Authentication method, device, system and non-volatile computer readable storage medium
By receiving the authentication information of the multicast receiver and determining the access control list, the problem of poor multicast security is solved, and the controllability and security of the multicast transmission process are achieved.
Patent Information
- Application Number
- CN202111180999.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-11
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2041-10-11
AI Technical Summary
Multicast security is poor and lacks an authentication mechanism.
By receiving the authentication information of the multicast receiver, determining the matching access control list, and after the multicast receiver passes the authentication, sending the BitString or permission information to the edge router, the multicast message is copied and forwarded in the BIER network.
The controllability and security of multicast are achieved, and the security of multicast transmission is improved.
Smart Images

Figure CN115967505B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of communication technology, and in particular to an authentication method, an authentication device, an authentication system, and a non-volatile computer-readable storage medium. Background Art
[0002] In related technologies, during the multicast information transmission process, one only needs to know the multicast group or the multicast source in order to join the multicast. Summary of the Invention
[0003] The inventors of the present disclosure have discovered that the above-mentioned related technologies have the following problems: lack of an authentication mechanism, resulting in poor multicast security.
[0004] In view of this, the present disclosure proposes an authentication technology solution that can improve multicast security by utilizing a multicast authentication mechanism.
[0005] According to some embodiments of the present disclosure, an authentication method is provided, comprising: receiving authentication information for joining a multicast from a multicast receiver, the authentication information including identification information of a multicast group or multicast source that the multicast receiver applies to join; determining an access control list of a matching multicast group or multicast source based on the authentication information; and authenticating the multicast receiver based on the access control list to determine whether the multicast receiver is allowed to join the multicast.
[0006] In some embodiments, the authentication method further includes: receiving registration information of the multicast group or multicast source sent by the edge router on the multicast group or multicast source side; sending the registration information to the application corresponding to the multicast group or multicast source; and receiving the access control list returned by the application.
[0007] In some embodiments, the registration information is a PCEP (Path Computation Element Communication Protocol) message.
[0008] In some embodiments, the receiving of authentication information for joining the multicast sent by the multicast receiver includes: receiving a PCEP message carrying the authentication information sent by the edge router on the multicast receiver side, the PCEP message being generated after the edge router on the multicast receiver side converts the IGMPv3 (Internet Group Management Protocol) information or MLDv2 (Multicast Listener Discover) message carrying the authentication information sent by the multicast receiver.
[0009] In some embodiments, the authentication method also includes: when the multicast receiver passes the authentication, sending a BitString to the edge router on the matching multicast group or multicast source side, so that the edge router on the multicast group or multicast source side copies and forwards the multicast message to the edge router on the multicast receiver side according to the BitString in the BIER (Bit Index Explicit Replication) network.
[0010] In some embodiments, the authentication method further includes: when the multicast receiver passes the authentication, sending permission information to the edge router on the multicast receiver side, so that the edge router on the multicast receiver side copies and forwards the multicast message to the multicast receiver according to the permission information.
[0011] According to other embodiments of the present disclosure, an authentication device is provided, comprising: a receiver for receiving authentication information for joining a multicast sent by a multicast receiver, wherein the authentication information includes identification information of the multicast group or multicast source that the multicast receiver applies to join; and a processor for determining an access control list of a matching multicast group or multicast source based on the authentication information, and authenticating the multicast receiver based on the access control list to determine whether the multicast receiver is allowed to join the multicast.
[0012] In some embodiments, the authentication device also includes: a transmitter, which is used to send a BitString to the edge router on the matching multicast group or multicast source side if the multicast receiver passes the authentication, so that the edge router on the multicast group or multicast source side copies and forwards the multicast message to the edge router on the multicast receiver side according to the BitString in the BIER network; and / or is used to send permission information to the edge router on the multicast receiver side if the multicast receiver passes the authentication, so that the edge router on the multicast receiver side copies and forwards the multicast message to the multicast receiver according to the permission information.
