WO2013189392A2 - 基于交互式网络电视的桌面云系统鉴权的方法及系统 - Google Patents
基于交互式网络电视的桌面云系统鉴权的方法及系统 Download PDFInfo
- Publication number
- WO2013189392A2 WO2013189392A2 PCT/CN2013/081915 CN2013081915W WO2013189392A2 WO 2013189392 A2 WO2013189392 A2 WO 2013189392A2 CN 2013081915 W CN2013081915 W CN 2013081915W WO 2013189392 A2 WO2013189392 A2 WO 2013189392A2
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- user
- desktop cloud
- iptv
- server
- user account
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 32
- 230000002452 interceptive effect Effects 0.000 claims description 8
- 230000004044 response Effects 0.000 claims description 5
- 238000012423 maintenance Methods 0.000 abstract description 8
- 238000012545 processing Methods 0.000 abstract description 4
- 238000010586 diagram Methods 0.000 description 4
- 230000001360 synchronised effect Effects 0.000 description 4
- 230000009977 dual effect Effects 0.000 description 3
- 238000005516 engineering process Methods 0.000 description 3
- 230000008569 process Effects 0.000 description 3
- 238000013515 script Methods 0.000 description 3
- 230000003993 interaction Effects 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 230000008520 organization Effects 0.000 description 2
- 230000009286 beneficial effect Effects 0.000 description 1
- 230000000977 initiatory effect Effects 0.000 description 1
- 238000012546 transfer Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/20—Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
- H04N21/25—Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
- H04N21/258—Client or end-user data management, e.g. managing client capabilities, user preferences or demographics, processing of multiple end-users preferences to derive collaborative data
- H04N21/25866—Management of end-user data
- H04N21/25875—Management of end-user data involving end-user authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/20—Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
- H04N21/25—Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
- H04N21/258—Client or end-user data management, e.g. managing client capabilities, user preferences or demographics, processing of multiple end-users preferences to derive collaborative data
- H04N21/25866—Management of end-user data
- H04N21/25891—Management of end-user data being end-user preferences
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/40—Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
- H04N21/43—Processing of content or additional data, e.g. demultiplexing additional data from a digital video stream; Elementary client operations, e.g. monitoring of home network or synchronising decoder's clock; Client middleware
- H04N21/441—Acquiring end-user identification, e.g. using personal code sent by the remote control or by inserting a card
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/40—Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
- H04N21/47—End-user applications
- H04N21/475—End-user interface for inputting end-user data, e.g. personal identification number [PIN], preference data
- H04N21/4751—End-user interface for inputting end-user data, e.g. personal identification number [PIN], preference data for defining user accounts, e.g. accounts for children
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/40—Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
- H04N21/47—End-user applications
- H04N21/475—End-user interface for inputting end-user data, e.g. personal identification number [PIN], preference data
- H04N21/4753—End-user interface for inputting end-user data, e.g. personal identification number [PIN], preference data for user identification, e.g. by entering a PIN or password
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/60—Network structure or processes for video distribution between server and client or between remote clients; Control signalling between clients, server and network components; Transmission of management data between server and client, e.g. sending from server to client commands for recording incoming content stream; Communication details between server and client
- H04N21/63—Control signaling related to video distribution between client, server and network components; Network processes for video distribution between server and clients or between remote clients, e.g. transmitting basic layer and enhancement layers over different transmission paths, setting up a peer-to-peer communication via Internet between remote STB's; Communication protocols; Addressing
- H04N21/643—Communication protocols
- H04N21/64322—IP
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/60—Network structure or processes for video distribution between server and client or between remote clients; Control signalling between clients, server and network components; Transmission of management data between server and client, e.g. sending from server to client commands for recording incoming content stream; Communication details between server and client
- H04N21/65—Transmission of management data between client and server
- H04N21/658—Transmission by the client directed to the server
- H04N21/6582—Data stored in the client, e.g. viewing habits, hardware capabilities, credit card number
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/10—Protocols in which an application is distributed across nodes in the network
Definitions
- the invention relates to a technology for integrating an Internet Protocol TV/Interactive Personal TV (IPTV) set-top box with a desktop cloud client, and particularly relates to a method and system for authenticating a desktop cloud system based on an interactive network television.
