution method is characterized in that, this method comprises:
Receive the user's in the private network visit public network request;
If said user not through authentication, then selects a public network IP address to distribute to said user in first address pool, the triggering authentication server is to said user's authentication; After of the authentication of triggering authentication server, if the authentification of user success then selects the public network IP address of a free time to distribute to said user in second address pool to said user;
If said user is through authentication, then with said user's private network IP address transition in second address pool, selecting and distribute to said user's public network IP address, with so that said user uses this public network IP address to visit public network.
2. second level address according to claim 1 distribution method is characterized in that,
Before the authentication of triggering authentication server to said user; Further comprise: judge whether to allow to use the public network IP address of in first address pool, selecting and distribute to said user to visit the target network resource of said visit public network request; If then the private network IP address transition with the user is this public network IP address, with so that said user uses this public network IP address to visit said target network resource; Otherwise the triggering authentication server is to said user's authentication.
3. second level address according to claim 2 distribution method is characterized in that, the permission access list is set in advance; Comprise the all-network resource in the public network of the public network IP address visit of allow using in first address pool in the said permission access list;
Adopt many-to-one network address translation NAT will be not user's the public network IP address of private network IP address transition through authentication in first address pool, selecting and distribute;
Adopt the user's that man-to-man NAT will be through authentication the public network IP address of private network IP address transition in second address pool, selecting and distribute.
4. second level address according to claim 1 distribution method is characterized in that,
When the public network IP address of a free time of selection is distributed to said user in second address pool, further be released in the public network IP address of selecting and distribute to said user in first address pool;
After the said authentification of user success, further comprise:, then be released in the public network IP address of selecting and distribute to said user in second address pool if receive said user's the request of rolling off the production line.
5. second level address according to claim 4 distribution method is characterized in that, is released in second address pool to select and when distributing to said user's public network IP address, further in first address pool, select a public network IP address to distribute to said user.
6. according to the described second level address of arbitrary claim distribution method among the claim 1-5, it is characterized in that,
Said authentication is the web authentication, and said certificate server is the web certificate server;
The triggering authentication server comprises said user's authentication: the web certification page is sent to said user; Receive said user and receive the web authentication request that generates behind the said web certification page, said user's web authentication request is sent to the web certificate server, and write down the said user's who carries in the said web authentication request port information; Receive said web certificate server authentication result to said user after receiving said web authentication request; Said authentication result comprises authentication success and authentification failure;
In second address pool, select the public network IP address of a free time to distribute to after the said user, further comprise: with the said user's of this public network IP address and record port information notice web certificate server.
7. a second level address distributor is applied to it is characterized in that in the authenticating device that this device comprises: receiving element, allocation units, authentication ' unit, NAT converting unit;
Said receiving element is used to receive user's visit public network request;
Said allocation units are used for after receiving element receives user's visit public network request, if said user not through authentication, then selects a public network IP address to distribute to said user in first address pool, and send authentication notification to authentication ' unit; After sending authentication notification,, then in second address pool, select the public network IP address of a free time to distribute to said user if receive the authentication success notice of authentication ' unit to authentication ' unit; If said user through authentication, then sends second address transition notice to the NAT converting unit;
Said authentication ' unit, after being used to receive the authentication notification of allocation units, the triggering authentication server is to said user's authentication, if the success of said authentification of user is then sent the authentication success notice to allocation units;
Said NAT converting unit; After being used to receive second address transition notice of allocation units; With said user's private network IP address transition is allocation units selected and distributed to said user in second address pool public network IP address, with so that said user uses this public network IP address visit public network.
8. second level address according to claim 7 distributor is characterized in that,
Allocation units are before sending authentication notification to authentication ' unit; Be further used for: judge whether to allow to use the public network IP address of in first address pool, selecting and distribute to said user to visit the target network resource of said visit public network request; If; Then send first address transition notice to the NAT converting unit, otherwise, authentication notification sent to authentication ' unit;
Said NAT converting unit; After being used to receive first address transition notice of allocation units; With said user's private network IP address transition is to convert allocation units selected and distributed to said user in second address pool public network IP address into, with so that said user uses this public network IP address to visit said target network resource.
9. second level address according to claim 8 distributor is characterized in that this device also comprises dispensing unit, is used for being provided with in advance the permission access list; Comprise the all-network resource in the public network of the public network IP address visit of allow using in first address pool in the said permission access list;
Said NAT converting unit, be used for adopting many-to-one network address translation NAT will be not user's the public network IP address of private network IP address transition through authentication for selecting and distribute in first address pool; Adopt the user's that man-to-man NAT will be through authentication the public network IP address of private network IP address transition in second address pool, selecting and distribute.
10. second level address according to claim 7 distributor is characterized in that,
When said allocation units select the public network IP address of one free time to distribute to said user, further be released in the public network IP address of selecting and distribute to said user in first address pool in second address pool;
Said receiving element is further used for receiving said user's the request of rolling off the production line;
Said allocation units if receiving element receives said user's the request of rolling off the production line, then are released in the public network IP address of selecting and distribute to said user in second address pool after said authentification of user success.
11. second level address according to claim 10 distributor; It is characterized in that; Allocation units are selected in being released in second address pool and when distributing to said user's public network IP address; Further in first address pool, select a public network IP address, this public network IP address is distributed to said user.
12. according to the described second level address of arbitrary claim distributor among the claim 7-11, it is characterized in that said authentication is the web authentication, said certificate server is the web certificate server;
Said authentication ' unit, is used for: the web certification page is sent to said user during to said user's authentication at the triggering authentication server; Receive said user and receive the web authentication request that generates behind the said web certification page, said user's web authentication request is sent to the web certificate server, and write down the said user's who carries in the said web authentication request port information; Receive said web certificate server authentication result to said user after receiving said web authentication request; Said authentication result comprises authentication success and authentification failure;
Said receiving element, being used for will be after second address pool selects the public network IP address of a free time to distribute to said user at allocation units, with the said user's of this public network IP address and authentication ' unit record port information notice web certificate server.
CN201210034732.3A 2012-02-16 2012-02-16 Secondary address allocation method and device Active CN102594939B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201210034732.3A CN102594939B (en) 2012-02-16 2012-02-16 Secondary address allocation method and device

