Method for multicasting messages in a communications network implementing a direct multicast protocol.
The method enhances multicast protocol security by adding protective parameters to message headers, ensuring secure broadcasts to unidentifiable recipients without prior secret distribution, thereby addressing the security vulnerabilities of existing protocols.
Patent Information
- Application Number
- FR2023012940
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-23
- Publication Date
- 2025-05-30
AI Technical Summary
Existing multicast protocols, such as the BSR protocol, face security vulnerabilities due to insecure message broadcasting, which allows any machine to forge messages and modify network configurations, and require prior distribution of secrets for secure exchanges.
A method for multicasting messages in a communication network that adds additional parameters to the message header, including the type and version of the multicast protocol, assured protection (integrity, authenticity, confidentiality, and anti-replay), certificate information, and message signature, to secure message exchanges without requiring prior secret distribution.
The method effectively secures message broadcasts by ensuring integrity, authenticity, and confidentiality, even to unidentifiable and unlocatable recipients, without the need for prior secret exchange, thus addressing the security vulnerabilities of existing multicast protocols.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Method for multicasting messages in a communications network implementing a direct multicast protocol.
[0001] The invention relates to a method for multicasting or multiple broadcasting of messages in a communication network implementing a multiple broadcasting protocol, or "multicast" or "broadcast" in English.
[0002] The invention relates to any system requiring direct multicasting of information without requiring identification of potentially interested receivers.
[0003] In many use cases, it may be useful to broadcast information without the potential receivers being known or identifiable in advance (global configuration data, logs, time, operational messages, informative messages, etc.) and without the possibility of implementing a broadcast service from a unicast application broadcast server.
[0004] The integrity and origin of information can be important criteria for such systems.
[0005] For example, the BSR protocol (RFC 5059) allows, within the framework of dynamic IP multicast routing, or "multicast" in English, as illustrated in [Fig.l], to configure all the routers of a multicast IP network. For this, BSM messages, for acronym of "BootStrap Message" in English, are broadcast by the BSR router or "BootStrap Router" in English, in order to distribute to all the routers all the configuration elements (addresses of the Rendezvous Points, associated multicast addresses, etc.). These messages are currently broadcast in an insecure manner, which represents a significant vulnerability of the standard and therefore of the networks. Any machine can forge messages and broadcast them to modify the configuration of the network; the same is true for other similar proprietary mechanisms (CISCO: "Auto_RP").
[0006] A direct broadcast protocol has the advantage of being implemented at the link or routing level, therefore without requiring an application server, and allows bandwidth savings. The use of this protocol poses security problems linked to the control of broadcasting.
[0007] For direct point-to-point or multipoint exchanges, as illustrated in [Fig.2], there are different secure exchange protocols (TLS, IPsec, etc.). These protocols require the prior distribution of secrets, either by bidirectional negotiation of protection secrets, or by sharing common secrets. These principles can prove complicated when the interlocutors are not always known or change frequently.
[0008] There are other secure broadcasting modes, as illustrated in [Fig.3], (messaging, conferences, collaborative communications, etc.), but which rely on application services and unicast exchanges (in a star on an application server).
[0009] Such an application service broadcast protocol allows for a great wealth of services, however the direct point-to-point or "unicast" exchanges in English that they generate, overload the network due to the duplication of information from end to end.
[0010] Secure broadcasting without application service in a technical perimeter that cannot be controlled in space and time (evolving) is complex because it requires knowledge of technical modifications within the perimeter and frequent configuration actions. Security protocols, when they exist, are either implemented directly and bidirectionally between transmitters and receivers for non-application exchanges, or implemented via application unicast broadcasting services (example: secure messaging, videoconferencing).
[0011] In the context of a direct multicast protocol, such as the BSR protocol, security is difficult because the exchanges take place at the IP protocol level and the recipient interlocutors are not known and all directly accessible (relaying of messages from one to another).
[0012] One aim of the invention is to overcome the problems mentioned above.
[0013] According to one aspect of the invention, there is proposed a method for multicasting messages in a communication network implementing a multicast protocol, in which additional parameters are added to the header of a message based on the multicast protocol implemented, the additional parameters comprising: - a type of multicast protocol; - a version of the multicast protocol; - assured protection for the message, including integrity and authenticity and / or confidentiality and / or anti-replay; - a type of certificate used by the sender of the message; - a length of the certificate; - a certificate from the sender of the message; - a length of the message signature; and - a signature of the message.
[0014] In one embodiment, the additional parameters include a message type of a message requiring security or not.
[0015] According to one embodiment, the additional parameters comprise, in the case of using a plurality of cryptographic algorithms, the identifier of each al- cryptographic algorithm and associated parameters.
[0016] In one embodiment, the additional parameters include an anti-replay counter.
[0017] According to one embodiment, the additional parameters comprising the anti-replay counter, the additional parameters comprise a signature of the anti-replay counter.
[0018] In one embodiment, security checks performed by machines in the communications network use a certificate from the same certification authority.
[0019] According to one embodiment, the multicast protocol is a routing control protocol.
[0020] For example, the routing control protocol is a PIM, or BSR, or IGMP, or MLD, or OSPF protocol.
[0021] In one embodiment, the multicast protocol is a traffic protocol.
[0022] For example, the traffic protocol is a SYSLOG protocol, or Auto-RP, or VLC multicast.
