The invention relates to a method for providing an internet-layer address from a serving device via a relaying device to a client device and comprising the steps of, at the relaying device,
receiving a first message from the client device and transmitting a further first message to the serving device, which first messages comprise internet-layer addresses and lower-layer addresses; and
receiving a second message from the serving device and transmitting a further second message to the client device, which second messages comprise internet-layer addresses and lower-layer addresses and higher-layer fields for identifying the serving device.
Examples of such a serving device are servers, examples of such a relaying device are relays, and examples of such a client device are personal computers and/or modems.
A prior art method is of common general knowledge and defines a client device to generate a first message for requesting an internet-layer address. A relaying device receives this first message and in response sends a further first message to a serving device, possibly via other relaying devices. The relaying device receives in return a second message from the serving device and in response sends a further second message to the client device for offering the internet-layer address to the client device.
The first messages comprise internet-layer addresses such as for example source internet-layer addresses and destination internet-layer addresses and comprise lower-layer addresses such as for example source lower-layer addresses and destination lower-layer addresses. The second messages comprise internet-layer addresses such as for example source internet-layer addresses and destination internet-layer addresses and comprise lower-layer addresses such as for example source lower-layer addresses and destination lower-layer addresses and comprise higher-layer fields for identifying the serving device.
In the further second message, the higher-layer field originally designed for identifying the serving device comprises an internet-layer address defining the serving device.
The known method is disadvantageous, inter alia, owing to the fact that the relaying device in this method cannot monitor certain traffic relatively sufficiently. The client device is provided with the internet-layer address defining the serving device. As a result, certain future messages to be sent from the client device to the serving device no longer need to pass the relaying device, in which case the relaying device cannot monitor this traffic relatively sufficiently.
It is an object of the invention, inter alia, to provide a method as defined in the preamble in which method the relaying device can monitor certain traffic relatively sufficiently.
The method according to the invention is characterized in that the method further comprises the step of, at the relaying device,
inserting an internet-layer address defining the relaying device into the higher-layer field of the further second message.
By not inserting the internet-layer address defining the serving device into the higher-layer field of the further second message, which higher-layer field is originally designed for identifying the serving device, but instead of that inserting the internet-layer address defining the relaying device into this higher-layer field of the further second message, future messages to be sent from the client device to the serving device must pass the relaying device. In this case, the relaying device can monitor this traffic relatively sufficiently. The invention is further advantageous in that relaying device can be a stand-alone device which does not need to be able to process at the internet layer or at a higher layer.
The further second message is either generated by taking the second message and replacing and/or overwriting parts of the second message or is generated by generating a new further second message and copying and/or shifting first parts originating from the second message and inserting second parts. These second parts either do not originate from the second message or do originate from the second message but then originate from different locations and/or are being processed before being inserted.
It should be noted that US 2002/0023160 discloses in its paragraph 40 that a server is to be configured to ensure that every response that changes an internet-layer address assignment or a lease on an internet-layer address assignment gets relayed to the relay agent. It should further be noted that US 2002/0165972 discloses in its paragraph 10 methods and apparatus for use in reducing traffic over a communication link used by a computer network, including the steps of monitoring, at a gateway, communications involving address assignment between an address-assigning computer device and one or more computer devices and of storing and identifying, at the gateway, computer device identifiers. Both patent applications do however not prevent that certain future messages to be sent from the client device to the serving device will not pass the relaying device and do neither disclose nor suggest to insert the internet-layer address defining the relaying device into the higher-layer field of the further second message originally designed for identifying the serving device.
An embodiment of the method according to the invention is characterized in that the method further comprises the steps of, at the relaying device,
receiving a third message from the client device and transmitting a further third message to the serving device, which third messages comprise internet-layer addresses and lower-layer addresses;
receiving a fourth message from the serving device and transmitting a further fourth message to the client device, which fourth messages comprise internet-layer addresses and lower-layer addresses and higher-layer fields for identifying the serving device; and
inserting an internet-layer address defining the relaying device into the higher-layer field of the further fourth message.
