Secure multicast flow
    4.
    发明授权
    Secure multicast flow 有权
    安全组播流

    公开(公告)号:US07263610B2

    公开(公告)日:2007-08-28

    申请号:US10208562

    申请日:2002-07-30

    IPC分类号: H04L9/00 H04L9/32

    摘要: Methods, devices and systems for providing content providers with a secure way to multicast their data flows only to legitimate end users. By making a specific decision for each potentially legitimate end user requesting a specific data flow, differing subscriber profiles may be taken into account. Furthermore, end to end encryption is avoided by having a switch and/or router control the specific data flow to a specific end user. Each end user sends a request DTU to the switch and/or router asking for permission to join a multicast group. The switch and/or router extracts identification data from the request data transmission unit (DTU) and determines whether the requesting end user is cleared for the requested specific data flow. This determination may be made by sending a query DTU containing the identification data to a policy server which checks the identification data against preprogrammed criteria in its databases. The policy server then sends a response DTU to the switch and/or router confirming or denying the authenticity or legitimacy of the request based on the identification data. In the meantime, after the switch and/or router sends the query DTU to the policy server, the switch and/or router allows the specific requested data flow to proceed to the requesting end user. If, based on the response from the policy server, the request is determined to not be legitimate or authentic, the specific data flow is terminated. If the request is legitimate or authentic, then the data flow is allowed to flow uninterrupted by the switch and/or router.

    摘要翻译: 用于向内容提供商提供安全的方式,设备和系统,以仅将数据流多播到合法的最终用户。 通过对每个可能合法的最终用户请求特定数据流进行具体决定,可以考虑不同的用户简档。 此外,通过使交换机和/或路由器控制到特定最终用户的特定数据流来避免端对端加密。 每个终端用户向交换机和/或路由器发送请求DTU,要求加入组播组的权限。 交换机和/或路由器从请求数据传输单元(DTU)提取识别数据,并确定请求的最终用户是否被清除所请求的特定数据流。 可以通过将包含标识数据的查询DTU发送到根据其数据库中的预编程标准来检查标识数据的策略服务器来进行该确定。 然后,策略服务器基于识别数据向交换机和/或路由器发送响应DTU来确认或拒绝请求的真实性或合法性。 同时,在交换机和/或路由器将查询DTU发送到策略服务器之后,交换机和/或路由器允许特定请求的数据流进行到请求的最终用户。 如果根据策略服务器的响应确定请求不合法或可信,则特定的数据流将被终止。 如果请求是合法或真实的,则允许数据流由交换机和/或路由器不间断地流动。