[0013] In some embodiments, the receiver receives registration information of the multicast group or multicast source sent by the edge router on the multicast group or multicast source side; the transmitter sends the registration information to the application corresponding to the multicast group or multicast source; and the receiver receives the access control list returned by the application.
[0014] In some embodiments, the registration information is a PCEP message.
[0015] In some embodiments, the receiver receives a PCEP message carrying the authentication information sent by an edge router at the multicast receiver side, the PCEP message being generated by the edge router at the multicast receiver side after converting an IGMPv3 message or an MLDv2 message carrying the authentication information sent by the multicast receiver.
[0016] According to yet some embodiments of the present disclosure, there is provided an authentication apparatus, comprising: a memory; and a processor coupled to the memory, the processor being configured to perform the authentication method of any one of the above embodiments based on instructions stored in the memory apparatus.
[0017] According to still some embodiments of the present disclosure, there is provided a non-volatile computer readable storage medium having stored thereon a computer program, the program being executed by a processor to implement the authentication method of any one of the above embodiments.
[0018] According to still some embodiments of the present disclosure, there is provided an authentication system, comprising: a controller configured to perform the authentication method of any one of the above embodiments; and an edge router at the multicast receiver side configured to send authentication information of a multicast receiver joining a multicast to the controller.
[0019] In some embodiments, the authentication system further comprises: an edge router at the multicast group or multicast source side configured to send registration information of the multicast group or multicast source to the controller.
[0020] In the above embodiments, the received authentication message is matched with an access control list to authenticate the receiver, so as to achieve the technical effect of controllable multicast, thereby improving the security of multicast. BRIEF DESCRIPTION OF DRAWINGS
[0021] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0022] The present disclosure can be more clearly understood with reference to the following detailed description when considered in conjunction with the following drawings, in which:
[0023] Figure 1 Flowcharts showing some embodiments of the authentication method of the present disclosure;
[0024] Figure 2 Schematic diagrams showing some embodiments of the authentication method of the present disclosure;
[0025] Figure 3 Schematic diagrams showing some other embodiments of the authentication method of the present disclosure;
[0026] Figure 4 Block diagrams showing some embodiments of the authentication apparatus of the present disclosure;
[0027] Figure 5 A block diagram showing some other embodiments of the authentication device disclosed herein;
[0028] Figure 6 A block diagram showing some further embodiments of the authentication device disclosed herein;
[0029] Figure 7 A block diagram illustrating some embodiments of the authentication system of the present disclosure is shown. DETAILED DESCRIPTION
[0030] Various exemplary embodiments of the present disclosure will now be described in detail with reference to the accompanying drawings. It should be noted that unless otherwise specifically stated, the relative arrangement of components and steps, numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present disclosure.
[0031] At the same time, it should be understood that for the convenience of description, the sizes of the various parts shown in the drawings are not drawn according to the actual proportional relationship.
[0032] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the present disclosure, its application, or uses.
[0033] Technologies, methods, and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and equipment should be considered part of the specification.
[0034] In all examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not limiting. Therefore, other examples of the exemplary embodiments may have different values.
[0035] It should be noted that like reference numerals and letters refer to like items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0036] To address the above technical issues, the present disclosure uses a controller to match received multicast authentication messages with application-layer access restrictions and distributes multicast control information via PCEP messages. This enables the technical effect of multicast controllability based on PCEP message propagation. For example, the technical solution of this disclosure can be implemented through the following embodiments.
[0037] Figure 1 A flowchart illustrating some embodiments of the authentication method of the present disclosure.
[0038] like Figure 1As shown, in step 110, the authentication information for joining the multicast is received from the multicast receiver. The authentication information includes the identification information of the multicast group or multicast source that the multicast receiver applies to join.
[0039] In some embodiments, a PCEP message carrying authentication information is received from an edge router on the multicast receiver side. The PCEP message is generated by the edge router on the multicast receiver side converting an IGMP message (such as an IGMPv3 message) or an MLD message (such as an MLDv2 message) carrying authentication information sent by the multicast receiver.
