Access Device Multicast IP Filtering for Mobile IPv4 Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In mobile telecommunication networks, user equipment (UE) experiences service interruptions when moving from one subnet to another due to the prohibition of sending multicast IP packets, which prevents agent solicitation and registration request messages from reaching mobile agents, disrupting service handover and registration processes.

Innovation Solution

Access devices in the network are enhanced to filter and allow only specific multicast IP packets, such as agent solicitation and registration request messages, to pass through, ensuring timely registration and uninterrupted service by determining and validating multicast IP packets based on predetermined addresses and types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access devices prohibit multicast IP packets from UE for security and economic reasons, then network security and cost control are improved, but service handover and registration processes are disrupted

Engineering Contradiction:
Improvenetwork securityVSAvoidservice handover efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments multicast IP packets into two categories: control packets (AS, RRQ) that are allowed to pass, and data packets that are blocked. This segmentation enables selective filtering based on packet type and destination address, resolving the contradiction by permitting essential control communications while maintaining security restrictions on data transmission.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality rules to different multicast packets: control packets destined for multicast address 224.0.0.11 are permitted, while other multicast packets are blocked. This local quality differentiation allows the system to maintain security while enabling specific control functions that require multicast communication.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If access devices block all multicast IP packets from UE, then malicious attacks are prevented, but agent solicitation and registration requests cannot reach mobile agents

Engineering Contradiction:
Improvemalicious attacksVSAvoidregistration completeness
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent introduces an intermediary filtering mechanism at the access device that mediates between security requirements and registration needs. The filter examines packet characteristics (destination address, type) and selectively permits control packets while blocking potentially harmful data packets, thus preventing attacks while ensuring registration completeness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the filtering parameters from a blanket block of all multicast packets to a selective filter based on destination address (224.0.0.11) and packet type. This parameter change enables the system to distinguish between safe control packets and potentially harmful data packets, resolving the contradiction between attack prevention and registration reliability.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If UE sends AS message as multicast IP packet, then service handover can be initiated, but the message is discarded by access devices and cannot reach mobile agents

Engineering Contradiction:
Improveservice handover initiationVSAvoidmessage delivery
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces dynamic filtering rules that adapt based on packet characteristics. Control packets with specific destination addresses and types are dynamically permitted through the access device, while other packets are blocked. This dynamic approach enables service handover initiation while maintaining security control.

Inventive Principle:
Principle #15Dynamics

4Productivity

If access devices allow all multicast IP packets from UE, then service handover and registration are supported, but network security is compromised and costs increase

Engineering Contradiction:
Improveservice continuityVSAvoidnetwork security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments multicast traffic into control plane traffic (permitted) and data plane traffic (blocked). This segmentation enables the system to support service continuity through control packets while preventing security risks by blocking data packets, thus resolving the contradiction between productivity and security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2197161B1Method and apparatus for controlling multicast IP packets in access network
Publication Date: 2019.11.06 ALCATEL LUCENT SA
  • EP2197161B1 patent drawingFigure 1
  • EP2197161B1 patent drawingFigure 2
  • EP2197161B1 patent drawingFigure 3

AI summary

The present invention proposes a method for controlling the uplink transmission of the multicast IP packet sourced from the UE in field of IP packet transmission in access network. According to the technical solution of the present invention, the access devices receives IP packet from the UE, checks the IP packet and determines whether the IP packet is multicast IP packet that is allowed to be accessed. If the access device determines that the IP packet is multicast IP packet that is allowed to be accessed, then it sends the multicast IP packet in multicast form. Via the present invention, the access device can allow the uplink valid multicast IP packet to pass, preferably, determines and intercepts the malicious attacks via multicast IP packet, so as to ensure the DSL access device's support for mobile IPv4, so as to keep the uninterrupted connection of the service to the user when the user moves between different subnets.