- IPTV Internet Protocol TV/Interactive Personal TV
- AD domain control system
- AD is usually deployed as a regular IT system, storing all user information, user passwords, etc. within the organization and acting as an authentication and authentication unit within the organization.
- the desktop cloud system After receiving the authentication request from the user, the desktop cloud system forwards the authentication related information to the AD for authentication. After the authentication is passed, the user's desktop is obtained. The information is returned to the client in order to use the desktop cloud normally.
- the IPTV server authenticates the user by using the user account and the user token, and sends the authentication result to the desktop cloud server.
- the method further includes:
- the desktop cloud server saves the received user account.
- the IPTV set top box sends an authentication request for requesting a user token to the IPTV server, and receives an encryption token that the server responds to the authentication request;
- the IPTV set-top box encrypts the user account, the encryption token, the IPTV set-top box account, the Internet Protocol (IP) address of the desktop cloud client, and the Media Access Control (MAC) address to generate an encryption. a string and send it to the IPTV server;
- IP Internet Protocol
- MAC Media Access Control
- the IPTV server authenticates the encrypted character string, and when the authentication is successful, sends an authentication success message including the user token to the IPTV set top box.
- the method further includes: when the desktop cloud server does not find the user account in all user accounts saved by itself, generating a message that the authentication fails, and sending the message to the desktop cloud client.
- the IPTV server searches for the user account in all user accounts saved by itself, and determines the validity of the user token
- the desktop cloud server When the desktop cloud server receives the successful authentication message, it will include the authentication of the virtual desktop information.
- the success message is sent to the desktop cloud client, and the virtual desktop information is information used by the desktop cloud client to access the cloud desktop.
- the method further includes:
- the desktop cloud server When the desktop cloud server receives the message that the authentication fails, the authentication failure message containing the error information is sent to the desktop cloud client, so that the desktop cloud client notifies the IPTV set-top box to re-request the effective request to the IPTV server according to the error information.
- User token When the desktop cloud server receives the message that the authentication fails, the authentication failure message containing the error information is sent to the desktop cloud client, so that the desktop cloud client notifies the IPTV set-top box to re-request the effective request to the IPTV server according to the error information.
- a system for IPTV-based desktop cloud system authentication including:
- the desktop cloud client is configured to automatically generate a user authentication request including a user account and a user token when the user starts the desktop cloud client, and send the request to the desktop cloud server.
- the desktop cloud server is configured to save a user account of the interactive network television IPTV server that needs to use the desktop cloud server, and when receiving the user authentication request, search for the user account in all user accounts saved by itself, when the user is found
- the user account and the user token are sent to the IPTV server, and the desktop cloud server includes the user account of the IPTV server that needs to use the desktop cloud server in all user accounts saved by the desktop cloud server;
- the IPTV server is configured to authenticate the user by using the user account and the user token, and send the authentication result to the desktop cloud server, so that the desktop cloud server performs corresponding processing.
- the system further comprises:
- the IPTV set-top box is configured to deliver the user account and the user token to the desktop cloud client when the user initiates the convergence of the desktop cloud client in the IPTV set-top box.
- the user can complete the authentication without using any account information when using the desktop cloud system to improve the user experience
- the desktop cloud system uses the IPTV account directly or according to specific rules, the administrator does not need a single Maintaining a desktop cloud system account exclusively reduces the maintenance workload and reduces the operation and maintenance costs.
- FIG. 1 is a schematic block diagram of a method for authenticating an IPTV-based desktop cloud system according to an embodiment of the present invention
- FIG. 2 is a system structural diagram of an IPTV-based desktop cloud system authentication according to an embodiment of the present invention
- FIG. 1 is a schematic block diagram of a method for authenticating an IPTV-based desktop cloud system according to an embodiment of the present invention. As shown in FIG. 1, the steps include:
- the desktop cloud server sends a request for user account synchronization to the IPTV server; after receiving the request, the IPTV server sends all user accounts that need to use the desktop cloud server to the desktop cloud server. ; The desktop cloud server saves the received user account.
- the desktop cloud client when the user starts the desktop cloud client, the desktop cloud client obtains the user account and the user token from the IPTV set-top box that is merged with the user, and generates the user account and the user token.
- User authentication request In the IPTV set top box
- the IPTV set-top box In a preferred embodiment in which the user account and the user token are saved, and the IPTV set-top box acquires the user token, the IPTV set-top box sends an authentication request for requesting the user token to the IPTV server, and receives the server response to the authentication request.
