Authentication Method, Apparatus, System, and Non-volatile Computer-readable Storage Medium

By introducing a unified controller to manage a single domain controller and adopting the H-PCE architecture, the problems of poor scalability and cumbersome authentication process in cross-autonomous domain multicast scenarios are solved, and the effect of simplifying authentication and improving network scalability is achieved.

CN115967506BActive Publication Date: 2025-07-25CHINA TELECOM CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111181998.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-11
Publication Date
2025-07-25
Estimated Expiration
2041-10-11

AI Technical Summary

Technical Problem

In multicast scenarios across autonomous domains, in the prior art, the controllers need to be fully interconnected, resulting in poor scalability and authentication information needs to be broadcast to all connected single domain controllers, which is cumbersome.

Method used

Introduce a unified controller to manage all single-domain controllers, and review and manage authentication information through a unified controller to reduce direct connections between controllers and improve network scalability using the H-PCE architecture.

Benefits of technology

It simplifies the authentication process, improves the scalability of the network, reduces the maintenance cost of authentication information, and provides authentication functions for multicast users with cross-domain access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115967506B_ABST
    Figure CN115967506B_ABST
Patent Text Reader

Abstract

The present disclosure relates to an authentication method, apparatus, system, and non-volatile computer-readable storage medium, and relates to the field of communication technologies. The authentication method includes: the unified controller authenticates a multicast source and a multicast group according to the authentication information reported by the first controller of the first autonomous domain; in the case where the authentication of the multicast source and the multicast group is successful, the unified controller authenticates a receiver applying to join the multicast according to the authentication parameters reported by the second controller of the second autonomous domain; in the case where the authentication of the receiver is successful, the unified controller sends the information indicating the successful authentication of the receiver to the second controller, so as to determine whether to send a multicast packet to the receiver.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communication technologies, and particularly to an authentication method, an authentication device, an authentication system, and a non-volatile computer-readable storage medium. Background Art

[0002] Currently, each autonomous domain in a multicast scenario across autonomous domains has a separate controller, that is, a single-domain controller is equipped for each autonomous domain.

[0003] In the related art, when the multicast source and the accessor are not in the same autonomous domain, the controllers of these two autonomous domains need to perform authentication information interaction, and the authentication information needs to be broadcast to all other single-domain controllers connected to them. Summary of the Invention

[0004] The inventors of the present disclosure found the following problems in the above-mentioned related art: The controllers need to be connected in a full-mesh mode, resulting in poor scalability. Moreover, since the single-domain controller does not know which autonomous domain the multicast source is located in, it needs to broadcast the authentication information to all other single-domain controllers connected to it, and the process is very cumbersome.

[0005] In view of this, the present disclosure proposes an authentication technical solution that can improve scalability and simplify the authentication process.

[0006] According to some embodiments of the present disclosure, an authentication method is provided, including: The unified controller authenticates the multicast source and the multicast group according to the authentication information reported by the first controller in the first autonomous domain; in the case of successful authentication of the multicast source and the multicast group, the unified controller authenticates the receiver applying to join the multicast according to the authentication parameters reported by the second controller in the second autonomous domain; in the case of successful authentication of the receiver, the information of successful authentication of the receiver is sent to the second controller to determine whether to send a multicast packet to the receiver.

[0007] In some embodiments, the unified controller authenticating the multicast source and the multicast group according to the authentication information reported by the first controller in the first autonomous domain includes: The unified controller sends the authentication information to a third-party application; the unified controller audits the authentication information according to the admission rules returned by the third-party application to complete the authentication of the multicast source and the multicast group.

[0008] In some embodiments, the unified controller authenticating the multicast source and the multicast group according to the authentication information reported by the first controller in the first autonomous domain includes: The unified controller saves the authentication information in the authentication information database; the unified controller sends the authentication information to a third-party application; the unified controller audits the authentication information in the authentication information database according to the admission rules returned by the above-mentioned third-party application to complete the authentication of the multicast source and the multicast group.

[0009] In some embodiments, the access rule is returned by a third-party application calling the northbound service interface of the unified controller.

[0010] In some embodiments, the unified controller audits the authentication information according to the access rule returned by the third-party application, including: formulating an authentication policy according to the access rule returned by the third-party application; auditing the authentication information according to the authentication policy.

