DNS-Based Multicast Source Authentication for IPTV Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multicast technologies cannot effectively control or dynamically control the multicast source, leading to security hazards due to the complexity in realizing source filtering functions at user terminal devices.
Innovation Solution
A multicast security control method and device based on DNS, which involves address verification using a multicast source DNS address list and a locally maintained multicast address list, where the method parses and matches IP addresses within the multicast data message, and conducts forwarding control based on verification results to ensure secure transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If source filtering function is implemented at user terminal device, then multicast source authentication is improved, but device complexity increases
Solution Approach 1:
The patent introduces a gateway device as an intermediary between the multicast source and user terminal devices. The gateway maintains a local multicast address list and performs source filtering, acting as a mediator that offloads the complex authentication functionality from user terminals to a centralized gateway, thus improving reliability without increasing terminal device complexity
Solution Approach 2:
The patent extracts the source filtering function from user terminal devices and relocates it to the gateway device. By separating this complex authentication function from terminals, the system achieves reliable multicast source control while keeping terminal devices simple and easy to implement
2Reliability
If dynamic control of multicast source is implemented, then security control is improved, but device complexity increases
Solution Approach 1:
The gateway serves as an intermediary that dynamically controls multicast sources by maintaining and updating a local multicast address list. This centralized control mechanism enables dynamic security management without requiring complex implementation at each terminal device
Solution Approach 2:
The patent implements dynamic control through the gateway's ability to update the multicast address list in real-time based on IGMPV3 protocol messages. The gateway can dynamically add or remove multicast addresses from the list, enabling flexible and adaptive security control without permanent complex configurations
3Reliability
If IGMPV3 source filtering protocol is used, then multicast source authentication is improved, but ease of operation deteriorates
Solution Approach 1:
The gateway acts as an intermediary that handles the complex IGMPV3 source filtering protocol operations. User terminals only need to send simple IGMPV3 join/leave messages, while the gateway performs the complex source filtering and address list management, making the system easy to operate at the terminal level
4Adaptability or versatility
If any multicast server transmits multicast stream, then service availability is improved, but security deteriorates
Solution Approach 1:
The patent applies preliminary anti-action by pre-configuring a multicast address list at the gateway that contains only authorized multicast sources. Before any multicast transmission occurs, the gateway checks the source against this pre-established list, preventing unauthorized sources from transmitting while still allowing legitimate services to operate
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
The present invention relates to a multicast security control method and device based on DNS. The method includes: transmitting a DNS request message to a domain name server to acquire a multicast source DNS address list of an IPTV server; conducting address verification on a multicast data message according to the multicast source DNS address list and a locally maintained multicast address list after the multicast data message issued by the IPTV server is received; and conducting forwarding control on the multicast data message according to a verification result. The present invention can effectively carry out the authentication of the multicast source, thereby realizing the effective security control over a multicast service flow, not only ensuring the stability of the multicast service and reducing network attacks, but also simplifying a complex processing flow of the multicast source filtering, and being simple in engineering realization and deployment.