CN1455548A - Management method of user's connecting network in wideband network - Google Patents

Management method of user's connecting network in wideband network Download PDF

Info

Publication number
CN1455548A
CN1455548A CN 02116068 CN02116068A CN1455548A CN 1455548 A CN1455548 A CN 1455548A CN 02116068 CN02116068 CN 02116068 CN 02116068 A CN02116068 A CN 02116068A CN 1455548 A CN1455548 A CN 1455548A
Authority
CN
China
Prior art keywords
user
address
information
mapping table
account number
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN 02116068
Other languages
Chinese (zh)
Other versions
CN1204713C (en
Inventor
涂伯颜
史文江
张劲峰
谢晓娟
罗成
董靖宇
肖维
王峰波
温元德
杨宏杰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN 02116068 priority Critical patent/CN1204713C/en
Publication of CN1455548A publication Critical patent/CN1455548A/en
Application granted granted Critical
Publication of CN1204713C publication Critical patent/CN1204713C/en
Anticipated expiration legal-status Critical
Expired - Lifetime legal-status Critical Current

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The present invention establishes the combined correspondence relation table among permanent virtual connection information in user physical link information or virtual local area network, user account number, address and media access control. Whether the correspondence relation among permanent virtual connection information in user physical link information or virtual locak area network, user account number, address and media access control is in consistency with the information listed in the correspondence table or not is judged when the user is on the network. The on-network connection is set up for the user if it is in consistency or otherwise the on-network connection is refused.