[0011] In some embodiments, the unified controller authenticates the receivers applying to join the multicast according to the authentication parameters reported by the second controller of the second autonomous domain, including: the unified controller receives a PCEP (Path Computation Element Communication Protocol) message containing the authentication parameters sent by the second controller. The PCEP message is sent by the receiver to the edge router of the second autonomous domain and reported by the edge router to the second controller.

[0012] In some embodiments, the authentication method further includes: the unified controller sends the authentication results of the multicast source and the multicast group to the first controller.

[0013] According to some other embodiments of the present disclosure, an authentication device is provided. The authentication device is set in the unified controller and includes: an authentication unit for authenticating the multicast source and the multicast group according to the authentication information reported by the first controller of the first autonomous domain, and authenticating the receivers applying to join the multicast according to the authentication parameters reported by the second controller of the second autonomous domain when the authentication of the multicast source and the multicast group is successful; a sending unit for sending the information that the receiver authentication is successful to the second controller when the receiver authentication is successful, so that the second controller determines whether to send multicast packets to the receiver.

[0014] In some embodiments, the authentication unit sends the authentication information to a third-party application; audits the authentication information according to the access rule returned by the third-party application to complete the authentication of the multicast source and the multicast group.

[0015] In some embodiments, the authentication unit saves the authentication information in the authentication information database; sends the authentication information to a third-party application; audits the authentication information in the authentication information database according to the access rule returned by the above-mentioned third-party application to complete the authentication of the multicast source and the multicast group.

[0016] In some embodiments, the access rule is returned by a third-party application calling the northbound service interface of the unified controller.

[0017] In some embodiments, the authentication unit formulates an authentication policy according to the access rules returned by the third-party application, and audits the authentication information according to the authentication policy.

[0018] In some embodiments, the authentication unit receives a PCEP message containing authentication parameters sent by the second controller. The PCEP message is sent by the receiver to the edge router of the second autonomous domain and reported by the edge router to the second controller.

[0019] In some embodiments, the sending unit sends the authentication results of the multicast source and the multicast group to the first controller.

[0020] According to still some other embodiments of the present disclosure, there is provided an authentication device, wherein the authentication device is disposed in a unified controller and includes: a memory; and a processor coupled to the memory. The processor is configured to execute the authentication method in any of the above embodiments based on instructions stored in the memory device.

[0021] According to still some other embodiments of the present disclosure, there is provided a non-volatile computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the authentication method in any of the above embodiments is implemented.

[0022] According to still some other embodiments of the present disclosure, there is provided an authentication system, including: a unified controller for executing the authentication method in any of the above embodiments; a first controller of the first autonomous domain for reporting authentication information of the multicast source and the multicast group; and a second controller of the second autonomous domain for reporting authentication parameters of the receiver applying to join the multicast.

[0023] In some embodiments, after receiving the information that the receiver authentication is successful sent by the unified controller, the second controller sends authentication control information to the edge router of the second autonomous domain, so that the edge router of the second autonomous domain processes the authentication parameters of the receiver according to the authentication control information, and determines whether to send a multicast packet to the receiver according to the processing result.

[0024] In the above embodiments, through the unified controller added on the network side, all single-domain controllers are uniformly managed. Each single-domain controller only needs to interact with the unified controller to complete the authentication. In this way, there is no need to establish a full-mesh connection, thereby improving scalability and simplifying the authentication process. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The drawings forming a part of the specification depict embodiments of the present disclosure and, together with the specification, are used to explain the principles of the present disclosure.

[0026] Referring to the drawings, the present disclosure can be more clearly understood from the following detailed description:

[0027] Figure 1 Flowchart showing some embodiments of the authentication method of the present disclosure;

[0028] Figure 2 Schematic diagram showing some embodiments of the authentication method of the present disclosure;

[0029] Figure 3a Schematic diagram showing some other embodiments of the authentication method of the present disclosure;

[0030] Figure 3b Schematic diagram showing some further embodiments of the authentication method of the present disclosure;

[0031] Figure 4 Block diagram showing some embodiments of the authentication apparatus of the present disclosure;

[0032] Figure 5 Block diagram showing some other embodiments of the authentication apparatus of the present disclosure;

[0033] Figure 6 Block diagram showing some further embodiments of the authentication apparatus of the present disclosure;

[0034] Figure 7 Block diagram showing some embodiments of the authentication system of the present disclosure. Detailed Description of the Embodiments

[0035] Various exemplary embodiments of the present disclosure will now be described in detail with reference to the accompanying drawings. It should be noted that: Unless otherwise specifically stated, the relative arrangements, numerical expressions, and numerical values of the components and steps set forth in these embodiments do not limit the scope of the present disclosure.

