WO2011097804A1 - 媒体流传输密钥操作方法、装置及系统 - Google Patents

媒体流传输密钥操作方法、装置及系统 Download PDF

Info

Publication number
WO2011097804A1
WO2011097804A1 PCT/CN2010/070637 CN2010070637W WO2011097804A1 WO 2011097804 A1 WO2011097804 A1 WO 2011097804A1 CN 2010070637 W CN2010070637 W CN 2010070637W WO 2011097804 A1 WO2011097804 A1 WO 2011097804A1
Authority
WO
WIPO (PCT)
Prior art keywords
key
media
media gateway
lifetime
expiration
Prior art date
Application number
PCT/CN2010/070637
Other languages
English (en)
French (fr)
Inventor
杨玮玮
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201080001613.7A priority Critical patent/CN102812681B/zh
Priority to EP10845478.6A priority patent/EP2487856B1/en
Priority to PT108454786T priority patent/PT2487856E/pt
Priority to HUE10845478A priority patent/HUE027832T2/en
Priority to PCT/CN2010/070637 priority patent/WO2011097804A1/zh
Priority to ES10845478.6T priority patent/ES2583727T3/es
Publication of WO2011097804A1 publication Critical patent/WO2011097804A1/zh
Priority to US13/489,872 priority patent/US9130961B2/en
Priority to US15/692,949 priority patent/USRE48132E1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/10Architectures or entities
    • H04L65/102Gateways
    • H04L65/1043Gateway controllers, e.g. media gateway control protocol [MGCP] controllers
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/06Network architectures or network communication protocols for network security for supporting key management in a packet data network
    • H04L63/068Network architectures or network communication protocols for network security for supporting key management in a packet data network using time-dependent keys, e.g. periodically changing keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/108Network architectures or network communication protocols for network security for controlling access to devices or network resources when the policy decisions are valid for a limited amount of time
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/60Network streaming of media packets
    • H04L65/65Network streaming protocols, e.g. real-time transport protocol [RTP] or real-time control protocol [RTCP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/14Session management
    • H04L67/143Termination or inactivation of sessions, e.g. event-controlled end of session
    • H04L67/145Termination or inactivation of sessions, e.g. event-controlled end of session avoiding end of session, e.g. keep-alive, heartbeats, resumption message or wake-up for inactive or interrupted session