- the IPTV set-top box encrypts the user account, the encryption token, the IPTV set-top box account, the IP address and the MAC address of the desktop cloud client, generates an encrypted string, and sends the encrypted string to the IPTV server;
- the encrypted string is authenticated, and when the authentication is successful, an authentication success message including the user token is sent to the IPTV set top box.
- Step 103 The desktop cloud server searches for the user account number in all user accounts saved by itself, and sends the user account and the user token to the IPTV server when the user account is found.
- step 103 when the desktop cloud server does not find the user account in all user accounts saved by itself, a message that the authentication fails is generated and sent to the desktop cloud client.
- the desktop cloud server 23 ie, the desktop cloud system
- the user account UserlD and the user token of the IPTV set top box are used, and the user account and the user token are sent to the desktop cloud server 23, the desktop.
- the cloud server 23 uses the user account and the user token to authenticate to the IPTV server 22.
- FIG. 3 is a flowchart of acquiring a user token by an IPTV set top box according to an embodiment of the present invention. As shown in FIG. 3, the steps include:
- Step 304 The IPTV set top box generates an encrypted character string.
- the IPTV set-top box uploads the encrypted string to the IPTV service management platform through an HTTP push (Post) manner.
- Step 306 to step 307 The IPTV service management platform authenticates the encrypted character string and returns a user token when the authentication is successful.
- the IPTV service management platform verifies the encrypted string, and after verifying, returns the authentication result in the form of an extended js script through the HTTP response Response, and sends the user token to the IPTV set-top box when the authentication is successful, and sets the resource server list and other information. .
- FIG. 4 is a flowchart of a desktop cloud system authentication according to an embodiment of the present invention.
- a desktop cloud system (desktop cloud server)
- the account synchronization interface of the desktop cloud system is used to set the user account of the IPTV service management platform (IPTV server).
- IPTV server IPTV service management platform
- the user account of the desktop cloud system is used to synchronize to the desktop cloud system, and the desktop cloud system allocates a virtual desktop to the corresponding user according to the synchronized user account.
- the desktop cloud system During the operation of the desktop cloud system, if the user of the IPTV set-top box newly opens an account and needs to use the desktop cloud system, the user account of the IPTV set-top box is synchronized to the desktop cloud system in real time, and the desktop cloud system creates a virtual desktop for the newly synchronized user account. .
- the IPTV set-top box After the IPTV set-top box is activated, the IPTV set-top box
- the user token is automatically requested from the flow illustrated in FIG. 3 to the IPTV service management platform, and the obtained user token is saved in the IPTV set top box.
- the desktop cloud client that is, the desktop cloud client software is started
- the desktop cloud client software automatically starts the authentication process of the desktop cloud system. As shown in FIG. 4, the following steps are included:
- Step 401 The desktop cloud client carries the acquired user account and the user token in the user authentication request, and initiates an authentication request to the desktop cloud system.
- the desktop cloud client software When the user starts the desktop cloud client, the desktop cloud client software reads the user information such as UserlD and the user token obtained by the user after being authenticated by the IPTV service management platform, and the user authentication request is obtained from the IPTV set-top box merged with the desktop cloud client. Carrying the obtained user account and the user token of the user, and initiating an authentication request to the desktop cloud system by using HTTP or socket.
- Step 402 The desktop cloud system sends information such as the User ID and the user token carried by the user authentication request to the IPTV system (or the IPTV service management platform and the IPTV server) for authentication.
- the desktop cloud system After receiving the user authentication request, the desktop cloud system first searches for the existence of the user in the system. If the user account is not in the desktop cloud system, the user account is not successfully synchronized or is not authorized to use the desktop cloud. The user of the system, the desktop cloud system authentication failed. If the user account is in the desktop cloud system, the user ID and the user token carried by the user authentication request are sent to the IPTV system (or the IPTV service management platform and the IPTV server) by using HTTP or Socket. Authentication.
- Step 404 The IPTV service management platform notifies the authentication information of the desktop cloud system user.
- the IPTV service management platform notifies the desktop cloud system of the authentication result of the user in the HTTP or Socket mode, that is, the message that the authentication succeeds or the authentication fails.
- Step 405 The desktop cloud system sends the authentication information to the desktop cloud client.