Description

User's connection management method of surfing the Net in the broadband network
Technical field
The present invention relates to a kind of in broadband network the method for leading subscriber, refer in particular to by setting up permanent virtual in user's physical link information and connect the method that PVC information or VLAN ID VLANID are connected with the corresponding relation managing user network access of user account number.
Background technology
In existing broadband network,, can be divided into that ADSL inserts and the Ethernet access according to the surf the Net difference of used access technology of user.In the broadband network that adopts the ADSL access way, operator or ISP distribute a corresponding physical link for a user, be that permanent virtual connects PVC, the Frame that ADSL user sends is by this physical link, peel off link layer information behind the BAS Broadband Access Server BRAS in arriving broadband network, then the IP bag is transmitted accordingly, its handling process as shown in Figure 1.Here it has utilized the link layer transfer function of atm network, be about to Frame that ADSL user sends etc. and be packaged into that to be carried on a physical link after the ATM cell be that permanent virtual connects on the PVG, on BAS Broadband Access Server BRAS, finish the ATM termination, look into route according to the purpose IP in the IP bag then and finish forwarding capability.
In the broadband network that adopts Ethernet Ethernet access way, operator or ISP distribute a corresponding virtual LAN ID VLANID for a user, the user is directly connected in the broadband network of operator or ISP by Category-5 twisted pair (netting twine), the Frame that sends for the user, by peeling off link layer information behind the BAS Broadband Access Server BRAS in the Ethernet net arrival broadband network, then the IP bag is transmitted accordingly.Here it has utilized the link layer transfer function of Ethernet net, on BAS Broadband Access Server BRAS VLAN ID VLANID is terminated, and looks into routing forwarding according to the purpose IP in the IP bag then.
Broadband network has the advantages that scale is big, the user is many, can safeguard, can manage, can run.Can not prevent that the disabled user from surfing the Net, usurping Internet resources, not possessing the user and review network security problem such as function after under fire but exist.
Summary of the invention
The purpose of this invention is to provide the management method that user that a kind of disabled user of preventing surfed the Net, can discern rogue attacks surfs the Net and connects.
The present invention realizes by following manner: user's connection management method of surfing the Net in the broadband network, in the broadband network that adopts the ADSL access way, may further comprise the steps,
Set up the mapping table that permanent virtual in user's physical link information connects PVC information and user account number;
When the user surfs the Net, search described mapping table according to permanent virtual link information or account in user's physical link information, judge whether the permanent virtual link information is consistent with permanent virtual link information and usersaccount information in the mapping table with account in user's physical link information;
If consistent, the online of setting up described user connects;
If inconsistent, the online that refusal is set up described user connects.
For have the fixed the Internet agreement ' address user, when setting up permanent virtual connection PVC information and usersaccount information mapping table, set up the corresponding relation of the two and IP address, form the mapping table that IP address, permanent virtual connect PVC information, user account number three.
When the user surfs the Net, permanent virtual in judging user's physical link information connect PVC information and account be connected with permanent virtual in the mapping table PVC information and usersaccount information whether consistent in, judge also whether user's IP address is consistent with this user's IP address in the mapping table, has only user's IP address, permanent virtual connects PVC information in user's the physical link information, IP address in user account number and the mapping table, permanent virtual connects PVC information, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
In the mapping table that forms IP address, permanent virtual connection PVC information, user account number three, increase the corresponding relation of controlling MAC Address with media interviews, form the mapping table of IP address, media access control address MAC, permanent virtual connection PVC, user account number.
When the user surfs the Net, permanent virtual link information in judging user's physical link information and account be connected with permanent virtual in the mapping table PVC information and usersaccount information whether consistent in, also judge user's IP address, this user's IP address in media interviews control MAC Address and the mapping table, whether media interviews control MAC Address is consistent, has only user's IP address, media interviews control MAC Address, permanent virtual in user's physical link information connects PVC information, IP address in user account number and the mapping table, media interviews control MAC Address, permanent virtual connects PVC, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
For there not being fixed the Internet protocol IP address user, when setting up permanent virtual connection PVC information and user account number mapping table, set up the corresponding relation of the two and user media access control MAC addresses, form the mapping table that media interviews control MAC Address, permanent virtual connect PVC information, user account number three.