Definitions

  • the present invention relates to the field of communications technologies, and in particular, to a media streaming key operation method, apparatus, and system.
  • a gateway control protocol such as H.248, is usually used as a control protocol between the service layer control entity and the media plane execution entity.
  • the media plane execution entity includes a Media Gateway (MG)
  • the business layer control entity includes a Media Gateway Controller (MGC).
  • the security of the IP service mainly includes two aspects, one is the security of the control plane, and the other is the security of the media plane.
  • RTP Real-Time Transport Protocol
  • IETF Internet Engineering Task Force
  • RTP is responsible for the transmission of multimedia data
  • RTP Control the real-time transmission control protocol
  • RTCP provides services such as quality of service monitoring, congestion control, and media synchronization.
  • RTP provides some privacy and can encrypt RTP payloads. However, its default algorithm is easy to be cracked.
  • the IETF extends the RTP protocol and proposes a Secure Real-time Transport Protocol (SRTP).
  • SRTP Secure Real-time Transport Protocol
  • the session initiation protocol (SIP) is used to negotiate the SRTP key information used in the session, and the key layer is transmitted through the interaction between the service layer control entity and the media plane execution entity, thereby implementing the security function of the media plane.
  • the inventors have found that the prior art has at least the following drawbacks: In the current network scenario, although the reception and use of the media stream transmission key on the support service and the bearer layer are supported, However, it is not possible to operate on the lifetime state of the media streaming key.
  • the embodiment of the invention provides a method, a device and a system for operating a media stream transmission key, so as to solve the problem that the lifetime of the media stream transmission key cannot be operated in the prior art.
  • An embodiment of the present invention provides a media stream transmission key operation method, including:
  • the media gateway detects the lifetime status information of the media streaming key
  • the media gateway determines that the lifetime of the media streaming key expires, the media gateway performs a media streaming key lifetime expiration behavior according to the indication of the media gateway controller.
  • the embodiment of the present invention further provides a media gateway, including a detection module, a determination module, and an operation module: the detection module is configured to detect lifetime status information of the media stream transmission key;
  • the determining module is configured to determine whether the lifetime information of the media streaming key expires; the operation module is configured to: when the determining module determines that the lifetime of the media streaming key expires, according to the media gateway The controller's instructions perform a media streaming key lifetime expiration behavior.
  • the embodiment of the invention further provides a media stream transmission key operating system, including a media gateway controller and a media gateway:
  • the media gateway controller is configured to send a key expiration event to the media gateway
  • the media gateway is configured to receive a key expiration event sent by the media gateway controller, and detect a lifetime status information of the media streaming key according to the key expiration event sent by the received media gateway controller; Whether the lifetime information of the media stream transmission key expires; when it is determined that the lifetime of the media stream transmission key expires, performing a media stream transmission key lifetime expiration behavior according to the indication of the media gateway controller .
  • the media gateway when the media gateway determines that the lifetime of the media streaming key expires, the media gateway performs a media streaming key lifetime expiration behavior according to the indication of the media gateway controller.
  • This embodiment fills in the lifetime state of the media stream transmission key under the MG and MGC separation architecture. Technical gap in operation.
  • FIG. 1 is a flowchart of an embodiment of a method for operating a media stream transmission key according to the present invention
  • FIG. 2 is a flowchart of another embodiment of a method for operating a media stream transmission key according to the present invention
  • FIG. 3 is a flowchart of still another embodiment of a method for operating a media stream transmission key according to the present invention
  • FIG. 5 is a signaling flow diagram of an embodiment provided by the method of the present invention
  • FIG. 6 is a schematic structural diagram of an embodiment of a media gateway according to the present invention.
  • FIG. 7 is a schematic structural diagram of another embodiment of a media gateway according to the present invention.
  • FIG. 8 is a schematic structural diagram of an embodiment of a media gateway controller according to the present invention.
  • FIG. 9 is a schematic structural diagram of an embodiment of a media streaming key operating system according to the present invention.
  • FIG. 1 is a flowchart of an embodiment of a method for operating a media stream transmission key according to the present invention. As shown in FIG. 1, the method in this embodiment includes:
  • Step 101 The media gateway detects lifetime status information of the media stream transmission key.
  • the MG may detect the lifetime status information of the media streaming key based on the received key expiration event.
  • the key expiration event is sent by the media gateway controller to the media gateway, and may also be preset in the media gateway.
  • the embodiment may extend an event in an existing H.248 protocol-based function package or an extended function package.
  • the event may be named as "key expiration” (Key Expi ry )" event, abbreviated as "ke”.
  • key expiration Key Expi ry
  • the MG may be triggered to detect the lifetime status information of the media streaming key.
  • Step 102 When the media gateway determines that the lifetime of the media streaming key expires, the media gateway performs a media streaming key lifetime expiration behavior according to the indication of the media gateway controller.
  • the media gateway detects the lifetime status information of the media stream transmission key, and determines the lifetime status information of the detected media stream transmission key, when the media gateway determines the media stream transmission key.
  • the media gateway may perform a media streaming key lifetime expiration behavior according to the indication of the media gateway controller.
  • the determining condition that the lifetime of the media stream transmission key expires may be that the number of packets transmitted by using the same media stream transmission key reaches the maximum number set by the media stream transmission key. If the media stream transmission key is still not updated, the lifetime of the media stream transmission key can be determined.
  • the MGC may extend a parameter in the "key expiration" event in order to instruct the MG to perform the corresponding media streaming key lifetime expiration behavior.
  • the parameter can be named "Key Li fet ime Expi ry Behaviour” parameter, abbreviated as "kleb”, indicating that the MG performs the corresponding media streaming key survival. Period expiration.
  • the MG receives the media streaming key lifetime expiration behavior parameter indicated by the MGC, the corresponding media streaming key lifetime expiration behavior may be performed when the media streaming key expires.
  • the parameter type of the "key lifetime expiration behavior" parameter can be defined as an enumeration type (Enume ra t ion ), and its possible values include at least one of the following:
  • the media gateway autonomous behavior that is, the media gateway determines the processing behavior (MG de termined ac t ion ), at this time, the media gateway does not need to further instruct the media gateway controller to indicate the processing behavior, for example, the parameter can be defined. Value is 0x0001; or
  • the media gateway closes the media stream and sends a media stream close message (eg, RTCP BYE).
  • a media stream close message eg, RTCP BYE
  • the value of this parameter can be defined as 0x0002; or
  • the media gateway reports the key expiration event to the media gateway controller, and does not send a media stream close message (for example, RTCP BYE).
  • a media stream close message for example, RTCP BYE.
  • the value of this parameter can be defined as 0x0003; or
  • the media gateway reports the key expiration event to the media gateway controller, closes the media stream, and sends a media stream close message (eg, RTCP BYE).
  • a media stream close message eg, RTCP BYE
  • the value of this parameter can be defined as 0x0004.
  • the media gateway sends a media stream close message to the other network entity, for example, a user equipment (UE).
  • the media gateway can send an RTCP BYE message to the bearer layer network entity of the peer end to close the media stream on the bearer plane.
  • the media gateway reports a key expiration event to the media gateway controller, that is, when the MG notifies the MGC through the message of the gateway control protocol, where the key expiration event is carried.
  • an indication parameter of the expiration of the key may be carried in the reported expiration of the key, by using different values of the indication parameter. Indicates whether the current media streaming key is still in use.
  • the indication parameter can be defined as Boolean (Boo lean). When the value is "On”, the number of media stream packets applied by the current media stream transmission key has reached the maximum lifetime of the key lifetime, that is, the current media. The lifetime of the streaming key expires. If the value is "Of f", the number of media stream packets applied to the current media streaming key has not been reached. The maximum period of the key lifetime.
  • the "key lifetime expiration behavior” parameter may be carried in the key expiration event and sent to the MG, and may be separately sent.
  • “Key lifetime expiration behavior” parameter When the key expiration event is pre-set on the media gateway, the MGC issues the "key lifetime expiration behavior” parameter to the MG.
  • the media gateway when the media gateway determines that the lifetime of the media streaming key expires, the media gateway may perform a media streaming key lifetime expiration behavior according to the indication of the media gateway controller.
  • This embodiment fills in the technical blank for performing the lifetime operation of the media stream transmission key under the MG and MGC separation architecture. Moreover, by detecting the lifetime state of the media stream transmission key, secure transmission of the media stream can be achieved.
  • one or more different transport keys are often involved, such as a master key (Sear Key) and a session key (Ses s ion Key).
  • a master key Sear Key
  • Ses s ion Key Ses s ion Key
  • the key expiration "(Key Exp i ry )" event may be embodied.
  • a specific "Ma s ter Key Exp ry” event abbreviated as “mke”. This embodiment may include the steps of:
  • the media gateway When the media gateway receives the "mke" event of the master key issued by the media gateway controller, the media gateway can be triggered to detect the lifetime status information of the media stream transmission master key.
  • the media gateway determines that the lifetime of the media stream transmission master key expires, the media gateway performs a media stream transmission key lifetime expiration behavior according to the indication of the media gateway controller.
  • the media stream transmission key may be classified to implement a lifetime expiration behavior of different types of media stream transmission keys.
  • a "Key Type” parameter abbreviated as "kt”
  • the value may include a master key and a session key, thereby achieving different Detection of the type of media streaming key lifetime status.
  • This embodiment may include the steps of:
  • the media gateway may be triggered to detect the lifetime status information of the specified type of media streaming key.
  • the media gateway determines that the lifetime of the specified type of media streaming key expires, the media gateway performs a media streaming key lifetime expiration according to the indication of the media gateway controller.
  • the MGC indicates a specific method for the MG to perform the corresponding media streaming key lifetime expiration behavior, and the description of Embodiment 1 can be referred to.
  • the media stream transmission key may be identified to implement a lifetime expiration behavior of a specific media stream transmission key.
  • a key identifier (Key Ident if ier), a parameter, abbreviated as "ki”, may be defined in the "key expiration" event, and the value may be a specific key.
  • An example can include the steps:
  • the media gateway may be triggered to detect the lifetime information of the media streaming key of the specified identifier.
  • the media gateway determines that the lifetime of the media streaming key of the specified identifier expires, the media gateway performs a media streaming key lifetime expiration behavior according to the indication of the media gateway controller. For specific judgment conditions, reference may be made to the description of the first embodiment.
  • the MGC indicates a specific method for the MG to perform the corresponding media streaming key lifetime expiration behavior, and the description of Embodiment 1 can be referred to.
  • the media stream transmission key operation method of the present invention may be embodied by the "Key Expi ry" event, or the media stream transmission key may be classified, or may be transmitted to the media stream.
