CN101917280A - Method and system for authenticating and accounting group user for using multicast service - Google Patents
Method and system for authenticating and accounting group user for using multicast service Download PDFInfo
- Publication number
- CN101917280A CN101917280A CN2010102627921A CN201010262792A CN101917280A CN 101917280 A CN101917280 A CN 101917280A CN 2010102627921 A CN2010102627921 A CN 2010102627921A CN 201010262792 A CN201010262792 A CN 201010262792A CN 101917280 A CN101917280 A CN 101917280A
- Authority
- CN
- China
- Prior art keywords
- group
- identification information
- multicast
- vlan
- request
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Images
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
The invention relates to a method and a system for authenticating and accounting group users for using a multicast service. The system comprises an exchanger and an authenticating, authorizing and accounting (AAA) server. The method comprises the following steps that: when receiving a multicast request sent by the group user and judging that the user is the first user to apply for jointing a multicast group, the exchanger initiates an authenticating and accounting request to the AAA server, wherein the authenticating and accounting request carries identification information of a virtual local area network (VLAN) affiliated by the group; and after receiving the authenticating and accounting request and determining the identification information of the virtual local area network (VLAN) affiliated by the group is legal, the AAA server starts accounting; and when receiving a multicast logging-out request sent by the last user in the multicast group, the exchanger initiates an accounting stopping request to the AAA server, and the AAA server stops accounting after receiving the accounting stopping request. When the method and the system are used, the diversity of the accounting is improved effectively, legal rights and interests of the users are protected, the benefit maximization of operators is guaranteed, and service is provided for the operators and client groups preferably.
Description
Technical field
The present invention relates to the computer communication field, relate in particular to authentication and charging method and system that a kind of group user uses multicast service.
Background technology
In the data communication field, the group user that uses same group business is when the visit multicast resource, and network side authenticates separately each group user that adds this multicast group respectively usually and charges, and wherein, group user is meant the client who uses group's business.As: for adopting 802.1x agreement, PPP (Pointto Point Protocol, point-to-point protocol), DHCP (Dynamic Host Configuration Protocol, DynamicHost is provided with agreement) multicast user that carries out data communication, network side authenticates according to this user's username and password and charges; Perhaps the physical location information according to the multicast user carries out authentication and accounting; Or authenticate and charge according to multicast user's MAC (Media Access Control, medium access control) address.This charging way is equivalent to this group is repeated to charge, and can cause the increase of communication fee concerning group, therefore can not satisfy client's demand.
Summary of the invention
The technical problem to be solved in the present invention provides authentication and charging method and the system that a kind of group user uses multicast service, to overcome the defective that existing group user is repeated to charge by system when using multicast service.
For addressing the above problem, the invention provides authentication and charging method that a kind of group user uses multicast service, comprising:
Switch is when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of described group to authentication and authorization charging (AAA) server; After described aaa server is received, after the identification information of judging VLAN under this group is legal, begin to charge; Described switch last user sends in receiving this multicast group withdraw from multicast request after, initiate to stop the request of chargeing to described aaa server, stop after described aaa server is received chargeing.
Further, said method also can have following feature:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described method also comprises: described aaa server carries out expense according to the charging policy of the identification information correspondence of VLAN under the described group and calculates after stopping to charge, then the corresponding expense of deduction the group account of VLAN identification information correspondence under described group.
Further, said method also can have following feature:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described aaa server is judged legal being meant of identification information of the affiliated VLAN of described group: the charging policy of preserving the identification information correspondence of the affiliated VLAN of this group on the described aaa server.
Further, said method also can have following feature:
Dispose the corresponding relation of VLAN identification information and inbound port identification information on the described switch;
Described method also comprises: described switch is when receiving the multicast request that group user is sent, after the inbound port identification information of the identification information of VLAN and described multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
Further, said method also can comprise:
Described switch the user sends in receiving this multicast group withdraw from multicast request after, the multicast list that deletion is corresponding.
The present invention also provides a kind of group user to use the authentication and the charge system of multicast service, comprising: switch and authentication and authorization charging (AAA) server;
Described switch is used for when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of described group to described aaa server; Also be used for receive that last user of this multicast group sends withdraw from multicast request after, initiate to stop the request of chargeing to described aaa server;
Described aaa server is used for after the identification information of judging VLAN under this group is legal, beginning to charge after receiving described authentication and charging request; Also be used for after receiving described termination charging request, stopping to charge.