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201210034732.3A CN102594939B (en) 2012-02-16 2012-02-16 Secondary address allocation method and device

Publications (2)

Publication Number Publication Date
CN102594939A true CN102594939A (en) 2012-07-18
CN102594939B CN102594939B (en) 2014-11-12

Family

ID=46483132

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201210034732.3A Active CN102594939B (en) 2012-02-16 2012-02-16 Secondary address allocation method and device

Country Status (1)

Country Link
CN (1) CN102594939B (en)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102801798A (en) * 2012-08-03 2012-11-28 浙江宇视科技有限公司 Method and device for distributing IP (Internet Protocol) address
CN103841219A (en) * 2012-11-21 2014-06-04 华为技术有限公司 IP address releasing method and device and access device
CN104519150A (en) * 2014-12-31 2015-04-15 迈普通信技术股份有限公司 Network address translation port distribution method and system
CN105227686A (en) * 2014-06-20 2016-01-06 中国电信股份有限公司 The Dynamic Configuration of cloud host domain name and system
CN105323177A (en) * 2014-07-28 2016-02-10 国基电子(上海)有限公司 Router and routing method
CN105610863A (en) * 2016-02-04 2016-05-25 上海信昊信息科技有限公司 IP network communication encryption method without IP addresses
CN108322926A (en) * 2017-12-26 2018-07-24 努比亚技术有限公司 Method for network access, terminal, network server and computer readable storage medium

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1553341A (en) * 2003-06-08 2004-12-08 华为技术有限公司 Network address distributing method based on customer terminal
CN1798158A (en) * 2004-12-21 2006-07-05 华为技术有限公司 Method for distributing second level address
CN102148878A (en) * 2010-02-05 2011-08-10 中国移动通信集团公司 IP (internet protocol) address allocation method, system and device
CN102255918A (en) * 2011-08-22 2011-11-23 神州数码网络(北京)有限公司 DHCP (Dynamic Host Configuration Protocol) Option 82 based user accessing authority control method

