Dynamic multicast joining authentication method and system based on zero-trust model
By adopting a dynamic multicast addition authentication method based on a zero-trust model, combined with identity recognition, behavior assessment, and continuous auditing, the problems of DoS attacks and replay attacks in traditional multicast communication are solved. This enables real-time risk monitoring and access control of multicast nodes, thereby improving system security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGXI PUBLIC INFORMATION IND CO LTD
- Filing Date
- 2025-10-30
- Publication Date
- 2026-05-01
AI Technical Summary
Traditional IP multicast communication lacks multicast group member authentication and access control mechanisms, leading to DoS attacks and replay attacks. Existing technologies cannot identify and defend against potential abnormal nodes in real time.
A dynamic multicast joining authentication method based on a zero-trust model is adopted. Through identity recognition, behavior evaluation, context awareness, multi-factor verification and continuous auditing mechanisms, a multi-dimensional trust assessment and dynamic decision-making of nodes are achieved, including a trust scoring model and periodic review.
It effectively prevents DoS attacks and replay attacks, enables real-time risk monitoring and access control of multicast nodes, and improves the system's identification capabilities and security.
Smart Images

Figure CN121966909A_ABST
Abstract
Description
A dynamic multicast join authentication method and system based on a zero-trust model Technical Field
[0001] This invention belongs to the field of data communication and network security technology, and specifically relates to an access authentication method and system for multicast communication. Background Technology
[0002] In traditional IP multicast communication models, any host can freely join or send data to a multicast group, lacking multicast group member authentication and access control mechanisms. This deficiency can lead to Denial-of-Service (DoS) attacks and replay attacks. DoS is a malicious network attack method where attackers use various methods to prevent a target system or network resource from providing normal service to legitimate users. Multicast is a network communication method where a single sender corresponds to multiple receivers. SDN (Software-Defined Networking) is a technology architecture that centrally controls and manages networks through software; SDN allows network administrators to dynamically configure and optimize network traffic through a centralized software controller without manually configuring each network device. ACL (Access Control List) is a set of rules used to identify packet flows.
[0003] To address the aforementioned problems, numerous solutions have been proposed:
[0004] For example, Chinese Patent Publication No. CN101635724A discloses a method and system for implementing multicast member authentication, including a host and a router. In operation, the host first obtains encrypted authentication information via Kerberos, and then sends a Group Management Protocol (IGMPv3) message to the router to request joining a multicast group. The source address field of the message carries the authentication information. After receiving the message, the router extracts the authentication information and decrypts the authentication list and service ticket in the multicast member authentication information. If the list information in the decrypted service ticket matches the decrypted authentication list information... In this invention, the router returns the authentication result to the host through the Resv reserved field after successful authentication. This invention effectively prevents multicast from being attacked by DoS and replay attacks through the ticket and timestamp mechanism of Kerberos, and saves network traffic overhead through the flexible use of protocol fields. However, this invention only verifies the authentication information once when joining the request. After successful authentication, the node is trusted by default. It cannot remove the node from the multicast stream in a timely manner based on behavioral deviations or attack indicators. Moreover, it does not introduce dynamic indicators such as the node's historical behavior patterns, communication frequency, and abnormal behavior, and cannot identify and defend against potential abnormal nodes in real time.