  • the key is identified.
  • the media gateway determines that the lifetime of the media stream transmission key of the specific type or the specified type or the identifier expires, the media gateway performs the media stream transmission key expiration period according to the instruction of the media gateway controller. behavior.
  • the above embodiment of the present invention fills in the technical blank for performing the lifetime operation of the media stream transmission key under the MG and MGC separation architecture. Moreover, by detecting the lifetime state of the media stream transmission key, secure transmission of the media stream can be achieved.
  • FIG. 5 is a signaling flowchart of an embodiment of the method provided by the present invention. As shown in FIG. 5, the method in this embodiment includes:
  • Step 501 The MGC and the MG negotiate key information used by the media stream transmission.
  • the key information may be negotiated and determined by the service layer where the MGC is located, or may be generated and indicated to the MG by the MGC based on the local policy.
  • Step 502 The MG starts to send and receive the media stream protected by the key according to the indication of the MGC, and includes: encrypting the sent media stream, and decrypting the received media stream.
  • Step 503 Taking the user terminal as an example, the MG and the user terminal start secure transmission of the media stream.
  • Step 504 The MGC sends a media stream transmission key lifetime status information detection event request to the MG, where the message includes a "key expiration (ke), an event, and the "key expiration (ke), event carrying" Key lifetime expiration behavior (kleb) parameter.
  • the "key lifetime expiration behavior (kleb)" parameter takes the value "0x0004", that is, when the media streaming key expires, the media gateway expires on the media gateway controller.
  • Event close the media stream, and send a media stream close message (eg, RTCP BYE).
  • Step 505 The MG sends a response message to the MGC.
  • Step 506 The MG detects the lifetime status information of the corresponding media stream transmission key, and determines the lifetime status information of the detected media stream transmission key.
  • Step 507 When the MG determines that the lifetime of the media stream transmission key expires, the MG performs the media stream transmission key lifetime expiration behavior according to the indication of the MGC, and specifically includes reporting the key expiration event to the MGC.
  • Step 508 The MGC sends a response message to the MG.
  • Step 509 The MG performs the media stream transmission key lifetime expiration behavior according to the indication of the MGC, where the MG sends the RTCP BYE message to the user terminal to close the media stream.
  • This embodiment fills in the technical blank for performing the lifetime operation of the media stream transmission key under the MG and MGC separation architecture. Moreover, by detecting the lifetime state of the media stream transmission key, secure transmission of the media stream can be achieved.
  • the key expiration "Key Exp i ry" event can be embodied, for example, to implement the master key.
  • the detection may be performed by a defined "master key expiration mke” event; or the media streaming key may be classified to implement a lifetime expiration behavior of different types of media streaming keys, for example, "The key expires (ke), the event defines a "key type kt” parameter; the media stream transport key can be identified to achieve a specific media stream transport key lifetime expiration behavior, for example You can define a "key identification ki” parameter in the "key expiration (ke),” event, which can be a specific key.
  • the specific signaling flow chart of the above embodiment is not described in detail.
  • the present invention also provides a schematic structural diagram of an embodiment of a media stream transmission key operating device, which is exemplified by a media gateway.
  • FIG. 6 is a schematic structural diagram of an embodiment of a media gateway according to the present invention.
  • the media gateway in this embodiment includes: a detecting module 1 1 , a determining module 12 , and an operating module 13 , wherein the detecting module 1 1 is configured to detect The lifetime status information of the media streaming key; the determining module 12 is configured to determine the media Whether the lifetime information of the streaming key expires; the operation module 13 is configured to perform the media stream transmission according to the instruction of the media gateway controller when the determining module 12 determines that the lifetime of the media streaming key expires Key lifetime expiration behavior.
  • the media gateway in this embodiment corresponds to the media stream transmission key operation method embodiment shown in FIG. 1 , and the specific implementation principle is not described herein.
  • FIG. 7 is a schematic structural diagram of another embodiment of a media gateway according to the present invention.
  • the media gateway in this embodiment includes: a detection module 11, a determination module 12, and an operation module 13, and further includes: a receiving module 14
  • the receiving module 14 is configured to receive a key expiration event sent by the media gateway controller.
  • the detecting module 11 detects the media stream transmission confidentiality according to the key expiration event sent by the media gateway controller received by the receiving module 14.
  • the survival status information of the key the determining module 12 is configured to determine whether the lifetime status information of the media streaming key expires;
  • the operation module 13 is configured to determine, by the determining module 12, the lifetime of the media streaming key Upon expiration, the media streaming key lifetime expiration behavior is performed according to the instructions of the media gateway controller.
  • the receiving module 14 is configured to receive a “master key expired mke” event delivered by the media gateway controller; the detecting module 11 expires according to the master key delivered by the media gateway controller received by the receiving module 14
  • the event module detects the lifetime status information of the media stream transmission master key; the determining module 12 is configured to determine whether the lifetime status information of the media stream transmission master key expires; and the operation module 13 is configured to determine, by the determining module 12 When the lifetime of the media stream transmission master key expires, the media stream transmission key lifetime expiration behavior is performed according to the instruction of the media gateway controller.
  • the media gateway of this embodiment corresponds to the media stream transmission key operation method embodiment shown in FIG. 2, and the specific implementation principle is not described herein.
  • the receiving module 14 is further configured to receive a key expiration event that is sent by the media gateway controller and includes a key type "kt"parameter; the detecting module 11 sends the message according to the media gateway controller received by the receiving module 14 Key expiration event, detecting the lifetime status of a specified type of media streaming key
  • the determining module 12 is configured to determine whether the lifetime information of the specified type of media streaming key expires; the operation module 13 is configured to: when the determining module 12 determines that the lifetime of the specified type of media streaming key expires The media streaming key lifetime expiration behavior is performed according to the instructions of the media gateway controller.
  • the media gateway of this embodiment corresponds to the media stream transmission key operation method embodiment shown in FIG. 3, and the specific implementation principle is not described herein.
  • the receiving module 14 is further configured to receive a key expiration event that is sent by the media gateway controller and includes a key identifier "ki" parameter; the detecting module 11 sends the message according to the media gateway controller received by the receiving module 14 The expiration event of the key expires, detecting the lifetime status information of the media streaming key of the specified identifier; the determining module 12 is configured to determine whether the lifetime status information of the media streaming key of the specified identifier expires; the operation module 13 is configured to: When the judging module 12 judges that the lifetime of the media streaming key of the specified identifier expires, the media streaming key lifetime expiration behavior is performed according to the instruction of the media gateway controller.
  • the media gateway in this embodiment corresponds to the media stream transmission key operation method embodiment shown in FIG. 4, and the specific implementation principle is not described herein.
  • the receiving module 14 is further configured to receive a key expiration event that is sent by the media gateway controller and includes a “Key Li fet ime Expi ry Behaviour” parameter; the operation module 13 is configured to: When the judging module 12 judges that the lifetime of the media streaming key expires, the media stream is executed according to the instruction of the Key Lifetime Expiration Behavior (Key Lifetime Expires Behaviour) parameter delivered by the media gateway controller. The transmission key lifetime expiration behavior.
  • Key Lifetime Expiration Behavior Key Lifetime Expires Behaviour
  • the parameter type of the key lifetime expiration behavior parameter may be an enumerated type (Enume ra t ion ), and the possible values include at least one of the following:
  • the media gateway autonomous behavior that is, the media gateway determines the MG determined act ion, and the media gateway does not need to further instruct the media gateway controller to indicate the
  • the master decides to handle the behavior, for example, this parameter can be defined as 0x0001; or
  • the media gateway closes the media stream and sends a media stream close message (eg, RTCP BYE), for example, this parameter can be defined as 0x0002; or
  • the media gateway reports the key expiration event to the media gateway controller, and does not send a media stream close message (for example, RTCP BYE).
  • a media stream close message for example, RTCP BYE.
  • the parameter may be defined as 0x0003; or
  • the media gateway reports the key expiration event to the media gateway controller, closes the media stream, and sends a media stream close message (eg, RTCP BYE).
  • a media stream close message eg, RTCP BYE
  • this parameter can be defined as 0x0004.
  • the operating module may perform a media streaming key lifetime expiration behavior according to the indication of the media gateway controller.
  • This embodiment fills in the technical blank for performing the lifetime operation of the media stream transmission key under the MG and MGC separation architecture. Moreover, by detecting the lifetime state of the media stream transmission key, secure transmission of the media stream can be achieved.
  • FIG. 8 is a schematic structural diagram of an embodiment of a media gateway controller according to the present invention.
  • the media gateway controller of this embodiment includes: a sending module 11 configured to send a key period to a media gateway. Full event, so that the media gateway detects the lifetime status information of the media streaming key according to the key expiration event. .
  • the sending module 21 is configured to send a "master key expires mke" event to the media gateway.
  • the sending module 21 is configured to send a key expiration event including a key type "kt" parameter to the media gateway.
  • the sending module 21 is configured to send, to the media gateway, a key expiration event that includes a key identifier "ki" parameter.
  • the sending module 21 is configured to send, to the media gateway, a key expiration event including a “Key Li fet ime Expi ry Behaviour” parameter.
  • a key expiration event including a “Key Li fet ime Expi ry Behaviour” parameter.
  • the "closed The key gateway expiration behavior (Key L i fe t ime Exp i y Behav iour ) parameter includes the media gateway controller including the receiving module 22, when the media gateway reports the key expiration event to the media gateway controller, The key expiration event reported by the receiving media gateway.
  • the media gateway controller of this embodiment corresponds to the media stream transmission key operation method embodiment, and the specific implementation principle is not described again.
  • FIG. 9 is a schematic structural diagram of an embodiment of a media streaming key operating system according to the present invention.
  • the media streaming key operating system of this embodiment includes: a media gateway controller 2 and a media gateway 1 , and a media gateway The controller 2 is configured to send a key expiration event to the media gateway 1; the media gateway 1 is configured to receive a key expiration event sent by the media gateway controller 2; according to the received key expiration event delivered by the media gateway controller Detecting the lifetime status information of the media stream transmission key; determining whether the lifetime status information of the media stream transmission key is expired; and when determining that the lifetime of the media stream transmission key expires, controlling according to the media gateway The instructions of the device perform the media streaming key lifetime expiration behavior.
  • the technical blank for performing the lifetime operation of the media stream transmission key under the MG and MGC separation architecture is filled. Moreover, by detecting the lifetime state of the media stream transmission key, secure transmission of the media stream can be achieved.

