IGMP Multicast Encryption for PON Customer Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In passive optical networks (PONs), existing multicast encryption methods fail to securely deliver multicast services to specific customers without allowing unauthorized access, as the same multicast channel can be received by all ONTs, and existing key exchange methods are inefficient for fast channel changes.

Innovation Solution

A method using the IGMP protocol to manage multicast groups and deliver access data, including churning information and service information, to ensure only entitled customers receive the requested multicast channel, with the option to encrypt access data for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multicast channels are delivered to all ONTs in the PON network, then all customers can receive the channel, but unauthorized customers can access channels they are not entitled to

Engineering Contradiction:
Improvemulticast service deliveryVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the multicast service delivery by creating separate encrypted multicast channels for different customer groups. Each channel is encrypted with a unique key that only authorized ONTs possess, allowing the system to deliver multiple multicast services simultaneously while preventing unauthorized access to each specific channel

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encryption mechanism between the OLT and ONTs. The encryption function encrypts multicast channels using channel-specific keys before transmission, and authorized ONTs use their corresponding decryption keys to access only their entitled channels. This intermediary layer prevents unauthorized ONTs from accessing channels they are not entitled to

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If existing multicast encryption methods are used, then some security is provided, but all ONTs can still receive the same multicast channel

Engineering Contradiction:
ImprovesecurityVSAvoidunauthorized reception
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by providing different encryption keys to different ONTs based on their authorization. Each ONT receives a unique decryption key corresponding to the channels it is entitled to, rather than using a common key for all ONTs. This ensures that each ONT can only decrypt and receive channels for which it has the appropriate key

Inventive Principle:
Principle #3Local quality

3Reliability

If key exchange methods are used for multicast encryption, then security is improved, but the process is too slow for fast channel changes

Engineering Contradiction:
ImprovesecurityVSAvoidzapping time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-distributing decryption keys to ONTs before they are needed for channel reception. The OLT maintains a database of authorized ONTs and their corresponding decryption keys, so when a customer requests a channel change, the key is already available at the ONT, eliminating the need for time-consuming key exchange protocols during channel switching

Inventive Principle:
Principle #10Preliminary action

4Reliability

If unicast churning is applied to multicast streams, then access control is improved, but the encryption key must be shared between OLT and ONT which reduces security

Engineering Contradiction:
Improveaccess controlVSAvoidkey sharing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the key management by assigning unique decryption keys to each ONT for each encrypted multicast channel, rather than using a single shared churning key. This segmentation allows the OLT to control access to each channel independently and revoke or update keys for individual ONTs without affecting other customers' access to other channels

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7924835B2Method and device for providing multicast services to multiple customers
Publication Date: 2011.04.12 ECI TELECOM LTD
  • US7924835B2 patent drawing
  • US7924835B2 patent drawing
  • US7924835B2 patent drawing

AI summary

A method of multicast transmission in a communication network by using IGMP protocol, to a plurality of IGMP-equipped hosts serving end customers of the network, the method comprises:—using IGMP protocol to request receipt of information along a multicast channel, by a particular end customer;—adding the end customer to a multicast group including, upon adding said particular end customer, at least one of the end customers;—delivering information along the multicast channel to the end customers belonging to the multicast group, and in response to the request, ensuring for the particular end customer access to information delivered along the multicast channel by transmitting to that end customer access data, which includes: churning information indicative of a multicast churning key and/or service information, and/or a combination thereof.