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1553341A (en) * 2003-06-08 2004-12-08 华为技术有限公司 Network address distributing method based on customer terminal
CN1798158A (en) * 2004-12-21 2006-07-05 华为技术有限公司 Method for distributing second level address
CN102148878A (en) * 2010-02-05 2011-08-10 中国移动通信集团公司 IP (internet protocol) address allocation method, system and device
CN102255918A (en) * 2011-08-22 2011-11-23 神州数码网络(北京)有限公司 DHCP (Dynamic Host Configuration Protocol) Option 82 based user accessing authority control method

Cited By (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102801798A (en) * 2012-08-03 2012-11-28 浙江宇视科技有限公司 Method and device for distributing IP (Internet Protocol) address
CN102801798B (en) * 2012-08-03 2015-05-06 浙江宇视科技有限公司 Method and device for distributing IP (Internet Protocol) address
CN103841219A (en) * 2012-11-21 2014-06-04 华为技术有限公司 IP address releasing method and device and access device
CN105227686A (en) * 2014-06-20 2016-01-06 中国电信股份有限公司 The Dynamic Configuration of cloud host domain name and system
CN105323177A (en) * 2014-07-28 2016-02-10 国基电子(上海)有限公司 Router and routing method
CN104519150A (en) * 2014-12-31 2015-04-15 迈普通信技术股份有限公司 Network address translation port distribution method and system
CN104519150B (en) * 2014-12-31 2018-03-02 迈普通信技术股份有限公司 Network address conversion port distribution method and system
CN105610863A (en) * 2016-02-04 2016-05-25 上海信昊信息科技有限公司 IP network communication encryption method without IP addresses
CN105610863B (en) * 2016-02-04 2019-07-19 上海信昊信息科技有限公司 IP network communication encrypting method without IP address
CN108322926A (en) * 2017-12-26 2018-07-24 努比亚技术有限公司 Method for network access, terminal, network server and computer readable storage medium

Also Published As

Publication number Publication date
CN102594939B (en) 2014-11-12

Similar Documents

Publication Publication Date Title
CN102594939B (en) Secondary address allocation method and device
CN100502413C (en) IP address requesting method for DHCP client by DHCP repeater
CN100527752C (en) DHCP address allocation method
KR100766067B1 (en) Method and apparatus for supporting user mobility by allowing guest access and billing method based on the same in internet service network
CN109151009B (en) CDN node distribution method and system based on MEC
CN111107171B (en) Security defense method and device for DNS (Domain name Server), communication equipment and medium
CN105472048B (en) A kind of address distribution method, information aggregation method and relevant device
WO2009030135A1 (en) Method, device and system for assigning license
CN111917895A (en) Alias management method and device
CN112769965B (en) IP address management and distribution method, device and system
TW201244426A (en) Gateway and attack avoiding method thereof
CN104243625B (en) The distribution method and device of a kind of IP address
CN105323325A (en) Address assignment method for identity and position separation network, and access service node
US20210321253A1 (en) Virtual tenant for multiple dwelling unit
CN106790734B (en) Network address allocation method and device
CN101184099A (en) Second IP address assignment method based on dynamic host machine configuration protocol access authentication
CN101997931A (en) Position information acquiring method and equipment
WO2007101378A1 (en) A device and method and system for acquiring ipv6 address
CN106878487B (en) Public network address allocation method and device
CN114257439B (en) Service scheduling method, AAA server and service supporting system
CN101184100A (en) User access authentication method based on dynamic host machine configuration protocol
CN103905386A (en) SIP terminal non-register access method, edge device and network
CN108259639B (en) IP address allocation method and device
CN107995125B (en) Traffic scheduling method and device
KR101308649B1 (en) System and method for assigning virtual network

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CP03 Change of name, title or address

Address after: 310052 Binjiang District Changhe Road, Zhejiang, China, No. 466, No.

Patentee after: Xinhua three Technology Co., Ltd.

Address before: 310053 Hangzhou hi tech Industrial Development Zone, Zhejiang province science and Technology Industrial Park, No. 310 and No. six road, HUAWEI, Hangzhou production base

Patentee before: Huasan Communication Technology Co., Ltd.

CP03 Change of name, title or address