Background technology
With the development of network technology, what network security was increasingly received payes attention to, especially some important departments, such as formula
Inside developing network, the internal network of government organs, how bank network and military network etc. to improve network security,
As a kind of necessary problem.
DHCP (Dynamic Host Configuration Protocol, DHCP) is a local
The procotol of net, is worked using UDP (User Datagram Protocol, UDP), mainly there is two use
On the way:To internal network or Internet service provider's automatic IP address allocation, to user or internal network keeper as to institute
There is computer to make the means of central management.
DHCP method be generally applied in large-scale LAN environment, and Main Function is management, the distribution IP address concentrated,
Make the main frame in network environment dynamically obtain IP address, Gateway addresses, domain name system (Domain Name System,
DNS) the information such as server address, and the utilization rate of address can be lifted.
DHCP protocol uses the dynamically distributes task of client/server model, host address to be driven by network host.When
When Dynamic Host Configuration Protocol server receives the information from network host applied address, just related address configuration can be sent to network host
Etc. information, to realize the dynamic configuration of Network Host address information.
It is DHCP security features that DHCP monitors (Snooping) technology, and the Main Function of DHCP Snooping is exactly to completely cut off
Illegal Dynamic Host Configuration Protocol server (Server), by configuring non-trusted port, by setting up and maintaining DHCP Snooping binding tables
Fly-by-night DHCP information is filtered, these information refer to from the DHCP information for distrusting region.DHCP Snooping bind
Table includes user media access control (media access control, MAC) address, IP address, lease period, the virtual office for distrusting region
Domain network mark knows the information such as (Virtual Local Area Network Identity, VLAN-ID) interface.
After interchanger opens DHCP-Snooping, DHCP message can be intercepted, it is possible to from the DHCP for receiving
Extracted in request (Request) or DHCP feedback (Ack) messages and record IP address and mac address information.In addition, DHCP-
Snooping is allowed for certain physical port to be set to trusted port or is distrusted port.Trusted port can be normally received and turned
Hair DHCP Offer messages, without the DHCP Offer packet loss that trusted port will can be received.So, can complete to exchange
Shielding action of the machine to personation DHCP Server, it is ensured that client obtains IP address from legal DHCP Server.
Trusted port can receive all of DHCP message.By the end for only connecting a switch to legal Dynamic Host Configuration Protocol server
Mouth is set to trusted port, and other ports are set to non-trusted port, it is possible to prevent user from forging Dynamic Host Configuration Protocol server to attack
Network.DHCP monitors characteristic and can also carry out speed limit to the DHCP message of port.Limited by under each non-trusted port
Speed, will can prevent the broadcast of legal DHCP request message from attacking.
Multi-user's multiple-input, multiple-output (Multi-User Multiple-Input Multiple-Output, MU-MIMO) skill
Art, is a kind of multi-antenna technology for allowing router to be linked up with multiple equipment simultaneously, is the new of the proposition in 802.11ac wave2
Technology.Up MU-MIMO:Different user terminals carry out up transmission (single antenna transmission) using identical running time-frequency resource, from connecing
From the point of view of receiving end, these data flows are considered as from a different antennae for user terminal, virtual so as to constitute one
Mimo system, i.e., up MU-MIMO.Descending MU-MIMO:Different user terminals, multiple users are given by multiple data stream transmittings
Terminal and base station (eNB) constitute descending MU-MIMO system;The side that descending MU-MIMO can pass through elimination/null in receiving terminal
Method, data flow of the separated transmission to different user terminals;Descending MU-MIMO can also use wave beam forming by transmitting terminal
Method, separates the data flow of different user terminals in advance, so as to simplify the operation of receiving terminal.
The content of the invention
The embodiment of the present invention provides the sending method and device of a kind of DHCP message so that the DHCP snooping of realization
The access point of function can " snooping " (monitoring) on antenna.
The first aspect of the present invention provides a kind of sending method of DHCP message, wherein, methods described includes:
Monitoring (snooping) list item that access point (AP) is set up under multi-user's multiple-input, multiple-output (MU-MIMO), wherein described
Monitoring list item includes the mapping of antenna ID, user terminal ID user terminal media access control (MAC) address related to DHCP
Relation;
When the AP receives the DHCP message related to a user terminal, the AP according to it is described monitoring list item only with
Launch the DHCP message of the user terminal on the corresponding transmission antenna of the user terminal.