In case the protocol defining the first and second messages further requires the third and fourth messages to be exchanged, the higher-layer field of the further fourth message originally designed for identifying the serving device should also be provided with the insertion of internet-layer address defining the relaying device.
An embodiment of the method according to the invention is characterized in that the method further comprises the steps of, at the client device,
inserting a destination internet-layer address and a destination lower-layer address both defining the relaying device into a fifth message; and
transmitting the fifth message to the relaying device; which fifth message further comprises a source internet-layer address and a source lower-layer address.
In case the protocol defining the first, second, third and fourth messages to be exchanged further requires the fifth message to be exchanged, this fifth message should be provided with an insertion of the destination internet-layer address and the destination lower-layer address both defining the relaying device.
An embodiment of the method according to the invention is characterized in that the method further comprises the steps of, at the relaying device,
receiving the fifth message from the client device and transmitting a further fifth message to the serving device, which further fifth message comprises internet-layer addresses and lower-layer addresses.
In case the protocol defining the first, second, third, fourth and fifth messages to be exchanged further requires the further fifth message to be exchanged, this further fifth message should be provided with internet-layer addresses and lower-layer addresses.
An embodiment of the method according to the invention is characterized in that the higher-layer field of the further second message comprises a server internet protocol address field and a server identification field, the server identification field comprising the internet-layer address defining the relaying device and the server internet protocol address field comprising the value of the server identification field.
The value of the server identification field as comprised by the server internet protocol address field may be the internet-layer address defining the relaying device or may be a link to the internet-layer address.
An embodiment of the method according to the invention is characterized in that other higher-layer fields of the further second message further comprise a gateway internet protocol address field and a hopcount field, both fields comprising the value zero.
This increases the security of the method, by not giving more information to the client device than necessary.
An embodiment of the method according to the invention is characterized in that the higher-layer field of the further fourth message comprises a server internet protocol address field and a server identification field, the server identification field comprising the internet-layer address defining the relaying device and the server internet protocol address field comprising the value of the server identification field.
Again, the value of the server identification field as comprised by the server internet protocol address field may be the internet-layer address defining the relaying device or may be a link to the internet-layer address defining the relaying device.
An embodiment of the method according to the invention is characterized in that other higher-layer fields of the further fourth message further comprise a gateway internet protocol address field and a hopcount field, both fields comprising the value zero.
Again, this increases the security of the method, by not giving more information to the client device than necessary.
An embodiment of the method according to the invention is characterized in that the messages are dynamic host configuration protocol messages, the first messages being discover messages, the second messages being offer messages, the third messages being request messages, the fourth messages being acknowledge messages and the fifth messages being request and/or renew and/or release messages. The dynamic host configuration protocol is defined in RFCs. The server identification field may then correspond with an option-54 field. Further messages are not to be excluded.
An embodiment of the method according to the invention is characterized in that the internet-layer addresses are internet protocol addresses, the lower-layer addresses are medium access control addresses and the higher-layer fields are user datagram protocol fields.
The internet-layer addresses or the internet protocol addresses are layer-3 addresses, the lower-layer addresses or the medium access control addresses are layer-2 addresses and the higher-layer fields or the user datagram protocol fields are layer-4 fields. The higher-layer fields may refer to fields inside the dynamic host configuration protocol messages. And according to the RFCs the dynamic host configuration protocol messages are packed into a user datagram protocol packet. The user datagram protocol is a layer-4 (=Transport) protocol (according to the OSI Stack defined by ISO). When consulting information on the internet, the dynamic host configuration protocol is considered to be a networking layer protocol (layer-3). This is logical because it configures the networking layer of the clients (by assigning internet protocol addresses).