[0005] For example, CN114423094A discloses a distributed channel multicast access method based on service characteristics, including: 1) Each multicast group senses and accesses the channel according to a contention method. At the beginning of a micro-slot with a duration of δ, the source node in each multicast group sends RTS packets to all sink nodes in the group with a probability pk∈[0,1] to independently compete for the channel. The source node that does not send RTS packets monitors the channel occupancy in the slot δ through physical layer energy detection, and then proceeds to step 2); 2) If the source node that does not send RTS packets detects the slot If the channel is not occupied, no source node sends an RTS packet, the channel is idle, and all source nodes continue to compete for the channel in the next time slot, returning to step 1); if a source node that did not send an RTS packet detects that the channel is occupied in the time slot, the occupancy time is recorded as τRTS, then there are two cases, after which the process proceeds to step 3); 3) if a sink node sends a CTS packet to a source node, the source node can detect the channel occupancy within the τRTS time after sending the RTS packet, obtain the feedback time τ = minτk,m, and accordingly calculate the channel quality within the multicast group. The reachable rate of the worst-case target destination node is determined. At this point, one channel contention process is completed, and the source node Sk wins the channel contention and is called the winning source node. Source nodes that have not sent RTS packets remain silent, and then proceed to step 4). If a source node detects that the channel is not occupied within τRTS time after sending an RTS packet, it knows that a channel collision has occurred, and all source nodes continue to compete in the next time slot, returning to step 1), where min represents the minimum value; 4) The winning source node Sk is determined based on the reachable rate Rworst of the worst-case target destination node in its multicast group and the current... The equivalent multicast service transmission rate that can be obtained by multicast transmission is calculated based on the number of destination nodes corresponding to the service and compared with the threshold λ. If it is, the winning source node Sk performs multicast at the rate Rworst and then proceeds to step 5). Otherwise, if the winning source node Sk abandons this transmission opportunity, all multicast group source nodes start a new round of channel competition and return to step 1). After the transmission is completed, the target destination node with the worst channel quality sends an acknowledgment character (ACK) to the winning source node. The winning source node confirms the success of the multicast transmission by monitoring that the channel is occupied, and one multicast transmission process is completed.
[0006] For example, CN118509847A discloses a WAPI-based authentication method, including the following steps: S1. Certificate Issuance Stage: A trusted third-party authentication server issues WAPI certificates and public / private key certificates to the access points and terminals participating in the authentication; S2. Certificate Authentication Stage: The access points and terminals participating in the authentication authenticate each other's certificates and negotiate to generate a base key; S3. Unicast Key Negotiation Stage: Based on the base key obtained in step S2, the access points and terminals negotiate to obtain a unicast key and an encryption key for multicast key announcement; S4. Multicast Key Announcement Stage: The access point multicasts the key to the terminal channel and completes WAPI-based authentication; S5. In subsequent communication processes, the access points and terminals update the unicast key and multicast key according to the actual communication situation to ensure the security of the communication process. This patent discloses the multicast key from the access point to the terminal channel and completes WAPI-based identity authentication, which is equivalent to authenticating and evaluating the access point and the terminal based on WAPI certificates. However, it does not introduce dynamic indicators such as node historical behavior patterns, communication frequency, and abnormal behavior, and cannot identify and defend against potential abnormal nodes in real time. Summary of the Invention
[0007] The purpose of this invention is to provide a dynamic multicast join authentication method and system based on a zero-trust model to address the security blind spot of "authorization equals permanent trust" and to continuously audit the multicast nodes that have been joined. By introducing the zero-trust concept and a dynamic scoring mechanism, it achieves multi-factor verification of multicast node join permissions, a security closed loop of "verification required for each join", and continuous risk monitoring and permission revocation after access.
[0008] The technical solution adopted in this invention is as follows:
[0009] A dynamic multicast joining authentication method based on a zero-trust model includes the following steps:
[0010] S1. The host node sends an access request to join the multicast group to the SDN controller through the router;
[0011] After receiving an access request, the S2.SDN controller's multicast access control system activates the identity recognition module to extract the node's identity information; wherein the identity information includes the terminal's virtual identity identifier.
[0012] S3. The multicast access control system obtains the real-time context environment information of the node through the context awareness module; wherein the real-time context environment information includes the network location to which the node belongs;
[0013] S4. The multicast access control system analyzes the historical communication behavior data of the nodes through the behavior evaluation module to obtain behavior indicators including access frequency and abnormal records;
[0014] S5. The behavior assessment module calculates the trust score of the node based on the trust scoring model and the data obtained in steps S2, S3, and S4 above;
[0015] S6. If the trust score is lower than the security threshold, the multicast access control system triggers the multi-factor verification module to initiate an additional request for human-computer interaction authentication to the node. If the trust score is higher than the security threshold, it is authorized to join the multicast group, and the SDN controller issues the corresponding multicast policy instruction.
[0016] S7. After the node successfully joins, the multicast access control system periodically reviews its communication behavior through the continuous monitoring and disqualification module. Once an abnormal deviation from the behavior pattern is detected, it is forcibly removed from the multicast group.
[0017] This invention primarily introduces a zero-trust access control model based on existing multicast access requests. Through identity recognition, behavior assessment, context awareness, multi-factor authentication, trust scoring, and continuous auditing mechanisms, it achieves dynamic decision-making regarding whether a node can join a multicast channel. Specifically, after receiving a node's join request, the system performs a multi-dimensional trust assessment of the node and decides whether to allow it to join the multicast group based on the assessment results. Even after joining, behavior monitoring continues; if the trust level decreases, access is automatically revoked, forming a closed-loop mechanism of "verification upon access, and verification after access."
