Controlled Multicast System Using AAA Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IP multicast systems lack effective methods for controlling host access and ensuring authorized reception, leading to security concerns and inefficiencies in managing multicast groups, particularly in shared networks where unauthorized hosts can receive multicast data.
Innovation Solution
A controlled multicast system incorporating an Ethernet switch, multicast router, portal server, and AAA server, utilizing IGMP V2, RADIUS+, and HGMP protocols for user authentication, privilege management, and multicast forwarding control, ensuring only authorized users can join and receive multicast data, with active management of multicast forwarding trees.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If any host can join any multicast group without limitation, then the ease of operation is improved, but the security and control capability deteriorates
Solution Approach 1:
The patent introduces a multicast router as an intermediary between hosts and multicast groups. The router acts as a mediator that receives join requests from hosts, authenticates them against authorized receiver lists, and selectively forwards multicast data only to authenticated hosts. This resolves the contradiction by maintaining easy host operation while implementing security control through the intermediary router.
Solution Approach 2:
The patent implements preliminary authentication and authorization before hosts can receive multicast data. The system pre-establishes authorized receiver lists at the router, and hosts must present valid credentials before being added to the distribution tree. This preliminary action ensures security is enforced before data transmission begins, resolving the contradiction between ease of operation and security control.
2Reliability
If authentication protocols like IGMP extension and RADIUS are implemented, then the security is improved, but the device complexity increases
Solution Approach 1:
The patent merges multiple authentication functions into the multicast router itself. Rather than requiring separate authentication servers and complex protocol implementations at each host, the router consolidates authentication, authorization, and account management capabilities. This merging reduces overall system complexity while maintaining security, as the router becomes a single point of control for all multicast access decisions.
Solution Approach 2:
The multicast router is designed with multi-functionality, serving both as a traditional multicast forwarding device and as an authentication/authorization server. By making the router universal - capable of handling both data forwarding and security management - the system avoids adding separate specialized devices, thereby improving security without proportionally increasing device complexity.
3Productivity
If multicast data is forwarded to all hosts in a shared network, then the productivity is improved, but the loss of energy and resources increases
Solution Approach 1:
The patent implements local quality control by maintaining separate authorized receiver lists at the multicast router for different network segments or VLANs. The router selectively forwards multicast data only to hosts that are both authenticated and appropriate for receiving that specific data stream. This local quality filtering prevents unnecessary data transmission to unauthorized or inappropriate hosts, reducing energy waste while maintaining efficient delivery to authorized receivers.
Solution Approach 2:
The system dynamically manages multicast distribution trees based on authenticated receiver lists. As hosts authenticate and deauthenticate, the router dynamically adjusts the distribution tree to include or exclude specific hosts. This dynamic adaptation ensures multicast data is delivered efficiently only to currently authorized hosts, preventing energy waste on inactive or unauthorized receivers while maintaining high productivity for authorized groups.
Data Source
AI summary
A system and method for implementing controlled multicast, wherein comprises Ethernet switch 1, multicast router 2, as well as portal server 3 and AAA server 4 that connect with the multicast router, where Ethernet switch 1 connects with each hosts of user in a downlink, in an uplink connects with multicast router 5 and implements multicast switch of layer 2; portal server 3 is used as an interface for access authentication of the user, AAA server 4 is used to store configuration of user privilege for joining in a multicast group; multicast router 2 connects with multicast router 5 of other systems in the uplink, and cooperates together with AAA server 4 to completes privilege authentication for the user when he joins in the multicast group, distributes a control command according to results of the authentication, and controls forwarding of the multicast made by Ethernet switch 1. The method according to the present invention can resolve better the authenticated authorization and controlled problem of the sender and receiver joining in the multicast, and can identify the host joining in or leaving the multicast group expediently, actively stop the user's group member identification through offline without any influence on the forwarding efficiency.