[0040] For example, a receiver uses an IGMPv3 message or MLDv2 message to carry application multicast service access authentication information, apply to join a multicast group, and use one or more multicast sources. The edge router on the receiver side converts the IGMPv3 or MLDv2 message into a PCEP message and sends it to the controller.
[0041] In some embodiments, when a receiver wishes to access a multicast application, the Auxiliary Data (32-bit) in an IGMPv3 or MLDv2 message carries authentication information. For example, the edge router on the receiver side adds an object to the PCEP message sent to the controller to carry the authentication information carried in the Auxiliary Data in the IGMPv3 or MLDv2 message.
[0042] In step 120, an access control list of a matching multicast group or multicast source is determined based on the authentication information.
[0043] In some embodiments, a multicast group or multicast source registration message is received from an edge router on the multicast group or multicast source side; the registration message is sent to an application corresponding to the multicast group or multicast source; and an access control list returned by the application is received. For example, the registration message is a PCEP message.
[0044] For example, edge routers on the multicast group or source side register the multicast group or source with the controller using PCEP messages. The controller stores the registration information sent by each edge router and provides it to applications (APPs) through service-based interfaces for access. The application customizes its access control list based on the multicast group or source registration information and sends it to the controller for authentication of multicast receivers. The controller can be an SDN (Software Defined Network) controller.
[0045] In step 130, the multicast receiver is authenticated according to the access control list to determine whether the multicast receiver is allowed to join the multicast.
[0046] In some embodiments, when the multicast receiver passes authentication, a BitString is sent to the edge router on the matching multicast group or multicast source side, so that the edge router on the multicast group or multicast source side copies the BitString in the BIER network and forwards the multicast message to the edge router on the multicast receiver side.
[0047] In some embodiments, when the multicast receiver passes authentication, permission information is sent to the edge router on the multicast receiver side, so that the edge router on the multicast receiver side copies and forwards the multicast message to the multicast receiver according to the permission information.
[0048] For example, the controller matches the receiver's authentication information with the application's access control list; if the match is successful, it sends a BitString to the edge router on the multicast source side for multicast message forwarding in the BIER network; the controller sends application access permission information to the edge router on the receiver side; the multicast source sends the application multicast message, which is copied and forwarded in the BIER network according to the BitString; the edge router on the receiver side copies and forwards the application multicast message to the receiver based on the access permission information.
[0049] In some embodiments, the controller adds a flag for identifying the authentication result to the PCEP message sent to the edge router on the receiver side, so as to control whether the edge router on the receiver side copies and forwards the application multicast message.
[0050] Figure 2 Schematic diagram showing some embodiments of the authentication method disclosed herein.
[0051] like Figure 2 As shown, in step 1, the edge router on the multicast group or multicast source side registers the multicast group or multicast source with the controller through a PCEP message. For example, the controller may be a PCE controller.
[0052] For example, the edge router is PE (Provider Edge), and the edge router on the multicast group or multicast source side is PE5. Each PE is located in an AS (Autonomous System), namely AS Y.
[0053] In step 2, the controller saves the registration information sent by each edge router and provides it to applications (such as streaming media applications) for access through a service-based interface; the application customizes the access control list of the application based on the registration information of the multicast group or multicast source and sends it to the controller for authentication of the multicast receiver to join.
[0054] In step 3, the receiver applies to join the multicast group and use one or more multicast sources by using an IGMPv3 message or an MLDv2 message, carrying the application multicast service access authentication information.
[0055] In step 4, the edge router on the receiver side converts the IGMPv3 message or MLDv2 message into a PCEP message and sends it to the controller. For example, receiver 1 sends the PCEP message through PE2, and receiver 2 sends the PCEP message through PE3.