Description

媒体流传输密钥操作方法、 装置及系统
技术领域
本发明涉及通信技术领域, 尤其涉及一种媒体流传输密钥操作方法、 装 置及系统。
背景技术
在承载与控制分离架构下, 通常釆用网关控制协议, 如 H.248, 作为业务 层控制实体和媒体面执行实体之间的控制协议。在这种机制下,媒体面执行实 体包括媒体网关(Media Gateway, MG ), 而业务层控制实体包括媒体网关控制 器 ( Media Gateway Controller, MGC )。
伴随着 IP业务的广泛使用, 网络中数据传输的安全性问题也变得越来越 重要。 从协议角度来看, IP 业务的安全性主要包括两个方面, 一个是控制面 的安全性, 一个是媒体面的安全性。
实时传输协议 (Real-Time Transport Protocol, RTP )是互联网工程任 务组 ( Internet Engineering Task Force, IETF )制定的一种针对多媒体数 据流传输的协议。 RTP负责多媒体数据的传输,而实时传输控制协议( RTP Control
Protocol, RTCP) 则提供服务质量监控、 拥塞控制以及媒体同步等功能。 RTP 提供了一定的保密性, 可以对 RTP有效载荷进行加密。 不过其默认的算法容易 被破解, IETF对 RTP协议进行了扩展,提出了一种安全实时传输协议(Secure Real-time Transport Protocol, SRTP )。 通常通过会话初始化协议 ( Session Initiation Protocol, SIP )协商会话中使用的 SRTP密钥信息, 通过业务层控制实体与媒体面执行实体的交互进行密钥信息的传递,从而实现 媒体面的安全功能。
在实现本发明的过程中, 发明人发现现有技术至少存在如下缺陷: 在当 前的网络场景中, 虽然支持业务和承载层面上媒体流传输密钥的接收和使用, 但是无法对媒体流传输密钥的生存期状态进行操作。
发明内容
本发明实施例提供一种媒体流传输密钥操作方法、 装置及系统, 以解决 现有技术中无法对媒体流传输密钥的生存期状态进行操作的问题。
本发明实施例提供一种媒体流传输密钥操作方法, 包括:
媒体网关检测媒体流传输密钥的生存期状态信息;
当所述媒体网关判断所述媒体流传输密钥的生存期期满时,所述媒体网关 根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行为。
本发明实施例还提供一种媒体网关,包括检测模块、判断模块和操作模块: 所述检测模块用于检测媒体流传输密钥的生存期状态信息;
所述判断模块用于判断所述媒体流传输密钥的生存期状态信息是否期满; 所述操作模块用于当判断模块判断所述媒体流传输密钥的生存期期满 时, 根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行为。
本发明实施例还提供一种媒体流传输密钥操作系统,包括媒体网关控制器 和媒体网关:
所述媒体网关控制器用于向媒体网关发送密钥期满事件;
所述媒体网关用于接收媒体网关控制器发送的密钥期满事件; 根据接收 的媒体网关控制器下发的密钥期满事件,检测媒体流传输密钥的生存期状态信 息; 判断所述媒体流传输密钥的生存期状态信息是否期满; 当判断所述媒体流 传输密钥的生存期期满时,根据所述媒体网关控制器的指示执行媒体流传输密 钥生存期期满行为。
本发明实施例中, 当媒体网关判断媒体流传输密钥的生存期期满时, 所 述媒体网关根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行为。 本实施例填补了在 MG和 MGC分离架构下, 进行媒体流传输密钥的生存期状态 操作的技术空白。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施 例或现有技术描述中所需要使用的附图作一简单地介绍, 显而易见地, 下面描 述中的附图是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出 创造性劳动性的前提下, 还可以根据这些附图获得其他的附图。
图 1为本发明媒体流传输密钥操作方法一个实施例的流程图;
图 2为本发明媒体流传输密钥操作方法另一个实施例的流程图; 图 3为本发明媒体流传输密钥操作方法再一个实施例的流程图; 图 4为本发明媒体流传输密钥操作方法又再一个实施例的流程图; 图 5为本发明方法提供的一个实施例的信令流程图;
图 6为本发明媒体网关一个实施例的结构示意图;
图 7为本发明媒体网关另一个实施例的结构示意图;
图 8为本发明媒体网关控制器一个实施例的结构示意图;
图 9为本发明媒体流传输密钥操作系统一个实施例的结构示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清 楚、 完整地描述, 显然, 所描述的实施例仅是本发明一部分实施例, 而不是全 部的实施例。基于本发明中的实施例, 本领域普通技术人员在没有做出创造性 劳动前提下所获得的所有其他实施例, 都属于本发明保护的范围。
为了适应不同的应用场景,加强网络对不同安全隐患的防范,往往会部署 各种不同的密钥, 应用于不同的时段、 领域等, 因此网络中存在大量不同的媒 体流传输密钥,每一个传输密钥都会对应不同的生存期, 生存期决定新密钥的 生成时间。 图 1为本发明媒体流传输密钥操作方法一个实施例的流程图,如图 1所示, 本实施例的方法包括:
步骤 101、 媒体网关检测媒体流传输密钥的生存期状态信息。
举例来说, MG 可以根据接收的密钥期满事件, 检测媒体流传输密钥的生 存期状态信息。其中密钥期满事件由媒体网关控制器下发给媒体网关, 当然也 可以在媒体网关上预先设置。
在具体实现过程中,本实施例可以在某个已有的基于 H. 248协议的功能包 中或者扩展功能包中扩展一个事件,比如可以将该事件命名为 "密钥期满(Key Expi ry )" 事件, 缩写为 "ke"。 当 MG接收到 MGC下发的密钥期满事件时, 即 可触发 MG检测媒体流传输密钥的生存期状态信息。
步骤 102、 当所述媒体网关判断所述媒体流传输密钥的生存期期满时, 所 述媒体网关根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行为。
举例来说,媒体网关检测媒体流传输密钥的生存期状态信息, 并对检测到 的媒体流传输密钥的生存期状态信息进行判断,当所述媒体网关判断所述媒体 流传输密钥的生存期期满时,所述媒体网关可以根据媒体网关控制器的指示执 行媒体流传输密钥生存期期满行为。
举例来说, 所述媒体流传输密钥的生存期期满的判断条件可以为,使用相 同媒体流传输密钥传输的报文数目达到该媒体流传输密钥设定的最大数目,这 时, 该媒体流传输密钥仍没有更新, 则可以判断该媒体流传输密钥的生存期期
、/两。
当媒体流传输密钥的生存期期满时, MGC为了指示 MG执行相应的媒体流 传输密钥生存期期满行为, 本实施例可以在所述 "密钥期满" 事件中扩展一个 参数, 比如可以将该参数命名为 "密钥生存期期满行为(Key Li fet ime Expi ry Behaviour )" 参数, 缩写为 "kleb" , 指示 MG执行相应的媒体流传输密钥生存 期期满行为。当 MG接收到 MGC指示的媒体流传输密钥生存期期满行为参数时, 即可在媒体流传输密钥期满时执行相应的媒体流传输密钥生存期期满行为。
举例来说, 可以定义 "密钥生存期期满行为" 参数的参数类型为枚举型 ( Enume ra t ion ), 其可能的取值包括以下的至少一种:
媒体网关自治行为, 即媒体网关自主决定处理行为 (MG de termined ac t ion ), 这时媒体网关不需要再一步请示媒体网关控制器的指示, 而可以自 主决定处理行为, 例如可以定义此参数的取值为 0x0001 ; 或者
媒体网关关闭媒体流, 并且发送媒体流关闭消息 (如, RTCP BYE ), 例如 可以定义此参数的取值为 0x0002 ; 或者