[0018] As a further explanation of the method described in this invention, in step S1, the access request is an IGMPv3 message with a zero-trust authentication extension field.
[0019] As a further explanation of the method described in this invention, the zero-trust authentication extended fields include: node identifier, network location, count of the most recent N communication anomalies, access frequency, and previous historical trust level. Wherein:
[0020] Node identifier (16 bits): Represents the terminal's virtual identity identifier, a hash digest of the UUID;
[0021] Network location (32 bits): Network segment number, indicating the network area of the node;
[0022] Recent N Communication Anomaly Count (8 bits): The number of abnormal behaviors detected within the sliding window;
[0023] Access frequency (4 bits): The frequency with which a host requests to join a multicast group within one minute;
[0024] Previous historical trust score (4 digits): The previous historical trust score.
[0025] As a further explanation of the method described in this invention, in step S5, the trust scoring model is:
[0026] Trust score = Network location credibility + Abnormal behavior score + Access frequency score + Historical trust level
[0027] The following scoring criteria are used for each scoring point:
[0028] The network location credibility score is out of 10 points, depending on whether the network segment number is in the blacklist. If the network segment number is in the blacklist or unknown area, it gets 0 points, otherwise it gets 10 points.
[0029] The maximum score for abnormal behavior is 35 points, and points are deducted based on the number of abnormal communications in the most recent N communications. For example, if the number of abnormal communications is 0, the score is full. For each additional abnormal communication, 5 points are deducted. If the number of abnormal communications is 5 or more, it is considered abnormal communication and 0 points are awarded.
[0030] The access frequency score is out of 30 points. Based on the typical access frequency of a real multicast network, points are deducted according to the number of requests per minute. For example: 3 or fewer accesses per minute get full marks, 3 to 6 accesses per minute are considered low risk and get 20 points, 7 to 10 accesses per minute are considered medium risk and get 10 points, and more than 10 accesses per minute are considered high risk and get 0 points.
[0031] The historical trust score is out of 15 points, and the previous historical trust score is used as a soft history reference. In order to prevent the historical trust level from fluctuating sharply due to short-term behavior, the system adopts an exponential weighted average strategy, which integrates the current behavior score with the historical trust snapshot carried in the message to form a trust level update mechanism with inertia.
[0032] As a further explanation of the method described in this invention, the historical trust score is calculated using the following formula:
[0033]
[0034] In the formula, This refers to the newly calculated historical trust score; This is the previous historical trust score; This is a linear mapping of the sum of network location credibility, abnormal behavior score, access frequency score, and the previous historical credibility score within the interval [0, 15]. The parameter for adjusting sensitivity is set to 0.5; 7.5 is the center reference value.
[0035] This invention achieves dynamic decision-making on node joining requests through a trust scoring model, and the trust score is composed of multiple dimensions, including a weighted score of node identity information confidence, behavior stability and historical credibility.
[0036] As a further explanation of the method described in this invention, step S6 specifically involves: when the trust score is greater than 70, returning a "allow joining" feedback to the router; when the trust score is between 50 and 70, requesting additional verification through human-computer interaction; and when the trust score is less than 50, returning a "deny joining" feedback to the router.
[0037] As a further explanation of the method described in this invention, in step S7, the periodic review specifically involves the multicast access control system sending a collection request signal to the joined nodes every 120 seconds. When a node receives the request, it actively generates and sends an IGMPv3 message containing a "zero trust authentication extension field". The message structure is consistent with that in step S1. The trust score is calculated according to step S5. When the score is lower than 50, the node is removed from the multicast group.
[0038] This invention also provides a multicast access control system based on a zero-trust model, mounted on an SDN controller, for implementing the aforementioned dynamic multicast joining authentication method. The system includes:
[0039] The identity recognition module is used to parse and verify node identification information;
[0040] The context-aware module is used to collect real-time context information of nodes;
[0041] The behavior evaluation module is used to analyze the historical behavior of nodes and calculate trust scores.
