Access Device Multicast IP Filtering for Mobile IPv4 Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In mobile telecommunication networks, user equipment (UE) experiences service interruptions when moving from one subnet to another due to the prohibition of sending multicast IP packets, which prevents agent solicitation and registration request messages from reaching mobile agents, disrupting service handover and registration processes.
Innovation Solution
Access devices in the network are enhanced to filter and allow only specific multicast IP packets, such as agent solicitation and registration request messages, to pass through, ensuring timely registration and uninterrupted service by determining and validating multicast IP packets based on predetermined addresses and types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access devices prohibit multicast IP packets from UE for security and economic reasons, then network security and cost control are improved, but service handover and registration processes are disrupted
Solution Approach 1:
The patent segments multicast IP packets into two categories: control packets (AS, RRQ) that are allowed to pass, and data packets that are blocked. This segmentation enables selective filtering based on packet type and destination address, resolving the contradiction by permitting essential control communications while maintaining security restrictions on data transmission.
Solution Approach 2:
The patent applies different quality rules to different multicast packets: control packets destined for multicast address 224.0.0.11 are permitted, while other multicast packets are blocked. This local quality differentiation allows the system to maintain security while enabling specific control functions that require multicast communication.
2Object-affected harmful factors
If access devices block all multicast IP packets from UE, then malicious attacks are prevented, but agent solicitation and registration requests cannot reach mobile agents
Solution Approach 1:
The patent introduces an intermediary filtering mechanism at the access device that mediates between security requirements and registration needs. The filter examines packet characteristics (destination address, type) and selectively permits control packets while blocking potentially harmful data packets, thus preventing attacks while ensuring registration completeness.
Solution Approach 2:
The patent changes the filtering parameters from a blanket block of all multicast packets to a selective filter based on destination address (224.0.0.11) and packet type. This parameter change enables the system to distinguish between safe control packets and potentially harmful data packets, resolving the contradiction between attack prevention and registration reliability.
3Ease of operation
If UE sends AS message as multicast IP packet, then service handover can be initiated, but the message is discarded by access devices and cannot reach mobile agents
Solution Approach 1:
The patent introduces dynamic filtering rules that adapt based on packet characteristics. Control packets with specific destination addresses and types are dynamically permitted through the access device, while other packets are blocked. This dynamic approach enables service handover initiation while maintaining security control.
4Productivity
If access devices allow all multicast IP packets from UE, then service handover and registration are supported, but network security is compromised and costs increase
Solution Approach 1:
The patent segments multicast traffic into control plane traffic (permitted) and data plane traffic (blocked). This segmentation enables the system to support service continuity through control packets while preventing security risks by blocking data packets, thus resolving the contradiction between productivity and security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention proposes a method for controlling the uplink transmission of the multicast IP packet sourced from the UE in field of IP packet transmission in access network. According to the technical solution of the present invention, the access devices receives IP packet from the UE, checks the IP packet and determines whether the IP packet is multicast IP packet that is allowed to be accessed. If the access device determines that the IP packet is multicast IP packet that is allowed to be accessed, then it sends the multicast IP packet in multicast form. Via the present invention, the access device can allow the uplink valid multicast IP packet to pass, preferably, determines and intercepts the malicious attacks via multicast IP packet, so as to ensure the DSL access device's support for mobile IPv4, so as to keep the uninterrupted connection of the service to the user when the user moves between different subnets.