- the desktop cloud system fails to be authenticated.
- the desktop cloud system immediately returns an authentication failure message containing the error information to the desktop cloud client, and the desktop cloud client receives the authentication.
- the authentication module of the IPTV set-top box is notified of the correct user token to the IPTV system, and the user token is re-acquired, and then steps 401 to 404 are repeated; after the desktop cloud system receives the authentication success message of the IPTV system, The HTTP and Sockets are used to notify the desktop cloud client that the authentication is successful.
- the virtual desktop information is carried in the reply success message, and step 406 is performed.
- Step 406 The client accesses the cloud desktop.
- the client software automatically accesses the cloud desktop according to the returned virtual desktop information, and uses various desktop cloud functions.
- the user account that needs to use the desktop cloud server in the IPTV server is saved to the desktop cloud server; when the user starts the desktop cloud client, the desktop cloud client automatically generates the user account and the user token.
- the user authentication request is sent to the desktop cloud server; the desktop cloud server searches for the user account in all the user accounts saved by itself, and sends the user account and the user token when the user account is found.
- the IPTV server authenticates the user by using the user account and the user token, and sends the authentication result to the desktop cloud server, and the desktop cloud server performs corresponding processing according to the authentication result.
- the technical solution of the embodiment of the invention improves the user experience and reduces the maintenance worker. The amount of operation reduces the cost of operation and maintenance.
Landscapes
- Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Multimedia (AREA)