[0023] The invention will be better understood by studying a few embodiments described as non-limiting examples and illustrated by the appended drawings in which:
[0024] [Fig-1] schematically illustrates a multi-direct IP multicast protocol directional multipoint point not using an application server, according to the state of the art;
[0025] [Fig.2] schematically illustrates a unidirectional point-to-point indirect IP multicast protocol using an application server, according to the state of the art;
[0026] [Fig.3] schematically illustrate a unidirectional point-to-point indirect IP multicast protocol using an application server, according to one aspect of the invention;
[0027] [Fig.4] schematically illustrates a message of the multicast protocol, according to one aspect of the invention; and
[0028] [Fig.5] schematically illustrates the operation of the protocol of [Fig.4].
[0029] Throughout the figures, elements having identical references are similar.
[0030] [Fig.4] schematically illustrates the method according to one aspect of the invention.
[0031] The method of multicasting messages 1 in a communication network implementing a broadcast protocol, in which additional parameters 2 are added to the header of a message based on the implemented multicast protocol, the additional parameters 2 comprising: a type of multicast protocol; a version of the multicast protocol; - assured protection for the message, including integrity and authenticity and / or confidentiality and / or anti-replay; - a type of certificate used by the sender of the message; - a length of the certificate; - a certificate from the sender of the message; - a length of the message signature; and - a signature of the message.
[0032] An advantage of the method of the invention is in particular to be able to protect at least in integrity and authenticity and possibly in confidentiality and / or in anti-replay the messages broadcast to multiple, heterogeneous, unidentifiable and unlocatable interlocutors, and accessible without application service.
[0033] Furthermore, each message broadcast has the information necessary for its control without prior exchange of secrets between the different protagonists.
[0034] The broadcast message can also be protected in confidentiality so that it can be processed by one of the receiving machines (asymmetric encryption).
[0035] The broadcast message can also be anti-replay protected so that it cannot be replayed over time.
[0036] This secure broadcast mode makes it possible to satisfy numerous direct or relayed data exchanges, non-deterministic but sensitive in terms of integrity and origin.
[0037] The additional parameters 2 may include a message type among a message requiring confidentiality or not.
[0038] The additional parameters 2 may comprise, in the case of use of a plurality of cryptographic algorithms, the identifier of each cryptographic algorithm and the associated parameters.
[0039] Thus, each transmitted message can be signed with different algorithms allowing the same information to be sent to recipients not using the same cryptographic algorithms.
[0040] Additional parameters 2 may include an anti-replay counter.
[0041] When the additional parameters 2 include the anti-replay counter, the additional parameters 2 may also include a signature of the anti-replay counter.
[0042] The security checks (integrity and authenticity) carried out by the machines in the communication network use the issuer's certificate.
[0043] All machines involved in security checks can be covered by the same hierarchical root certification authority (only the authority's certificate must be known to all). Only message senders must have a private key.
[0044] Secure messages can be transmitted to all parties with or without message relaying.
[0045] The multicast protocol may be a control protocol, such as a PIM, BSR, Auto-RP, IGMP, MLD, or OSPF routing control protocol.
[0046] The multicast protocol may be a traffic protocol, such as a SYSLOG protocol, or VLC multicast.
[0047] The communication protocol does not require any prior exchange or distribution of shared secrets to all machines. Verification mechanisms accompany each exchanged data, making the secure broadcast self-supporting (in-band security signaling or "Inband" in English).
[0048] Additional parameters 2 can be added to the existing message header or in an encapsulation header.
[0049] [Fig.5] schematically illustrates the routing in a communication network implementing the method according to one aspect of the invention.
[0050] The present invention makes it possible in particular to: - secure exchanges from N to M interlocutors without application service: such as multicasting by routing information within communication networks; - avoid prior exchanges of shared secrets; - avoid bidirectional signaling necessary for the exchange, unidirectional links are possible; and - broadcast by multiple IP routing in dense mode.
Claims
Claims
1. Method for multicasting messages (1) in a communication network implementing a multicast protocol, in which additional parameters (2) are added to the header of a message based on the implemented multicast protocol, the additional parameters (2) comprising: - a type of the multicast protocol; - a version of the multicast protocol; - protection provided for the message including integrity and authenticity and / or confidentiality and / or anti-replay; - a type of certificate used by the sender of the message; - a length of the certificate; - a certificate of the sender of the message; - a length of the signature of the message; and - a signature of the message.
2. The method of claim 1, wherein the additional parameters (2) comprise a message type of a message requiring security or not.
3. Method according to one of the preceding claims, in which the additional parameters (2) comprise, in the case of use of a plurality of cryptographic algorithms, the identifier of each cryptographic algorithm and the associated parameters.
4. Method according to one of the preceding claims, in which the additional parameters (2) comprise an anti-replay counter.
5. The method of claim 4, wherein, the additional parameters (2) comprising the anti-replay counter, the additional parameters comprise a signature of the anti-replay counter.
6. Method according to one of the preceding claims, in which security checks carried out by machines in the communication network use a certificate from the same certification authority.
7. Method according to one of the preceding claims, in which the multicast protocol is a routing control protocol.
8. The method of claim 7, wherein the control protocol is a PIM, or BSR, or Auto-RP, or IGMP, or MLD, or OSPF protocol.
9. Method according to one of claims 1 to 6, in which the multicast protocol is a traffic protocol.
10. The method of claim 9, wherein the traffic protocol is a SYSLOG, or VLC multicast protocol.
Citation Information
Patent Citations
Network security by integrating mutual attestation
US20220222347A1