Optionally, methods described also includes:Irrelevant with the user terminal other user terminals of antenna transmission
DHCP message.
Optionally, the related DHCP message of the user terminal carries the user terminal ID and user terminal of the user terminal
MAC Address, methods described also includes:
Antenna ID, user terminal IDs and user terminal MAC Address of the AP according to included by the monitoring list item reflects
Penetrate relation and determine that the user terminal is corresponding according to the user terminal ID and user terminal MAC Address of the user terminal
Transmission antenna.
Optionally, by N number of antenna and M user terminal communication, wherein N and M are more than or equal to 1 just the AP
Integer.
Optionally, the user terminal includes 1x1MIMO user terminals or 2x2MIMO user terminals.
The second aspect of the present invention provides a kind of dispensing device of DHCP message, including:Multiple antennas, processor, transmission
Device, receiver and memory, the multiple antenna, processor, transmitter, receiver and memory are connected and completed by bus
Mutual communication, wherein,
The processor is used for monitoring (snooping) list item set up under multi-user's multiple-input, multiple-output (MU-MIMO), wherein
The list item of monitoring includes antenna ID, user terminal ID user terminal media access control (MAC) address related to DHCP
Mapping relations;
The receiver is used to receive the DHCP message related to certain user terminal;
The processor is used for according to the related DHCP message of the user terminal and the monitoring list item, it is determined that with the use
The corresponding transmission antenna of family terminal.
The transmitter is used to only launch the user terminal on the transmission antenna corresponding with the user terminal
The DHCP message.
Optionally, the antenna irrelevant with the user terminal is used to transmit the DHCP message of other user terminals.
Optionally, the related DHCP message of the user terminal carries the user terminal ID and user terminal of the user terminal
MAC Address, wherein,
The processor is additionally operable to antenna ID, user terminal ID and user terminal according to included by the monitoring list item
The mapping relations of MAC Address and the use is determined according to the user terminal ID and user terminal MAC Address of the user terminal
The corresponding transmission antenna of family terminal.
Optionally, the multiple antenna is N number of antenna, N number of antenna and M user terminal communication, and wherein N and M are equal
It is the positive integer more than or equal to 1.
Optionally, the user terminal includes 1x1MIMO user terminals or 2x2MIMO user terminals.
The sending method and device of the DHCP message of the above embodiments description so that the DHCP snooping work(of realization
Can access point can " snooping " (monitoring) on antenna.
Specific embodiment
To make the purpose, technical scheme and advantage of the embodiment of the present invention clearer, below in conjunction with the embodiment of the present invention
In accompanying drawing, the technical scheme in the embodiment of the present invention is clearly and completely described, it is clear that described embodiment is
A part of embodiment of the present invention, rather than whole embodiments.Based on the embodiment in the present invention, those of ordinary skill in the art
The every other embodiment obtained under the premise of creative work is not made, belongs to the scope of protection of the invention.
The techniques described herein may be used in various communication systems, such as 2G, 3G, 4G communication system and next generation communication system
System (for example, 5G), such as global mobile communication (GSM, Global System for Mobile Communication) system,
CDMA (CDMA, Code Division Multiple Access) system, time division multiple acess (TDMA, Time Division
Multiple Access) system, WCDMA (WCDMA, Wideband Code Division Multiple
Access) system, frequency division multiple access (FDMA, Frequency Division Multiple Access) system, orthogonal frequency is more
Location (OFDMA, Orthogonal Frequency-Division Multiple Access) system, Single Carrier Frequency Division Multiple Access (SC-
FDMA) system, GPRS (GPRS, General Packet Radio Service) system, Long Term Evolution
(LTE, Long Term Evolution) system, and other such communication systems.Cdma system can realize such as wireless universal
Access the radiotechnics such as (UTRA, Universal Terrestrial Radio Access), CDMA2000 in land.UTRA bags
Include broadband-CDMA (WCDMA) and other CDMA variants.In addition, CDAM2000 covers IS-2000, IS-95 and IS-856 standard.
