CN101917280A - Method and system for authenticating and accounting group user for using multicast service - Google Patents

Method and system for authenticating and accounting group user for using multicast service Download PDF

Info

Publication number
CN101917280A
CN101917280A CN2010102627921A CN201010262792A CN101917280A CN 101917280 A CN101917280 A CN 101917280A CN 2010102627921 A CN2010102627921 A CN 2010102627921A CN 201010262792 A CN201010262792 A CN 201010262792A CN 101917280 A CN101917280 A CN 101917280A
Authority
CN
China
Prior art keywords
group
identification information
multicast
vlan
request
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN2010102627921A
Other languages
Chinese (zh)
Inventor
王诗刚
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
ZTE Corp
Original Assignee
ZTE Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ZTE Corp filed Critical ZTE Corp
Priority to CN2010102627921A priority Critical patent/CN101917280A/en
Publication of CN101917280A publication Critical patent/CN101917280A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention relates to a method and a system for authenticating and accounting group users for using a multicast service. The system comprises an exchanger and an authenticating, authorizing and accounting (AAA) server. The method comprises the following steps that: when receiving a multicast request sent by the group user and judging that the user is the first user to apply for jointing a multicast group, the exchanger initiates an authenticating and accounting request to the AAA server, wherein the authenticating and accounting request carries identification information of a virtual local area network (VLAN) affiliated by the group; and after receiving the authenticating and accounting request and determining the identification information of the virtual local area network (VLAN) affiliated by the group is legal, the AAA server starts accounting; and when receiving a multicast logging-out request sent by the last user in the multicast group, the exchanger initiates an accounting stopping request to the AAA server, and the AAA server stops accounting after receiving the accounting stopping request. When the method and the system are used, the diversity of the accounting is improved effectively, legal rights and interests of the users are protected, the benefit maximization of operators is guaranteed, and service is provided for the operators and client groups preferably.