- Databases & Information Systems (AREA)
- Computer Security & Cryptography (AREA)
- Computer Graphics (AREA)
- Human Computer Interaction (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computer Hardware Design (AREA)
- Health & Medical Sciences (AREA)
- Child & Adolescent Psychology (AREA)
- General Health & Medical Sciences (AREA)
- Information Transfer Between Computers (AREA)
- Computer And Data Communications (AREA)
- Telephonic Communication Services (AREA)
Abstract
本发明实施例公开一种基于交互式网络电视(IPTV)的桌面云系统鉴权的方法及系统,所述方法包括:将IPTV服务器中需要使用桌面云服务器的用户账号保存至桌面云服务器;当用户启动桌面云客户端时,桌面云客户端将自动生成的包含用户账号和用户令牌的用户鉴权请求发送至桌面云服务器;桌面云服务器查找所述用户账号,并在找到所述用户账号时,将所述用户账号和所述用户令牌发送至IPTV服务器;IPTV服务器利用所述用户账号和所述用户令牌,对用户进行鉴权,并将鉴权结果发送至桌面云服务器,由桌面云服务器根据鉴权结果进行相应处理。通过本发明实施例的技术方案,能够提高用户体验,减少维护工作量,降低运维成本。
Description
基于交互式网络电视的桌面云系统鉴权的方法及系统 技术领域
本发明涉及交互式网络电视 ( IPTV , Internet Protocol TV/Interactive Personal TV )机顶盒与桌面云客户端融合的技术, 特别涉及一种基于交互 式网络电视的桌面云系统鉴权的方法及系统。 背景技术
随着云计算系统的不断成熟与普及, 桌面云系统等云计算技术逐渐应 用到酒店、 家庭等用户场景。
传统的 IPTV业务模式中, IPTV机顶盒使用 IPTV 系统的业务运营平 台接口进行鉴权等交互, 通过 IPTV用户密码( IPTV Password )或 IPTV 客户识别模块(SIM )卡密钥 ICKey、 用户令牌(UserToken )协同完成。 IPTV在接入认证过程中,使用用户密码或 IPTV SIM卡密钥通过安全认证, 并将获取到的 UserToken作为当前交互过程的认证凭据。 UserToken在超过 有效期、终端浏览器关闭连接、终端退出业务使用后失效。 当 UserToken超 出其有效期时, 系统判定其为失效, 并自动将终端重定向至 IPTV业务管理 平台进行重新认证, 认证结束继续使用服务。
普通的桌面云系统中, 为了保持用户账号系统并对其合法性进行校验 需要部署一套域控系统 AD。 AD通常作为常规的 IT系统进行部署,保存了 组织内的全部用户信息、 用户密码等, 并作为组织内的鉴权认证单元。 当 用户使用桌面云系统时, 在桌面云系统输入正确的账号、 密码, 桌面云系 统收到用户的鉴权请求后把鉴权相关信息转发给 AD进行鉴权, 鉴权通过 后把用户的桌面信息返回给客户端才能正常使用桌面云。
在桌面云系统与 IPTV机顶盒进行融合的场景中,用户已经习惯了 IPTV 不需要输入账号进行认证的使用方式。 如果在融合了桌面云系统客户端与
IPTV机顶盒的双模终端中使用桌面云系统需要用户输入账号及密码, 则和 用户原来使用 IPTV业务差异很大、用户体验非常不友善,不利于业务推广, 且桌面云系统客户端与 IPTV机顶盒对应的两套账号系统给维护工作带来 了很大的工作量。 发明内容
本发明实施例的目的在于提供一种基于 IPTV 的桌面云系统鉴权方法 及系统,能解决相关技术中 IPTV机顶盒与桌面云系统相融合的双模终端用 户体验差和账号维护工作量大的问题。
根据本发明实施例的一个方面,提供了一种基于 IPTV的桌面云系统鉴 权的方法, 包括:
当用户启动桌面云客户端时, 桌面云客户端自动生成包含用户账号和 用户令牌的用户鉴权请求, 并发送至桌面云服务器;
桌面云服务器在自身保存的所有用户账号中查找所述用户鉴权请求包 含的用户账号, 并在查找到所述用户账号时, 将所述用户账号和所述用户 令牌发送至 IPTV服务器, 其中, 桌面云服务器在自身保存的所有用户账号 中包含 IPTV服务器中需要使用桌面云服务器的用户账号;
