US20050138369A1

Secure transport of multicast traffic

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Secure tunneled multicast transmission and reception through a network is provided. A join request may be received from a second tunnel endpoint, the join request indicating a multicast group to be joined. Group keys may be transmitted to the second tunnel endpoint, where the group keys are based at least on the multicast group. A packet received at the first tunnel endpoint may be cryptographically processed to generate an encapsulated payload. A header may be appended to the encapsulated payload to form an encapsulated packet, wherein the header includes information associated with the second tunnel endpoint. A tunnel may be established between the first tunnel endpoint and the second tunnel endpoint based on the appended header. The encapsulated packet may be transmitted through the tunnel to the second tunnel endpoint. The second tunnel endpoint may receive the encapsulated packet. Cryptographic processing of the encapsulated packet may reveal the packet having a second header. The packet may then be forwarded on an interface toward at least one multicast recipient identified in the second header.

US20050138369A1, drawing sheet 1
Sheet 1 of 10

Term

0.7 yearsto projected expiry

Projected expiry 19 May 2027, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

30 claims: 5 independent, 25 dependent

  1. 1
    Broadest claimClaim Score 67, broad(NHIP)A method of providing secure multicast transmission through a network, comprising:receiving a first join request from a first downstream router, the join request indicating a multicast group to be joined;transmitting group keys to the first downstream router, wherein the group keys are based on at least the multicast group;cryptographically processing a first packet using the group keys to generate an encapsulated payload;appending a first header to the encapsulated payload to form a first encapsulated packet;establishing a tunnel with the first downstream router based on the appended first header;and transmitting the first encapsulated packet through the tunnel to the first downstream router.
  2. 18
    A method of receiving a multicast transmission through a network, the method comprising:transmitting a join request to a forwarding router via a unicast tunnel established between the forwarding router and a first downstream router, the join request indicating a multicast group to be joined;receiving group keys in response to the transmitted join request, the group keys based at least on the multicast group;establishing a group keying tunnel between the forwarding router and the first downstream router;receiving an encapsulated packet via the group keying tunnel;cryptographically processing the encapsulated packet using the group keys to reveal a multicast packet including an Internet Protocol (IP) header having a multicast destination address;and forwarding the multicast packet on an interface toward at least one multicast recipient corresponding to the multicast destination address.
  3. 24
    A device for receiving and transmitting packets within a computer network, the device configured to:receive a first join request from a first downstream router via a first tunnel established between the first downstream router and a forwarding router, the first join request indicating a multicast group to be joined;transmit group keys based on at least the multicast group to the first downstream router via the first tunnel;cryptographically process a first packet using the group keys to generate an encapsulated payload;append a first header to the encapsulated payload to form a first encapsulated packet, wherein the first header includes information associated with the first downstream router;establish a second tunnel with the first downstream router based on the appended first header;and transmit the first encapsulated packet through the second tunnel to the first downstream router.
  4. 27
    A device for receiving and transmitting packets within a computer network, the device configured to:receive a first join request from a first downstream router via a first unicast tunnel established between the first downstream router and a forwarding router;receive a second join request from a second downstream router via a second unicast tunnel established between the second downstream router and the forwarding router, wherein the first and second join request indicate a multicast group to be joined;generate group keys based at least on the multicast group;transmit the group keys to the first downstream router via the first unicast tunnel;transmit the group keys to the second downstream router via the second unicast tunnel;cryptographically process a first multicast packet using the group keys to generate an encapsulated payload;append a first unicast Internet Protocol (IP) header to the encapsulated payload to form a first encapsulated packet, wherein the first unicast IP header is associated with the first downstream router;establish a first group keying tunnel with the first downstream router based on the appended first unicast IP header;copy the encapsulated payload;append a second unicast Internet Protocol (IP) header to the copied encapsulated payload to form a second encapsulated packet, wherein the second unicast IP header is associated with the second downstream router;establish a second group keying tunnel with the second downstream router based on the appended second unicast IP header;transmit the first encapsulated packet through the first group keying tunnel to the first downstream router;and transmit the second encapsulated packet through the second group keying tunnel to the second downstream router.
  5. 29
    A device for receiving and transmitting packets within a computer network, comprising:means for receiving a join request from a second tunnel endpoint via a first tunnel established between the first tunnel endpoint and a second tunnel endpoint, the join request indicating a multicast group to be joined;means for transmitting group keys based on at least the multicast group to the second tunnel endpoint via the first tunnel;means for cryptographically processing a first packet using the group keys to generate an encapsulated payload;means for appending a header to the encapsulated payload to form an encapsulated packet, wherein the header includes information associated with the second tunnel endpoint;means for establishing a second tunnel between the first tunnel endpoint and the second tunnel endpoint based on the appended header;and means for transmitting the encapsulated packet through the second tunnel to the second tunnel endpoint.