The invention also relates to a relaying device for providing an internet-layer address from a serving device via the relaying device to a client device and comprising
a receiver for receiving a first message from the client device and for receiving a second message from the serving device; and
a transmitter for transmitting a further first message to the serving device and for transmitting a further second message to the client device; which first messages comprise internet-layer addresses and lower-layer addresses and which second messages comprise internet-layer addresses and lower-layer addresses and higher-layer fields for identifying the serving device, which relaying device according to the invention is characterized in that the relaying device further comprises
an inserter for inserting an internet-layer address defining the relaying device into the higher-layer field of the further second message.
The invention yet also relates to a network device comprising a relaying device for providing an internet-layer address from a serving device via the relaying device to a client device and comprising
a receiver for receiving a first message from the client device and for receiving a second message from the serving device; and
a transmitter for transmitting a further first message to the serving device and for transmitting a further second message to the client device;
which first messages comprise internet-layer addresses and lower-layer addresses and which second messages comprise internet-layer addresses and lower-layer addresses and higher-layer fields for identifying the serving device, which network device according to the invention is characterized in that the relaying device further comprises
an inserter for inserting an internet-layer address defining the relaying device into the higher-layer field of the further second message.
The invention further relates to a client device for receiving an internet-layer address from a serving device via a relaying device and comprising
a transmitter for transmitting a first message, a third message and a fifth message to the relaying device;
a receiver for receiving a further second message and a further fourth message from the relaying device;
which first message comprises internet-layer addresses and lower-layer addresses and which second message comprises internet-layer addresses and lower-layer addresses and higher-layer fields for identifying the serving device and which third message comprises internet-layer addresses and lower-layer addresses and which fourth message comprises internet-layer addresses and lower-layer addresses and higher-layer fields for identifying the serving device and which fifth message comprises internet-layer addresses and lower-layer addresses, which client device according to the invention is characterized in that the client device further comprises
an inserter for inserting a destination internet-layer address and a destination lower-layer address both defining the relaying device into the fifth message.
The invention yet further relates to a processor program product for providing an internet-layer address from a serving device via a relaying device to a client device and comprising the functions of, at the relaying device,
receiving a first message from the client device and transmitting a further first message to the serving device, which first messages comprise internet-layer addresses and lower-layer addresses; and
receiving a second message from the serving device and transmitting a further second message to the client device, which second messages comprise internet-layer addresses and lower-layer addresses and higher-layer fields for identifying the serving device;
which processor program product according to the invention is characterized in that the processor program product further comprises the function of, at the relaying device,
inserting an internet-layer address defining the relaying device into the higher-layer field of the further second message.
Embodiments of the relaying device according to the invention and of the network device according to the invention and of the client device according to the invention and of the processor program product according to the invention correspond with the embodiments of the method according to the invention.
The invention is based upon an insight, inter alia, that future messages to be sent from the client device to the serving device must pass the relaying device to allow this relaying device to monitor this traffic relatively sufficiently, and is based upon a basic idea, inter alia, that not the internet-layer address defining the serving device is to be inserted into the higher-layer field of the further second message, which higher-layer field is originally designed for identifying the serving device, but instead of that the internet-layer address defining the relaying device is to be inserted into this higher-layer field of the further second message.
The invention solves the problem, inter alia, to provide a method in which method the relaying device can monitor certain traffic relatively sufficiently, and is further advantageous, inter alia, in that the relaying device can be a stand-alone device which does not need to be able to process at the internet layer or at a higher layer, it for example only needs to be able to process dynamic host configuration protocol messages.
Theses and other aspects of the invention will be apparent from and elucidated with reference to the embodiments(s) described hereinafter.