Tdma system can realize the radiotechnics of global system for mobile communications (GSM) etc..OFDMA system can realize such as evolution
General land wireless access (E-UTRA, Evolved-UMTS Terrestrial Radio Access), Ultra-Mobile Broadband
(UMB, Ultra Mobile Broadband), IEEE802.11 (Wi-Fi), IEEE802.16 (WiMAX), IEEE802.20,
The radiotechnics such as Flash-OFDMA.UTRA and E-UTRA are UMTS (UMTS, Universal Mobile
Telecommunication System) a part.3GPP Long Term Evolutions (for example, LTE) are the use E-UTRA of UMTS
Version, it can use OFDMA on the uplink, and can use SC-FDMA on uplink.UTRA、E-UTRA、UMTS、
LTE and GSM descriptions are in the document of " third generation partnership project (3GPP) " tissue.In addition, CDAM2000 and UMB descriptions are " the
In the document of three generations's partnership projects 2 (3GPP2) " tissue.
The terms "and/or", only a kind of incidence relation for describing affiliated partner, represents there may be three kinds of passes
System, for example, A and/or B, can represent:Individualism A, while there is A and B, individualism B these three situations.In addition, herein
Middle character "/", typicallys represent forward-backward correlation pair as if a kind of relation of "or".
As shown in figure 1, the schematic flow sheet of the sending method for a kind of DHCP message of one embodiment of the invention, this implementation
In example, access point (AP) can be wireless router, be provided with multiple antennas, and the AP is used by the multiple antenna with multiple
Family terminal communication, for example, the AP is by N number of antenna and M user terminal communication, wherein N and M are more than or equal to 1
Positive integer, N and M can be with identical or different, and the user terminal can be 1x1MIMO, or 2x2MIMO, wherein, it is described
1x1MIMO represents that an antenna is received, and an antenna sends, and 2x2MIMO represents that two antennas are received, and two antennas send.
For example, the AP has 4 antennas:Antenna 1, antenna 2, antenna 3 and antenna 4, it is assumed that have 2 user terminals of 1x1,
Respectively STA1, STA2, the 1 user terminal STA3 of 2x2, then the AP can and STA1, STA2, STA3 set up following logical
Letter:Antenna 1 and STA1 are communicated, and antenna 2 and STA2 are communicated, and antenna 3,4 and STA3 are communicated.
Step 11, monitoring (snooping) list item that AP is set up under MU-MIMO, wherein the monitoring list item includes antenna
The mapping relations of user terminal MAC Address ID, user terminal ID related to DHCP.
For example, the monitoring list item can be as shown in table 1.
Mapping relations can be expressed as (antenna ID, user terminal ID, user terminal MAC Address), it can be seen from table 1, AP
The snooping list items set up under MU-MIMO include four kinds of mapping relations:(1,1, STA1 MAC), (2,2, STA2 MAC) (3,
3rd, STA3 MAC) and (4,3, STA31 MAC).
Step 12, when the AP receives the DHCP message related to a user terminal, the AP is according to the monitoring table
Item only launches the DHCP message of the user terminal on the transmission antenna corresponding with the user terminal.
For example, when the DHCP message related to the STA1 arrives, the STA1 related DHCP message carries described
Antenna ID, STA ID of the user terminal ID and user terminal MAC Address of STA1, the AP according to included by the monitoring list item
Determine with the mapping relations of user terminal MAC Address and the user terminal ID according to the STA1 and user terminal MAC Address
STA1 correspondence transmission antennas are antenna 1, so AP only sends the related DHCP messages of the STA1, antenna 2,3,4 on antenna 1
Transmit the message of other user terminals.
For example, when the DHCP message related to the STA2 arrives, the STA2 related DHCP message carries described
Antenna ID, STA ID of the user terminal ID and user terminal MAC Address of STA2, the AP according to included by the monitoring list item
Determine STA2 with the mapping relations of user terminal MAC Address and according to the user terminal ID and user terminal MAC Address of STA2
Correspondence transmission antenna is antenna 2, so AP only sends the related DHCP messages of the STA1 on antenna 2, antenna 1,3,4 is transmitted
The message of other user terminals.