媒体网关向媒体网关控制器上报密钥期满事件, 不发送媒体流关闭消息 (如, RTCP BYE ), 例如可以定义此参数的取值为 0x0003; 或者
媒体网关向媒体网关控制器上报密钥期满事件, 关闭媒体流, 并且发送媒 体流关闭消息 (如, RTCP BYE ), 例如可以定义此参数的取值为 0x0004。
本实施例中, 所述媒体网关发送媒体流关闭消息的发送对象,是承载层上 其它的网络实体, 例如可以是用户设备(User Equi pment , UE )。 媒体网关可 以发送 RTCP BYE消息给对端的承载层网络实体, 来关闭承载面上的媒体流。
本实施例中, 所述媒体网关向所述媒体网关控制器上报密钥期满事件, 即 当 MG通过网关控制协议的消息通报 MGC , 其中携带密钥期满事件。 为了可以 让 MG在媒体流传输密钥生存期期满之前及时通报给 MGC , 还可以在上报的密 钥期满事件中携带一个密钥期满的指示参数,通过该指示参数的不同取值来表 示当前的媒体流传输密钥是否还在继续使用。例如, 该指示参数可以定义为布 尔型(Boo lean ), 取值为 "On" 时表示当前媒体流传输密钥所应用的媒体流报 文数目已经达到密钥生存期的最大期限, 即当前媒体流传输密钥生存期期满; 取值为 "Of f" 时表示当前媒体流传输密钥所应用的媒体流报文数目尚未达到 密钥生存期的最大期限。
本实施例中, 当密钥期满事件由 MGC下发给 MG时, "密钥生存期期满行 为"参数可以携带在密钥期满事件中一起下发给 MG , 当然也可以单独下发 "密 钥生存期期满行为" 参数。 当密钥期满事件在媒体网关上预先设置时, MGC单 独下发 "密钥生存期期满行为" 参数给 MG。
本实施例中, 当媒体网关判断媒体流传输密钥的生存期期满时, 所述媒体 网关可以根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行为。本 实施例填补了在 MG和 MGC分离架构下, 进行媒体流传输密钥的生存期状态操 作的技术空白。 而且通过检测媒体流传输密钥的生存期状态, 可以实现媒体流 的安全传输。
在媒体流传输时, 常常会涉及到一个或多个不同的传输密钥, 比如可以包 括主密钥 (Ma s ter Key )和会话密钥 ( Ses s ion Key )。 在这种情况下, 可以通 过对上述机制进行增强, 以实现对不同粒度的密钥期满操作。
本发明媒体流传输密钥操作方法的另一个实施例中, 可以对密钥期满 "( Key Exp i ry )" 事件具体化。 例如, 要实现对主密钥的检测, 可以通过定义 具体的 "主密钥期满 (Ma s ter Key Exp i ry )" 事件, 缩写为 "mke"。 本实施例 可以包括步骤:
201、当媒体网关接收到媒体网关控制器下发的主密钥期满 "mke"事件时, 即可触发媒体网关检测媒体流传输主密钥的生存期状态信息。
202、 当所述媒体网关判断所述媒体流传输主密钥的生存期期满时, 所述 媒体网关根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行为。
具体的判断条件, 可以参照实施例一的描述。
MGC指示 MG执行相应的媒体流传输密钥生存期期满行为的具体方法, 可 以参照实施例一的描述。 本发明媒体流传输密钥操作方法的再一个实施例中,可以对媒体流传输密 钥进行分类, 实现对不同类别的媒体流传输密钥生存期期满行为。 例如, 可以 在所述 "密钥期满" 事件中定义一个 "密钥类型 (Key Type )" 参数, 缩写为 "kt" , 其取值可以包括主密钥和会话密钥, 从而实现对不同类型的媒体流传 输密钥生存期状态的检测。 本实施例可以包括步骤:
301、 当媒体网关接收到媒体网关控制器下发的包含密钥类型 "kt" 参数 的密钥期满事件时,即可触发媒体网关检测指定类型的媒体流传输密钥的生存 期状态信息。
302、 当所述媒体网关判断指定类型的媒体流传输密钥的生存期期满时, 所述媒体网关根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行 为。
具体的判断条件, 可以参照实施例一的描述。
MGC指示 MG执行相应的媒体流传输密钥生存期期满行为的具体方法, 可 以参照实施例一的描述。
本发明媒体流传输密钥操作方法的又再一个实施例中,可以对媒体流传输 密钥进行标识, 实现对某个具体的媒体流传输密钥生存期期满行为。 例如, 可 以在所述 "密钥期满"事件中定义一个 "密钥标识 ( Key Ident if ier ),,参数, 缩写为 "ki" , 其取值可以是某个具体的密钥。 本实施例可以包括步骤:
401、 当媒体网关接收到媒体网关控制器下发的包含密钥标识 "ki" 参数 的密钥期满事件时,即可触发媒体网关检测指定标识的媒体流传输密钥的生存 期状态信息。
402、 当所述媒体网关判断指定标识的媒体流传输密钥的生存期期满时, 所述媒体网关根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行 为。 具体的判断条件, 可以参照实施例一的描述。
MGC指示 MG执行相应的媒体流传输密钥生存期期满行为的具体方法, 可 以参照实施例一的描述。
本发明媒体流传输密钥操作方法上述实施例中, 可以通过对密钥期满 "( Key Expi ry )" 事件具体化, 或者可以对媒体流传输密钥进行分类、 或者可 以对媒体流传输密钥进行标识, 当媒体网关判断具体的、或者指定类型或标识 的媒体流传输密钥的生存期期满时,所述媒体网关根据媒体网关控制器的指示 执行媒体流传输密钥生存期期满行为。 本发明上述实施例填补了在 MG和 MGC 分离架构下, 进行媒体流传输密钥的生存期状态操作的技术空白。 而且通过检 测媒体流传输密钥的生存期状态, 可以实现媒体流的安全传输。
图 5为本发明方法提供的一个实施例的信令流程图,如图 5所示, 本实施 例的方法包括:
步骤 501、 MGC和 MG协商媒体流传输所釆用的密钥信息。 这里, 密钥信息 可以是 MGC所在业务层协商确定的,也可以是 MGC基于本地策略生成并指示给 MG的。
步骤 502、 MG根据 MGC的指示, 开始对密钥保护的媒体流的收发, 包括: 对发送的媒体流进行加密, 并对接收到的媒体流进行解密。
步骤 503、 以用户终端为例, MG和用户终端开始媒体流的安全传输。 步骤 504、 MGC向 MG发送媒体流传输密钥生存期状态信息检测事件请求, 其中包含 "密钥期满 (ke ),, 事件, 并且所述 "密钥期满 (ke ),, 事件携带 "密 钥生存期期满行为 (kleb )" 参数。 在本例中, "密钥生存期期满行为 (kleb )" 参数取值为 "0x0004" , 即当媒体流传输密钥期满时, 媒体网关向媒体网关控 制器上 "^密钥期满事件, 关闭媒体流, 并且发送媒体流关闭消息 (如, RTCP BYE )。 步骤 505、 MG向 MGC发送应答消息。
步骤 506、 MG检测对应媒体流传输密钥的生存期状态信息, 并对检测到的 媒体流传输密钥的生存期状态信息进行判断。
步骤 507、 MG判断所述媒体流传输密钥的生存期期满时,根据 MGC的指示 执行媒体流传输密钥生存期期满行为, 具体包括向 MGC上报密钥期满事件。
步骤 508、 MGC向 MG发送应答消息。
步骤 509、 MG根据 MGC的指示执行媒体流传输密钥生存期期满行为, 具体 包括 MG向用户终端发送 RTCP BYE消息, 关闭媒体流。
本实施例填补了在 MG和 MGC分离架构下, 进行媒体流传输密钥的生存期 状态操作的技术空白。 而且通过检测媒体流传输密钥的生存期状态, 可以实现 媒体流的安全传输。