When the user surfs the Net, permanent virtual in judging user's physical link information connect PVC information and account be connected with permanent virtual in the mapping table PVC information and usersaccount information whether consistent in, whether MAC Address is controlled in the media interviews control MAC Address of also judging the user and the media interviews in the mapping table consistent, the media interviews control MAC Address of having only the user, permanent virtual in user's physical link information connects PVC information, media interviews control MAC Address in user account number and the mapping table, permanent virtual connects PVC, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
The present invention may further comprise the steps in the broadband network that adopts the Ethernet access way,
Set up the mapping table of VLAN ID VLANID and user account number in user's physical link;
When the user surfs the Net, search described mapping table according to VLAN ID VLANID information or account in user's physical link, judge whether VLAN ID VLANID information is consistent with VLAN ID VLANID information and usersaccount information in the mapping table with account in user's physical link;
If consistent, the online of setting up described user connects;
If inconsistent, the online that refusal is set up described user connects.
For fixed the Internet protocol IP address user is arranged, when setting up VLAN ID VLANID and usersaccount information mapping table, set up the corresponding relation of the two and IP address, form IP address, VLAN ID VLANID, user account number three's mapping table.
When the user surfs the Net, when whether VLAN ID VLANID information in judging user's physical link in VLAN ID VLANID information and account and the mapping table and usersaccount information be consistent, judge also whether user's IP address is consistent with this user's IP address in the mapping table, has only user's IP address, VLAN ID VLANID information in user's the physical link, IP address in user account number and the mapping table, VLAN ID VLANID, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
In the mapping table that forms IP address, VLAN ID VLANID, user account number three, increase the corresponding relation of controlling MAC Address with media interviews, form the mapping table of IP address, media access control address MAC, VLAN ID VLANID, user account number.
When the user surfs the Net, when whether VLAN ID VLANID information in judging user's physical link in VLAN ID VLANID information and account and the mapping table and usersaccount information be consistent, also judge user's IP address, this user's IP address in media interviews control MAC Address and the mapping table, whether media interviews control MAC Address is consistent, has only user's IP address, media interviews control MAC Address, VLAN ID VLANID in user's physical link, IP address in user account number and the mapping table, media interviews control MAC Address, VLAN ID VLANID, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
For there not being fixed the Internet protocol IP address user, when setting up VLAN ID VLANID and user account number mapping table, set up the corresponding relation of the two and user media access control MAC addresses, form media interviews control MAC Address, VLAN ID VLANID, user account number three's mapping table.
When the user surfs the Net, when whether VLAN ID VLANID information in judging user's physical link in VLAN ID VLANID information and account and the mapping table and usersaccount information be consistent, whether MAC Address is controlled in the media interviews control MAC Address of also judging the user and the media interviews in the mapping table consistent, the media interviews control MAC Address of having only the user, VLAN ID VLANID information in user's physical link, media interviews control MAC Address in user account number and the mapping table, VLAN ID VLANID, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
After the correspondence table of having set up above-mentioned various binding relationships is stored in certificate server, when online, to check user's various parameters and the contrast of the correspondence table in the certificate server, the disabled user does not then connect in this way, because of the relevant parameter of physics access link be the user can not be counterfeit, prevent disabled user's online, avoided phenomenons such as user's address embezzlement and account embezzlement; When the user was under attack, the source region that comes of rogue attacks was judged by operator according to the parameter of attacking the user; The binding parameter increases in the correspondence table of binding relationship, will increase the fail safe of network gradually; The present invention simultaneously can carry out different management to the user and accurately settles accounts according to different user source information, is convenient to operator can release user's needs quickly according to user's actual needs network service.
Description of drawings
The invention will be further described below in conjunction with accompanying drawing and concrete execution mode.
Fig. 1 is that prior art adopts the flow chart that the IP bag is transmitted in the broadband network of ADSL access way;
Fig. 2 is the schematic flow sheet of the present invention in the broadband network of ADSL access way;
Fig. 3 is the schematic flow sheet of the present invention in the broadband network that adopts the ether access way.
Embodiment