[0056] In some embodiments, when a receiver wishes to access a multicast application, authentication information is carried in the Auxiliary Data section of an IGMPv3 or MLDv2 message. For example, the edge router on the receiver side adds an object to the PCEP message sent to the controller to carry the authentication information carried in the Auxiliary Data section of the IGMPv3 or MLDv2 message.
[0057] In step 5, the controller matches the receiver's authentication information with the application's access control list; if the match is successful, it sends the BitString to the edge router on the multicast source side for multicast message forwarding in the BIER network.
[0058] In step 6, the controller sends the application access permission information to the edge router on the receiver side.
[0059] In step 7, the multicast source sends the application multicast message, which is copied and forwarded according to the BitString in the BIER network; the edge router on the receiver side copies and forwards the application multicast message to the receiver based on the access permission information.
[0060] In some embodiments, the controller adds a flag for identifying the authentication result to the PCEP message sent to the edge router on the receiver side, so as to control whether the edge router on the receiver side copies and forwards the application multicast message.
[0061] In this embodiment, authentication policies can be generated based on the authentication rules of third-party applications, enabling refined control of multicast joins and improving security. Third-party applications connect to the controller, enabling unified management of receivers connected to all edge routers within the domain. IGMPv3 and MLDv2 are leveraged to carry authentication information, eliminating the need for further modifications.
[0062] Figure 3 Schematic diagrams showing other embodiments of the authentication method disclosed herein.
[0063] like Figure 3As shown, the edge router R1 on the multicast source side registers the information of the multicast group or multicast source Source1 with the SDN controller through a PCEP message.
[0064] The controller saves the registration information sent by R1 and informs the streaming app. The streaming app customizes the access control list based on the information of the multicast group or multicast source Source1 and sends it to the SDN controller.
[0065] Receiver 2 uses an IGMPv3 message or an MLDv2 message that carries the streaming media multicast service access authentication information to apply to join the multicast group and use Source 1.
[0066] The edge router R4 on the receiver side converts the IGMPv3 / MLDv2 message into a PCEP message and sends it to the controller.
[0067] The controller matches Receiver2's authentication message with the streaming app's access control list. If the match is successful, it sends a BitString to R1 for multicast message forwarding in the BIER network.
[0068] The controller sends streaming media multicast service access permission information to R4. Source1 sends the streaming media multicast service message, which is copied and forwarded according to the BitString in the BIER network. After receiving the multicast message, R4 copies and forwards it to Receiver2 based on the access permission information.
[0069] Figure 4 A block diagram showing some embodiments of the authentication device of the present disclosure.
[0070] like Figure 4 As shown, the authentication device 4 includes a receiver 41 and a processor 42 .
[0071] The receiver 41 receives the authentication information for joining the multicast sent by the multicast receiver, which includes the identification information of the multicast group or multicast source that the multicast receiver applies to join.
[0072] The processor 42 determines the access control list of the matching multicast group or multicast source based on the authentication information, and authenticates the multicast receiver based on the access control list to determine whether the multicast receiver is allowed to join the multicast.
[0073] In some embodiments, the authentication device 4 also includes a transmitter 43, which is used to send a BitString to the edge router on the matching multicast group or multicast source side when the multicast receiver passes the authentication, so that the edge router on the multicast group or multicast source side copies the BitString in the BIER network and forwards the multicast message to the edge router on the multicast receiver side.
[0074] In some embodiments, the transmitter 43 is configured to send permission information to the edge router on the multicast receiver side if the multicast receiver passes authentication, so that the edge router on the multicast receiver side copies and forwards the multicast message to the multicast receiver according to the permission information.
[0075] In some embodiments, the receiver 41 receives registration information of the multicast group or multicast source sent by the edge router on the multicast group or multicast source side; the transmitter 43 sends the registration information to the application corresponding to the multicast group or multicast source; the receiver 42 receives the access control list returned by the application.
[0076] In some embodiments, the registration information is a PCEP message.
