• 专利标题: Network interface that prevents MAC or IP address spoofing of a management station by making a management station address register unchangeable by software
  • 专利标题(中): 通信装置,通信终端和程序记录介质
  • 申请号: US09004596
    申请日: 1998-01-08
  • 公开(公告)号: US06205483B1
    公开(公告)日: 2001-03-20
  • 发明人: Takayuki Nakanishi
  • 申请人: Takayuki Nakanishi
  • 优先权: JP9-200442 19970725
  • 主分类号: G06F1516
  • IPC分类号: G06F1516
Network interface that prevents MAC or IP address spoofing of a management station by making a management station address register unchangeable by software
摘要:
In a local area network where communication between terminals is regulated by designating a management, or target, terminal, which is responsible for updating connecting regulation information on the other terminals, each communication terminal includes a station and a network interface. The network interface stores connecting regulation information in RAM. The network interface forwards or discards packets based on the connecting regulation information and the packet source and destination addresses. The network interface includes hardware, software, and a communication protocol designed to reduce the possibility of spoofing, where a terminal other than the target terminal changes the connecting regulation information. Each network interface includes a dip switch that is set to the target terminal's layer 2 MAC address or its layer 3 IP, or network, address. The network interface will only transmit a packet setting connecting regulation information if its own address is the same as the value in the dip switch. The network interface will only update its connecting regulation information if the packet source address equals the dip switch value. The system therefore reduces the chance of a terminal successfully pretending to be the target terminal.
信息查询
0/0