以上以某个媒体流传输密钥为例, 当涉及到多个不同的传输密钥时, 可以 对密钥期满 "(Key Exp i ry )" 事件具体化, 例如, 要实现对主密钥的检测, 可 以通过定义的 "主密钥期满 mke"事件; 或者可以对媒体流传输密钥进行分类, 实现对不同类别的媒体流传输密钥生存期期满行为, 例如, 可以在所述 "密钥 期满 (ke ),, 事件中定义一个 "密钥类型 k t " 参数; 可以对媒体流传输密钥 进行标识, 实现对某个具体的媒体流传输密钥生存期期满行为, 例如, 可以在 所述 "密钥期满 (ke ),, 事件中定义一个 "密钥标识 k i " 参数, 其取值可以 是某个具体的密钥。 以上实施例具体的信令流程图不再详述。
本发明还提供了媒体流传输密钥操作装置的实施例的结构示意图,以媒体 网关为例说明。
图 6为本发明媒体网关一个实施例的结构示意图, 如图 6所示, 本实施例 的媒体网关包括: 检测模块 1 1、 判断模块 12和操作模块 1 3 , 该检测模块 1 1 用于检测媒体流传输密钥的生存期状态信息; 判断模块 12用于判断所述媒体 流传输密钥的生存期状态信息是否期满;操作模块 1 3用于当判断模块 12判断 所述媒体流传输密钥的生存期期满时,根据媒体网关控制器的指示执行媒体流 传输密钥生存期期满行为。
本实施例的媒体网关与图 1 所示的媒体流传输密钥操作方法实施例相对 应, 具体实现原理不再赘述。
图 7为本发明媒体网关另一个实施例的结构示意图,如图 7所示, 本实本 实施例的媒体网关包括: 检测模块 11、 判断模块 12和操作模块 1 3 , 还包括: 接收模块 14 , 该接收模块 14用于接收媒体网关控制器下发的密钥期满事件; 所述检测模块 11根据接收模块 14接收的媒体网关控制器下发的密钥期满事 件, 检测媒体流传输密钥的生存期状态信息; 判断模块 12用于判断所述媒体 流传输密钥的生存期状态信息是否期满;操作模块 1 3用于当判断模块 12判断 所述媒体流传输密钥的生存期期满时,根据媒体网关控制器的指示执行媒体流 传输密钥生存期期满行为。
可选的, 接收模块 14用于接收媒体网关控制器下发的 "主密钥期满 mke" 事件;所述检测模块 11根据接收模块 14接收的媒体网关控制器下发的主密钥 期满事件, 检测媒体流传输主密钥的生存期状态信息; 判断模块 12用于判断 所述媒体流传输主密钥的生存期状态信息是否期满; 操作模块 1 3用于当判断 模块 12判断所述媒体流传输主密钥的生存期期满时, 根据媒体网关控制器的 指示执行媒体流传输密钥生存期期满行为。
本实施例的媒体网关与图 2 所示的媒体流传输密钥操作方法实施例相对 应, 具体实现原理不再赘述。
可选的, 接收模块 14 还用于接收媒体网关控制器下发的包含密钥类型 "kt"参数的密钥期满事件; 所述检测模块 11根据接收模块 14接收的媒体网 关控制器下发的密钥期满事件,检测指定类型的媒体流传输密钥的生存期状态 信息; 判断模块 12用于判断指定类型的媒体流传输密钥的生存期状态信息是 否期满;操作模块 13用于当判断模块 12判断所述指定类型的媒体流传输密钥 的生存期期满时,根据媒体网关控制器的指示执行媒体流传输密钥生存期期满 行为。
本实施例的媒体网关与图 3 所示的媒体流传输密钥操作方法实施例相对 应, 具体实现原理不再赘述。
可选的, 接收模块 14 还用于接收媒体网关控制器下发的包含密钥标识 "ki"参数的密钥期满事件; 所述检测模块 11根据接收模块 14接收的媒体网 关控制器下发的密钥期满事件,检测指定标识的媒体流传输密钥的生存期状态 信息; 判断模块 12用于判断指定标识的媒体流传输密钥的生存期状态信息是 否期满;操作模块 13用于当判断模块 12判断所述指定标识的媒体流传输密钥 的生存期期满时,根据媒体网关控制器的指示执行媒体流传输密钥生存期期满 行为。
本实施例的媒体网关与图 4 所示的媒体流传输密钥操作方法实施例相对 应, 具体实现原理不再赘述。
可选的, 接收模块 14还用于接收媒体网关控制器下发的包含 "密钥生存 期期满行为 (Key Li fet ime Expi ry Behaviour )" 参数的密钥期满事件; 操作 模块 13用于当判断模块 12判断所述媒体流传输密钥的生存期期满时,根据媒 体网关控制器下发的 "密钥生存期期满行为 ( Key Lifet ime Expi ry Behaviour )" 参数的指示执行媒体流传输密钥生存期期满行为。
具体的, 可以定义 "密钥生存期期满行为" 参数的参数类型为枚举型 ( Enume ra t ion ), 其可能的取值包括以下的至少一种:
媒体网关自治行为, 即媒体网关自主决定处理行为 (MG determined act ion ), 这时媒体网关不需要再一步请示媒体网关控制器的指示, 而可以自 主决定处理行为, 例如可以定义此参数为 0x0001 ; 或者
媒体网关关闭媒体流, 并且发送媒体流关闭消息 (如, RTCP BYE ), 例如 可以定义此参数为 0x0002; 或者
媒体网关向媒体网关控制器上报密钥期满事件, 不发送媒体流关闭消息 (如, RTCP BYE ), 例如可以定义此参数为 0x0003; 或者
媒体网关向媒体网关控制器上报密钥期满事件, 关闭媒体流, 并且发送媒 体流关闭消息 (如, RTCP BYE ), 例如可以定义此参数为 0x0004。
上述媒体网关实施例中, 当判断模块判断媒体流传输密钥的生存期期满 时,所述操作模块可以根据媒体网关控制器的指示执行媒体流传输密钥生存期 期满行为。 本实施例填补了在 MG和 MGC分离架构下, 进行媒体流传输密钥的 生存期状态操作的技术空白。 而且通过检测媒体流传输密钥的生存期状态, 可 以实现媒体流的安全传输。
图 8为本发明媒体网关控制器一个实施例的结构示意图, 如图 8所示, 本 实施例的媒体网关控制器包括: 发送模块 11, 该发送模块 14用于向媒体网关 下发密钥期满事件, 以使媒体网关根据所述密钥期满事件,检测媒体流传输密 钥的生存期状态信息。。
可选地, 所述发送模块 21 , 用于向媒体网关下发的 "主密钥期满 mke" 事 件。
可选地, 所述发送模块 21 , 用于向媒体网关下发包含密钥类型 "kt" 参 数的密钥期满事件。
可选地, 所述发送模块 21 , 用于向媒体网关下发包含密钥标识 "ki " 参 数的密钥期满事件。
可选地, 所述发送模块 21 , 用于向媒体网关下发包括 "密钥生存期期满 行为 (Key Li fet ime Expi ry Behaviour )" 参数的密钥期满事件。 当所述 "密 钥生存期期满行为 (Key L i fe t ime Exp i ry Behav iour )" 参数包括媒体网关向 媒体网关控制器上报密钥期满事件时, 所述媒体网关控制器还包括接收模块 22 , 用于接收媒体网关上报的密钥期满事件。
本实施例的媒体网关控制器与媒体流传输密钥操作方法实施例相对应,具 体实现原理不再赘述。
图 9 为本发明媒体流传输密钥操作系统一个实施例的结构示意图, 如图 98所示, 本实施例的媒体流传输密钥操作系统包括: 媒体网关控制器 2和媒 体网关 1 , 媒体网关控制器 2用于向媒体网关 1发送密钥期满事件; 媒体网关 1用于接收媒体网关控制器 2发送的密钥期满事件; 根据接收的媒体网关控制 器下发的密钥期满事件,检测媒体流传输密钥的生存期状态信息; 判断所述媒 体流传输密钥的生存期状态信息是否期满;当判断所述媒体流传输密钥的生存 期期满时, 根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行为。
上述系统实施例与媒体流传输密钥操作方法实施例相对应,具体实现原理 不再赘述。
上述系统实施例中, 填补了在 MG和 MGC分离架构下, 进行媒体流传输密 钥的生存期状态操作的技术空白。 而且通过检测媒体流传输密钥的生存期状 态, 可以实现媒体流的安全传输。
最后应说明的是: 以上实施例仅用以说明本发明的技术方案而非对其进 行限制,尽管参照较佳实施例对本发明进行了详细的说明, 本领域的普通技术 人员应当理解: 其依然可以对本发明的技术方案进行修改或者等同替换, 而这 些修改或者等同替换亦不能使修改后的技术方案脱离本发明技术方案的精神 和范围。

