一种访问控制方法、接入设备及系统技术方案

技术编号:6093827 阅读:176 留言:0更新日期:2012-04-11 18:40
本发明专利技术公开了访问控制方法、接入设备及系统,包括:接收访问请求,获取IP地址和MAC地址;当MAC地址已经绑定、与MAC地址进行绑定的绑定端口与当前端口不相同、MAC地址与绑定端口的绑定关系为无效时,删除MAC地址与绑定端口的绑定关系,建立与当前端口的绑定关系;当MAC地址没有绑定、当前端口上绑定的MAC地址的数量已经达到最大值、且当前端口上的绑定关系中包含无效的绑定关系时,删除无效的绑定关系,建立MAC地址与当前端口的绑定关系。本发明专利技术公开的访问控制方法,通过对绑定关系有效性的检测判定接收的协议请求是地址欺骗还是正常的业务需要导致的合法地址迁移,实现了即满足安全特性的需要,又满足特殊场景的需求。

Access control method, access device and system

The invention discloses an access control method, access equipment and system, including: receiving the access request, to obtain IP address and MAC address binding relationship; when binding to the port MAC address and MAC address binding, binding with the same MAC address, port and port binding is invalid, the binding between MAC address and delete binding to the port, establish a binding relationship with current port; when the MAC address is not binding, the number of the current port binding MAC address has reached the maximum value, and the binding relationship on the current port contains invalid binding relationship, delete invalid relation, binding relationship with the current port MAC address. The invention discloses a method of access control, through the detection of effective binding method to determine relationship between the received protocol request is spoofing or normal business needs to address the legal migration, the need to meet the security properties, and meet the needs of special scene.

【技术实现步骤摘要】

【技术保护点】
1.一种访问控制方法,其特征在于,包括:接收访问请求,获取用户的网络协议IP地址和用户的介质访问控制MAC地址;当所述MAC地址已经绑定、与所述MAC地址进行绑定的绑定端口与接收访问请求的当前端口不相同、且所述MAC地址与所述绑定端口间的绑定关系为无效时,删除所述MAC地址与所述绑定端口间的绑定关系,建立所述MAC地址与所述当前端口的绑定关系,允许用户访问;当所述MAC地址没有绑定、所述当前端口上绑定的MAC地址的数量已经达到最大值、且所述当前端口与所述当前端口上绑定的MAC地址间的绑定关系中包含无效的绑定关系时,删除所述无效的绑定关系,建立所述MAC地址与所述当前端口的绑定关系,允许用户访问...

【技术特征摘要】

【专利技术属性】
技术研发人员:杨显杰尹家生
申请(专利权)人:华为技术有限公司
类型:发明
国别省市:94

网友询问留言 已有0条评论
  • 还没有人留言评论。发表了对其他浏览者有用的留言会获得科技券。

1