In existing broadband network, employing ADSL access way, often permanent virtual connects PVC in physical link layer of user's correspondence, that is to say and to connect the unique user of sign of PVC with permanent virtual in the physical link layer, employing ether access way, corresponding VLAN ID VLANID of user often, that is to say can be with the user of sign that VLAN ID VLANID is unique, and the present invention is with IP, media interviews control MAC Address, permanent virtual connects PVC or VLAN ID VLANID in the physical link layer, relationship between the user account number gets up to discern user's method.
The present invention realizes by following manner: in the broadband network that adopts the ADSL access way, the present invention sets up the mapping table that permanent virtual in user's the physical link information connects PVC information and user account number, for fixed the Internet protocol IP address user is arranged, set up the IP address, permanent virtual connects PVC information, user account number three's mapping table or IP address, media access control address MAC, permanent virtual connects PVC, the mapping table of user account number, for there not being fixed the Internet protocol IP address user, set up media interviews control MAC Address, permanent virtual connects PVC information, user account number three's mapping table, these mapping tables are set up on certificate server, when carrying out transfer of data, whether the BAS Broadband Access Server BRAS in the broadband network just can judge correctly whether a frame is legal frame etc. by checking the corresponding relation between these several persons of a Frame, user on the physical link is immobilized, when the user surfs the Net, BAS Broadband Access Server BRAS is when certificate server sends user authentication request, in the report of user account number, the physical link information of report of user, certificate server just knows by checking whether this information conforms to the correspondence table of setting up in advance whether this user is fake user etc.Concrete binding relationship and online detect and comprise following several form;
One, sets up the mapping table that permanent virtual in user's physical link information connects PVC information and user account number;
When the user surfs the Net, search described mapping table according to permanent virtual link information or account in user's physical link information, judge whether the permanent virtual link information is consistent with permanent virtual link information and usersaccount information in the mapping table with account in user's physical link information;
If consistent, the online of setting up described user connects;
If inconsistent, the online that refusal is set up described user connects.
Two, for fixed the Internet protocol IP address user is arranged, when setting up permanent virtual connection PVC information and usersaccount information mapping table, set up the corresponding relation of the two and IP address, form the mapping table that IP address, permanent virtual connect PVC information, user account number three.
When the user surfs the Net, permanent virtual in judging user's physical link information connect PVC information and account be connected with permanent virtual in the mapping table PVC information and usersaccount information whether consistent in, judge also whether user's IP address is consistent with this user's IP address in the mapping table, have only permanent virtual in user's IP address, user's the physical link information to connect the connection that PVC information, user account number are connected PVC information with IP address, permanent virtual in the mapping table, just set up this user when user account number is in full accord, otherwise the dismounting connection.
Three, in the mapping table that forms above-mentioned IP address, permanent virtual connection PVC information, user account number three, increase the corresponding relation of controlling MAC Address with media interviews, form the mapping table of IP address, media access control address MAC, permanent virtual connection PVC, user account number.
When the user surfs the Net, permanent virtual link information in judging user's physical link information and account be connected with permanent virtual in the mapping table PVC information and usersaccount information whether consistent in, also judge user's IP address, this user's IP address in media interviews control MAC Address and the mapping table, whether media interviews control MAC Address is consistent, has only user's IP address, media interviews control MAC Address, permanent virtual in user's physical link information connects PVC information, IP address in user account number and the mapping table, media interviews control MAC Address, permanent virtual connects PVC, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
Four, for there not being fixed the Internet protocol IP address user, when setting up permanent virtual connection PVC information and user account number mapping table, set up the corresponding relation of the two and user media access control MAC addresses, form the mapping table that media interviews control MAC Address, permanent virtual connect PVC information, user account number three.
When the user surfs the Net, permanent virtual in judging user's physical link information connect PVC information and account be connected with permanent virtual in the mapping table PVC information and usersaccount information whether consistent in, whether MAC Address is controlled in the media interviews control MAC Address of also judging the user and the media interviews in the mapping table consistent, the media interviews control MAC Address of having only the user, permanent virtual in user's physical link information connects PVC information, media interviews control MAC Address in user account number and the mapping table, permanent virtual connects PVC, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