Claims

权 利 要求
1、 一种媒体流传输密钥操作方法, 其特征在于, 包括:
媒体网关检测媒体流传输密钥的生存期状态信息;
当所述媒体网关判断所述媒体流传输密钥的生存期期满时,所述媒体网关 根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行为。
2、 根据权利要求 1所述的方法, 其特征在于, 所述媒体网关根据接收的 密钥期满事件,检测媒体流传输密钥的生存期状态信息, 所述密钥期满事件由 所述媒体网关控制器下发给所述媒体网关;或所述密钥期满事件预先设置在所 述媒体网关。
3、 根据权利要求 2所述的方法, 其特征在于, 所述密钥期满事件中包括 密钥类型参数,媒体网关根据媒体网关控制器下发的包含密钥类型参数的密钥 期满事件,检测指定类型的媒体流传输密钥的生存期状态信息; 当所述媒体网 关判断指定类型的媒体流传输密钥的生存期期满时,所述媒体网关根据媒体网 关控制器的指示执行媒体流传输密钥生存期期满行为; 或
所述密钥期满事件中包括密钥标识参数,媒体网关根据媒体网关控制器下 发的包含密钥标识参数的密钥期满事件,检测指定标识的媒体流传输密钥的生 存期状态信息;当所述媒体网关判断指定标识的媒体流传输密钥的生存期期满 时,所述媒体网关根据媒体网关控制器的指示执行媒体流传输密钥生存期期满 行为。
4、 根据权利要求 1所述的方法, 其特征在于, 所述媒体网关根据接收的 主密钥期满事件,检测媒体流传输主密钥的生存期状态信息; 当所述媒体网关 判断所述媒体流传输主密钥的生存期期满时,所述媒体网关根据媒体网关控制 器的指示执行媒体流传输密钥生存期期满行为。
5、 根据权利要求 1所述的方法, 其特征在于, 所述媒体流传输密钥的生 存期期满的判断条件为,使用相同媒体流传输密钥传输的报文数目达到所述媒 体流传输密钥设定的最大数目。
6、 根据权利要求 1-5所述的方法, 其特征在于, 所述媒体网关控制器的 指示包括以下的至少一种:
指示所述媒体网关自主决定处理行为; 或者
指示所述媒体网关关闭媒体流, 并且发送媒体流关闭消息; 或者 指示所述媒体网关上报密钥期满事件, 不发送媒体流关闭消息; 或者 指示所述媒体网关上报密钥期满事件, 关闭媒体流, 并且发送媒体流关闭 消息。
7、 一种媒体网关, 其特征在于, 包括检测模块、 判断模块和操作模块: 所述检测模块用于检测媒体流传输密钥的生存期状态信息;
所述判断模块用于判断所述媒体流传输密钥的生存期状态信息是否期满; 所述操作模块用于当判断模块判断所述媒体流传输密钥的生存期期满时, 根据媒体网关控制器的指示执行媒体流传输密钥生存期期满行为。
8、 根据权利要求 7所述的媒体网关, 其特征在于, 还包括接收模块: 所述接收模块用于接收媒体网关控制器下发的密钥期满事件;
所述检测模块用于根据接收模块接收的媒体网关控制器下发的密钥期满 事件, 检测媒体流传输密钥的生存期状态信息。
9、 根据权利要求 8所述的媒体网关, 其特征在于, 所述接收模块还用于 接收包含密钥类型或密钥标识参数的密钥期满事件;
所述检测模块根据接收模块接收的媒体网关控制器下发的密钥期满事件, 检测指定类型或指定标识的媒体流传输密钥的生存期状态信息;
所述判断模块用于判断指定类型或指定标识的媒体流传输密钥的生存期 状态信息是否期满; 所述操作模块用于当判断模块判断所述指定类型或指定标识的媒体流传 输密钥的生存期期满时,根据媒体网关控制器的指示执行媒体流传输密钥生存 期期满行为。
10、 一种媒体流传输密钥操作系统, 其特征在于, 包括媒体网关控制器和 媒体网关:
所述媒体网关控制器用于向媒体网关发送密钥期满事件;
所述媒体网关用于接收媒体网关控制器发送的密钥期满事件;根据接收的 媒体网关控制器下发的密钥期满事件, 检测媒体流传输密钥的生存期状态信 息; 判断所述媒体流传输密钥的生存期状态信息是否期满; 当判断所述媒体流 传输密钥的生存期期满时,根据所述媒体网关控制器的指示执行媒体流传输密 钥生存期期满行为。
11、 根据权利要求 10所述的系统, 其特征在于, 所述的媒体网关包括权 利要求 7至 9任一所述的媒体网关。
PCT/CN2010/070637 2010-02-11 2010-02-11 媒体流传输密钥操作方法、装置及系统 WO2011097804A1 (zh)

Priority Applications (8)

Application Number Priority Date Filing Date Title
CN201080001613.7A CN102812681B (zh) 2010-02-11 2010-02-11 媒体流传输密钥操作方法、装置及系统
EP10845478.6A EP2487856B1 (en) 2010-02-11 2010-02-11 Media stream transmission key operating method, apparatus and system
PT108454786T PT2487856E (pt) 2010-02-11 2010-02-11 Método,operativo aparelho e sistema de chave de corrente de transmissão de mídia
HUE10845478A HUE027832T2 (en) 2010-02-11 2010-02-11 Procedure, equipment, and system for operating a media stream key
PCT/CN2010/070637 WO2011097804A1 (zh) 2010-02-11 2010-02-11 媒体流传输密钥操作方法、装置及系统
ES10845478.6T ES2583727T3 (es) 2010-02-11 2010-02-11 Método, equipo y sistema de operación para una clave de transmisión de flujos de medios
US13/489,872 US9130961B2 (en) 2010-02-11 2012-06-06 Operating method, apparatus and system for media stream transmission key
US15/692,949 USRE48132E1 (en) 2010-02-11 2017-08-31 Operating method, apparatus and system for media stream transmission key