[0042] The multi-factor authentication module is used to initiate an additional authentication process when the trust score is lower than the security threshold;
[0043] The access control and decision module is used to comprehensively analyze authorized access and rejection requests using a scoring model, and the SDN controller issues instructions accordingly.
[0044] The continuous monitoring and revocation module is used to monitor the behavior and status of nodes after they are connected and to dynamically manage their multicast permissions.
[0045] Advantages of this invention:
[0046] 1. This invention designs a trust scoring model, subdividing trust scores into four dimensions: network location trustworthiness, abnormal behavior score, access frequency score, and historical trust level. A hierarchical evaluation system is established, and an exponentially weighted average strategy is used for historical trust fusion processing. Existing multicast mechanisms use static ACLs or IP-based whitelist-based access control methods, which cannot reflect terminal behavior and status in real time and are ill-equipped to handle behavioral variations and attacker masquerading. The multidimensional scoring mechanism of this invention can effectively integrate node status and background behavior, improving system identification capabilities and preventing malicious nodes from evading detection by using legitimate identities.
[0047] 2. This invention effectively detects covert attacks and session hijacking by periodically collecting information for re-scoring and continuous verification. The SDN controller sends a collection request to the multicast nodes every 120 seconds. The nodes return the latest extended field information in IGMP messages. The system calls the scoring model to score the data and then determines whether to maintain or revoke the node's multicast permissions. Existing multicast mechanisms assume "permanent trust" after a node joins, without dynamic evaluation, leading to the risk of permission abuse. Attached Figure Description
[0048] Figure 1 is a schematic diagram of the system framework of an embodiment of the present invention.
[0049] Figure 2 is a schematic diagram of the original IGMPv3 protocol message format.
[0050] Figure 3 is a schematic diagram of an IGMPv3 message format with a zero-trust authentication extension field in one embodiment of the present invention. Detailed Implementation
[0051] The invention will be further described below with reference to the accompanying drawings.
[0052] Example:
[0053] A dynamic multicast joining authentication method based on a zero-trust model includes the following steps:
[0054] S1. The host node sends an access request to join the multicast group to the SDN controller through the router;
[0055] After receiving an access request, the S2.SDN controller's multicast access control system activates the identity recognition module to extract the node's identity information; wherein the identity information includes the terminal's virtual identity identifier.
[0056] S3. The multicast access control system obtains the real-time context environment information of the node through the context awareness module; wherein the real-time context environment information includes the network location to which the node belongs;
[0057] S4. The multicast access control system analyzes the historical communication behavior data of the nodes through the behavior evaluation module to obtain behavior indicators including access frequency and abnormal records;
[0058] S5. The behavior assessment module calculates the trust score of the node based on the trust scoring model and the data obtained in steps S2, S3, and S4 above;
[0059] S6. If the trust score is lower than the security threshold, the multicast access control system triggers the multi-factor verification module to initiate an additional request for human-computer interaction authentication to the node. If the trust score is higher than the security threshold, it is authorized to join the multicast group, and the SDN controller issues the corresponding multicast policy instruction.
[0060] S7. After the node successfully joins, the multicast access control system periodically reviews its communication behavior through the continuous monitoring and disqualification module. Once an abnormal deviation from the behavior pattern is detected, it is forcibly removed from the multicast group.
[0061] This embodiment further illustrates that, in step S1, the access request is an IGMPv3 message with a zero-trust authentication extension field. The zero-trust authentication extension field includes: node identifier, network location, the count of the most recent N communication anomalies, access frequency, and the last trust level snapshot.
[0062] The original IGMPv3 message format is shown in Figure 3. Each Group Record item can carry an auxiliary field at the end. This field is reserved but not defined in the original message and can be used to carry custom information. In this embodiment, it is used to define a set of "zero trust authentication extension fields", the specific structure of which is shown in Figure 3, wherein:
[0063] Auxiliary data length: set to 2, which means the extended length is twice the 32-bit unit, starting from 8 bytes.
[0064] Node identifier (16 bits): Represents the terminal's virtual identity identifier, a hash digest of the UUID;
[0065] Network location (32 bits): Network segment number, indicating the network area of the node;
[0066] Recent N Communication Anomaly Count (8 bits): The number of abnormal behaviors detected within the sliding window;
[0067] Access frequency (4 bits): The frequency with which a host requests to join a multicast group within one minute;
[0068] Previous historical trust score (4 digits): The previous historical trust score.