The network 10 shown in
The network 10 shown in
The network 10 shown in
The network 10 shown in
The relaying device 4 according to the invention shown in greater detail in
The client device 3 according to the invention shown in greater detail in
The dynamic host configuration protocol messages to be exchanged in accordance with a method according to the invention are shown in
The third message 103a is for example a request message defining (at layer-2) source Mac@=ClientMac@ and destination Mac@=ff:ff:ff:ff:ff:ff and (at layer-3) source IP=0.0.0.0 and destination IP=255.255.255.255 and gateway IP address giaddr=0. The further third message 103b is for example a request message defining (at layer-2) source Mac@=RelayMac@ and destination Mac@=ServerMac@ and (at layer-3) source IP=relayIP@ and destination IP=ServerIP@ and gateway IP address giaddr=relayIP@. The fourth message 104a is for example an acknowledge message defining (at layer-2) source Mac@=ServerMac@ and destination Mac@=RelayMac@ and (at layer-3) source IP=ServerIP@ and destination IP=relayIP@ and gateway IP address giaddr=relayIP@ and option-54=Server IP@. The further fourth message 104b is for example an acknowledge message defining (at layer-2) source Mac@=RelayMac@ and destination Mac@=UserMac@ or ff:ff:ff:ff:ff:ff and (at layer-3) source IP=relayIP@ and destination IP=255.255.255.255 or your IP address yiaddr and gateway IP address giaddr=0 and hopcount=0 and server IP address siaddr=option-54=relayIP@. The fifth message 105a is for example a request, a renew and/or a release message defining (at layer-2) source Mac@=ClientMac@ and destination Mac@=RelayMac@ and (at layer-3) source IP=ClientIP@ and destination IP=relayIP@ and gateway IP address giaddr=0.
The internet-layer addresses or the internet protocol addresses IP@ are layer-3 addresses, the lower-layer addresses or the medium access control addresses Mac@ are layer-2 addresses and the higher-layer fields or the user datagram protocol fields siaddr and option-54 and giaddr and hopcount are layer-4 fields.
In a prior art situation, the further second message 102b, the further fourth message 104b and the fifth message 105a look different. The further second message 102b and the further fourth message 104b do not define that (at layer-4) gateway IP address giaddr=0 and hopcount=0 and server IP address siaddr=option-54=relayIP@, but define (at layer-4) gateway IP address giaddr=RelayIP@ and hopcount >0 and option-54=ServerIP@. And the fifth message 105a does not define (at layer-2) destination Mac@=RelayMac@ and (at layer-3) destination IP=relayIP@ but defines (at layer-2) destination Mac@=RouterMac@ and (at layer-3) destination IP=ServerIP@. As a result, the fifth message 105a and following messages to be sent from the client device 3 to the serving device 1 no longer need to pass the relaying device 4, in which case the relaying device 4 cannot monitor this traffic relatively sufficiently.
According to the invention, the further second message 102b, the further fourth message 104b and the fifth message 105 are as described for
To realise the invention, in other words to change the further second message 102b, the further fourth message 104b and the fifth message 105a as described for
The addresses and fields at layer-2, layer-3 and layer-4 are just examples and the layers are just examples. In a minimum situation, an internet-layer and a higher-layer will be involved. The dynamic host configuration protocol messages are just examples, for other protocols other and more or less (kinds of) messages may be used. In a minimum situation, the first and second messages will be present. Therefore, the higher-layer field for example comprises giaddr and option-54 without excluding other higher-layer fields. And siaddr and hopcount are just preferred further fields to be filled with zero's to increase the security of the method, by not giving more information to the client device 3 than necessary.
The
The expression “for” in for example “for providing”, “for identifying”, “for receiving”, “for transmitting” etc. does not exclude that other functions are performed as well, simultaneously or not. The expressions “X coupled to Y” and “a coupling between X and Y” and “coupling/couples X and Y” etc. do not exclude that an element Z is in between X and Y. The expressions “P comprises Q” and “P comprising Q” etc. do not exclude that an element R is comprised/included as well. The terms “a” and “an” do not exclude the possible presence of one or more pluralities.
The steps/functions of receiving, transmitting, inserting etc. do not exclude further steps, like for example, inter alia, the steps/functions as described for the Figures.
Number | Date | Country | Kind |
---|---|---|---|
04292819.2 | Nov 2004 | EP | regional |