Background technology
Terminal will be implemented in access resources on the network, just need obtain the network address at resource place, provides the address just to become a key technology in the network to terminal.Particularly along with constantly the popularizing of broadband, the user data sharp increase, access technology is correspondingly maked rapid progress, and is used to satisfy various users and supplier's needs.And IPTV (Internet Protocol Television, Internet Protocol Television) is just obtaining application more and more widely as a new technology that colourful audio frequency and video business can be provided to the user.
IPTV utilizes broadband network as infrastructure, with domestic television set or PC as main display terminal, utilize carrying of a series of Internet protocols and transmission multimedia digital signal, for the domestic consumer provides the multiple interactive digital multimedia service that comprises TV programme and the brand-new technology of value-added service service through encoding compression.People can pass through PC (Personal Computer, PC), set-top box STB (Set Top Box, set-top box)+television set, multimedia handset multiple modes such as (being used for mobile IPTV) is enjoyed the IPTV service.From user perspective, the IPTV business can provide the order program service with personalized and real-time, interactive characteristics and be similar to the noninteractive direct broadcast service of traditional tv.
IPTV business common operation flow in set-top box is as follows:
Behind the set-top-box opening, initiate authentication request to access server;
Described authentication request is obtained IP (Internet Protocol, Internet protocol) address by the back from access server;
Described set-top box is according to described IP address, initiate login to the IPTV operation system, download EPG (Electronic Program Guide, electronic program guides), its content is different and different according to the STB authority, comprising basic channel, charging channel, VOD (Video On Demand, video request program) etc.;
The user selects certain direct broadcast band to watch program by EPG.
With above-mentioned different from the mode that access server obtains the IP address by the back in the access request, the implementation of another kind of prior art is made up of following steps:
Before set-top box is used, the IP address of an operation system must be set on set-top box at first;
Set-top-box opening, is visited corresponding IPTV operation system and is obtained the rendition list EPG according to described IP address by after authenticating, and the user selects relevant program according to described the rendition list.
The shortcoming of this technical scheme is: all must earlier an operation system IP address be set manually before each use of set-top box, this can increase the management workload and the cost of labor of operator; If because certain reason makes operation system IP address change, then need manually to reset the IP address of the operation system in the set-top box, workload is very big.And, because the operation system IP address of a plurality of IPTV content supplier may be different, if the manual IP address that fixedly installs what a content supplier's operation system, the user just can not select the program of other guide provider, the application space of having limited set-top box very bigly.
Another kind of technical scheme is usurped the circuit online of IPTV (be that the user is connected on PC on the interface that offers set-top box, perhaps use the account number of set-top box to authenticate) in order to prevent the user on PC.Generally by on access server, disposing ACL (Access Control List, Access Control List (ACL)), control the IPTV terminal now, the several destination addresses that allow its visit specific are set.
The deficiency of this technical scheme is:
1, acl lookup efficient is low, has reduced the systematic function of access server;
2, the configuration of ACL is dumb, need dispose many ACL on access server.When a plurality of content supplier, they allow the address visited different, and ACL disposes more loaded down with trivial details.
Therefore, the technical problem of prior art is: the process of the destination address that configurating terminal has the right to visit is very loaded down with trivial details, implement very inconvenient, inefficiency.
Summary of the invention
The purpose of the one or more embodiment of the present invention is to provide a kind of method of limiting terminal access address, device and system, with the EPG server address of realizing providing it to have the right to visit to terminal by network system, and described EPG server address is recorded in user's list item of described terminal correspondence, described terminal according to the described EPG server address that receives after network system is sent the message that the EPG server with corresponding EPG server address connects, if in user's list item of described terminal correspondence, write down described EPG server address, could visit described EPG server.
For addressing the above problem, the embodiment of the invention provides a kind of method of limiting terminal access address, comprising:
To inserting the terminal that request authentication is passed through, network system is inquired about the authorization message of described terminal, and described authorization message comprises the EPG server address;
Described network system sends to described terminal with described authorization message and described EPG server address is recorded in the list item corresponding with described terminal in the subscriber's meter;
That described network system is received is that described terminal is sent, obtain the request message of EPG programme to the EPG server after, if described EPG server address has been recorded in the list item corresponding with described terminal in the subscriber's meter, then described message is forwarded to described EPG server.
Also disclose a kind of device of limiting terminal access address, having comprised:
Insert the request authentication unit, be used for: to the terminal by the access request authentication, generate authorization message transmission instruction and also send, described authorization message transmission instruction is in order to obtain the authorization message of described terminal, and described authorization message comprises the EPG server address at least;
The authorization message record cell is used for: receive described authorization message, and the EPG server address in the described authorization message is recorded in the list item corresponding with described terminal in the subscriber's meter;
The authorization message transmitting element is used for: described authorization message is sent to described terminal;
The message retransmission unit, be used for: receive that described terminal is sent, after described EPG server obtains the request message of EPG programme, if described EPG server address has been recorded in the list item corresponding with described terminal in the subscriber's meter, then described message is forwarded to described EPG server.