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2010/070637 WO2011097804A1 (zh) 2010-02-11 2010-02-11 媒体流传输密钥操作方法、装置及系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US13/489,872 Continuation US9130961B2 (en) 2010-02-11 2012-06-06 Operating method, apparatus and system for media stream transmission key

Publications (1)

Publication Number Publication Date
WO2011097804A1 true WO2011097804A1 (zh) 2011-08-18

Family

ID=44367154

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2010/070637 WO2011097804A1 (zh) 2010-02-11 2010-02-11 媒体流传输密钥操作方法、装置及系统

Country Status (7)

Country Link
US (2) US9130961B2 (zh)
EP (1) EP2487856B1 (zh)
CN (1) CN102812681B (zh)
ES (1) ES2583727T3 (zh)
HU (1) HUE027832T2 (zh)
PT (1) PT2487856E (zh)
WO (1) WO2011097804A1 (zh)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9843489B2 (en) * 2013-06-12 2017-12-12 Blackfire Research Corporation System and method for synchronous media rendering over wireless networks with wireless performance monitoring
CN103945449B (zh) * 2013-01-18 2018-12-04 中兴通讯股份有限公司 Csi测量方法和装置
CN103560875B (zh) * 2013-08-27 2016-08-17 兴唐通信科技有限公司 基于h.248协议的专用通道密钥协商方法及装置

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1581858A (zh) * 2003-08-05 2005-02-16 中兴通讯股份有限公司 媒体网关鉴权的方法
CN101513013A (zh) * 2006-09-11 2009-08-19 艾利森电话股份有限公司 下一代网络中用于过载控制的系统和方法
CN101567876A (zh) * 2008-04-21 2009-10-28 华为技术有限公司 上报会话状态的方法、媒体网关和系统

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1667355B1 (en) 2001-02-21 2008-08-20 RPK New Zealand Limited Encrypted media key management
CN1275419C (zh) 2002-10-18 2006-09-13 华为技术有限公司 一种网络安全认证方法
CN100450109C (zh) 2003-07-14 2009-01-07 华为技术有限公司 一种基于媒体网关控制协议的安全认证方法
CN100461780C (zh) 2003-07-17 2009-02-11 华为技术有限公司 一种基于媒体网关控制协议的安全认证方法
US7581100B2 (en) 2003-09-02 2009-08-25 Authernative, Inc. Key generation method for communication session encryption and authentication system
US7592899B2 (en) 2004-06-01 2009-09-22 General Dynamics Advanced Information Systems, Inc. Low power telemetry system and method
US8031872B2 (en) 2006-01-10 2011-10-04 Intel Corporation Pre-expiration purging of authentication key contexts
CN101009551B (zh) * 2006-01-24 2010-12-08 华为技术有限公司 基于ip多媒体子系统的媒体流的密钥管理系统和方法
US8011012B2 (en) * 2006-02-17 2011-08-30 Microsoft Corporation Program substitution
US20070280256A1 (en) * 2006-06-01 2007-12-06 Jan Forslow Systems and methods for providing a heartbeat in a communications network
US20080186952A1 (en) * 2006-08-11 2008-08-07 Huawei Technologies Co., Ltd. Method and system for setting up a multimedia session in multimedia internetworking systems
KR101465263B1 (ko) * 2008-06-11 2014-11-26 삼성전자주식회사 휴대 방송 시스템에서 암호화 키 분배 방법 및 이를 위한시스템
US8331765B2 (en) * 2009-02-27 2012-12-11 Samsung Electronics Co., Ltd. Method and apparatus for protecting against copying contents by using WiHD device

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1581858A (zh) * 2003-08-05 2005-02-16 中兴通讯股份有限公司 媒体网关鉴权的方法
CN101513013A (zh) * 2006-09-11 2009-08-19 艾利森电话股份有限公司 下一代网络中用于过载控制的系统和方法
CN101567876A (zh) * 2008-04-21 2009-10-28 华为技术有限公司 上报会话状态的方法、媒体网关和系统

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP2487856A4 *

Also Published As

Publication number Publication date
EP2487856A4 (en) 2012-11-14
HUE027832T2 (en) 2016-11-28
CN102812681B (zh) 2015-04-15
EP2487856B1 (en) 2016-04-20
US9130961B2 (en) 2015-09-08
CN102812681A (zh) 2012-12-05
ES2583727T3 (es) 2016-09-21
PT2487856E (pt) 2016-06-08
EP2487856A1 (en) 2012-08-15
US20120243555A1 (en) 2012-09-27
USRE48132E1 (en) 2020-07-28

Similar Documents

Publication Publication Date Title
Westerlund et al. Explicit congestion notification (ECN) for RTP over UDP
EP2124379B1 (en) A method and system for distributing secret keys of media stream
EP2892194B1 (en) Media stream transmission method and device
US10469530B2 (en) Communications methods, systems and apparatus for protecting against denial of service attacks
KR20070108825A (ko) 보안 미디어 장치들 간의 스위칭
USRE48132E1 (en) Operating method, apparatus and system for media stream transmission key
WO2011131051A1 (zh) 一种安全通信协商方法和装置
US11218515B2 (en) Media protection within the core network of an IMS network
CN111163040B (zh) 一种重协商的会话重建方法及装置
CN111131182B (zh) 一种VoIP通信网络穿透装置及方法
CN102594781B (zh) Sip防火墙软件中的主备同步机制
WO2011097821A1 (zh) 一种媒体数据重放统计的方法、装置及系统
EP2226985A1 (en) A method for negotiating the redundant transmission
WO2012174945A1 (zh) Ip多媒体子系统中媒体内容监听方法及装置
WO2008083606A1 (fr) Procédé et dispositif de commande de communication d'estampille temporelle d'événement
CN109672692B (zh) 一种VoIP通信网络中基于RTP的媒体数据加密方法
JP2011077890A (ja) 中継装置及びプログラム、中継システム、並びに通信システム
JP4592705B2 (ja) マルチメディアストリーム交換セッションを初期化するためのメッセージを監視する方法と前記方法を実行するためのサーバおよび設備
Streams AVT A. Begen Internet-Draft Cisco Intended status: Standards Track C. Perkins Expires: April 26, 2012 University of Glasgow October 24, 2011
WO2008083620A1 (fr) Procédé, système et appareil pour une négociation de contexte de sécurité de flux multimédia
O’Hanlon et al. Explicit Congestion Notification (ECN) for RTP over UDP draft-ietf-avtcore-ecn-for-rtp-03
Westerlund et al. RFC 6679: Explicit Congestion Notification (ECN) for RTP over UDP
WO2008080335A1 (fr) Système d'interception légale, procédé et serveur d'application
Ott Network Working Group C. Perkins Internet-Draft University of Glasgow Intended status: Standards Track M. Westerlund Expires: September 13, 2012 Ericsson
O’Hanlon et al. Explicit Congestion Notification (ECN) for RTP over UDP draft-westerlund-avt-ecn-for-rtp-01 Status of this Memo This Internet-Draft is submitted to IETF in full conformance with the provisions of BCP 78 and BCP 79.

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201080001613.7

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 10845478

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2010845478

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE