State Key Laboratory of Networking and Switching Technology, Beijing University of Posts and Telecommunications, Beijing 100876, China.
Department of Computer Science and Technology, Tsinghua University, Beijing 100084, China.
Sensors (Basel). 2018 Jul 3;18(7):2135. doi: 10.3390/s18072135.
With the rapid increase of network users and services, the breadth and depth of Internet have greatly changed. The mismatch between current network requirements and original network architecture design has spurred the evolution or revolution of Internet to remedy this gap. Lots of research projects on future network architecture have been launched, in which Universal Identifier Network (UIN) architecture that is based on the identifier/location separation, access/core separation and control/forwarding separation can provide better mobility, security and reliability. On the other hand, the demand of group communication has increased due to the fine-grained network services and successive booming of new applications such as IoT (Internet of Things). Most of current multicast schemes are based on the open group model with open group membership (multicast only care the multicast group state, not the group member) and open access to send/receive multicast data, which are beneficial to multicast routing for its simplification. However, the open group membership makes the group member management difficult to be realized, and open access may result in lots of security vulnerabilities such as Denial of service (DoS), eavesdropping and masquerading, which make deployment more difficult. Therefore, in this paper we propose a Central-Controllable and Secure Multicast (CCSM) system based on the UIN architecture, and redesign the multicast service procedures including registration, join/leave, multicast routing construction and update with objective to achieve better mobility support, security, scalability and controllable. More specifically, we design a new group management scheme to perform the multicast members join/leave with authentication and a central-controllable multicast routing scheme to provide a secure way to set up multicast entries on routers. The CCSM inherits the characteristics of UIN in terms of mobility and security, and it can provide the centralized multicast routing computation and distributes the multicast routing into forwarders. We compare CCSM with Protocol Independent Multicast-Sparse Mode (PIM-SM), and the results show that CCSM reduces the multicast join delay, and performs better than PIM-SM in term of reconstruction cost under low multicast density.
随着网络用户和服务的快速增长,互联网的广度和深度发生了巨大变化。当前网络需求与原始网络架构设计之间的不匹配促使互联网进行演进或革命以弥补这一差距。许多关于未来网络架构的研究项目已经启动,其中基于标识符/位置分离、访问/核心分离和控制/转发分离的通用标识符网络 (UIN) 架构可以提供更好的移动性、安全性和可靠性。另一方面,由于细粒度的网络服务以及物联网 (IoT) 等新应用的连续蓬勃发展,对组通信的需求也有所增加。当前的大多数多播方案都是基于开放组模型的,该模型具有开放的组成员(多播仅关心多播组状态,而不关心组成员)和开放的访问权限来发送/接收多播数据,这有利于简化多播路由。然而,开放的组成员使得组成员管理难以实现,并且开放的访问可能会导致许多安全漏洞,例如拒绝服务 (DoS)、窃听和伪装,这使得部署更加困难。因此,在本文中,我们提出了一种基于 UIN 架构的集中控制和安全多播 (CCSM) 系统,并重新设计了包括注册、加入/离开、多播路由构建和更新在内的多播服务过程,旨在实现更好的移动性支持、安全性、可扩展性和可控性。更具体地说,我们设计了一种新的组管理方案,通过认证来执行多播成员的加入/离开,以及一种集中控制的多播路由方案,为路由器上设置多播条目提供安全的方式。CCSM 继承了 UIN 在移动性和安全性方面的特点,它可以提供集中的多播路由计算,并将多播路由分配给转发器。我们将 CCSM 与协议无关多播稀疏模式 (PIM-SM) 进行了比较,结果表明 CCSM 在低多播密度下减少了多播加入延迟,并且在重建成本方面比 PIM-SM 表现更好。