Also disclose a kind of system of limiting terminal access address, having comprised:
The authorization message query facility is used for: to by inserting the terminal of request authentication, inquire about the authorization message of described terminal, described authorization message comprises the EPG server address at least;
Authorization message record and message forwarding equipment are used for: described authorization message is sent to described terminal and described EPG server address is recorded in list item corresponding with described terminal in the subscriber's meter; If described EPG server address has been recorded in the list item corresponding with described terminal in the subscriber's meter, then receive that described terminal is sent, after described EPG server obtains the request message of EPG programme, described message is forwarded to described EPG server.
Compared with prior art, the embodiment of the invention has the following advantages:
Utilize embodiments of the invention, can inquire about the EPG server address that comprises in its authorization message and send to described terminal for the terminal by authentication, the request of the EPG server of described terminal access is through checking, be recorded in its subscriber's meter, then can visit described EPG server.Realized sending the IPTV system that allows its visit to terminal, do not needed the destination address of Device IP TV system on terminal in advance via network system.And, owing to can in subscriber's meter, define the address that terminal has the right to visit one or more IPTV system neatly, can realize free access neatly for a plurality of IPTV system, expanded the scope of the IPTV system that terminal can visit greatly.
Embodiment
Below in conjunction with accompanying drawing the embodiment of the invention is done further and to be elaborated.
As shown in Figure 1, be the flow chart of first embodiment of the method for limiting terminal access address of the present invention, comprise step:
S101, to inserting the terminal that request authentication is passed through, network system is inquired about the authorization message of described terminal, described authorization message comprises the EPG server address at least.Terminal includes but not limited to that set-top box, PC, mobile phone, video telephone etc. can insert the equipment of IP network; Terminal among each embodiment of the present invention can be the equipment of various types of accesses network system.
S102, described network system send to described terminal with described authorization message and described EPG server address are recorded in the list item corresponding with described terminal in the subscriber's meter;
That S103, described network system are received is that described terminal is sent, obtain the request message of EPG programme to the EPG server after, if the server address of described EPG server has been recorded in the list item corresponding with described terminal in the subscriber's meter, then described message is transmitted described EPG server.
Utilize embodiments of the invention, can be for terminal by authentication, inquire about the EPG server address that comprises in its authorization message and send to described terminal, the request of the EPG server of described terminal access is through checking, if the IP address of described EPG server is recorded in user's list item of described terminal correspondence, then can visit the IPTV system at described EPG server and place thereof.Realized sending the IPTV system that allows its visit to terminal, do not needed on terminal, to be provided with in advance the destination address of IPTV system via network system.And, owing to can in subscriber's meter, define the address that terminal has the right to visit one or more IPTV system neatly, can realize the free access for a plurality of IPTV system neatly, search efficiency height, flexible configuration have been expanded the scope of the IPTV system of terminal could access greatly.
Wherein, in the above-described embodiments, the authorization message that described network system is inquired about described terminal can be specially:
AAA (Authentication Authorization Accounting, authentication and authorization charging server) server is inquired about the authorization message of described terminal in database.
Wherein, in the above-described embodiments, described network system sends to described terminal with described authorization message and described EPG server address is recorded in the list item corresponding with described terminal in the subscriber's meter and can be specially:
Aaa server sends to described terminal with described authorization message;
Nas server (Network Access Server, network access server) is recorded in described EPG server address in the list item corresponding with described terminal in the subscriber's meter.
Wherein, in the above-described embodiments, described authorization message can also comprise: distribute to the EPG server address of described terminal or allow the channel of described terminal access.
Wherein, in the above-described embodiments, can be authenticated by related hardware information or the account that the nas server in the network system carries the access request of terminal, then described access request authentication can be specially:
After nas server is received the access request of described terminal, the hardware address of described terminal or hardware identifier or line attachment or account number and password are authenticated.
Wherein, in the above-described embodiments, the described request message that obtains the EPG programme to the EPG server is forwarded to described EPG server after, can also comprise step:
The IPTV system at described EPG server place and the described terminal passage that connects.
Wherein, in the above-described embodiments, by means of DHCP (Dynamic Host ConfigurationProtocol, DHCP) or PPP (Point to Point Protocol, point-to-point protocol) access protocol, the perhaps relevant access protocol in other concrete applied environments is as PPPoE (PPP overEthernet, point-to-point protocol on the Ethernet), described network system sends to described terminal with described authorization message and can be specially:
Described network system sends to described terminal with described authorization message by DHCP or PPP access protocol.