Concrete handling process such as Fig. 2 are: set up the correspondence table of various binding relationships, and be stored in the certificate server; When the BAS Broadband Access Server BRAS in the broadband network receives from ATM Frame that user side comes, by analyzing the physics link information, get access to permanent virtual in the physical link layer and connect various parameters such as the MAC Address of PVC information (corresponding VPI, VCI), user's PC and IP address, simultaneously these information and user account number are reported certificate server together, according to setting up good relevant entries in advance these information are carried out matching check by certificate server, identical agreement online connects, and then refusal inequality online connects.
The present invention is to set up the mapping table that the user sets up VLAN ID VLANID and user account number in user's physical link in advance in the Access Network that adopts the ether access way; For fixed the Internet protocol IP address user is arranged, set up the mapping table of IP address, VLAN ID VLANID, user account number three's mapping table or IP address, media access control address MAC, VLAN ID VLANID, user account number; For there not being fixed the Internet protocol IP address user, set up media interviews control MAC Address, VLAN ID VLANID, user account number three's mapping table, and these several persons' mapping table is based upon in the certificate server, BAS Broadband Access Server (BRAS) is when certificate server sends user authentication request, in the report of user account number, the physical link information of report of user, certificate server just knows by checking these information whether this user is fake user etc.Concrete binding and online detect and comprise following several form:
One, sets up the mapping table of VLAN ID VLANID and user account number in user's physical link;
When the user surfs the Net, search described mapping table according to VLAN ID VLANID information or account in user's physical link, judge whether VLAN ID VLANID information is consistent with VLAN ID VLANID information and usersaccount information in the mapping table with account in user's physical link;
If consistent, the online of setting up described user connects;
If inconsistent, the online that refusal is set up described user connects.
Two, for fixed the Internet protocol IP address user is arranged, when setting up VLAN ID VLANID and usersaccount information mapping table, set up the corresponding relation of the two and IP address, form IP address, VLAN ID VLANID, user account number three's mapping table.
When the user surfs the Net, when whether VLAN ID VLANID information in judging user's physical link in VLAN ID VLANID information and account and the mapping table and usersaccount information be consistent, judge also whether user's IP address is consistent with this user's IP address in the mapping table, has only user's IP address, VLAN ID VLANID information in user's the physical link, IP address in user account number and the mapping table, VLAN ID VLANID, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
Three, in the mapping table that forms above-mentioned IP address, VLAN ID VLANID, user account number three, increase the corresponding relation of controlling MAC Address with media interviews, form the mapping table of IP address, media access control address MAC, VLAN ID VLANID, user account number.
When the user surfs the Net, when whether VLAN ID VLANID information in judging user's physical link in VLAN ID VLANID information and account and the mapping table and usersaccount information be consistent, also judge user's IP address, this user's IP address in media interviews control MAC Address and the mapping table, whether media interviews control MAC Address is consistent, has only user's IP address, media interviews control MAC Address, VLAN ID VLANID in user's physical link, IP address in user account number and the mapping table, media interviews control MAC Address, VLAN ID VLANID, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
Four, for there not being fixed the Internet protocol IP address user, when setting up VLAN ID VLANID and user account number mapping table, set up the corresponding relation of the two and user media access control MAC addresses, form media interviews control MAC Address, VLAN ID VLANID, user account number three's mapping table.
When the user surfs the Net, when whether VLAN ID VLANID information in judging user's physical link in VLAN ID VLANID information and account and the mapping table and usersaccount information be consistent, whether MAC Address is controlled in the media interviews control MAC Address of also judging the user and the media interviews in the mapping table consistent, the media interviews control MAC Address of having only the user, VLAN ID VLANID information in user's physical link, media interviews control MAC Address in user account number and the mapping table, VLAN ID VLANID, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
Concrete handling process is as shown in Figure 3: set up the correspondence table of various binding relationships, and be stored in the certificate server; When the BAS Broadband Access Server BRAS in the broadband network receives from Ether frame that user side comes, by analyzing, get access to various parameters such as the MAC Address of VLAN ID VLANIDID in the Ether frame and this user's PC and IP address, simultaneously these parameters and user account number are reported certificate server, according to setting up good relevant entries in advance these parameters are carried out matching check by certificate server, identical agreement online connects, and then refusal inequality online connects.

