WO2006070256A1

System, method and computer program product for detecting a rogue member in a multicast group

Abstract

A system for multicasting a data packet in a multicast group includes a network entity, and a plurality of members of the multicast group. A member can notify the network entity of a rogue member of the group claiming an identity of a spoofed member of the group. In response to being notified, the network entity can distribute, to at least the members of the group other than the spoofed member, different versions of a symmetric key associated with the spoofed member. The member notifying the network entity of the rogue member can then receive a next data packet and a code for the next data packet, the code having been generated at the rogue member using a version of the symmetric key associated with the spoofed member such that the rogue member can be identified based upon the version of the symmetric key.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

28 claims: 4 independent, 24 dependent

  1. 1
    WHAT IS CLAIMED IS:1. A system for multicasting a data packet in a multicast group, the system comprising: a network entity;and a plurality of members of the multicast group, wherein at least one member is capable of notifying the network entity of a member of the group operating as a rogue member claiming an identity of another member of the group, that other member of the group being a spoofed member, wherein, in response to being notified, the network entity is capable of distributing, to at least the members of the group other than the spoofed member, different versions of a symmetric key associated with the spoofed member, and wherein the member notifying the network entity of the rogue member is also capable of receiving a next data packet and a code for the next data packet, the code having been generated at the rogue member using a version of the symmetric key associated with the spoofed member such that the rogue member is capable of being identified based upon the version of the symmetric key.
  2. 2
    A system according to Claim 1, wherein the member notifying the network entity of the rogue member is further capable of receiving a data packet and determining if the received data packet has been multicast from a member of the group operating as a rogue member, and wherein the respective member is capable of notifying the network entity when, and in response to determining that, the received data packet has been multicast from the rogue member.
  3. 3
    A system according to Claim 2, wherein the member notifying the network entity of the rogue member is capable of receiving a content packet comprising the data packet, a code for the data packet, and a member identifier, and wherein the respective member is capable of determining if the received data packet has been multicast from a rogue member by comparing the member identifier in the content packet and a member identifier associated with the member receiving the content packet, and determining that the received data packet has been multicast from a rogue member when the comparison identifies a match between the member identifier in the content packet to the member identifier associated with the member receiving the content packet.
  4. 4
    A system according to Claim 1, wherein at least one of the network entity and the member notifying the network entity of the rogue member is further capable of identifying the rogue member based upon the version of the symmetric key used to generate the code for the next data packet.
  5. 5
    A system according to Claim 4, wherein the network entity is further capable of excluding the rogue member from the multicast group after the rogue member has been identified.
  6. 6
    A system according to Claim 4, wherein in response to being notified, the network entity is also capable of distributing, to the spoofed member, all of the different versions of a symmetric key associated with the spoofed member, the network entity distributing all of the different versions of the symmetric key to thereby facilitate the respective member identifying the rogue member.
  7. 7
    A system according to Claim 1, wherein at least one member of the multicast group is capable of operating as a destination member to receive a data packet and a code for the data packet from another member of the group operating as a source member, the code having been generated at the source member using a symmetric key associated with the source member, wherein the destination member is capable of determining if the received data packet has been multicast from a member of the group operating as a rogue member, wherein the destination member is capable of multicasting a recall packet to the members of the multicast group when the received data packet has been multicast from a rogue member, and otherwise, authenticating the source member based upon the code associated with the data packet, and wherein the destination member is capable of notifying the network entity when, and in response to determining that, the received data packet has been multicast from the rogue member.
  8. 8
    A member of a multicast group including a plurality of members, wherein the member comprises:a processor capable of operating a client, wherein the client is capable of notifying a network entity of a member of the group operating as a rogue member claiming an identity of another member of the group, that other member being a spoofed member, wherein the client is capable of notifying the network entity such that the network entity distributes, to at least the members of the group other than the spoofed member, different versions of a symmetric key associated with the spoofed member, and wherein the client is capable of receiving a next data packet and a code for the next data packet, the code having been generated at the rogue member using a version of the symmetric key associated with the spoofed member such that the rogue member is capable of being identified based upon the version of the symmetric key.
  9. 9
    A member according to Claim 8, wherein the client is further capable of receiving a data packet and determining if the received data packet has been multicast from a member of the group operating as a rogue member, and wherein the client is capable of notifying the network entity when, and in response to determining that, the received data packet has been multicast from the rogue member.
  10. 10
    A member according to Claim 9, wherein the client is capable of receiving a content packet comprising the data packet, a code for the data packet, and a member identifier, and wherein the client is capable of determining if the received data packet has been multicast from a rogue member by comparing the member identifier in the content packet and a member identifier associated with the member receiving the content packet, and determining that the received data packet has been multicast from a rogue member when the comparison identifies a match between the member identifier in the content packet to the member identifier associated with the member receiving the content packet.
  11. 11
    A member according to Claim 8, wherein the client is further capable of identifying the rogue member based upon the version of the symmetric key used to generate the code for the next data packet.
  12. 12
    A member according to Claim 11, wherein the client is further capable of notifying the network entity of the identity of the rogue member such that the network entity is capable of thereafter excluding the rogue member from the multicast group .
  13. 13
    A member according to Claim 11, wherein the client is capable of receiving all of the different versions of a symmetric key associated with the spoofed member to thereby facilitate the client identifying the rogue member.
  14. 14
