IPSec Multicast Gateway Address Modification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing multicast satellite transmissions are limited by the requirement for unicast point-to-point transmissions, preventing the implementation of IPSec protocol for encrypting communications sent to multiple receivers.

Innovation Solution

The system modifies multicast communication address information to appear as unicast, allowing receivers to decrypt IPSec-encrypted multicast communications or forward them in their encrypted state, using a keyserver and gateway for IPSec key assignment and encryption, and employing markup language files for secure key communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSec protocol is used to encrypt multicast satellite transmissions, then security and access control are improved, but the requirement for unicast point-to-point transmissions prevents efficient multicast distribution

Engineering Contradiction:
ImprovesecurityVSAvoidmulticast distribution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a gateway as an intermediary device between the multicast source and receivers. The gateway receives multicast traffic, modifies the address information to appear as unicast, and forwards it to individual receivers. This mediator enables IPSec encryption to work with multicast by converting the multicast stream into unicast-like packets that can be securely encrypted and delivered to authorized receivers only.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multicast transmissions are encrypted using traditional scrambling algorithms, then access control is achieved, but the transmissions cannot be forwarded in encrypted state and require specialized hardware at receivers

Engineering Contradiction:
Improveaccess controlVSAvoidreceiver hardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the fundamental parameter of how encryption is applied - instead of using traditional scrambling algorithms that require specialized receiver hardware, the system uses IPSec protocol that modifies packet address information and applies encryption at the network layer. This parameter change allows standard network hardware to handle the encrypted traffic and enables forwarding capability while maintaining access control.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If unicast point-to-point transmissions are used for IPSec encryption, then security between two devices is achieved, but the protocol cannot encrypt multicast transmissions sent to multiple receivers

Engineering Contradiction:
ImprovesecurityVSAvoidmulticast support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the multicast transmission process into two phases: first, the gateway receives the original multicast packet and segments it into individual unicast-like packets for each authorized receiver; second, each segment is independently modified with the receiver's address information and encrypted using IPSec. This segmentation allows the versatile multicast protocol to maintain security by treating each receiver individually while still distributing content to multiple devices.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8176317B2System and method for multicasting IPSec protected communications
Publication Date: 2012.05.08 HUGHES NETWORK SYST
  • US8176317B2 patent drawing
  • US8176317B2 patent drawing
  • US8176317B2 patent drawing

AI summary

A system and method is provided which allows multicast communications encrypted using IPSec protocol to be received by receivers in a network. In order to allow the receivers to receive the encrypted multicast communication, the address information of the received multicast communication is modified to appear as a unicast communication being transmitted directly to the address of the receiver, such that the receiver may then decrypt the received multicast communication using IPSec decryption capabilities or may, alternatively, forward the received multicast communication in its encrypted state to other devices. The system and method further provide IPSec encryption key delivery to the receiver using an encrypted markup language file. Multiple keys may also be generated for a given IP address of a receiver with each key being generated for a particular multicasting hierarchical classification.