Claims (14)

1, user's connection management method of surfing the Net in the broadband network is characterized in that: may further comprise the steps,
Set up the mapping table that permanent virtual in user's physical link information connects (PVC) information and user account number;
When the user surfs the Net, search described mapping table according to permanent virtual link information or account in user's physical link information, judge whether the permanent virtual link information is consistent with permanent virtual link information and usersaccount information in the mapping table with account in user's physical link information;
If consistent, the online of setting up described user connects;
If inconsistent, the online that refusal is set up described user connects.
2, user's connection management method of surfing the Net in the broadband network according to claim 1, it is characterized in that: for fixed the Internet agreement (IP) address user is arranged, when setting up permanent virtual connection (PVC) information and usersaccount information mapping table, set up the corresponding relation of the two and IP address, form the mapping table that IP address, permanent virtual connect (PVC) information, user account number three.
3, user's method of attachment of surfing the Net in the broadband network according to claim 2, it is characterized in that: when the user surfs the Net, permanent virtual in judging user's physical link information connect (PVC) information and account be connected with permanent virtual in the mapping table (PVC) information and usersaccount information whether consistent in, judge also whether user's IP address is consistent with this user's IP address in the mapping table, has only user's IP address, permanent virtual connects (PVC) information in user's the physical link information, IP address in user account number and the mapping table, permanent virtual connects (PVC) information, just set up this user's connection when user account number is in full accord, otherwise refusal connects.
4, user's method of attachment of surfing the Net in the broadband network according to claim 2, it is characterized in that: in the mapping table that forms IP address, permanent virtual connection (PVC) information, user account number three, increase the corresponding relation of controlling (MAC) address with media interviews, form the mapping table of IP address, media access control address (MAC), permanent virtual connection (PVC), user account number.
5, user's method of attachment of surfing the Net in the broadband network according to claim 4, it is characterized in that: when the user surfs the Net, permanent virtual link information in judging user's physical link information and account be connected with permanent virtual in the mapping table (PVC) information and usersaccount information whether consistent in, also judge user's IP address, this user's IP address in media interviews control (MAC) address and the mapping table, whether media interviews control (MAC) address is consistent, has only user's IP address, media interviews control (MAC) address, permanent virtual in user's physical link information connects (PVC) information, IP address in user account number and the mapping table, media interviews control (MAC) address, permanent virtual connects (PVC), just set up this user's connection when user account number is in full accord, otherwise refusal connects.
6, user's method of attachment of surfing the Net in the broadband network according to claim 1, it is characterized in that: for there not being fixed the Internet agreement (IP) address user, when setting up permanent virtual connection (PVC) information and user account number mapping table, set up the corresponding relation of the two and user media access control (MAC) address, form the mapping table that media interviews control (MAC) address, permanent virtual connect (PVC) information, user account number three.
7, user's connection management method of surfing the Net in the broadband network according to claim 6, it is characterized in that: when the user surfs the Net, permanent virtual in judging user's physical link information connect (PVC) information and account be connected with permanent virtual in the mapping table (PVC) information and usersaccount information whether consistent in, whether media interviews control (MAC) address of also judging the user is consistent with media interviews control (MAC) address in the mapping table, media interviews control (MAC) address of having only the user, permanent virtual in user's physical link information connects (PVC) information, media interviews control (MAC) address in user account number and the mapping table, permanent virtual connects (PVC), just set up this user's connection when user account number is in full accord, otherwise refusal connects.
8, user's connection management method of surfing the Net in the broadband network is characterized in that: may further comprise the steps,
Set up the mapping table of VLAN ID in user's physical link (VLANID) and user account number;
When the user surfs the Net, search described mapping table according to VLAN ID (VLANID) information or account in user's physical link information, judge whether VLAN ID in user's physical link (VLANID) information is consistent with VLAN ID (VLANID) information and usersaccount information in the mapping table with account;
If consistent, the online of setting up described user connects;
If inconsistent, the online that refusal is set up described user connects.
9, user's connection management method of surfing the Net in the broadband network according to claim 8, it is characterized in that: for fixed the Internet agreement (IP) address user is arranged, when setting up VLAN ID (VLANID) and usersaccount information mapping table, set up the corresponding relation of the two and IP address, form IP address, VLAN ID (VLANID), user account number three's mapping table.
10, user's method of attachment of surfing the Net in the broadband network according to claim 9, it is characterized in that: when the user surfs the Net, when whether VLAN ID (VLANID) information in VLAN ID in judging user's physical link (VLANID) information and account and the mapping table and usersaccount information be consistent, judge also whether user's IP address is consistent with this user's IP address in the mapping table, has only user's IP address, VLAN ID in user's the physical link (VLANID) information, IP address in user account number and the mapping table, VLAN ID (VLANID), just set up this user's connection when user account number is in full accord, otherwise refusal connects.
11, user's method of attachment of surfing the Net in the broadband network according to claim 9, it is characterized in that: in the mapping table that forms IP address, VLAN ID (VLANID), user account number three, increase the corresponding relation of controlling (MAC) address with media interviews, form the mapping table of IP address, media access control address (MAC), VLAN ID (VLANID), user account number.
12, user's method of attachment of surfing the Net in the broadband network according to claim 11, it is characterized in that: when the user surfs the Net, when whether VLAN ID (VLANID) information in VLAN ID in judging user's physical link (VLANID) information and account and the mapping table and usersaccount information be consistent, also judge user's IP address, this user's IP address in media interviews control (MAC) address and the mapping table, whether media interviews control (MAC) address is consistent, has only user's IP address, media interviews control (MAC) address, VLAN ID in user's physical link (VLANID), IP address in user account number and the mapping table, media interviews control (MAC) address, VLAN ID (VLANID), just set up this user's connection when user account number is in full accord, otherwise refusal connects.
13, user's method of attachment of surfing the Net in the broadband network according to claim 8, it is characterized in that: for there not being fixed the Internet agreement (IP) address user, when setting up VLAN ID (VLANID) and user account number mapping table, set up the corresponding relation of the two and user media access control (MAC) address, form media interviews control (MAC) address, VLAN ID (VLANID), user account number three's mapping table.
14, user's connection management method of surfing the Net in the broadband network according to claim 13, it is characterized in that: when the user surfs the Net, when whether VLAN ID (VLANID) information in VLAN ID in judging user's physical link (VLANID) information and account and the mapping table and usersaccount information be consistent, whether media interviews control (MAC) address of also judging the user is consistent with media interviews control (MAC) address in the mapping table, media interviews control (MAC) address of having only the user, VLAN ID in user's physical link (VLANID) information, media interviews control (MAC) address in user account number and the mapping table, VLAN ID (VLANID), just set up this user's connection when user account number is in full accord, otherwise refusal connects.
CN 02116068 2002-05-01 2002-05-01 Management method of user's connecting network in wideband network Expired - Lifetime CN1204713C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN 02116068 CN1204713C (en) 2002-05-01 2002-05-01 Management method of user's connecting network in wideband network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN 02116068 CN1204713C (en) 2002-05-01 2002-05-01 Management method of user's connecting network in wideband network