    A member according to Claim 8, wherein the client is further capable of receiving a data packet and a code for the data packet from a member of the group operating as a source member, the code having been generated at the source member using a symmetric key associated with the source member, wherein the client is capable of determining if the received data packet has been multicast from a member of the group operating as a rogue member, wherein the client is capable of multicasting a recall packet to the members of the multicast group when the received data packet has been multicast from a rogue member, and otherwise, authenticating the source member based upon the code associated with the data packet, and wherein the client is capable of notifying the network entity when, and in response to determining that, the received data packet has been multicast from the rogue member.
  15. 15
    A method of identifying a rogue member within a multicast group including a plurality of members, wherein, for at least one member of the group, the method comprises:notifying a network entity of a member of the group operating as a rogue member claiming an identity of another member of the group, that other member being a spoofed member, wherein notifying a network entity comprises notifying a network entity such that the network entity distributes, to at least the members of the group other than the spoofed member, different versions of a symmetric key associated with the spoofed member;and receiving a next data packet and a code for the next data packet, the code having been generated at the rogue member using a version of the symmetric key associated with the spoofed member such that the rogue member is capable of being identified based upon the version of the symmetric key.
  16. 16
    A method according to Claim 15 further comprising:receiving a data packet;and determining if the received data packet has been multicast from a member of the group operating as a rogue member, wherein notifying a network entity comprises notifying a network entity when, and in response to deteπnining that, the received data packet has been multicast from the rogue member.
  17. 17
    A method according to Claim 16, wherein receiving a data packet comprises receiving a content packet comprising a data packet, a code for the data packet, and a member identifier, and wherein determining if the received data packet has been multicast from a rogue member comprises:comparing the member identifier in the content packet and a member identifier associated with the member receiving the content packet;and determining that the received data packet has been multicast from a rogue member when the comparison identifies a match between the member identifier in the content packet to the member identifier associated with the member receiving the content packet.
  18. 18
    A method according to Claim 15 further comprising:identifying the rogue member based upon the version of the symmetric key used to generate the code for the next data packet.
  19. 19
    A method according to Claim 18 further comprising:notifying the network entity of the identity of the rogue member such that the network entity is capable of thereafter excluding the rogue member from the multicast group.
  20. 20
    A method according to Claim 18 further comprising:receiving all of the different versions of a symmetric key associated with the spoofed member to thereby facilitate identifying the rogue member.
  21. 21
    A method according to Claim 15 further comprising:receiving a data packet and a code for the data packet from a member of the group operating as a source member, the code having been generated at the source member using a symmetric key associated with the source member;determining if the received data packet has been multicast from a member of the group operating as a rogue member;multicasting a recall packet to the members of the multicast group when the received data packet has been multicast from a rogue member;and otherwise, authenticating the source member based upon the code associated with the data packet, wherein notifying a network entity comprises notifying a network entity when, and in response to determining that, the received data packet has been multicast from the rogue member.
  22. 22
    A computer program product for identifying a rogue member within a multicast group including a plurality of members, wherein the computer program product is adapted to be embodied within at least one member of the group, and wherein the computer program product comprises at least one computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions comprising:a first executable portion for notifying a network entity of a member of the group operating as a rogue member claiming an identity of another member of the group, that member being a spoofed member, wherein the first executable portion is adapted to notify the network entity such that the network entity distributes, to at least the members of the group other than the spoofed member, different versions of a symmetric key associated with the spoofed member;and a second executable portion for receiving a next data packet and a code for the next data packet, the code having been generated at the rogue member using a version of the symmetric key associated with the spoofed member such that the rogue member is capable of being identified based upon the version of the symmetric key.
  23. 23
    A computer program product according to Claim 22 further comprising:a third executable portion for receiving a data packet;and a fourth executable portion for determining if the received data packet has been multicast from a member of the group operating as a rogue member, wherein the first executable portion is adapted to notify the network entity when, and in response to the fourth executable portion determining that, the received data packet has been multicast from the rogue member.
  24. 24
    A computer program product according to Claim 23, wherein the third executable portion is adapted to receive a content packet comprising the data packet, a code for the data packet, and a member identifier, and wherein the fourth executable portion is adapted to compare the member identifier in the content packet and a member identifier associated with the member receiving the content packet, and determine that the received data packet has been multicast from a rogue member when the comparison identifies a match between the member identifier in the content packet to the member identifier associated with the member receiving the content packet.
  25. 25
    A computer program product according to Claim 22 further comprising:a third executable portion for identifying the rogue member based upon the version of the symmetric key used to generate the code for the next data packet.
  26. 26
    A computer program product according to Claim 25 further comprising:a fourth executable portion for notifying the network entity of the identity of the rogue member such that the network entity is capable of thereafter excluding the rogue member from the multicast group.
  27. 27
    A computer program product according to Claim 25 further comprising:a fourth executable portion for receiving all of the different versions of a symmetric key associated with the spoofed member to thereby facilitate the third executable portion identifying the rogue member.
  28. 28
    A computer program product according to Claim 22 further comprising:a third executable portion for receiving a data packet and a code for the data packet from a member of the group operating as a source member, the code having been generated at the source member using a symmetric key associated with the source member;a fourth executable portion for determining if the received data packet has been multicast from a member of the group operating as a rogue member;and a fifth executable portion for multicasting a recall packet to the members of the multicast group when the received data packet has been multicast from a rogue member, and otherwise, authenticating the source member based upon the code associated with the data packet, wherein the first executable portion is adapted to notify the network entity when, and in response to the fourth executable portion determining that, the received data packet has been multicast from the rogue member.
Independent claims28