[0036] At the same time, it should be understood that, for the sake of convenience of description, the dimensions of the various parts shown in the drawings are not drawn in actual proportional relationship.

[0037] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way a limitation on the present disclosure or its application or use.

[0038] Technologies, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and devices should be regarded as part of the specification.

[0039] In all the examples shown and discussed here, any specific value should be construed as merely exemplary and not as a limitation. Therefore, other examples of the exemplary embodiments may have different values.

[0040] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.

[0041] As described above, relying solely on a single domain controller, when the multicast source and the accessor are not in the same autonomous domain, the controllers of these two autonomous domains need to interact with authentication information. Therefore, full-mesh connections are required between the controllers, resulting in poor scalability. Moreover, since the single domain controller does not know which autonomous domain the multicast source is located in, it needs to broadcast the authentication information to all other single domain controllers connected to it, making the authentication process cumbersome.

[0042] To address the above technical problems, the present disclosure proposes a cross-domain multicast accessor authentication technical solution, which can provide cross-domain authentication means for scenarios where the multicast source and the accessor do not belong to the same autonomous domain. For example, the technical solution of the present disclosure can be implemented based on the H-PCE (High level-Path Computation Element) architecture, and can rely on the H-PCE architecture to improve the scalability of the network architecture.

[0043] In some embodiments, a unified controller is added, which can manage all single domain controllers. For example, an authentication information database can be set up in the unified controller, and all authentication-related information is stored therein.

[0044] In this way, each single domain controller only needs to establish a connection with the unified controller, without the need for full-mesh connections between single domain controllers, which can improve the scalability of the network architecture. For example, the technical solution of the present disclosure can be implemented through the following embodiments.

[0045] Figure 1 The flowchart showing some embodiments of the authentication method of the present disclosure.

[0046] As Figure 1 shown, in step 110, the unified controller authenticates the multicast source and the multicast group according to the authentication information reported by the first controller in the first autonomous domain.

[0047] In some embodiments, the unified controller sends the authentication information to a third-party application; the unified controller audits the authentication information according to the admission rules returned by the third-party application to complete the authentication of the multicast source and the multicast group.

[0048] For example, the unified controller saves the authentication information in the authentication information database; the unified controller sends the authentication information to a third-party application; the unified controller audits the authentication information in the authentication information database according to the admission rules returned by the above-mentioned third-party application to complete the authentication of the multicast source and the multicast group. For example, the admission rules are returned by the third-party application invoking the northbound service interface of the unified controller.

[0049] In some embodiments, the unified controller formulates an authentication policy according to the access rules returned by a third-party application; the unified controller audits the authentication information according to the authentication policy.

[0050] In some embodiments, the unified controller sends the authentication results of the multicast source and the multicast group to the first controller.

[0051] In some embodiments, the first controller reports the authentication information related to the multicast source and the multicast group to the unified controller; the unified controller sends the authentication results of the multicast source and the multicast group to the first controller.

[0052] For example, the unified controller saves the information reported by the first controller in the authentication information database and sends it to the third-party APP. The third-party APP calls the northbound service interface of the unified controller to issue access rules; the unified controller formulates an authentication policy according to the rules issued by the APP; the unified controller audits the authentication information reported by the first controller 1 according to the authentication policy and sends the authentication results to the first controller.

[0053] In step 120, when the authentication of the multicast source and the multicast group is successful, the unified controller authenticates the receiver applying to join the multicast according to the authentication parameters reported by the second controller in the second autonomous domain.

[0054] In some embodiments, the unified controller receives a PCEP message containing authentication parameters sent by the second controller. The PCEP message is sent by the receiver to the edge router in the second autonomous domain and reported by the edge router to the second controller.

[0055] For example, the receiver sends a PCEP message containing authentication parameters to the edge router in the second autonomous domain to apply to join the multicast; the edge router on the receiver side (i.e., the edge router in the second autonomous domain) reports the authentication parameters to the second controller through the PCEP message; the second controller forwards the PCEP message carrying the multicast join information to the unified controller; the unified controller performs access rule authentication and sends the result to the second controller after successful authentication.

[0056] In step 130, when the authentication of the receiver is successful, the information indicating the successful authentication of the receiver is sent to the second controller to determine whether to send multicast packets to the receiver.

[0057] In some embodiments, after receiving the information indicating the successful authentication of the receiver sent by the unified controller, the second controller sends authentication control information to the edge router in the second autonomous domain so that the edge router in the second autonomous domain processes the authentication parameters of the receiver according to the authentication control information and determines whether to send multicast packets to the receiver according to the processing result.

[0058] For example, the second controller sends a PCEP message to the receiver-side edge router, carrying authentication control information; according to the authentication control information, the edge router processes the authentication information of the accesser locally; and determines whether to forward the multicast packet to the receiver according to the local processing result.

[0059] Figure 2 Schematic diagram showing some embodiments of the authentication method of the present disclosure.

[0060] As Figure 2 As shown, the newly added unified controller is used to manage all single-domain controllers (controllers 1 to 4). An authentication information database is set up in the unified controller, and all authentication-related information is stored therein. AS (Autonomous System) 1 to 4 each have corresponding single-domain controllers and PEs (Provider Edge, i.e., edge routers), and the PEs of each AS are connected to their controllers.

[0061] Figure 3a Schematic diagram showing some other embodiments of the authentication method of the present disclosure.

[0062] As Figure 3a As shown, the cross-domain access of multicast users is controlled according to the authentication information stored in the unified controller.

[0063] In step 310, controller 1 reports the authentication information related to the multicast source and multicast group to the unified controller.

[0064] In step 320, the unified controller sends the authentication result of the multicast source and multicast group to controller 1.

[0065] In step 330, the receiver sends a PCEP message containing authentication parameters to the edge router PE4 to apply to join the multicast.

[0066] In step 340, the receiver-side edge router PE4 reports the authentication parameters to controller 2 through the PCEP message.

[0067] In step 350, controller 2 forwards the PCEP message carrying the multicast join information to the unified controller.

[0068] In step 360, the unified controller performs access rule authentication, and sends the result to controller 2 after successful authentication.

[0069] In step 370, controller 2 sends a PCEP message to the receiver-side edge router PE4, carrying authentication control information; according to the authentication control information, the edge router PE4 processes the authentication information of the new accesser locally; and determines whether to forward the multicast packet to the receiver according to the local processing result.

[0070] Figure 3b Schematic diagram showing some additional embodiments of the authentication method of the present disclosure.

[0071] As Figure 3b shown, control the cross-domain access of multicast users according to the authentication information sent by the APP.

[0072] In step 410, the controller 1 reports the authentication information related to the multicast source and multicast group to the unified controller.

[0073] In step 420, the unified controller saves the information reported by the controller 1 in the authentication information database and sends it to the third-party APP (application).

[0074] In step 430, the third-party APP calls the northbound service interface of the unified controller to issue an access rule, and the unified controller formulates an authentication policy according to the rule sent by the APP.

[0075] In step 440, the unified controller audits the authentication information reported by the controller 1 according to the authentication policy and sends the authentication result to the controller 1.

[0076] In step 450, the receiver sends a PCEP message containing authentication parameters to the edge router PE4 to apply to join the multicast.

[0077] In step 460, the edge router PE4 on the receiver side reports the authentication parameters to the controller 2 through the PCEP message.

[0078] In step 470, the controller 2 forwards the PCEP message carrying the multicast join information to the unified controller.

[0079] In step 480, the unified controller performs access rule authentication and sends the result to the controller 2 after successful authentication.

[0080] In step 490, the controller 2 sends a PCEP message to the edge router PE4 on the receiver side, carrying authentication control information; according to the authentication control information, the edge router PE4 processes the authentication information of the newly accessed user locally; according to the local processing result, determine whether to forward the multicast packet to the receiver.

[0081] In the above embodiments, a unified controller is added to manage all single-domain controllers; an authentication information database is set in the unified controller, and all authentication-related information is stored therein; cross-domain multicast receiver authentication is performed based on the H-PCE architecture.

[0082] In this way, saving the user authentication information in the unified controller can reduce the maintenance cost of the authentication information; it can simplify the connection between controllers using the H-PCE architecture and improve the scalability of the network.

[0083] Moreover, it can provide an authentication function for multicast users accessing across domains; it can receive authentication rules from a third-party APP and generate an authentication policy according to the authentication rules to restrict user access.

[0084] Figure 4 The block diagram showing some embodiments of the authentication device of the present disclosure.

[0085] As Figure 4 shown, the authentication device 4 is provided in the unified controller and includes an authentication unit 41 and a sending unit 42.

