IGMP Multicast Encryption for PON Customer Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In passive optical networks (PONs), existing multicast encryption methods fail to securely deliver multicast services to specific customers without allowing unauthorized access, as the same multicast channel can be received by all ONTs, and existing key exchange methods are inefficient for fast channel changes.
Innovation Solution
A method using the IGMP protocol to manage multicast groups and deliver access data, including churning information and service information, to ensure only entitled customers receive the requested multicast channel, with the option to encrypt access data for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multicast channels are delivered to all ONTs in the PON network, then all customers can receive the channel, but unauthorized customers can access channels they are not entitled to
Solution Approach 1:
The patent segments the multicast service delivery by creating separate encrypted multicast channels for different customer groups. Each channel is encrypted with a unique key that only authorized ONTs possess, allowing the system to deliver multiple multicast services simultaneously while preventing unauthorized access to each specific channel
Solution Approach 2:
The patent introduces an intermediary encryption mechanism between the OLT and ONTs. The encryption function encrypts multicast channels using channel-specific keys before transmission, and authorized ONTs use their corresponding decryption keys to access only their entitled channels. This intermediary layer prevents unauthorized ONTs from accessing channels they are not entitled to
2Reliability
If existing multicast encryption methods are used, then some security is provided, but all ONTs can still receive the same multicast channel
Solution Approach 1:
The patent applies local quality by providing different encryption keys to different ONTs based on their authorization. Each ONT receives a unique decryption key corresponding to the channels it is entitled to, rather than using a common key for all ONTs. This ensures that each ONT can only decrypt and receive channels for which it has the appropriate key
3Reliability
If key exchange methods are used for multicast encryption, then security is improved, but the process is too slow for fast channel changes
Solution Approach 1:
The patent implements preliminary action by pre-distributing decryption keys to ONTs before they are needed for channel reception. The OLT maintains a database of authorized ONTs and their corresponding decryption keys, so when a customer requests a channel change, the key is already available at the ONT, eliminating the need for time-consuming key exchange protocols during channel switching
4Reliability
If unicast churning is applied to multicast streams, then access control is improved, but the encryption key must be shared between OLT and ONT which reduces security
Solution Approach 1:
The patent segments the key management by assigning unique decryption keys to each ONT for each encrypted multicast channel, rather than using a single shared churning key. This segmentation allows the OLT to control access to each channel independently and revoke or update keys for individual ONTs without affecting other customers' access to other channels
Data Source
AI summary
A method of multicast transmission in a communication network by using IGMP protocol, to a plurality of IGMP-equipped hosts serving end customers of the network, the method comprises:—using IGMP protocol to request receipt of information along a multicast channel, by a particular end customer;—adding the end customer to a multicast group including, upon adding said particular end customer, at least one of the end customers;—delivering information along the multicast channel to the end customers belonging to the multicast group, and in response to the request, ensuring for the particular end customer access to information delivered along the multicast channel by transmitting to that end customer access data, which includes: churning information indicative of a multicast churning key and/or service information, and/or a combination thereof.