Further, said system also can have following feature:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described aaa server also is used for after stopping to charge, and carries out expense according to the charging policy of the identification information correspondence of VLAN under the described group and calculates, then the corresponding expense of deduction the group account of VLAN identification information correspondence under described group.
Further, said system also can have following feature:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Whether the identification information that described aaa server is used to judge VLAN under the described group legal being meant: described aaa server is used for judging according to the charging policy of whether preserving the identification information correspondence of VLAN under this group on it whether the identification information of VLAN is legal under the described group.
Further, said system also can have following feature:
Dispose the corresponding relation of VLAN identification information and inbound port identification information on the described switch;
Described switch also is used for when receiving the multicast request that group user is sent, after the inbound port identification information of the identification information of VLAN and described multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
Further, said system also can have following feature:
Described switch also be used for receive that this multicast group user sends withdraw from multicast request after, the multicast list that deletion is corresponding.
After adopting the present invention, can satisfy special user's networking requirement, effectively increase the diversity of chargeing, protection user's reasonable rights and interests guarantee the benefits of operators maximization, provide service for operator and customer group better.
Description of drawings
Fig. 1 is that group user uses the authentication of multicast service and the flow chart of charging method in the embodiment of the invention.
Embodiment
As shown in Figure 1, the method for the invention may further comprise the steps:
1, switch is when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then to AAA (Authentication AuthorizationAccounting, authentication and authorization charging) server is initiated authentication and the request of chargeing, and wherein carries the identification information of the affiliated VLAN of above-mentioned group;
Corresponding relation at configurable VLAN identification information of exchanger side and inbound port identification information; Like this, this switch is when receiving the multicast request that each group user is sent, after the inbound port identification information of the identification information of VLAN and this multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, can generate the multicast list of a correspondence in judging this request.
2, after aaa server is received above-mentioned authentication and charging request, after the identification information of judging VLAN under this group is legal, begin to charge;
Can on this aaa server, dispose the corresponding relation of VLAN identification information and charging policy (comprising charging way and rate); Judge then that the identification information of VLAN under this group is whether legal and can whether preserve the charging policy of the identification information correspondence of VLAN under this group and obtain by judging aaa server this locality, if that is: preserve the charging policy of the identification information correspondence of the affiliated VLAN of this group on the aaa server, illustrate that then this VLAN identification information is legal; Otherwise, illegal.As judge and can not send out, then can notify switch to refuse this user and add this multicast group.
3, switch last user sends in receiving this multicast group withdraw from multicast request after, initiate to stop the request of chargeing to aaa server;
Wherein, switch each user sends in receiving this multicast group withdraw from multicast request after, all need multicast list deletion with this user's correspondence.
4, aaa server receives that above-mentioned termination charges after the request, stop to charge, then according to the charging policy computational costs of above-mentioned correspondence, and from the group account of this VLAN identification information correspondence the corresponding expense of deduction.
For example: charging way is for chargeing by the professional duration of use, and then aaa server can multiply by the rate of configuration according to the duration of receiving above-mentioned authentication and charging request and stopping interval between the charging request as the charging duration, obtains corresponding expense.
In addition, the present invention also provides a kind of group user to use the authentication and the charge system of multicast service, comprising: switch and aaa server;
Switch is used for when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of this group to described aaa server; Also be used for receive that last user of this multicast group sends withdraw from multicast request after, initiate to stop the request of chargeing to aaa server;
Aaa server is used for after the identification information of judging VLAN under this group is legal, beginning to charge after receiving above-mentioned authentication and charging request; Also be used for after receiving above-mentioned termination charging request, stopping to charge.
In addition, can on aaa server, dispose the corresponding relation of VLAN identification information and charging policy; After then aaa server also is used in and stops to charge, carry out expense according to the charging policy of the identification information correspondence of VLAN under this group and calculate, then the corresponding expense of deduction the group account of VLAN identification information correspondence under this group.
And the identification information that aaa server is used to judge VLAN under the described group legal can being meant whether: aaa server is used for judging according to the charging policy of whether preserving the identification information correspondence of VLAN under this group on it whether the identification information of VLAN is legal under this group.
And, can also on switch, dispose the corresponding relation of VLAN identification information and inbound port identification information; Then switch also is used in when receiving the multicast request that group user sends, after the inbound port identification information of the identification information of VLAN and this multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
In addition, switch also be used in receive that the user sends in this multicast group withdraw from multicast request after, the multicast list that deletion is corresponding.