[0077] In some embodiments, the receiver 41 receives a PCEP message carrying authentication information sent by an edge router on the multicast receiver side. The PCEP message is generated by the edge router on the multicast receiver side converting an IGMPv3 message or MLDv2 message carrying authentication information sent by the multicast receiver.
[0078] Figure 5 A block diagram showing some other embodiments of the authentication device of the present disclosure.
[0079] like Figure 5 As shown, the authentication device 5 of this embodiment includes: a memory 51 and a processor 52 coupled to the memory 51 , and the processor 52 is configured to execute the authentication method in any one embodiment of the present disclosure based on instructions stored in the memory 51 .
[0080] The memory 51 may include, for example, a system memory, a fixed non-volatile storage medium, etc. The system memory may store, for example, an operating system, an application program, a boot loader, a database, and other programs.
[0081] Figure 6 A block diagram showing some further embodiments of the authentication device of the present disclosure.
[0082] like Figure 6 As shown, the authentication device 6 of this embodiment includes: a memory 610 and a processor 620 coupled to the memory 610 , and the processor 620 is configured to execute the authentication method in any of the aforementioned embodiments based on instructions stored in the memory 610 .
[0083] The memory 610 may include, for example, a system memory, a fixed non-volatile storage medium, etc. The system memory may store, for example, an operating system, application programs, a boot loader, and other programs.
[0084] The authentication device 6 may also include an input / output interface 630, a network interface 640, a storage interface 650, and the like. These interfaces 630, 640, 650, as well as the memory 610 and the processor 620, may be connected, for example, via a bus 660. The input / output interface 630 provides a connection interface for input / output devices such as a display, mouse, keyboard, touch screen, microphone, and speakers. The network interface 640 provides a connection interface for various networked devices. The storage interface 650 provides a connection interface for external storage devices such as SD cards and USB flash drives.
[0085] Figure 7 A block diagram illustrating some embodiments of the authentication system of the present disclosure is shown.
[0086] like Figure 7 As shown, the authentication system 7 includes: a controller 71, which is used to execute the authentication method in any of the above embodiments; an edge router 72 on the multicast receiver side, which is used to send the multicast receiver's authentication information for joining the multicast to the controller.
[0087] In some embodiments, the authentication system 7 further includes: an edge router 73 on the multicast group or multicast source side, configured to send registration information of the multicast group or multicast source to the controller.
[0088] Those skilled in the art will appreciate that embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present disclosure may take the form of a computer program product implemented on one or more computer-usable non-transient storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0089] The authentication method, apparatus, system, and non-volatile computer-readable storage medium according to the present disclosure have been described in detail. To avoid obscuring the concepts of the present disclosure, some details known in the art have been omitted. Based on the above description, those skilled in the art will fully understand how to implement the technical solutions disclosed herein.
[0090] The methods and systems of the present disclosure may be implemented in many ways. For example, the methods and systems of the present disclosure may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of steps for the method is for illustration only, and the steps of the method of the present disclosure are not limited to the order specifically described above unless otherwise specified. In addition, in some embodiments, the present disclosure may also be implemented as programs recorded in a recording medium, which include machine-readable instructions for implementing the methods according to the present disclosure. Thus, the present disclosure also covers recording media that store programs for executing the methods according to the present disclosure.
[0091] Although some specific embodiments of the present disclosure have been described in detail by way of examples, those skilled in the art will appreciate that the above examples are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Those skilled in the art will appreciate that modifications may be made to the above embodiments without departing from the scope and spirit of the present disclosure. The scope of the present disclosure is defined by the appended claims.