For example, when the DHCP message related to the STA3 arrives, the STA3 related DHCP message carries described
Antenna ID, STA ID of the user terminal ID and user terminal MAC Address of STA3, the AP according to included by the monitoring list item
Determine STA3 with the mapping relations of user terminal MAC Address and according to the user terminal ID and user terminal MAC Address of STA3
Corresponding transmission antenna is antenna 3,4, so AP only sends the related DHCP messages of the STA3, antenna 1,2 on antenna 3,4
Transmit the message of other user terminals.
In sum, the sending method of the DHCP message of this implementation, can communicate simultaneously during due to MU-MIMO multiple antennas,
It it is not the time-division, if when the DHCP message of certain user terminal is transmitted on antenna 1, antenna 2,3,4 can be with simultaneous transmission
The message of other users terminal, is entirely unaffected by, for example, the non-use of the antenna transmission irrelevant with the user terminal
The DHCP message of family terminal.
As shown in Fig. 2 the structural representation of the dispensing device for a kind of DHCP message of another embodiment of the present invention, this reality
Apply in example, the dispensing device of the DHCP message is access point (AP), for example, the AP can be wireless router, it is described
The dispensing device of DHCP message includes multiple antennas 200, processor 201, transmitter 202, receiver 203 and memory 204, institute
Multiple antennas 200, processor 201, transmitter 202, receiver 203 and memory 204 is stated to be connected by bus and completed mutually
Between communication.
The processor 201 can be for central processing unit (Central Processing Unit, CPU), at data signal
Reason device (Digital Signal Processor, DSP) chip, application specific integrated circuit (Application Specific
Integrated Circuit, ASIC), field programmable gate array (Field Programmable Gate Array, FPGA)
Or other PLDs etc..
The bus can be Industry Standard Architecture (Industry Standard Architecture, ISA) bus, extension
Industrial standard architectures (Extended Industry Standard Architecture, EISA) bus, external equipment interconnection
(Peripheral Component Interconnect, PCI) bus or inter-integrated circuit (Inter-Integrated
Circuit, I2C) bus etc., the bus can be divided into address bus, data/address bus, controlling bus etc..
The memory 204 is used to store executable program code, and the program code includes computer-managed instruction.
The memory 204 can be volatile memory (volatile memory), for example random access memory (RAM,
Random-access memory), or nonvolatile memory (NVM, non-volatile memory), for example only
Read memory (ROM, read-only memory), flash memory (flash memory), hard disk (HDD, hard disk
) or solid state hard disc (SSD, solid-state drive) drive.
The AP passes through the multiple antenna 200 and multiple user terminal communications, for example, the AP passes through N number of antenna and M
Individual user terminal communication, wherein N and M are the positive integer more than or equal to 1, and N and M can be with identical or different, user's end
End can be 1x1MIMO, or 2x2MIMO, wherein, the 1x1MIMO represents that an antenna is received, an antenna hair
Send, 2x2MIMO represents that two antennas are received, two antennas send.
For example, the antenna 200 of the AP has 4 antennas:Antenna 1, antenna 2, antenna 3 and antenna 4, it is assumed that have 2 1x1's
The user terminal STA3 of user terminal, respectively STA1, STA2,1 2x2, then the AP can and STA1, STA2, STA3 build
Communicated under Liru:Antenna 1 and STA1 are communicated, and antenna 2 and STA2 are communicated, and antenna 3,4 and STA3 are communicated.
The processor 201 can call the operational order that stores in the memory 204 or program code to perform
The sending method of the DHCP message provided in an embodiment of the present invention, is described as follows.
The processor 201 is used for monitoring (snooping) list item set up under MU-MIMO, wherein the monitoring list item bag
Include the mapping relations of antenna ID, user terminal ID the user terminal MAC Address related to DHCP.
For example, the monitoring list item can be as shown in table 1.
Mapping relations can be expressed as (antenna ID, user terminal ID, user terminal MAC Address), it can be seen from table 1, institute
Stating snooping list item of the processor 201 for setting up under MU-MIMO includes four kinds of mapping relations:(1,1, STA1 MAC), (2,
2nd, STA2 MAC) (3,3, STA3 MAC) and (4,3, STA31 MAC).
The receiver 203 is used to receive the DHCP message related to certain user terminal.
The processor 201 is used for according to the related DHCP message of the user terminal and the monitoring list item, it is determined that with
The corresponding transmission antenna of the user terminal.
The transmitter 202, for only launching user's end on the transmission antenna corresponding with the user terminal
The DHCP message at end.
