Group Based Multicast Access Control via SGT and SXP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network multicasting technologies lack effective mechanisms to securely restrict multicast traffic between specific user or device groups, leading to potential unauthorized access and data security breaches.
Innovation Solution
Implementing a Scalable Group Tag (SGT) system and SGT Exchange Protocol (SXP) to manage and filter multicast traffic, allowing access only to predetermined user or device groups, utilizing protocols like PIM and IGMPv3/v2 to ensure secure content delivery within defined user/device groups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional multicast technologies are used, then multicast traffic can be delivered across the network, but unauthorized access and security breaches occur due to lack of access control mechanisms
Solution Approach 1:
The patent introduces an intermediary access control mechanism that mediates between multicast sources and receivers. This intermediary layer validates receiver credentials and authorization tokens before allowing multicast traffic delivery, thereby enhancing security without requiring fundamental changes to the multicast infrastructure itself.
Solution Approach 2:
The access control system is segmented into distinct functional components: token generation modules, validation modules, and enforcement points distributed across network devices. This segmentation allows the complex security function to be implemented in manageable parts that can be deployed incrementally across the network infrastructure.
2Reliability
If access control mechanisms are implemented to restrict multicast traffic, then data security is improved, but the system complexity increases
Solution Approach 1:
The access control mechanism is designed to be universal and multi-functional, working across different multicast protocols and network device types. By creating a protocol-agnostic framework that can be implemented on various network devices (routers, switches, firewalls), the system achieves comprehensive security coverage without requiring device-specific complex implementations.
Solution Approach 2:
Instead of implementing complex access control logic in every network device, the patent uses a centralized policy server that generates and distributes access control rules to multiple enforcement points. This copying approach allows a single source of truth for security policies to be replicated across the network, reducing overall system complexity while maintaining effective access control.
3Reliability
If multicast traffic is restricted to specific user groups, then unauthorized access is prevented, but the complexity of managing group permissions increases
Solution Approach 1:
The system implements self-service capabilities where receivers can autonomously obtain authorization tokens by presenting valid credentials to the policy server. This automated credential verification and token issuance process eliminates the need for manual permission management, reducing operational complexity while maintaining strong authorization security.
Solution Approach 2:
The access control system incorporates feedback mechanisms where the policy server continuously monitors multicast traffic patterns and authorization requests. Based on this feedback, the system can dynamically adjust access policies and provide real-time information to administrators about group membership and authorization status, simplifying permission management through automated monitoring and reporting.
Data Source
AI summary
Group based multicasts may be provided. First, a request may be received. The request may comprise a receiver tag, a request source identifier, and a request multicast group identifier. Next, a source tag corresponding to the request source identifier may be obtained and then it may be determined that a group corresponding to the receiver tag is allowed to access content from a source corresponding to the obtained source tag. In response to determining that the group corresponding to the receiver tag is allowed to access content from the source corresponding to the obtained source tag, content may be received from the source at a multicast group corresponding to the request multicast group identifier. The content may then be forwarded to a receiver corresponding to the request.