Description

A kind of group user uses authentication and the charging method and the system of multicast service
Technical field
The present invention relates to the computer communication field, relate in particular to authentication and charging method and system that a kind of group user uses multicast service.
Background technology
In the data communication field, the group user that uses same group business is when the visit multicast resource, and network side authenticates separately each group user that adds this multicast group respectively usually and charges, and wherein, group user is meant the client who uses group's business.As: for adopting 802.1x agreement, PPP (Pointto Point Protocol, point-to-point protocol), DHCP (Dynamic Host Configuration Protocol, DynamicHost is provided with agreement) multicast user that carries out data communication, network side authenticates according to this user's username and password and charges; Perhaps the physical location information according to the multicast user carries out authentication and accounting; Or authenticate and charge according to multicast user's MAC (Media Access Control, medium access control) address.This charging way is equivalent to this group is repeated to charge, and can cause the increase of communication fee concerning group, therefore can not satisfy client's demand.
Summary of the invention
The technical problem to be solved in the present invention provides authentication and charging method and the system that a kind of group user uses multicast service, to overcome the defective that existing group user is repeated to charge by system when using multicast service.
For addressing the above problem, the invention provides authentication and charging method that a kind of group user uses multicast service, comprising:
Switch is when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of described group to authentication and authorization charging (AAA) server; After described aaa server is received, after the identification information of judging VLAN under this group is legal, begin to charge; Described switch last user sends in receiving this multicast group withdraw from multicast request after, initiate to stop the request of chargeing to described aaa server, stop after described aaa server is received chargeing.
Further, said method also can have following feature:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described method also comprises: described aaa server carries out expense according to the charging policy of the identification information correspondence of VLAN under the described group and calculates after stopping to charge, then the corresponding expense of deduction the group account of VLAN identification information correspondence under described group.
Further, said method also can have following feature:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described aaa server is judged legal being meant of identification information of the affiliated VLAN of described group: the charging policy of preserving the identification information correspondence of the affiliated VLAN of this group on the described aaa server.
Further, said method also can have following feature:
Dispose the corresponding relation of VLAN identification information and inbound port identification information on the described switch;
Described method also comprises: described switch is when receiving the multicast request that group user is sent, after the inbound port identification information of the identification information of VLAN and described multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
Further, said method also can comprise:
Described switch the user sends in receiving this multicast group withdraw from multicast request after, the multicast list that deletion is corresponding.
The present invention also provides a kind of group user to use the authentication and the charge system of multicast service, comprising: switch and authentication and authorization charging (AAA) server;
Described switch is used for when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of described group to described aaa server; Also be used for receive that last user of this multicast group sends withdraw from multicast request after, initiate to stop the request of chargeing to described aaa server;
Described aaa server is used for after the identification information of judging VLAN under this group is legal, beginning to charge after receiving described authentication and charging request; Also be used for after receiving described termination charging request, stopping to charge.
Further, said system also can have following feature:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described aaa server also is used for after stopping to charge, and carries out expense according to the charging policy of the identification information correspondence of VLAN under the described group and calculates, then the corresponding expense of deduction the group account of VLAN identification information correspondence under described group.
Further, said system also can have following feature:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Whether the identification information that described aaa server is used to judge VLAN under the described group legal being meant: described aaa server is used for judging according to the charging policy of whether preserving the identification information correspondence of VLAN under this group on it whether the identification information of VLAN is legal under the described group.
Further, said system also can have following feature:
Dispose the corresponding relation of VLAN identification information and inbound port identification information on the described switch;
Described switch also is used for when receiving the multicast request that group user is sent, after the inbound port identification information of the identification information of VLAN and described multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
Further, said system also can have following feature:
Described switch also be used for receive that this multicast group user sends withdraw from multicast request after, the multicast list that deletion is corresponding.
After adopting the present invention, can satisfy special user's networking requirement, effectively increase the diversity of chargeing, protection user's reasonable rights and interests guarantee the benefits of operators maximization, provide service for operator and customer group better.
Description of drawings
Fig. 1 is that group user uses the authentication of multicast service and the flow chart of charging method in the embodiment of the invention.
Embodiment
As shown in Figure 1, the method for the invention may further comprise the steps:
1, switch is when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then to AAA (Authentication AuthorizationAccounting, authentication and authorization charging) server is initiated authentication and the request of chargeing, and wherein carries the identification information of the affiliated VLAN of above-mentioned group;
Corresponding relation at configurable VLAN identification information of exchanger side and inbound port identification information; Like this, this switch is when receiving the multicast request that each group user is sent, after the inbound port identification information of the identification information of VLAN and this multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, can generate the multicast list of a correspondence in judging this request.
2, after aaa server is received above-mentioned authentication and charging request, after the identification information of judging VLAN under this group is legal, begin to charge;
Can on this aaa server, dispose the corresponding relation of VLAN identification information and charging policy (comprising charging way and rate); Judge then that the identification information of VLAN under this group is whether legal and can whether preserve the charging policy of the identification information correspondence of VLAN under this group and obtain by judging aaa server this locality, if that is: preserve the charging policy of the identification information correspondence of the affiliated VLAN of this group on the aaa server, illustrate that then this VLAN identification information is legal; Otherwise, illegal.As judge and can not send out, then can notify switch to refuse this user and add this multicast group.
3, switch last user sends in receiving this multicast group withdraw from multicast request after, initiate to stop the request of chargeing to aaa server;
Wherein, switch each user sends in receiving this multicast group withdraw from multicast request after, all need multicast list deletion with this user's correspondence.
4, aaa server receives that above-mentioned termination charges after the request, stop to charge, then according to the charging policy computational costs of above-mentioned correspondence, and from the group account of this VLAN identification information correspondence the corresponding expense of deduction.
For example: charging way is for chargeing by the professional duration of use, and then aaa server can multiply by the rate of configuration according to the duration of receiving above-mentioned authentication and charging request and stopping interval between the charging request as the charging duration, obtains corresponding expense.
In addition, the present invention also provides a kind of group user to use the authentication and the charge system of multicast service, comprising: switch and aaa server;
Switch is used for when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of this group to described aaa server; Also be used for receive that last user of this multicast group sends withdraw from multicast request after, initiate to stop the request of chargeing to aaa server;
Aaa server is used for after the identification information of judging VLAN under this group is legal, beginning to charge after receiving above-mentioned authentication and charging request; Also be used for after receiving above-mentioned termination charging request, stopping to charge.
In addition, can on aaa server, dispose the corresponding relation of VLAN identification information and charging policy; After then aaa server also is used in and stops to charge, carry out expense according to the charging policy of the identification information correspondence of VLAN under this group and calculate, then the corresponding expense of deduction the group account of VLAN identification information correspondence under this group.
And the identification information that aaa server is used to judge VLAN under the described group legal can being meant whether: aaa server is used for judging according to the charging policy of whether preserving the identification information correspondence of VLAN under this group on it whether the identification information of VLAN is legal under this group.
And, can also on switch, dispose the corresponding relation of VLAN identification information and inbound port identification information; Then switch also is used in when receiving the multicast request that group user sends, after the inbound port identification information of the identification information of VLAN and this multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
In addition, switch also be used in receive that the user sends in this multicast group withdraw from multicast request after, the multicast list that deletion is corresponding.
One of ordinary skill in the art will appreciate that all or part of step in the said method can instruct related hardware to finish by program, described program can be stored in the computer-readable recording medium, as read-only memory, disk or CD etc.Alternatively, all or part of step of the foregoing description also can use one or more integrated circuits to realize.Correspondingly, each the module/unit in the foregoing description can adopt the form of hardware to realize, also can adopt the form of software function module to realize.The present invention is not restricted to the combination of the hardware and software of any particular form.