One of ordinary skill in the art will appreciate that all or part of step in the said method can instruct related hardware to finish by program, described program can be stored in the computer-readable recording medium, as read-only memory, disk or CD etc.Alternatively, all or part of step of the foregoing description also can use one or more integrated circuits to realize.Correspondingly, each the module/unit in the foregoing description can adopt the form of hardware to realize, also can adopt the form of software function module to realize.The present invention is not restricted to the combination of the hardware and software of any particular form.
Claims (10)
1. a group user uses the authentication and the charging method of multicast service, comprising:
Switch is when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of described group to authentication and authorization charging (AAA) server; After described aaa server is received, after the identification information of judging VLAN under this group is legal, begin to charge; Described switch last user sends in receiving this multicast group withdraw from multicast request after, initiate to stop the request of chargeing to described aaa server, stop after described aaa server is received chargeing.
2. the method for claim 1 is characterized in that:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described method also comprises: described aaa server carries out expense according to the charging policy of the identification information correspondence of VLAN under the described group and calculates after stopping to charge, then the corresponding expense of deduction the group account of VLAN identification information correspondence under described group.
3. method as claimed in claim 1 or 2 is characterized in that:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described aaa server is judged legal being meant of identification information of the affiliated VLAN of described group: the charging policy of preserving the identification information correspondence of the affiliated VLAN of this group on the described aaa server.
4. method as claimed in claim 1 or 2 is characterized in that:
Dispose the corresponding relation of VLAN identification information and inbound port identification information on the described switch;
Described method also comprises: described switch is when receiving the multicast request that group user is sent, after the inbound port identification information of the identification information of VLAN and described multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
5. method as claimed in claim 4 is characterized in that, described method also comprises:
Described switch the user sends in receiving this multicast group withdraw from multicast request after, the multicast list that deletion is corresponding.
6. the authentication and the charge system of a group user use multicast service comprise: switch and authentication and authorization charging (AAA) server;
Described switch is used for when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of described group to described aaa server; Also be used for receive that last user of this multicast group sends withdraw from multicast request after, initiate to stop the request of chargeing to described aaa server;
Described aaa server is used for after the identification information of judging VLAN under this group is legal, beginning to charge after receiving described authentication and charging request; Also be used for after receiving described termination charging request, stopping to charge.
7. system as claimed in claim 6 is characterized in that:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described aaa server also is used for after stopping to charge, and carries out expense according to the charging policy of the identification information correspondence of VLAN under the described group and calculates, then the corresponding expense of deduction the group account of VLAN identification information correspondence under described group.
8. as claim 6 or 7 described systems, it is characterized in that:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Whether the identification information that described aaa server is used to judge VLAN under the described group legal being meant: described aaa server is used for judging according to the charging policy of whether preserving the identification information correspondence of VLAN under this group on it whether the identification information of VLAN is legal under the described group.
9. as claim 6 or 7 described systems, it is characterized in that:
Dispose the corresponding relation of VLAN identification information and inbound port identification information on the described switch;
Described switch also is used for when receiving the multicast request that group user is sent, after the inbound port identification information of the identification information of VLAN and described multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
10. system as claimed in claim 9 is characterized in that:
Described switch also be used for receive that this multicast group user sends withdraw from multicast request after, the multicast list that deletion is corresponding.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2010102627921A CN101917280A (en) | 2010-08-19 | 2010-08-19 | Method and system for authenticating and accounting group user for using multicast service |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2010102627921A CN101917280A (en) | 2010-08-19 | 2010-08-19 | Method and system for authenticating and accounting group user for using multicast service |