Publications (2)

Publication Number Publication Date
CN1455548A true CN1455548A (en) 2003-11-12
CN1204713C CN1204713C (en) 2005-06-01

Family

ID=29256982

Family Applications (1)

Application Number Title Priority Date Filing Date
CN 02116068 Expired - Lifetime CN1204713C (en) 2002-05-01 2002-05-01 Management method of user's connecting network in wideband network

Country Status (1)

Country Link
CN (1) CN1204713C (en)

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100478936C (en) * 2004-07-09 2009-04-15 株式会社知识潮 Unauthorized connection detection system and unauthorized connection detection method
CN102118271A (en) * 2011-03-29 2011-07-06 上海北塔软件股份有限公司 Method for discovering illegally-accessed equipment
CN102946351A (en) * 2012-10-23 2013-02-27 杭州华三通信技术有限公司 Data transmission method and system
CN104363234A (en) * 2014-11-19 2015-02-18 胡永成 Protection method and system for achieving dial-up networking on basis of public network IP and protection device
CN105208026A (en) * 2015-09-29 2015-12-30 努比亚技术有限公司 Hostile attack preventing method and network system
CN105915664A (en) * 2016-04-25 2016-08-31 珠海市魅族科技有限公司 Method for enhancing communication reliability and device thereof
CN107276819A (en) * 2017-07-06 2017-10-20 杭州敦崇科技股份有限公司 A kind of authentication method of the three-layer network based on snmp protocol
CN111083139A (en) * 2019-12-13 2020-04-28 夏侯淑琴 Electronic product for network access and corresponding three-level double-access method