Claims (10)

1. a group user uses the authentication and the charging method of multicast service, comprising:
Switch is when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of described group to authentication and authorization charging (AAA) server; After described aaa server is received, after the identification information of judging VLAN under this group is legal, begin to charge; Described switch last user sends in receiving this multicast group withdraw from multicast request after, initiate to stop the request of chargeing to described aaa server, stop after described aaa server is received chargeing.
2. the method for claim 1 is characterized in that:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described method also comprises: described aaa server carries out expense according to the charging policy of the identification information correspondence of VLAN under the described group and calculates after stopping to charge, then the corresponding expense of deduction the group account of VLAN identification information correspondence under described group.
3. method as claimed in claim 1 or 2 is characterized in that:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described aaa server is judged legal being meant of identification information of the affiliated VLAN of described group: the charging policy of preserving the identification information correspondence of the affiliated VLAN of this group on the described aaa server.
4. method as claimed in claim 1 or 2 is characterized in that:
Dispose the corresponding relation of VLAN identification information and inbound port identification information on the described switch;
Described method also comprises: described switch is when receiving the multicast request that group user is sent, after the inbound port identification information of the identification information of VLAN and described multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
5. method as claimed in claim 4 is characterized in that, described method also comprises:
Described switch the user sends in receiving this multicast group withdraw from multicast request after, the multicast list that deletion is corresponding.
6. the authentication and the charge system of a group user use multicast service comprise: switch and authentication and authorization charging (AAA) server;
Described switch is used for when receiving the multicast request that group user is sent, as to judge this user be user that first application adds this multicast group, then initiate authentication and the request of chargeing, wherein carry the identification information of the affiliated Virtual Local Area Network of described group to described aaa server; Also be used for receive that last user of this multicast group sends withdraw from multicast request after, initiate to stop the request of chargeing to described aaa server;
Described aaa server is used for after the identification information of judging VLAN under this group is legal, beginning to charge after receiving described authentication and charging request; Also be used for after receiving described termination charging request, stopping to charge.
7. system as claimed in claim 6 is characterized in that:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Described aaa server also is used for after stopping to charge, and carries out expense according to the charging policy of the identification information correspondence of VLAN under the described group and calculates, then the corresponding expense of deduction the group account of VLAN identification information correspondence under described group.
8. as claim 6 or 7 described systems, it is characterized in that:
Dispose the corresponding relation of VLAN identification information and charging policy on the described aaa server;
Whether the identification information that described aaa server is used to judge VLAN under the described group legal being meant: described aaa server is used for judging according to the charging policy of whether preserving the identification information correspondence of VLAN under this group on it whether the identification information of VLAN is legal under the described group.
9. as claim 6 or 7 described systems, it is characterized in that:
Dispose the corresponding relation of VLAN identification information and inbound port identification information on the described switch;
Described switch also is used for when receiving the multicast request that group user is sent, after the inbound port identification information of the identification information of VLAN and described multicast request meets the corresponding relation of local VLAN identification information that disposes and inbound port identification information under this group of carrying, generate multicast list in judging this request.
10. system as claimed in claim 9 is characterized in that:
Described switch also be used for receive that this multicast group user sends withdraw from multicast request after, the multicast list that deletion is corresponding.
CN2010102627921A 2010-08-19 2010-08-19 Method and system for authenticating and accounting group user for using multicast service Pending CN101917280A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2010102627921A CN101917280A (en) 2010-08-19 2010-08-19 Method and system for authenticating and accounting group user for using multicast service

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2010102627921A CN101917280A (en) 2010-08-19 2010-08-19 Method and system for authenticating and accounting group user for using multicast service

Publications (1)