IPTV服务器利用所述用户账号和所述用户令牌, 对用户进行鉴权, 并 将鉴权结果发送至桌面云服务器。
优选地, 所述方法还包括:
桌面云服务器向 IPTV服务器发送用于用户账号同步的请求;
IPTV服务器收到所述请求后, 将所有需要使用桌面云服务器的用户账 号发送至桌面云服务器;
桌面云服务器保存所收到的用户账号。
优选地, 所述桌面云客户端自动生成包含用户账号和用户令牌的用户 鉴权请求, 包括:
当用户启动桌面云客户端时, 桌面云客户端从与桌面云客户端融合的
IPTV机顶盒中获取用户账号和用户令牌, 并生成包含所述用户账号和用户 令牌的用户鉴权请求。
优选地,所述桌面云客户端从与其融合的 IPTV机顶盒中获取用户账号 和用户令牌之前, 所述方法还包括:
IPTV机顶盒向 IPTV服务器发送用于请求用户令牌的认证请求, 并接 收所述服务器响应所述认证请求的加密令牌;
IPTV机顶盒对所述用户账号、 所述加密令牌、 IPTV机顶盒账号、 桌 面云客户端的网际协议( IP, Internet Protocol )地址和媒体接入控制( MAC, Media Access Control )地址进行加密处理,生成加密字符串,并发送至 IPTV 服务器;
IPTV服务器对所述加密字符串进行认证, 并在认证成功时, 将包含用 户令牌的认证成功消息发送至 IPTV机顶盒。
优选地, 所述方法还包括: 当桌面云服务器在自身保存的所有用户账 号中未找到所述用户账号时, 生成鉴权失败的消息, 并发送至桌面云客户 端。
优选地,所述 IPTV服务器利用所述用户账号和所述用户令牌对用户进 行鉴权, 包括:
IPTV服务器在自身保存的所有用户账号中查找所述用户账号, 并确定 所述用户令牌的有效性;
若能够找到所述用户账号, 且所述用户令牌有效, 则生成鉴权成功的 消息, 并发送至桌面云服务器, 否则生成鉴权失败的消息, 并发送至桌面 云服务器。
优选地, 所述方法还包括:
当桌面云服务器收到鉴权成功的消息时, 将包含虚拟桌面信息的鉴权
成功消息发送至桌面云客户端, 所述虚拟桌面信息为桌面云客户端接入云 桌面所使用的信息。
优选地, 所述方法还包括:
当桌面云服务器收到鉴权失败的消息时, 将包含错误信息的鉴权失败 消息发送至桌面云客户端,以便桌面云客户端根据所述错误信息,通知 IPTV 机顶盒向 IPTV服务器重新请求有效的用户令牌。
根据本发明实施例的另一方面,提供了一种基于 IPTV的桌面云系统鉴 权的系统, 包括:
桌面云客户端, 配置为当用户启动桌面云客户端时, 自动生成包含用 户账号和用户令牌的用户鉴权请求, 并发送至桌面云服务器;
桌面云服务器,配置为保存交互式网络电视 IPTV服务器中需要使用桌 面云服务器的用户账号, 并在收到用户鉴权请求时, 在自身保存的所有用 户账号中查找所述用户账号, 当找到所述用户账号时, 将所述用户账号和 所述用户令牌发送至 IPTV服务器,桌面云服务器在自身保存的所有用户账 号中包含 IPTV服务器中需要使用桌面云服务器的用户账号;
IPTV服务器, 配置为利用所述用户账号和所述用户令牌, 对用户进行 鉴权, 并将鉴权结果发送至桌面云服务器, 以便桌面云服务器进行相应处 理。
优选地, 所述系统还包括:
IPTV机顶盒, 配置为当用户启动融合在 IPTV机顶盒内桌面云客户端 时, 将用户账号和用户令牌传递给桌面云客户端。
与相关技术相比较, 本发明实施例的有益效果在于:
1、 用户在使用桌面云系统时无需输入任何账号信息即可完成认证, 提 高用户体验;
2、 桌面云系统直接或者根据特定规则使用 IPTV账号, 管理员无需单
独维护桌面云系统账号, 减少了维护工作量, 降低了运维成本。 附图说明
图 1是本发明实施例提供的基于 IPTV的桌面云系统鉴权的方法原理框 图;
图 2是本发明实施例提供的基于 IPTV的桌面云系统鉴权的系统结构 图;
图 3是本发明实施例提供的 IPTV机顶盒获取用户令牌的流程图; 图 4是本发明实施例提供的桌面云系统认证流程图。 具体实施方式
以下结合附图对本发明的优选实施例进行详细说明, 应当理解, 以下 所说明的优选实施例仅用于说明和解释本发明, 并不用于限定本发明。
图 1是本发明实施例提供的基于 IPTV的桌面云系统鉴权的方法原理框 图, 如图 1所示, 步驟包括:
步驟 101: 将交互式网络电视 IPTV服务器中需要使用桌面云服务器的 用户账号保存至桌面云服务器。
在步驟 101—个优选的实施方式中,桌面云服务器向 IPTV服务器发送 用于用户账号同步的请求; IPTV服务器收到所述请求后, 将所有需要使用 桌面云服务器的用户账号发送至桌面云服务器; 桌面云服务器保存所收到 的用户账号。