[0086] The authentication unit 41 authenticates the multicast source and multicast group according to the authentication information reported by the first controller of the first autonomous domain. When the authentication of the multicast source and multicast group is successful, the unified controller authenticates the receiver applying to join the multicast according to the authentication parameters reported by the second controller of the second autonomous domain.

[0087] The sending unit 42, when the authentication of the receiver is successful, sends the information that the receiver authentication is successful to the second controller so that the second controller can determine whether to send multicast packets to the receiver.

[0088] In some embodiments, the authentication unit 41 sends the authentication information to a third-party application; according to the admission rules returned by the third-party application, it audits the authentication information to complete the authentication of the multicast source and multicast group.

[0089] In some embodiments, the authentication unit saves the authentication information in the authentication information database; sends the authentication information to a third-party application; according to the admission rules returned by the above-mentioned third-party application, it audits the authentication information in the authentication information database to complete the authentication of the multicast source and multicast group.

[0090] In some embodiments, the admission rules are returned by the third-party application invoking the northbound service interface of the unified controller.

[0091] In some embodiments, the authentication unit formulates an authentication policy according to the admission rules returned by the third-party application; according to the authentication policy, it audits the authentication information.

[0092] In some embodiments, the authentication unit receives a PCEP message containing authentication parameters sent by the second controller. The PCEP message is sent by the receiver to the edge router of the second autonomous domain and reported by the edge router to the second controller.

[0093] In some embodiments, the sending unit sends the authentication result of the multicast source and multicast group to the first controller.

[0094] Figure 5Block diagram showing other embodiments of the authentication device of the present disclosure.

[0095] As Figure 5 shown, the authentication device 5 is provided in a unified controller. The authentication device 5 in this embodiment includes: a memory 51 and a processor 52 coupled to the memory 51. The processor 52 is configured to execute the authentication method in any one of the embodiments of the present disclosure based on the instructions stored in the memory 51.

[0096] Among them, the memory 51 may include, for example, a system memory, a fixed non-volatile storage medium, etc. The system memory stores, for example, an operating system, application programs, a boot loader, a database, and other programs.

[0097] Figure 6 Block diagram showing still other embodiments of the authentication device of the present disclosure.

[0098] As Figure 6 shown, the authentication device 6 is provided in a unified controller. The authentication device 6 in this embodiment includes: a memory 610 and a processor 620 coupled to the memory 610. The processor 620 is configured to execute the authentication method in any one of the foregoing embodiments based on the instructions stored in the memory 610.

[0099] The memory 610 may include, for example, a system memory, a fixed non-volatile storage medium, etc. The system memory stores, for example, an operating system, application programs, a boot loader, and other programs.

[0100] The authentication device 6 may further include an input / output interface 630, a network interface 640, a storage interface 650, etc. These interfaces 630, 640, 650 and the memory 610 and the processor 620 may be connected through a bus 660, for example. Among them, the input / output interface 630 provides a connection interface for input / output devices such as a display, a mouse, a keyboard, a touch screen, a microphone, a speaker, etc. The network interface 640 provides a connection interface for various networking devices. The storage interface 650 provides a connection interface for external storage devices such as an SD card and a USB flash drive.

[0101] Figure 7 Block diagram showing some embodiments of the authentication system of the present disclosure.

[0102] As Figure 7 shown, the authentication system 7 includes: a unified controller 71 for executing the authentication method in any one of the above embodiments; a first controller 72 of the first autonomous domain for reporting authentication information of a multicast source and a multicast group; and a second controller 73 of the second autonomous domain for reporting authentication parameters of a receiver applying to join the multicast.

[0103] In some embodiments, after receiving the information that the receiver authentication is successful sent by the unified controller, the second controller 73 sends authentication control information to the edge router of the second autonomous domain, so that the edge router of the second autonomous domain processes the authentication parameters of the receiver according to the authentication control information, and determines whether to send multicast packets to the receiver according to the processing result.

[0104] Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, a system, or a computer program product. Therefore, the present disclosure can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer-usable non-transitory storage media including but not limited to disk storage, CD-ROM, optical storage, etc. that contain computer-usable program code.

[0105] So far, the authentication method, authentication device, authentication system, and non-volatile computer-readable storage medium according to the present disclosure have been described in detail. To avoid obscuring the concept of the present disclosure, some details well known in the art have not been described. Those skilled in the art can fully understand how to implement the technical solutions disclosed herein based on the above description.

