In this paper an approach for providing security services for multicast routing based on IPSEC is presented. We assume the use of PIM-SM and BGMP for an intra-domain routing algorithm and an inter-domain routing algorithm, respectively. All the member...
In this paper an approach for providing security services for multicast routing based on IPSEC is presented. We assume the use of PIM-SM and BGMP for an intra-domain routing algorithm and an inter-domain routing algorithm, respectively. All the members and senders are authenticated and receive/use proper capabilities when they join a multicast group so that illegal hosts or routers may not be able to expand the multicast delivery tree. Messages are encrypted with either a group data key or sender specific key which is shared by all members and changed efficiently whenever a membership changes. So not only illegal hosts cannot read packets but also members cannot read packets exchanged before they join the group or after they leave the group. The authenticity and freshness of a packet is checked by the edge router of the sending host and then all the core routers. Therefore, if a hosts attempt to inject a bogus packet or replay a packet is thwarted by an edge router. Similar attempts by a corrupt router are blocked by core routers and the effects of such attempts are contained in a single domain. We show how IPSEC can be used to implement this proposed protocols.