Controlled Multicast System Using AAA Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IP multicast systems lack effective methods for controlling host access and ensuring authorized reception, leading to security concerns and inefficiencies in managing multicast groups, particularly in shared networks where unauthorized hosts can receive multicast data.

Innovation Solution

A controlled multicast system incorporating an Ethernet switch, multicast router, portal server, and AAA server, utilizing IGMP V2, RADIUS+, and HGMP protocols for user authentication, privilege management, and multicast forwarding control, ensuring only authorized users can join and receive multicast data, with active management of multicast forwarding trees.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If any host can join any multicast group without limitation, then the ease of operation is improved, but the security and control capability deteriorates

Engineering Contradiction:
Improveease of joining multicast groupVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a multicast router as an intermediary between hosts and multicast groups. The router acts as a mediator that receives join requests from hosts, authenticates them against authorized receiver lists, and selectively forwards multicast data only to authenticated hosts. This resolves the contradiction by maintaining easy host operation while implementing security control through the intermediary router.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and authorization before hosts can receive multicast data. The system pre-establishes authorized receiver lists at the router, and hosts must present valid credentials before being added to the distribution tree. This preliminary action ensures security is enforced before data transmission begins, resolving the contradiction between ease of operation and security control.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication protocols like IGMP extension and RADIUS are implemented, then the security is improved, but the device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication functions into the multicast router itself. Rather than requiring separate authentication servers and complex protocol implementations at each host, the router consolidates authentication, authorization, and account management capabilities. This merging reduces overall system complexity while maintaining security, as the router becomes a single point of control for all multicast access decisions.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The multicast router is designed with multi-functionality, serving both as a traditional multicast forwarding device and as an authentication/authorization server. By making the router universal - capable of handling both data forwarding and security management - the system avoids adding separate specialized devices, thereby improving security without proportionally increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If multicast data is forwarded to all hosts in a shared network, then the productivity is improved, but the loss of energy and resources increases

Engineering Contradiction:
Improvedata delivery efficiencyVSAvoidnetwork resource waste
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent implements local quality control by maintaining separate authorized receiver lists at the multicast router for different network segments or VLANs. The router selectively forwards multicast data only to hosts that are both authenticated and appropriate for receiving that specific data stream. This local quality filtering prevents unnecessary data transmission to unauthorized or inappropriate hosts, reducing energy waste while maintaining efficient delivery to authorized receivers.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically manages multicast distribution trees based on authenticated receiver lists. As hosts authenticate and deauthenticate, the router dynamically adjusts the distribution tree to include or exclude specific hosts. This dynamic adaptation ensures multicast data is delivered efficiently only to currently authorized hosts, preventing energy waste on inactive or unauthorized receivers while maintaining high productivity for authorized groups.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7680884B2System and implementation method of controlled multicast
Publication Date: 2010.03.16 CHENGDU HUAWEI TECH CO LTD
  • US7680884B2 patent drawing
  • US7680884B2 patent drawing
  • US7680884B2 patent drawing

AI summary

A system and method for implementing controlled multicast, wherein comprises Ethernet switch 1, multicast router 2, as well as portal server 3 and AAA server 4 that connect with the multicast router, where Ethernet switch 1 connects with each hosts of user in a downlink, in an uplink connects with multicast router 5 and implements multicast switch of layer 2; portal server 3 is used as an interface for access authentication of the user, AAA server 4 is used to store configuration of user privilege for joining in a multicast group; multicast router 2 connects with multicast router 5 of other systems in the uplink, and cooperates together with AAA server 4 to completes privilege authentication for the user when he joins in the multicast group, distributes a control command according to results of the authentication, and controls forwarding of the multicast made by Ethernet switch 1. The method according to the present invention can resolve better the authenticated authorization and controlled problem of the sender and receiver joining in the multicast, and can identify the host joining in or leaving the multicast group expediently, actively stop the user's group member identification through offline without any influence on the forwarding efficiency.