DNS-Based Multicast Source Authentication for IPTV Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multicast technologies cannot effectively control or dynamically control the multicast source, leading to security hazards due to the complexity in realizing source filtering functions at user terminal devices.

Innovation Solution

A multicast security control method and device based on DNS, which involves address verification using a multicast source DNS address list and a locally maintained multicast address list, where the method parses and matches IP addresses within the multicast data message, and conducts forwarding control based on verification results to ensure secure transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If source filtering function is implemented at user terminal device, then multicast source authentication is improved, but device complexity increases

Engineering Contradiction:
Improvemulticast source authenticationVSAvoidrealization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a gateway device as an intermediary between the multicast source and user terminal devices. The gateway maintains a local multicast address list and performs source filtering, acting as a mediator that offloads the complex authentication functionality from user terminals to a centralized gateway, thus improving reliability without increasing terminal device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the source filtering function from user terminal devices and relocates it to the gateway device. By separating this complex authentication function from terminals, the system achieves reliable multicast source control while keeping terminal devices simple and easy to implement

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If dynamic control of multicast source is implemented, then security control is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway serves as an intermediary that dynamically controls multicast sources by maintaining and updating a local multicast address list. This centralized control mechanism enables dynamic security management without requiring complex implementation at each terminal device

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic control through the gateway's ability to update the multicast address list in real-time based on IGMPV3 protocol messages. The gateway can dynamically add or remove multicast addresses from the list, enabling flexible and adaptive security control without permanent complex configurations

Inventive Principle:
Principle #15Dynamics

3Reliability

If IGMPV3 source filtering protocol is used, then multicast source authentication is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvemulticast source authenticationVSAvoidprotocol implementation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The gateway acts as an intermediary that handles the complex IGMPV3 source filtering protocol operations. User terminals only need to send simple IGMPV3 join/leave messages, while the gateway performs the complex source filtering and address list management, making the system easy to operate at the terminal level

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If any multicast server transmits multicast stream, then service availability is improved, but security deteriorates

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity potential hazard
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by pre-configuring a multicast address list at the gateway that contains only authorized multicast sources. Before any multicast transmission occurs, the gateway checks the source against this pre-established list, preventing unauthorized sources from transmitting while still allowing legitimate services to operate

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3188492B1Multicast security control method and device based on DNS
Publication Date: 2020.09.09 ZTE CORP
  • EP3188492B1 patent drawingFigure 1
  • EP3188492B1 patent drawingFigure 2
  • EP3188492B1 patent drawingFigure 3~4

AI summary

The present invention relates to a multicast security control method and device based on DNS. The method includes: transmitting a DNS request message to a domain name server to acquire a multicast source DNS address list of an IPTV server; conducting address verification on a multicast data message according to the multicast source DNS address list and a locally maintained multicast address list after the multicast data message issued by the IPTV server is received; and conducting forwarding control on the multicast data message according to a verification result. The present invention can effectively carry out the authentication of the multicast source, thereby realizing the effective security control over a multicast service flow, not only ensuring the stability of the multicast service and reducing network attacks, but also simplifying a complex processing flow of the multicast source filtering, and being simple in engineering realization and deployment.