[0069] This embodiment further illustrates that, in step S5, the trust scoring model is:
[0070] Trust score = Network location credibility + Abnormal behavior score + Access frequency score + Historical trust level
[0071] The following scoring criteria are used for each scoring point:
[0072] The network location credibility score is out of 10 points, depending on whether the network segment number is in the blacklist. If the network segment number is in the blacklist or unknown area, it gets 0 points, otherwise it gets 10 points.
[0073] The maximum score for abnormal behavior is 35 points, and points are deducted based on the number of abnormal communications in the most recent N communications. In this embodiment, it is defined that when the number of abnormal communications is 0, it is the full score. For each additional abnormal communication, 5 points are deducted. When the number of abnormal communications is 5 or more, it is considered abnormal communication and scores 0 points.
[0074] The access frequency score is out of 30 points. Based on the typical access frequency of real-world multicast networks, points are deducted according to the number of requests per minute. In this embodiment, the following is defined: 3 or fewer accesses per minute earn full marks; 3 to 6 accesses per minute are considered low risk and earn 20 points; 7 to 10 accesses per minute are considered medium risk and earn 10 points; and more than 10 accesses per minute are considered high risk and earn 0 points.
[0075] The historical trust score is out of 15 points, and the previous historical trust score is used as a soft history reference. In order to prevent the historical trust level from fluctuating sharply due to short-term behavior, the system adopts an exponential weighted average strategy, which integrates the current behavior score with the historical trust snapshot carried in the message to form a trust level update mechanism with inertia.
[0076] The historical trust score is calculated using the following formula:
[0077]
[0078] In the formula, This is the newly calculated historical trust score; This is the previous historical trust score; This is a linear mapping of the sum of the current network location credibility, abnormal behavior score, access frequency score, and the previous historical credibility score within the interval [0, 15]. The parameter for adjusting sensitivity is set to 0.5; 7.5 is the center reference value.
[0079] The above calculation formula allows for a slight increase in historical trust scores when they are above the median and a slight decrease when they are below the median, demonstrating a resilient characteristic.
[0080] This embodiment further explains that step S6 specifically involves: when the trust score is greater than 70, returning "allow to join" feedback to the router; when the trust score is between 50 and 70, requesting additional verification through human-computer interaction; and when the trust score is less than 50, returning "deny to join" feedback to the router.
[0081] This embodiment further explains that in step S7, the periodic review specifically involves the multicast access control system sending a collection request signal to the joined nodes every 120 seconds. When a node receives the request, it actively generates and sends an IGMPv3 message containing a "zero trust authentication extension field". The message structure is consistent with that in step S1. The trust score is calculated according to step S5. When the score is lower than 50, the node is removed from the multicast group.
[0082] The multicast access control system of this embodiment includes:
[0083] The identity recognition module is used to parse and verify node identification information;
[0084] The context-aware module is used to collect real-time context information of nodes;
[0085] The behavior evaluation module is used to analyze the historical behavior of nodes and calculate trust scores.
[0086] The multi-factor authentication module is used to initiate an additional authentication process when the trust score is lower than the security threshold;
[0087] The access control and decision module is used to comprehensively analyze authorized access and rejection requests using a scoring model, and the SDN controller issues instructions accordingly.
[0088] The continuous monitoring and revocation module is used to monitor the behavior and status of nodes after they are connected and to dynamically manage their multicast permissions.
[0089] The above embodiments extend the "zero trust authentication extension field" in the IGMPv3 protocol, so that multicast access no longer relies on static IP and MAC whitelists, but makes judgments based on dimensions such as terminal identity, network location, and behavior records, and continuously monitors nodes, realizing the network security concept of "default distrust and continuous verification".
[0090] Obviously, the above embodiments are merely examples for clearly illustrating the present invention, and are not intended to limit the implementation of the present invention. Those skilled in the art will recognize that other variations or modifications can be made based on the above description; it is neither necessary nor possible to exhaustively list all possible implementations; however, obvious variations or modifications derived therefrom are still within the scope of protection of the present invention.
