Multicast Right Control in Optical Network Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In current GPON systems, users can receive unauthorized multicast data even when joining unauthorized multicast groups, as the IGMP snooping mechanism fails to filter out such data effectively, leading to security issues and potential unauthorized access to multicast services.

Innovation Solution

Implementing a multicast right control system within the Optical Network Terminal (ONT) that utilizes a multicast right control table to determine whether received multicast data is authorized for transmission, ensuring only authorized data is forwarded to users, thereby enhancing security and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IGMP snooping mechanism is used for multicast data transmission, then multicast service delivery is enabled, but unauthorized multicast data cannot be filtered effectively

Engineering Contradiction:
Improvemulticast service deliveryVSAvoidunauthorized access prevention
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the multicast data filtering function into two parts: IGMP snooping handles basic multicast group management, while a separate multicast right control module handles authorization verification. This segmentation allows each module to specialize in its function, with the right control module maintaining a multicast right control table to verify user permissions before forwarding data, thus preventing unauthorized access while maintaining service delivery capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a multicast right control module as an intermediary between the IGMP snooping mechanism and the data forwarding process. This intermediary verifies user authorization rights against the multicast right control table before allowing data transmission, acting as a security gatekeeper that prevents unauthorized multicast data from reaching users while allowing legitimate traffic to pass through

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If all multicast data is transmitted to users, then complete service coverage is achieved, but security risks increase due to unauthorized content access

Engineering Contradiction:
Improveservice coverageVSAvoidunauthorized content access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authorization verification by checking user rights against the multicast right control table before multicast data is transmitted. This preliminary action ensures that only authorized users receive multicast data, preventing unauthorized content access while maintaining complete service coverage for all legitimate users. The verification occurs at the point of data reception at the ONT, before any forwarding to user terminals

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2530891B1A multicast flow control method, device and system in a passive optical network
Publication Date: 2013.07.31 HUAWEI TECH CO LTD
  • EP2530891B1 patent drawingFigure 1
  • EP2530891B1 patent drawingFigure 2~3
  • EP2530891B1 patent drawingFigure 4

AI summary

A multicast flow control method in passive optical network includes: the optical network terminal receiving multicasting data from the optical line terminal, judging whether or not the received multicast data satisfies multicast purview controlled conditions, if yes then transmitting the multicast data to user side, else discarding the multicast data. Meanwhile the corresponding optical network terminal, optical line terminal and the system which composites of the optical network terminal, optical line terminal and optical hand out network could be used for realizing said method. The present invention could prevent the optical network terminal from receiving illegal multicast data and increasing the multicast security of the whole passive optical network system.