For example, when the DHCP message related to the STA1 arrives, the STA1 related DHCP message carries described
The user terminal ID and user terminal MAC Address of STA1, antenna of the processor 201 according to included by the monitoring list item
The mapping relations and the user terminal ID and user terminal MAC according to the STA1 of ID, STA ID and user terminal MAC Address
Address determines that STA1 correspondence transmission antennas are antenna 1, and the transmitter 202 only sends the STA1 correlations on antenna 1
DHCP message, antenna 2,3,4 transmits the message of other user terminals.
For example, when the DHCP message related to the STA2 arrives, the STA2 related DHCP message carries described
The user terminal ID and user terminal MAC Address of STA2, antenna of the processor 201 according to included by the monitoring list item
The mapping relations and the user terminal ID and user terminal MAC Address according to STA2 of ID, STA ID and user terminal MAC Address
Determine that STA2 correspondence transmission antennas are antenna 2, the transmitter 202 only sends the related DHCP reports of the STA1 on antenna 2
Text, antenna 1,3,4 transmits the message of other user terminals.
For example, when the DHCP message related to the STA3 arrives, the STA3 related DHCP message carries described
The user terminal ID and user terminal MAC Address of STA3, antenna of the processor 201 according to included by the monitoring list item
The mapping relations and the user terminal ID and user terminal MAC Address according to STA3 of ID, STA ID and user terminal MAC Address
The corresponding transmission antennas of STA3 are determined for antenna 3,4, and the transmitter 202 only sends the STA3 correlations on antenna 3,4
DHCP message, antenna 1,2 transmits the message of other user terminals.
Can simultaneously be communicated when in sum, due to the MU-MIMO multiple antennas of the dispensing device of DHCP message, not be the time-division
, if when the DHCP message of certain user terminal is transmitted on antenna 1, antenna 2,3,4 can be with simultaneous transmission other users
The message of terminal, is entirely unaffected by, for example, the non-user terminal of the antenna transmission irrelevant with the user terminal
DHCP message.
In several embodiments provided herein, it should be understood that disclosed system, apparatus and method can be with
Realize by another way.For example, device embodiment described above is only schematical, for example, the module or
The division of unit, only a kind of division of logic function, can there is other dividing mode when actually realizing, such as multiple units
Or component can be combined or be desirably integrated into another system, or some features can be ignored, or not perform.It is another, institute
Display or the coupling each other for discussing or direct-coupling or communication connection can be by some interfaces, device or unit
INDIRECT COUPLING or communication connection, can be electrical, mechanical or other forms.
The unit that is illustrated as separating component can be or may not be it is physically separate, it is aobvious as unit
The part for showing can be or may not be physical location, you can with positioned at a place, or can also be distributed to multiple
On NE.Some or all of unit therein can be according to the actual needs selected to realize the mesh of this embodiment scheme
's.
In addition, during each functional unit in the application each embodiment can be integrated in a processing unit, it is also possible to
It is that unit is individually physically present, it is also possible to which two or more units are integrated in a unit.Above-mentioned integrated list
Unit can both be realized in the form of hardware, it would however also be possible to employ the form of SFU software functional unit is realized.
If the integrated unit is to realize in the form of SFU software functional unit and as independent production marketing or use
When, can store in a computer read/write memory medium.Based on such understanding, the technical scheme of the application is substantially
The part for being contributed to prior art in other words or all or part of the technical scheme can be in the form of software products
Embody, the computer software product is stored in a storage medium, including some instructions are used to so that a computer
Equipment (can be personal computer, server, or network equipment etc.) or processor (processor) perform the application each
The all or part of step of embodiment methods described.And foregoing storage medium includes:USB flash disk, mobile hard disk, read-only storage
(ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disc or CD
Etc. it is various can be with the medium of store program codes.
The above, above example is only used to illustrate the technical scheme of the application, rather than its limitations;Although with reference to preceding
Embodiment is stated to be described in detail the application, it will be understood by those within the art that:It still can be to preceding
State the technical scheme described in each embodiment to modify, or equivalent is carried out to which part technical characteristic;And these
Modification is replaced, and does not make the spirit and scope of essence disengaging each embodiment technical scheme of the application of appropriate technical solution.