Subnet Scoped Multicast Encapsulation via IP Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data networks face challenges in efficiently routing subnet scoped multicast and broadcast traffic due to vulnerabilities in IPv4/IPv6 protocols, which are prone to attacks and require complex router configuration, and traditional Ethernet multicast/flooding functions depend on all hosts being in the same broadcast domain.
Innovation Solution
The method involves encapsulating data packets with headers and routing them over a distribution tree, using point-to-point unicast tunnels and multicast distribution trees to efficiently forward subnet scoped multicast or broadcast packets, while maintaining security and scalability by separating management and operational IP addresses and using protocols like OSPF and EIGRP for route propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IPv4/IPv6 protocols are used for communication at end nodes, then communication paths can be established, but the system becomes vulnerable to spoofing, man-in-the-middle, and denial of service attacks
Solution Approach 1:
The patent introduces a tunneling mechanism as an intermediary layer between end nodes. Data packets are encapsulated within tunnel packets that traverse the network through intermediate routing devices. This intermediary tunneling structure protects the inner data packets from direct exposure to network threats, allowing communication path establishment while mitigating security vulnerabilities like spoofing and man-in-the-middle attacks.
2Object-affected harmful factors
If routers are configured to block attacks, then security is improved, but the configuration process becomes very involved and complex
Solution Approach 1:
The tunneling mechanism enables self-service security by automatically encapsulating data packets in protective tunnel packets without requiring manual router configuration for attack blocking. The routing devices simply forward the encapsulated packets based on standard routing protocols, and the security protection is inherently provided by the tunneling structure itself, eliminating the need for complex security configuration.
3Productivity
If Ethernet multicast/flooding functions are used, then subnet scoped multicast traffic can be distributed, but all host devices must be attached to the same broadcast domain or VLAN
Solution Approach 1:
The patent transitions from layer 2 Ethernet multicast/flooding to layer 3 IP-based tunneling with distribution trees. Instead of requiring all hosts to be in the same broadcast domain (layer 2 constraint), the solution uses IP routing and encapsulation to create virtual distribution trees that span multiple subnets and VLANs. This dimensional shift from layer 2 to layer 3 enables multicast traffic distribution across diverse network topologies without the broadcast domain constraint.
4Object-affected harmful factors
If layer 3 routing is used to improve security, then attack blocking is enhanced, but routing protocol configuration and tuning becomes very involved
Solution Approach 1:
The tunneling mechanism provides universal security protection that works across different routing protocols and network configurations without requiring protocol-specific security configuration. The encapsulation approach is protocol-agnostic, allowing the same tunneling mechanism to protect traffic regardless of whether OSPF, EIGRP, or other routing protocols are used, thereby enhancing attack blocking while avoiding the need for complex routing protocol security tuning.
Data Source
AI summary
In one embodiment, a subnet-scoped multicast packet is received on an interface of a forwarding device that is connected to a host device of a subnet of a forwarding domain. The received subnet-scoped multicast packet is transmitted from one or more other interfaces of the forwarding device that are connected to one or more other host devices of the subnet. The received subnet-scoped multicast packet is also encapsulated with an additional header. The encapsulated subnet-scoped multicast packet is forwarded from the forwarding device to an intermediate router which routes the encapsulated subnet-scoped multicast packet to one or more other forwarding devices configured to decapsulate the encapsulated subnet-scoped multicast packet and transmit the decapsulated subnet-scoped multicast packet to one or more connected host devices of an additional portion of the subnet.


