Multicast Right Control in Optical Network Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In current GPON systems, users can receive unauthorized multicast data even when joining unauthorized multicast groups, as the IGMP snooping mechanism fails to filter out such data effectively, leading to security issues and potential unauthorized access to multicast services.
Innovation Solution
Implementing a multicast right control system within the Optical Network Terminal (ONT) that utilizes a multicast right control table to determine whether received multicast data is authorized for transmission, ensuring only authorized data is forwarded to users, thereby enhancing security and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IGMP snooping mechanism is used for multicast data transmission, then multicast service delivery is enabled, but unauthorized multicast data cannot be filtered effectively
Solution Approach 1:
The patent segments the multicast data filtering function into two parts: IGMP snooping handles basic multicast group management, while a separate multicast right control module handles authorization verification. This segmentation allows each module to specialize in its function, with the right control module maintaining a multicast right control table to verify user permissions before forwarding data, thus preventing unauthorized access while maintaining service delivery capability
Solution Approach 2:
The patent introduces a multicast right control module as an intermediary between the IGMP snooping mechanism and the data forwarding process. This intermediary verifies user authorization rights against the multicast right control table before allowing data transmission, acting as a security gatekeeper that prevents unauthorized multicast data from reaching users while allowing legitimate traffic to pass through
2Productivity
If all multicast data is transmitted to users, then complete service coverage is achieved, but security risks increase due to unauthorized content access
Solution Approach 1:
The patent implements preliminary authorization verification by checking user rights against the multicast right control table before multicast data is transmitted. This preliminary action ensures that only authorized users receive multicast data, preventing unauthorized content access while maintaining complete service coverage for all legitimate users. The verification occurs at the point of data reception at the ONT, before any forwarding to user terminals
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A multicast flow control method in passive optical network includes: the optical network terminal receiving multicasting data from the optical line terminal, judging whether or not the received multicast data satisfies multicast purview controlled conditions, if yes then transmitting the multicast data to user side, else discarding the multicast data. Meanwhile the corresponding optical network terminal, optical line terminal and the system which composites of the optical network terminal, optical line terminal and optical hand out network could be used for realizing said method. The present invention could prevent the optical network terminal from receiving illegal multicast data and increasing the multicast security of the whole passive optical network system.