步驟 102: 当用户启动桌面云客户端时, 桌面云客户端自动生成包含用 户账号和用户令牌的用户鉴权请求, 并发送至桌面云服务器。
在步驟 102—个优选的实施方式中, 当用户启动桌面云客户端时, 桌 面云客户端从与其融合的 IPTV机顶盒中获取用户账号和用户令牌,并生成 包含所述用户账号和用户令牌的用户鉴权请求。 其中, 所述 IPTV机顶盒中
保存有用户账号和用户令牌,在 IPTV机顶盒获取用户令牌的一个优选的实 施方式中, IPTV机顶盒向 IPTV服务器发送用于请求用户令牌的认证请求, 并接收所述服务器响应所述认证请求的加密令牌; IPTV机顶盒对所述用户 账号、 所述加密令牌、 IPTV机顶盒账号、 桌面云客户端的 IP地址和 MAC 地址进行加密处理, 生成加密字符串, 并发送至 IPTV服务器; IPTV服务 器对所述加密字符串进行认证, 并在认证成功时, 将包含用户令牌的认证 成功消息发送至 IPTV机顶盒。
步驟 103:桌面云服务器在自身保存的所有用户账号中查找所述用户账 号 ,并在找到所述用户账号时 ,将所述用户账号和所述用户令牌发送至 IPTV 服务器。
在步驟 103 的一个优选的实施方式中, 当桌面云服务器在自身保存的 所有用户账号中未找到所述用户账号时, 生成鉴权失败的消息, 并发送至 桌面云客户端。
步驟 104: IPTV服务器利用所述用户账号和所述用户令牌, 对用户进 行鉴权, 并将鉴权结果发送至桌面云服务器。
在步驟 104的一个优选的实施方式中, IPTV服务器在自身保存的所有 用户账号中查找所述用户账号, 并确定所述用户令牌的有效性; 若能够找 到所述用户账号, 且所述用户令牌有效, 则生成鉴权成功的消息, 并发送 至桌面云服务器, 否则生成鉴权失败的消息, 并发送至桌面云服务器。
步驟 104之后, 当桌面云服务器收到鉴权成功的消息时, 将包含虚拟 桌面信息的鉴权成功消息发送至桌面云客户端, 以便桌面云客户端根据所 述虚拟桌面信息接入云桌面; 当桌面云服务器收到鉴权失败的消息时, 将 包含错误信息的鉴权失败消息发送至桌面云客户端, 以便桌面云客户端根 据所述错误信息, 通知 IPTV机顶盒向 IPTV服务器重新请求有效的用户令 牌。
图 2是本发明实施例提供的基于 IPTV的桌面云系统鉴权的系统结构 图, 如图 2所示, 包括: 双模终端 21、 IPTV服务器 22、 桌面云服务器 23。
当用户使用桌面云服务器 23(即桌面云系统)并向其鉴权时,使用 IPTV 机顶盒的用户账号 UserlD和用户令牌, 即将所述用户账号和所述用户令牌 发送到桌面云服务器 23,桌面云服务器 23使用所述用户账号和所述用户令 牌到 IPTV服务器 22进行验证。
其中, 所述双模终端 21融合了桌面云客户端与 IPTV机顶盒, 当用户 启动桌面云客户端时, 所述桌面云客户端自动生成包含用户账号和用户令 牌的用户鉴权请求, 并发送至桌面云服务器 23; 当用户启动融合在双模终 端 21 内的桌面云客户端时, 所述双模终端 21将用户账号和用户令牌传递 给桌面云客户端, 以便所述桌面客户端生成包含所述用户账号和用户令牌 的用户鉴权请求;所述桌面云服务器保存交互式网络电视 IPTV服务器中需 要使用桌面云服务器的用户账号, 并在收到用户鉴权请求时, 在自身保存 的所有用户账号中查找所述用户鉴权请求中的用户账号, 当查找到所述用 户账号时, 将所查找到的用户账号和所述用户令牌发送至 IPTV服务器 22; 所述 IPTV服务器 22利用所述用户账号和所述用户令牌, 对用户进行 鉴权, 并将鉴权结果发送至桌面云服务器 23 , 以便桌面云服务器 23进行相 应处理。
图 3是本发明实施例提供的 IPTV机顶盒获取用户令牌的流程图,如图 3所示, 步驟包括:
步驟 301: IPTV机顶盒( STB ) 向 IPTV业务管理平台请求用户令牌。
IPTV机顶盒通过超文本传输协议( HTTP , HyperText Transfer Protocol ) 请求( GET )方式向 IPTV业务管理平台 (即 IPTV服务器)发送用于请求 用户令牌的认证请求, 请求中包括用户账号 User ID等信息。
步驟 302: IPTV业务管理平台生成加密令牌。
IPTV业务管理平台生成随机的加密令牌 EncryToken字段,该字段中包 括加密令牌等用于认证加密的挑战字。
步驟 303: IPTV业务管理平台返回用户令牌。
IPTV业务管理平台通过 HTTP响应方式返回包含扩展加密 js脚本、 EncryToken等内容的页面。
步驟 304: IPTV机顶盒生成加密字符串。