Claims
1. An authentication method, performed by a software-defined network (SDN) controller, comprising: receiving authentication information for joining a multicast sent by a multicast receiver, wherein the authentication information includes identification information of the multicast group or multicast source that the multicast receiver applies to join; Determining an access control list of a matching multicast group or multicast source based on the authentication information; authenticating the multicast receiver according to the access control list to determine whether the multicast receiver is allowed to join the multicast; The step of determining the access control list of the matching multicast group or multicast source according to the authentication information includes: Receiving registration information of the multicast group or multicast source sent by an edge router on the multicast group or multicast source side; Sending the registration information to an application corresponding to the multicast group or multicast source, where the corresponding application is a third-party streaming media application of the multicast group or multicast source; receiving the access control list returned by the application, where the access control list is customized by the application according to the registration information, The sending of the registration information to the application corresponding to the multicast group or the multicast source includes: Saving the registration information in the SDN controller; The registration information is provided to the third-party streaming media application for access via a service-oriented interface.
2. The authentication method according to claim 1, wherein: The registration information is a Path Computation Element Communication Protocol (PCEP) message.
3. The authentication method according to claim 1, wherein: The multicast joining authentication information sent by the multicast receiver includes: Receive a PCEP message carrying the authentication information sent by the edge router on the multicast receiver side, where the PCEP message is generated after the edge router on the multicast receiver side converts the Internet Group Management Protocol IGMPv3 message or Multicast Listener Discovery MLDv2 information carrying the authentication information sent by the multicast receiver.
4. The authentication method according to any one of claims 1 to 3, further comprising: When the multicast receiver passes the authentication, the bit string BitString is sent to the edge router on the matching multicast group or multicast source side, so that the edge router on the multicast group or multicast source side copies the multicast message according to the BitString in the bit index explicit replication BIER network and forwards the multicast message to the edge router on the multicast receiver side.
5. The authentication method according to any one of claims 1 to 3, further comprising: When the multicast receiver passes the authentication, permission information is sent to the edge router on the multicast receiver side, so that the edge router on the multicast receiver side copies and forwards the multicast message to the multicast receiver according to the permission information.
6. An authentication device, configured in a software-defined network (SDN) controller, comprising: a receiver, configured to receive authentication information for joining a multicast sent by a multicast receiver, the authentication information including identification information of the multicast group or multicast source that the multicast receiver applies to join, and receive registration information of the multicast group or multicast source sent by an edge router on the multicast group or multicast source side; a processor, configured to determine an access control list of a matching multicast group or multicast source based on the authentication information, and authenticate the multicast receiver based on the access control list to determine whether to allow the multicast receiver to join the multicast; a transmitter, configured to send the registration information to an application corresponding to the multicast group or multicast source, wherein the corresponding application is a third-party streaming media application of the multicast group or multicast source, The receiver receives the access control list returned by the application, where the access control list is customized by the application according to the registration information. The transmitter stores the registration information in the SDN controller, and provides the registration information to the third-party streaming media application for access through a service-based interface.
7. The authentication device according to claim 6, further comprising: A transmitter is used to send a bit string BitString to the edge router on the matching multicast group or multicast source side when the multicast receiver passes the authentication, so that the edge router on the multicast group or multicast source side copies the multicast message according to the BitString in the bit index explicit replication BIER network and forwards the multicast message to the edge router on the multicast receiver side; And / or for sending permission information to the edge router on the multicast receiver side if the multicast receiver passes the authentication, so that the edge router on the multicast receiver side copies and forwards the multicast message to the multicast receiver according to the permission information.
8. An authentication system comprising: A controller, configured to execute the authentication method according to any one of claims 1 to 5; The edge router on the multicast receiver side is used to send the multicast receiver's authentication information for joining the multicast to the controller.
9. The authentication system according to claim 8, further comprising: The edge router on the multicast group or multicast source side is configured to send registration information of the multicast group or multicast source to the controller.
10. An authentication device comprising: Memory; and A processor coupled to the memory, the processor being configured to execute the authentication method according to any one of claims 1 to 5 based on instructions stored in the memory.
11. A non-volatile computer-readable storage medium having a computer program stored thereon, wherein when the program is executed by a processor, the authentication method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Trusted controllable multicast controller based on Open Flow
CN103825828A
System, device, and method for receiver access control in an internet television
US8370507B1