JP2008060631A

Communication equipment and multicast user authentication method

Abstract

[Subject] A switch performs attestation to multicasting communication. [Solution means] The switch 30 receives the distribution request containing a group address and the address of a terminal through a port from the terminal 41*43. The switch 30 specifies VLAN ID of VLAN to which the port belongs. The switch 30 judges whether the group of the address of a terminal and VLAN ID is memorized about the group address which snooping (s) a distribution request and is contained in a distribution request with reference to an authentication table. If it memorizes, the switch 30 will memorize a group address and the port identifier of this port to a forwarding table. If the multicasting data containing a group address is received from the router 20, with reference to a forwarding table, the switch 30 will specify the port identifier corresponding to a group address, and will transmit the multicasting data to a terminal. [Selection figure] Fig. 2

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

7 claims: 2 independent, 5 dependent

  1. 1
    A virtual network having a first port for receiving multicast data and a plurality of second ports for transmitting the multicast data to a terminal, and one or more of the second ports is configured. The address of the terminal, which is previously authorized to receive the multicast data of the group in a specific virtual network, and the virtual, corresponding to the plurality of ports for being used and the group identifier that identifies the group of the multicast data. Forwarding that stores the authentication table that stores the pair with the network identifier and the port identifier of the second port for transmitting the received multicast data of the group corresponding to the group identifier of the multicast data. For the table and the distribution request of the multicast data from the terminal, the authentication process for determining whether or not the reception is permitted, and the transfer of transmitting the received multicast data to the terminal according to the forwarding table. The processing unit is provided with a processing unit that performs processing. A delivery request including the group identifier and the address of the terminal is received from the terminal via one of the second ports, and the second port is based on the second port for receiving the delivery request. Identifying the identifier of the virtual network to which the port belongs, and referring to the authentication table, the virtual identified as the address of the terminal included in the delivery request corresponding to the group identifier included in the received delivery request. It is determined whether the pair with the network identifier is stored, and if it is determined that the pair is stored in the authentication table, the group identifier included in the received delivery request and the second second that received the delivery request. A communication device that stores the port identifier of the port of the above in the forwarding table, and discards the received delivery request when it is determined that the port identifier is not stored in the authentication table. マルチキャストデータを受信するための第1のポートと、該マルチキャストデータを端末に送信するための複数の第2のポートとを有し、前記第2のポートのひとつ又は複数を含む仮想ネットワークが複数構成されるための複数のポートと、 マルチキャストデータのグループを識別するグループ識別子に対応して、該グループのマルチキャストデータを特定の仮想ネットワークにおいて受信することが予め許可された前記端末のアドレスと、該仮想ネットワークの識別子との組が記憶された認証テーブルと、 マルチキャストデータのグループ識別子に対応して、受信された該グループのマルチキャストデータを送信するための前記第2のポートのポート識別子が記憶されるフォワーディングテーブルと、 前記端末からのマルチキャストデータの配信要求に対して、受信が許可されているか否かを判断するための認証処理、及び、受信されたマルチキャストデータを前記フォワーディングテーブルに従い前記端末へ送信する転送処理を行う処理部とを備え 前記認証処理は、前記処理部が、 前記端末から、グループ識別子と前記端末のアドレスとを含む配信要求を、前記第2のポートのひとつを介して受信することと、 該配信要求を受信した前記第2のポートに基づき、該第2のポートが属する仮想ネットワークの識別子を特定することと、 前記認証テーブルを参照し、受信された配信要求に含まれるグループ識別子に対応して、配信要求に含まれる前記端末のアドレスと特定された仮想ネットワークの識別子との組が記憶されているか判断することと、 前記認証テーブルに記憶されていると判断されると、受信された配信要求に含まれるグループ識別子と、配信要求を受信した前記第2のポートのポート識別子とを、前記フォワーディングテーブルに記憶し、及び、前記認証テーブルに記憶されていないと判断されると、受信された配信要求を廃棄することを含む通信装置。
  2. 7
    A virtual network including a communication device having a first port for receiving multicast data and a plurality of second ports for transmitting the multicast data to a terminal, and including one or more of the second ports. In a network composed of a plurality of networks, a step of receiving a delivery request including a group identifier and a terminal address from a terminal, a step of specifying an identifier of a virtual network to which the port receiving the delivery request belongs, and a step of specifying multicast data. Corresponding to the group identifier that identifies the group, an authentication table that stores a set of the address of the terminal that is previously permitted to receive the multicast data of the group in a specific virtual network and the identifier of the virtual network is stored. A step to refer to and determine whether the pair of the terminal address included in the delivery request and the identified virtual network identifier is stored corresponding to the group identifier included in the received delivery request. If it is determined that it is stored in the authentication table, the group identifier included in the received delivery request and the port identifier of the port that received the delivery request are stored in the forwarding table and stored in the authentication table. A multicast user authentication method that includes a step of discarding the received delivery request and a step of sending the received multicast data to the terminal connected to the port according to the forwarding table. マルチキャストデータを受信するための第1のポートと、該マルチキャストデータを端末に送信するための複数の第2のポートとを有する通信装置を備え、前記第2のポートのひとつ又は複数を含む仮想ネットワークが複数構成されたネットワークにおいて、 端末から、グループ識別子と端末のアドレスとを含む配信要求を受信するステップと、 該配信要求を受信したポートが属する仮想ネットワークの識別子を特定するステップと、 マルチキャストデータのグループを識別するグループ識別子に対応して、該グループのマルチキャストデータを特定の仮想ネットワークにおいて受信することが予め許可された端末のアドレスと、該仮想ネットワークの識別子との組が記憶された認証テーブルを参照し、受信された配信要求に含まれるグループ識別子に対応して、配信要求に含まれる端末のアドレスと特定された仮想ネットワークの識別子との組が記憶されているか判断するステップと、 認証テーブルに記憶されていると判断されると、受信された配信要求に含まれるグループ識別子と、配信要求を受信したポートのポート識別子とを、フォワーディングテーブルに記憶し、及び、認証テーブルに記憶されていないと判断されると、受信された配信要求を廃棄するステップと、 受信されたマルチキャストデータを、フォワーディングテーブルに従いポートに接続された端末へ送信するステップとを含むマルチキャストユーザ認証方法。