As shown in Figure 2, be the signaling process figure of second embodiment of method of the present invention, comprise step:
S201, the STB nas server in network system sends the request of access; Can comprise hardware address, STB self identification, account number and the password of described STB or the line information of STB access etc. in the described access request, these information that comprise are used to discern described STB.Described access request can be used PPP, DHCP, EAP (Extend Authentication Protocol, Extensible Authentication Protocol) multiple access protocol such as, only be used to help further to understand the present invention for example herein, be not limited to protection scope of the present invention;
S202, after described nas server is received the access request of described STB, described nas server sends on the aaa server in the network system for information about with described STB's, send the request of access and can use RADIUS (Remote Access Dial up User Service, the dial access service of user's far-end), COPS (Common Open Policy Service, general open policy service protocol agreement), DIAMETER (Diameter Protocol, the updating protocol of radius protocol) etc. authentication protocol sends, example only is used to help further to understand the embodiment of the invention herein, is not limited to protection scope of the present invention;
If the described STB of S203 is by the authentication of described aaa server, the authorization message of then inquiring about described STB, described authorization message comprises the EPG server address at least;
Wherein, in practice, as preferred embodiment, described authorization message can also comprise: distribute to the IP address of described terminal or the channel of permission STB visit etc.;
Aaa server in S204, the described network system is issued nas server to authorization message by agreements such as RADIUS, COPS, DIAMETER;
After S205, described nas server are received the authorization message of described AAA, allow described STB the described EPG server address of visit to be recorded in the subscriber's meter;
Wherein, the described EPG server address that writes down in subscriber's meter can be one, also can be several, so long as the EPG server address that inquiry obtains comprising in the authorization message of described STB just can be recorded in the subscriber's meter.Correspondingly, the EPG server address in the subscriber's meter has shown that described STB has the EPG server that is write down in the authority calling party table, and a STB can visit several EPG servers.So long as the EPG server address that writes down under the STB item described in the subscriber's meter in nas server, described STB has the right to visit;
S206, described nas server send to described STB and insert response message, insert response message and comprise the EPG server address at least, can also comprise the information such as IP address of distributing to set-top box, wherein in practice, information such as described EPG server address can be carried in the scaling option of DHCP, PPPoE agreement;
207, described STB is according to described access response message, and the EPG server address etc. that upgrades self storage for information about;
S208, described STB initiate EPG programme request message according to the EPG server address of self storing;
After S209, described nas server are received the EPG server programme request message of described STB, judge in the subscriber's meter in the described nas server in the network system, under the described STB item, whether write down described EPG server address, if in the subscriber's meter in the described nas server in network system, under the described STB item, write down described EPG server address, then enter step S210, otherwise, step 212 entered;
S210, described nas server are forwarded to the EPG server programme request message of described STB the IPTV operation system at described EPG server place;
After S211, described IPTV operation system are received the EPG server programme request message of described STB, and connect between the described STB, normally information such as interactive program list is carried out the interchange of audio, video data;
S212, described nas server abandon the EPG server programme request message of described STB, and dismounting is connected with current terminal.
Utilize the embodiment of the invention, can be for terminal by authentication, inquire about the EPG server address that comprises in its authorization message and send to described terminal, the request of described terminal access EPG server is through checking, if the IP address of described EPG server is recorded in its subscriber's meter, then can visit described EPG server.Realized not needing the destination address of Device IP TV system on terminal in advance via the EPG server address of network system in the IPTV system of its visit of terminal transmission permission.And, owing to can in subscriber's meter, define the destination address that terminal has the right to visit one or more IPTV system neatly, can realize visit neatly for a plurality of IPTV system, expanded the scope of the IPTV system of terminal could access greatly.
Wherein, in the above-described embodiments,, with the different of setting of NAS following two kinds of processing modes can be arranged according to the IPTV system so in the process of using if STB wants to switch to another IPTV system from current IPTV system:
If comprise several EPG server address of having the right to visit of described STB in the authorization message that described NAS issues, then described STB does not need to insert once more request authentication, and NAS directly is forwarded to another IPTV system with the message of the acquisition request EPG programme of described STB;
If only comprise the EPG server address that described STB has the right to visit in the authorization message that described NAS issues, then described STB need insert request authentication once more, insert request authentication by after step such as carry out that authorization message is obtained.
And, if in the process of using, run into the user that has with the address setting of PC for the same with STB, and insert set top box interface, visit Internet network.So, by technical scheme of the present invention, after nas server is received above-mentioned message, find this user by authentication, but in the address that the destination address of this request does not write down, then abandon this message in this user's list item.Realized safeguard protection for the IPTV system.
