IP Library Granted Patent US 8,037,303
Granted Patent B2
US 8,037,303 · App. 11/374,645 · Granted Oct 11, 2011

System and method for providing secure multicasting across virtual private networks

Assignee: Cisco Technology, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,037,303
App. No.
11/374,645
Granted
Oct 11, 2011
Kind
B2
Abstract

A method is provided for securely transmitting multicast data across an unsecured public network. Such a method includes receiving a join message identifying at least one private multicast group; mapping the private multicast group to a public multicast group; generating a membership report specifying the public multicast group; and sending the membership report to the unsecured network. Additionally, the method may further comprise creating a secure tunnel through the unsecured network to a network element coupled; generating an encrypted control message specifying the private multicast group; and sending the encrypted control message through the secure tunnel to the network element.

Claims (53)

1. A method for providing a secure multicast of data across an unsecured network, the method comprising:

receiving, at an IPSec virtual private network device (IVD), a join message identifying at least one private multicast group;

identifying, by the IVD, a public multicast group of the unsecured network that is mapped to the private multicast group;

generating, by the IVD, a membership report specifying the public multicast group;

inserting a public IVD address of the IVD into a source field of the membership report;

sending the membership report to the unsecured network;

creating an IPSec tunnel through the unsecured network to a network element;

generating an IPSec encrypted control message specifying the private multicast group; and

sending the encrypted control message through the tunnel to allow the network element to decrypt the encrypted control message and send the decrypted control message to another network element.

2. The method of claim 1 , wherein the join message is a control message.

3. The method of claim 2 , wherein the control message is a Protocol Independent Multicast control message.

4. The method of claim 1 , wherein the join message is a membership report.

5. The method of claim 4 , wherein the membership report is an Internet Group Message Protocol membership report.

6. The method of claim 1 , wherein the network element is an encryption device.

7. The method of claim 1 , further comprising:

receiving the encrypted control message from the secure tunnel;

decrypting the encrypted control message; and

sending the decrypted control message to a second network element.

8. A system for securely transmitting multicast data across a public network, the system comprising:

a first encryptor network element comprising an IPSec virtual private network device (IVD) and operable to

receive a join message from a first network element, the join message identifying at least one private multicast group,

identify a public multicast group of the unsecured network that is mapped to the private multicast group,

generate a membership report specifying the public multicast group,

send the membership report to the public network,

generate an IPSec encrypted control message specifying the private multicast group,

insert a public IVD address of the IVD into a source field of the membership report,

send the encrypted control message through the secure tunnel to the second encryptor network element to allow the second encryptor network element to decrypt the encrypted control message and send the decrypted control message to another network element.

9. The system of claim 8 , wherein the first network element is selected from a group consisting of:

a router;

a switch;

a gateway;

a bridge;

a load-balancer; and

a firewall.

10. The system of claim 8 , wherein the join message is a control message.

11. The system of claim 10 , wherein the control message is a Protocol Independent Multicast control message.

12. The system of claim 8 , wherein the first network element is a multicast receiver.

13. The system of claim 12 , wherein the join message is a membership report.

14. The system of claim 13 , wherein the membership report is an Internet Group Message Protocol membership report.

15. A non-transitory computer readable medium storing software for securely transmitting multicast data across a public network, the software being embodied in the non-transitory computer readable medium and comprising code such that when executed is operable to:

receive a join message identifying at least one private multicast group;

identify a public multicast group of the unsecured network that is mapped to the private multicast group;

generate a membership report specifying the public multicast group;

insert a public IVD address of the IVD into a source field of the membership report;

send the membership report to the unsecured network;

create an IPSec tunnel through the unsecured network to a network element;

generate an IPSec encrypted control message specifying the private multicast group; and

send the encrypted control message through the tunnel to allow the network element to decrypt the encrypted control message and send the decrypted control message to another network element.

16. The non-transitory computer readable medium of claim 15 , wherein the join message is a control message.

17. The non-transitory computer readable Medium of claim 16 , wherein the control message is a Protocol Independent Multicast control message.

18. The non-transitory computer readable medium of claim 15 , wherein the join message is a membership report.

19. The non-transitory computer readable medium of claim 18 , wherein the membership report is an Internet Group Message Protocol membership report.

20. The non-transitory computer readable medium of claim 15 , wherein the network element is an encryption device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2006
From: WILLIAMSON, GARY BEAU
To: CISCO TECHNOLOGY, INC.
Reel/Frame 017687/0259 →
Continuity (1)
Related Publication 20070214359A1 · Sep 13, 2007