Publication Number Publication Date
CN101917280A true CN101917280A (en) 2010-12-15

Family

ID=43324677

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2010102627921A Pending CN101917280A (en) 2010-08-19 2010-08-19 Method and system for authenticating and accounting group user for using multicast service

Country Status (1)

Country Link
CN (1) CN101917280A (en)

Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101114900A (en) * 2006-07-27 2008-01-30 上海贝尔阿尔卡特股份有限公司 Multicast service authentication method and device, system
CN101150405A (en) * 2006-09-22 2008-03-26 华为技术有限公司 Method and system for multicast and broadcast service authentication and authorization
CN101155046A (en) * 2006-09-25 2008-04-02 华为技术有限公司 Network control system and method for implementing multicast control
JP2008530891A (en) * 2005-02-14 2008-08-07 テレフオンアクチーボラゲット エル エム エリクソン(パブル) Methods and nodes for processing multicast messages
CN101340301A (en) * 2007-07-03 2009-01-07 华为技术有限公司 Method and system for obtaining media data in application layer multicasting network
CN101394277A (en) * 2007-09-17 2009-03-25 华为技术有限公司 Method and apparatus for implementing multicast authentication
CN101547100A (en) * 2009-05-07 2009-09-30 杭州华三通信技术有限公司 Method and system for multicast receiving control
CN101702797A (en) * 2009-11-09 2010-05-05 中兴通讯股份有限公司 Flow accounting method of group user, device thereof and system thereof

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008530891A (en) * 2005-02-14 2008-08-07 テレフオンアクチーボラゲット エル エム エリクソン(パブル) Methods and nodes for processing multicast messages
CN101114900A (en) * 2006-07-27 2008-01-30 上海贝尔阿尔卡特股份有限公司 Multicast service authentication method and device, system
CN101150405A (en) * 2006-09-22 2008-03-26 华为技术有限公司 Method and system for multicast and broadcast service authentication and authorization
CN101155046A (en) * 2006-09-25 2008-04-02 华为技术有限公司 Network control system and method for implementing multicast control
CN101340301A (en) * 2007-07-03 2009-01-07 华为技术有限公司 Method and system for obtaining media data in application layer multicasting network
CN101394277A (en) * 2007-09-17 2009-03-25 华为技术有限公司 Method and apparatus for implementing multicast authentication
CN101547100A (en) * 2009-05-07 2009-09-30 杭州华三通信技术有限公司 Method and system for multicast receiving control
CN101702797A (en) * 2009-11-09 2010-05-05 中兴通讯股份有限公司 Flow accounting method of group user, device thereof and system thereof

Similar Documents

Publication Publication Date Title
CN101247396B (en) Method, device and system for distributing IP address
CN102244866A (en) Portal verifying method and access controller
EP2337307A2 (en) Secure subscriber identity module service
CN101399726B (en) Method for WLAN terminal authentication
CN100544343C (en) The implementation method of user login name and IP address binding
EP2641163B1 (en) Cross access login controller
CN103701760A (en) Wireless LAN (Local Area Network) Portal authentication method and system and Portal server
CN101986598B (en) Authentication method, server and system
CN101455041A (en) Detection of network environment
CN102143136B (en) Method for accessing service wholesale network, equipment, server and system
CN101765114A (en) Method, system and equipment for controlling wireless user access
CN103780711A (en) Address assignment method and address assignment system for intelligent access type decision, and AAA system
CN102571729A (en) Internet protocol version (IPV)6 network access authentication method, device and system
CN106559785B (en) Authentication method, device and system, access device and terminal
CN102404293A (en) Dual-stack user managing method and broadband access server
CN102833815A (en) AP (access point) accessing control method for AC (access controller)
CN101711031A (en) Portal authenticating method during local forwarding and access controller (AC)
CN101895587A (en) Method, device and system for preventing users from modifying IP addresses privately
CN101742497B (en) Method for realizing access authentication and client
CN103067407A (en) Authentication method and authentication device of user terminal access network
CN101697550A (en) Method and system for controlling access authority of double-protocol-stack network
CN113055835B (en) Vehicle-mounted application traffic processing method, device and system
CN100438446C (en) Switch-in control equipment, Switch-in control system and switch-in control method
CN106878099B (en) Traffic management method, terminal equipment, server and system
KR101991340B1 (en) Apparatus and method for managing security

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C02 Deemed withdrawal of patent application after publication (patent law 2001)
WD01 Invention patent application deemed withdrawn after publication

Application publication date: 20101215