Cited By (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100478936C (en) * 2004-07-09 2009-04-15 株式会社知识潮 Unauthorized connection detection system and unauthorized connection detection method
CN102118271B (en) * 2011-03-29 2013-03-27 上海北塔软件股份有限公司 Method for discovering illegally-accessed equipment
CN102118271A (en) * 2011-03-29 2011-07-06 上海北塔软件股份有限公司 Method for discovering illegally-accessed equipment
CN102946351B (en) * 2012-10-23 2016-06-08 杭州华三通信技术有限公司 A kind of data transmission method and system
CN102946351A (en) * 2012-10-23 2013-02-27 杭州华三通信技术有限公司 Data transmission method and system
CN104363234A (en) * 2014-11-19 2015-02-18 胡永成 Protection method and system for achieving dial-up networking on basis of public network IP and protection device
CN104363234B (en) * 2014-11-19 2018-01-23 广州市极越电子有限公司 The means of defence and apparatus and system to be dialled up on the telephone based on public network IP address
CN105208026A (en) * 2015-09-29 2015-12-30 努比亚技术有限公司 Hostile attack preventing method and network system
CN105915664A (en) * 2016-04-25 2016-08-31 珠海市魅族科技有限公司 Method for enhancing communication reliability and device thereof
CN105915664B (en) * 2016-04-25 2019-03-08 珠海市魅族科技有限公司 A kind of method and device improving communication reliability
CN107276819A (en) * 2017-07-06 2017-10-20 杭州敦崇科技股份有限公司 A kind of authentication method of the three-layer network based on snmp protocol
CN111083139A (en) * 2019-12-13 2020-04-28 夏侯淑琴 Electronic product for network access and corresponding three-level double-access method
CN111083139B (en) * 2019-12-13 2020-09-11 夏侯淑琴 Electronic product for network access and corresponding three-level double-access method

Also Published As

Publication number Publication date
CN1204713C (en) 2005-06-01

Similar Documents

Publication Publication Date Title
CN1177439C (en) Method of acting address analytic protocol Ethernet Switch in application
CN1252961C (en) Method for authenticating group broadcast service
CN101047618A (en) Method and system for acquiring network route information
CN1487696A (en) Intelligent terminal managing method
CN101043331A (en) System and method for distributing address for network equipment
CN1713593A (en) Security system and method using server security solution and network security solution
CN1248447C (en) Broadband network access method
CN1416239A (en) Method for switching in virtual local area network of the access network with mixed optical fiber and coaxial line
CN1838592A (en) Firewall method and system based on high-speed network data processing platform
CN1855812A (en) Method for preventing from fakery MAC addresses
CN1761252A (en) Method for implementing experimental system of firewall under multiple user's remote concurrency control in large scale
CN1859409A (en) Method and system for improving network dynamic host configuration DHCP safety
CN101079746A (en) Secure implementation method and device of broadband access device
CN1929448A (en) Method of processing packets with different grade service quality in network switch
CN1553674A (en) Method for wideband connection server to obtain port numbers of its uers
CN1175621C (en) Method of detecting and monitoring malicious user host machine attack
CN1204713C (en) Management method of user's connecting network in wideband network
CN101035012A (en) Ethernet multi-layer switcher secure protection method based on DHCP and IP
CN1852187A (en) Method for realizing access-in management of on-line apparatus
CN1486025A (en) Checking method of PPPoE L2 transparent transmission port-username binding
CN1176540C (en) Method for realizing switch in with mixed multiple users'types in Ethernet network switch in devices
CN1510872A (en) Method for opposing refuse service attack with DNS and applied agency combination
CN1359212A (en) Comprehensive strategic realizing service for telecommunicaltion network
CN1859384A (en) Method for controlling user's message passing through network isolation device
CN101043330A (en) Apparatus and method for preventing MAC address from passing-off

Legal Events

Date Code Title Description
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C06 Publication
PB01 Publication
C14 Grant of patent or utility model
GR01 Patent grant
CX01 Expiry of patent term

Granted publication date: 20050601

CX01 Expiry of patent term