Group Based Multicast Access Control via SGT and SXP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network multicasting technologies lack effective mechanisms to securely restrict multicast traffic between specific user or device groups, leading to potential unauthorized access and data security breaches.

Innovation Solution

Implementing a Scalable Group Tag (SGT) system and SGT Exchange Protocol (SXP) to manage and filter multicast traffic, allowing access only to predetermined user or device groups, utilizing protocols like PIM and IGMPv3/v2 to ensure secure content delivery within defined user/device groups.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional multicast technologies are used, then multicast traffic can be delivered across the network, but unauthorized access and security breaches occur due to lack of access control mechanisms

Engineering Contradiction:
Improvedata securityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary access control mechanism that mediates between multicast sources and receivers. This intermediary layer validates receiver credentials and authorization tokens before allowing multicast traffic delivery, thereby enhancing security without requiring fundamental changes to the multicast infrastructure itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control system is segmented into distinct functional components: token generation modules, validation modules, and enforcement points distributed across network devices. This segmentation allows the complex security function to be implemented in manageable parts that can be deployed incrementally across the network infrastructure.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control mechanisms are implemented to restrict multicast traffic, then data security is improved, but the system complexity increases

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control mechanism is designed to be universal and multi-functional, working across different multicast protocols and network device types. By creating a protocol-agnostic framework that can be implemented on various network devices (routers, switches, firewalls), the system achieves comprehensive security coverage without requiring device-specific complex implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of implementing complex access control logic in every network device, the patent uses a centralized policy server that generates and distributes access control rules to multiple enforcement points. This copying approach allows a single source of truth for security policies to be replicated across the network, reducing overall system complexity while maintaining effective access control.

Inventive Principle:
Principle #26Copying

3Reliability

If multicast traffic is restricted to specific user groups, then unauthorized access is prevented, but the complexity of managing group permissions increases

Engineering Contradiction:
Improveauthorization securityVSAvoidpermission management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service capabilities where receivers can autonomously obtain authorization tokens by presenting valid credentials to the policy server. This automated credential verification and token issuance process eliminates the need for manual permission management, reducing operational complexity while maintaining strong authorization security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access control system incorporates feedback mechanisms where the policy server continuously monitors multicast traffic patterns and authorization requests. Based on this feedback, the system can dynamically adjust access policies and provide real-time information to administrators about group membership and authorization status, simplifying permission management through automated monitoring and reporting.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20180255002A1Group Based Multicast in Networks
Publication Date: 2018.09.06 CISCO TECHNOLOGY INC
  • US20180255002A1 patent drawing
  • US20180255002A1 patent drawing
  • US20180255002A1 patent drawing

AI summary

Group based multicasts may be provided. First, a request may be received. The request may comprise a receiver tag, a request source identifier, and a request multicast group identifier. Next, a source tag corresponding to the request source identifier may be obtained and then it may be determined that a group corresponding to the receiver tag is allowed to access content from a source corresponding to the obtained source tag. In response to determining that the group corresponding to the receiver tag is allowed to access content from the source corresponding to the obtained source tag, content may be received from the source at a multicast group corresponding to the request multicast group identifier. The content may then be forwarded to a receiver corresponding to the request.