As shown in Figure 3, be the device of the limiting terminal access address that provides of the embodiment of the invention, comprising:
Insert request authentication unit 301, be used for: to terminal by the access request authentication, generate authorization message and send instruction and transmission, described authorization message sends instruction in order to obtain the authorization message of described terminal, and described authorization message comprises the EPG server address at least;
Authorization message record cell 302 is used for: receive described authorization message, and the EPG server address in the described authorization message is recorded in the list item corresponding with described terminal in the subscriber's meter;
Authorization message transmitting element 303 is used for: described authorization message is sent to described terminal;
Message retransmission unit 304, be used for: receive that described terminal is sent, after described EPG server obtains the request message of EPG programme, if described EPG server address has been recorded in the list item corresponding with described terminal in the subscriber's meter, then described message is forwarded to described EPG server.
Utilize the embodiment of the invention, can be for terminal by authentication, inquire about the EPG server address that comprises in its authorization message and send to described terminal, the request of described terminal access EPG server is through checking, if the IP address of described EPG server is recorded in its subscriber's meter, then can visit described EPG server.Realized not needing the destination address of Device IP TV system on terminal in advance via the EPG server address of network system in the IPTV system of its visit of terminal transmission permission.And, owing to can in subscriber's meter, define the destination address that terminal has the right to visit one or more IPTV system neatly, can realize visit neatly for a plurality of IPTV system, expanded the scope of the IPTV system of terminal could access greatly.
Wherein, in the above-described embodiments, described access request authentication unit 301 can comprise:
The hardware address authentication ' unit is used for: after receiving the access request of described terminal, the hardware address of described terminal is authenticated; Or
The hardware identifier authentication ' unit is used for: after receiving the access request of described terminal, the hardware identifier of described terminal is authenticated; Or
The account number cipher authentication ' unit is used for: after receiving the access request of described terminal, the line attachment of described terminal or account number and password are authenticated.
Utilize present embodiment, can realize carrying out safety certification according to the hardware information or the account information of terminal.
Wherein, in the above-described embodiments, described authorization message transmitting element 303 can be specially:
DHCP agreement authorization message sends subelement, is used for: by the DHCP access protocol described authorization message is sent to described terminal; Or
The ppp protocol authorization message sends subelement, is used for: by the PPP access protocol described authorization message is sent to described terminal.
Certainly, under other applied environments, also can described authorization message be sent to described terminal by other access protocols.Therefore, above-mentioned example only is used for helping to understand the embodiment of the invention, is not limited to protection scope of the present invention.
As shown in Figure 4, be the system of the limiting terminal access address that provides of the embodiment of the invention, comprising:
Authorization message query facility 401 is used for: to by inserting the terminal of request authentication, inquire about the authorization message of described terminal, described authorization message comprises the EPG server address at least;
Authorization message record and message forwarding equipment 402 are used for: described authorization message is sent to described terminal and described EPG server address is recorded in list item corresponding with described terminal in the subscriber's meter; If described EPG server address has been recorded in the list item corresponding with described terminal in the subscriber's meter, then receive that described terminal is sent, after described EPG server obtains the request message of EPG programme, described message is forwarded to described EPG server.
Utilize the embodiment of the invention, can be for terminal by authentication, inquire about the EPG server address that comprises in its authorization message and send to described terminal, the request of described terminal access EPG server is through checking, if the IP address of described EPG server is recorded in its subscriber's meter, then can visit described EPG server.Realized not needing the destination address of Device IP TV system on terminal in advance via the EPG server address of network system in the IPTV system of its visit of terminal transmission permission.And, owing to can in subscriber's meter, define the destination address that terminal has the right to visit one or more IPTV system neatly, can realize visit neatly for a plurality of IPTV system, expanded the scope of the IPTV system of terminal could access greatly.
Through the above description of the embodiments, the those skilled in the art can be well understood to the present invention and can realize by the mode that software adds essential general hardware platform, can certainly pass through hardware, but the former is better execution mode under a lot of situation.Based on such understanding, the part that technical scheme of the present invention contributes to prior art in essence in other words can embody with the form of software product, this computer software product is stored in the storage medium that can read, floppy disk as computer, hard disk or CD etc., comprise some instructions with so that computer equipment (can be personal computer, server, the perhaps network equipment etc.) carry out the described method of each embodiment of the present invention.
Above-described embodiment of the present invention does not constitute the qualification to protection range of the present invention.Any modification of being done within the spirit and principles in the present invention, be equal to and replace and improvement etc., all should be included within protection scope of the present invention.