[0106] The methods and systems of the present disclosure can be implemented in many ways. For example, the methods and systems of the present disclosure can be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of steps for the method is only for illustration, and the steps of the method of the present disclosure are not limited to the specific order described above unless otherwise specifically stated. In addition, in some embodiments, the present disclosure can also be implemented as a program recorded in a recording medium, and these programs include machine-readable instructions for implementing the methods according to the present disclosure. Therefore, the present disclosure also covers a recording medium storing a program for executing the methods according to the present disclosure.

[0107] Although some specific embodiments of the present disclosure have been described in detail by way of examples, those skilled in the art should understand that the above examples are only for illustration and not for limiting the scope of the present disclosure. Those skilled in the art should understand that the above embodiments can be modified without departing from the scope and spirit of the present disclosure. The scope of the present disclosure is defined by the appended claims.

Claims

1. An authentication method, comprising: The unified controller authenticates the multicast source and the multicast group according to the authentication information reported by the first controller of the first autonomous domain; When the authentication of the multicast source and the multicast group is successful, the unified controller authenticates the receivers applying to join the multicast according to the authentication parameters reported by the second controller of the second autonomous domain; When the authentication of the receivers is successful, the unified controller sends the information indicating the successful authentication of the receivers to the second controller, so as to determine whether to send multicast packets to the receivers; Wherein, the unified controller authenticating the multicast source and the multicast group according to the authentication information reported by the first controller of the first autonomous domain includes: The unified controller stores the authentication information in the authentication information database; The unified controller sends the authentication information to a third-party application; The unified controller audits the authentication information in the authentication information database according to the admission rules returned by the third-party application, so as to complete the authentication of the multicast source and the multicast group.

2. The authentication method according to claim 1, wherein, The admission rules are returned by the third-party application by invoking the northbound service interface of the unified controller.

3. The authentication method according to claim 1, wherein, The unified controller auditing the authentication information according to the admission rules returned by the third-party application includes: The unified controller formulates an authentication policy according to the admission rules returned by the third-party application; The unified controller audits the authentication information according to the authentication policy.

4. The authentication method according to any one of claims 1 to 3, wherein, The unified controller authenticating the receivers applying to join the multicast according to the authentication parameters reported by the second controller of the second autonomous domain includes: The unified controller receives a Path Computation Element Communication Protocol (PCEP) message containing the authentication parameters sent by the second controller, and the PCEP message is sent by the receivers to the edge router of the second autonomous domain and reported by the edge router to the second controller.

5. The authentication method according to any one of claims 1-3, further comprising: The unified controller sends the authentication result of the multicast source and the multicast group to the first controller.

6. An authentication device, wherein, The authentication device is disposed in the unified controller and includes: An authentication unit, configured to authenticate the multicast source and the multicast group according to the authentication information reported by the first controller of the first autonomous domain, and authenticate the receivers applying to join the multicast according to the authentication parameters reported by the second controller of the second autonomous domain when the authentication of the multicast source and the multicast group is successful; A sending unit, configured to send the information indicating the successful authentication of the receivers to the second controller when the authentication of the receivers is successful, so that the second controller determines whether to send multicast packets to the receivers; Wherein, the authentication unit stores the authentication information in the authentication information database, sends the authentication information to a third-party application, and audits the authentication information in the authentication information database according to the admission rules returned by the third-party application, so as to complete the authentication of the multicast source and the multicast group.

7. An authentication system, comprising: A unified controller, configured to execute the authentication method according to any one of claims 1-5; The first controller of the first autonomous domain is used to report the authentication information of the multicast source and multicast group; The second controller of the second autonomous domain is used to report the authentication parameters of the receivers applying to join the multicast.

8. The authentication system according to claim 7, wherein, After receiving the information that the receiver authentication is successful sent by the unified controller, the second controller sends authentication control information to the edge router of the second autonomous domain, so that the edge router of the second autonomous domain processes the authentication parameters of the receiver according to the authentication control information, and determines whether to send multicast packets to the receiver according to the processing result.

9. An authentication device, wherein, The authentication device is arranged in the unified controller and includes: A memory; and A processor coupled to the memory, the processor being configured to execute the authentication method according to any one of claims 1-5 based on instructions stored in the memory.

10. A non-volatile computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the authentication method according to any one of claims 1-5 is implemented.

Citation Information

Patent Citations

  • IP multicast communication system

    US20050111474A1