Claims
1. A dynamic multicast joining authentication method based on a zero-trust model, characterized in that... Includes the following steps: S1. The host node sends an access request to join the multicast group to the SDN controller through the router; After receiving an access request, the S2.SDN controller's multicast access control system activates the identity recognition module to extract the node's identity information; wherein the identity information includes the terminal's virtual identity identifier. S3. The multicast access control system obtains the real-time context environment information of the node through the context awareness module; wherein the real-time context environment information includes the network location to which the node belongs; S4. The multicast access control system analyzes the historical communication behavior data of the node through the behavior evaluation module to obtain behavior indicators including access frequency and abnormal records; S5. The behavior evaluation module calculates the trust score of the node based on the trust scoring model and the data obtained in steps S2, S3, and S4; S6. If the trust score is lower than the security threshold, the multi-factor verification module is triggered to initiate an additional request for human-computer interaction authentication for the node. If the trust score is higher than the security threshold, it is authorized to join the multicast group, and the SDN controller issues multicast policy instructions; S7. After the node successfully joins, the multicast access control system periodically reviews its communication behavior through the continuous monitoring and deauthorization module. Once an abnormal deviation from the behavior pattern is detected, it is forcibly removed from the multicast group.
2. The dynamic multicast joining authentication method based on a zero-trust model according to claim 1, characterized in that: In step S1, the access request is an IGMPv3 message with a zero-trust authentication extension field.
3. The dynamic multicast joining authentication method based on a zero-trust model according to claim 2, characterized in that: The zero-trust authentication extended fields include: node identifier, network location, count of the most recent N communication anomalies, access frequency, and previous historical trust level.
4. The dynamic multicast joining authentication method based on a zero-trust model according to claim 3, characterized in that: In step S5, the trust scoring model is as follows: Trust Score = Network Location Trustworthiness + Abnormal Behavior Score + Access Frequency Score + Historical Trustworthiness. Each scoring point uses the following scoring criteria: Network Location Trustworthiness has a maximum score of 10 points, depending on whether the network segment number is in a blacklist. If the network segment number is in a blacklist or unknown area, 0 points are awarded; otherwise, 10 points are awarded. Abnormal Behavior Score has a maximum score of 35 points, deducted based on the number of abnormal occurrences in the most recent N communications. Access Frequency Score has a maximum score of 30 points, deducted based on the typical access frequency of a real multicast network, calculated as the number of requests per minute. Historical Trustworthiness has a maximum score of 15 points, using the previous historical trustworthiness score as a soft history reference.
5. The dynamic multicast joining authentication method based on a zero-trust model according to claim 4, characterized in that: The historical trust score is calculated using the following formula: In the formula, This refers to the newly calculated historical trust score; This is the previous historical trust score; This is a linear mapping of the sum of the current network location credibility, abnormal behavior score, access frequency score, and the previous historical credibility score within the interval [0, 15]. The parameter for adjusting sensitivity is set to 0.5; 7.5 is the center reference value.
6. The dynamic multicast joining authentication method based on a zero-trust model according to claim 1, characterized in that: Step S6 specifically involves: when the trust score is greater than 70, returning "allow to join" feedback to the router; when the trust score is between 50 and 70, requesting additional verification through human-computer interaction; and when the trust score is less than 50, returning "deny to join" feedback to the router.
7. The dynamic multicast joining authentication method based on a zero-trust model according to claim 1, characterized in that: In step S7, the periodic review specifically involves the multicast access control system sending a collection request signal to the joined nodes every 120 seconds. When a node receives the request, it actively generates and sends an IGMPv3 message containing a "zero trust authentication extension field". The message structure is the same as in step S1. The trust score is calculated according to step S5. When the score is lower than 50, the node is removed from the multicast group.
8. A multicast access control system based on a zero-trust model, used to implement the dynamic multicast joining authentication method as described in any one of claims 1-7, characterized in that... include: The identity recognition module is used to parse and verify node identification information; The context-aware module is used to collect real-time context information of nodes; The behavior evaluation module is used to analyze the historical behavior of nodes and calculate trust scores. The multi-factor authentication module is used to initiate an additional authentication process when the trust score is lower than the security threshold; The access control and decision-making module is used to comprehensively analyze authorized access and rejection requests using a scoring model, and the SDN controller issues instructions; the continuous monitoring and deprivation module is used to monitor the behavior status of nodes after they are connected and dynamically manage their multicast permissions.
Citation Information
Patent Citations
Method and system for realizing multicast member authentication
CN101635724A
Distributed channel multicast access method based on service characteristics
CN114423094A
Identity authentication method and system based on WAPI and data transmission method
CN118509847A