Publications (1)
Publication Number | Publication Date |
---|---|
CN101917280A true CN101917280A (en) | 2010-12-15 |
Family
ID=43324677
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN2010102627921A Pending CN101917280A (en) | 2010-08-19 | 2010-08-19 | Method and system for authenticating and accounting group user for using multicast service |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN101917280A (en) |
Citations (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101114900A (en) * | 2006-07-27 | 2008-01-30 | 上海贝尔阿尔卡特股份有限公司 | Multicast service authentication method and device, system |
CN101150405A (en) * | 2006-09-22 | 2008-03-26 | 华为技术有限公司 | Method and system for multicast and broadcast service authentication and authorization |
CN101155046A (en) * | 2006-09-25 | 2008-04-02 | 华为技术有限公司 | Network control system and method for implementing multicast control |
JP2008530891A (en) * | 2005-02-14 | 2008-08-07 | テレフオンアクチーボラゲット エル エム エリクソン(パブル) | Methods and nodes for processing multicast messages |
CN101340301A (en) * | 2007-07-03 | 2009-01-07 | 华为技术有限公司 | Method and system for obtaining media data in application layer multicasting network |
CN101394277A (en) * | 2007-09-17 | 2009-03-25 | 华为技术有限公司 | Method and apparatus for implementing multicast authentication |
CN101547100A (en) * | 2009-05-07 | 2009-09-30 | 杭州华三通信技术有限公司 | Method and system for multicast receiving control |
CN101702797A (en) * | 2009-11-09 | 2010-05-05 | 中兴通讯股份有限公司 | Flow accounting method of group user, device thereof and system thereof |
-
2010
- 2010-08-19 CN CN2010102627921A patent/CN101917280A/en active Pending
Patent Citations (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2008530891A (en) * | 2005-02-14 | 2008-08-07 | テレフオンアクチーボラゲット エル エム エリクソン(パブル) | Methods and nodes for processing multicast messages |
CN101114900A (en) * | 2006-07-27 | 2008-01-30 | 上海贝尔阿尔卡特股份有限公司 | Multicast service authentication method and device, system |
CN101150405A (en) * | 2006-09-22 | 2008-03-26 | 华为技术有限公司 | Method and system for multicast and broadcast service authentication and authorization |
CN101155046A (en) * | 2006-09-25 | 2008-04-02 | 华为技术有限公司 | Network control system and method for implementing multicast control |
CN101340301A (en) * | 2007-07-03 | 2009-01-07 | 华为技术有限公司 | Method and system for obtaining media data in application layer multicasting network |
CN101394277A (en) * | 2007-09-17 | 2009-03-25 | 华为技术有限公司 | Method and apparatus for implementing multicast authentication |
CN101547100A (en) * | 2009-05-07 | 2009-09-30 | 杭州华三通信技术有限公司 | Method and system for multicast receiving control |
CN101702797A (en) * | 2009-11-09 | 2010-05-05 | 中兴通讯股份有限公司 | Flow accounting method of group user, device thereof and system thereof |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101247396B (en) | Method, device and system for distributing IP address | |
CN102244866A (en) | Portal verifying method and access controller | |
EP2337307A2 (en) | Secure subscriber identity module service | |
CN101399726B (en) | Method for WLAN terminal authentication | |
CN100544343C (en) | The implementation method of user login name and IP address binding | |
EP2641163B1 (en) | Cross access login controller | |
CN103701760A (en) | Wireless LAN (Local Area Network) Portal authentication method and system and Portal server | |
CN101986598B (en) | Authentication method, server and system | |
CN101455041A (en) | Detection of network environment | |
CN102143136B (en) | Method for accessing service wholesale network, equipment, server and system | |
CN101765114A (en) | Method, system and equipment for controlling wireless user access | |
CN103780711A (en) | Address assignment method and address assignment system for intelligent access type decision, and AAA system | |
CN102571729A (en) | Internet protocol version (IPV)6 network access authentication method, device and system | |
CN106559785B (en) | Authentication method, device and system, access device and terminal | |
CN102404293A (en) | Dual-stack user managing method and broadband access server | |
CN102833815A (en) | AP (access point) accessing control method for AC (access controller) | |
CN101711031A (en) | Portal authenticating method during local forwarding and access controller (AC) | |
CN101895587A (en) | Method, device and system for preventing users from modifying IP addresses privately | |
CN101742497B (en) | Method for realizing access authentication and client | |
CN103067407A (en) | Authentication method and authentication device of user terminal access network | |
CN101697550A (en) | Method and system for controlling access authority of double-protocol-stack network | |
CN113055835B (en) | Vehicle-mounted application traffic processing method, device and system | |
CN100438446C (en) | Switch-in control equipment, Switch-in control system and switch-in control method | |
CN106878099B (en) | Traffic management method, terminal equipment, server and system | |
KR101991340B1 (en) | Apparatus and method for managing security |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C02 | Deemed withdrawal of patent application after publication (patent law 2001) | ||
WD01 | Invention patent application deemed withdrawn after publication |
Application publication date: 20101215 |