IPTV机顶盒通过调用扩展加密 js脚本中的扩展 js函数对 EncryToken、 User ID、 机顶盒账号 ( STB ID )、 IPTV机顶盒的 IP地址和 MAC地址等信 息进行加密, 生成加密字符串。
步驟 305: IPTV机顶盒所生成的加密字符串上传到 IPTV业务管理平
IPTV机顶盒通过 HTTP推送( Post )方式将所述加密字符串上传到 IPTV 业务管理平台。
步驟 306〜步驟 307: IPTV业务管理平台认证所述加密字符串, 并在 认证成功时返回用户令牌。
IPTV业务管理平台进行验证所述加密字符串, 验证通过后通过 HTTP 响应 Response以扩展 js脚本的形式返回认证结果, 并在认证成功时将用 户令牌发送给 IPTV机顶盒, 并设置资源服务器列表等信息。
图 4是本发明实施例提供的桌面云系统认证流程图,在桌面云系统(桌 面云服务器)建设时,使用桌面云系统的账号同步接口把 IPTV业务管理平 台 (IPTV服务器)的用户账号中需要使用桌面云系统的用户账号同步到桌 面云系统, 桌面云系统根据同步的用户账号为对应用户分配虚拟桌面。 桌 面云系统运行过程中,如果有 IPTV机顶盒的用户新开户且需要使用桌面云 系统, 则实时把 IPTV机顶盒的用户账号同步到桌面云系统, 并由桌面云系 统为新同步的用户账号创建虚拟桌面。 IPTV机顶盒启动后, IPTV机顶盒
自动根据图 3所说明的流程到 IPTV业务管理平台请求用户令牌,并把得到 的用户令牌保存在 IPTV机顶盒中。 当用户启动桌面云客户端(即启动桌面 云客户端软件) 时, 桌面云客户端软件自动启动桌面云系统的认证流程, 如图 4所示, 包括以下步驟:
步驟 401:桌面云客户端在用户鉴权请求中携带所获取用户账号和用户 令牌, 向桌面云系统发起鉴权请求。
当用户启动桌面云客户端时,桌面云客户端软件从与其融合的 IPTV机 顶盒读取 UserlD等用户信息以及该用户在 IPTV业务管理平台通过认证后 所得到的用户令牌, 并在用户鉴权请求中携带所获取的该用户的所述用户 账号和所述用户令牌, 以 HTTP、 套接字 (Socket )方式向桌面云系统发起 鉴权请求。
步驟 402: 桌面云系统将所述用户鉴权请求携带过来的 User ID、 用户 令牌等信息发送给 IPTV系统(或 IPTV业务管理平台、 IPTV服务器)进 行鉴权。
桌面云系统收到所述用户鉴权请求后, 先在自身系统中查找是否有该 用户存在, 如果在桌面云系统中没有该用户账号, 则说明该用户账号未成 功同步或者是非授权使用桌面云系统的用户, 桌面云系统鉴权失败。 如果 在桌面云系统中有该用户账号,则把所述用户鉴权请求携带过来的 User ID、 用户令牌等信息以 HTTP、 Socket方式发送给 IPTV系统(或 IPTV业务管 理平台、 IPTV服务器 )进行鉴权。
步驟 403: IPTV系统验证用户令牌有效性。
IPTV系统收到桌面云系统的认证请求后, 首先根据 User ID判断所述 用户是否是本系统的用户, 然后再判断用户令牌是否正确且没有超期, 如 果以上两点均满足则为合法用户, 鉴权成功, 否则鉴权失败。
步驟 404: IPTV业务管理平台通知桌面云系统用户的鉴权信息。
IPTV业务管理平台以 HTTP、 Socket方式通知桌面云系统该用户的鉴 权结果, 即发送鉴权成功或鉴权失败的消息。
步驟 405: 桌面云系统将鉴权信息发送给桌面云客户端。
步驟 403、步驟 404中的任意一个执行不成功都会导致桌面云系统鉴权 失败, 桌面云系统马上返回包含错误信息的鉴权失败消息给桌面云客户端, 桌面云客户端收到所述鉴权失败消息后, 通知 IPTV机顶盒的鉴权模块向 IPTV 系统请求正确的用户令牌, 重新获取用户令牌后再次重复执行步驟 401〜步驟 404; 桌面云系统收到 IPTV 系统鉴权成功消息后, 以 HTTP、 Socket方式通知桌面云客户端鉴权成功, 在回复的鉴权成功消息中携带虚 拟桌面信息, 并执行步驟 406。
步驟 406: 客户端接入云桌面。
客户端软件根据返回的所述虚拟桌面信息自动接入云桌面, 使用各项 桌面云的功能。
尽管上文对本发明进行了详细说明, 但是本发明不限于此, 本技术领 域技术人员可以根据本发明的原理进行各种修改。 因此, 凡按照本发明原 理所作的修改, 都应当理解为落入本发明的保护范围。 工业实用性
本发明实施例的技术方案中,将 IPTV服务器中需要使用桌面云服务器 的用户账号保存至桌面云服务器; 当用户启动桌面云客户端时, 桌面云客 户端自动生成包含用户账号和用户令牌的用户鉴权请求, 并发送至桌面云 服务器; 桌面云服务器在自身保存的所有用户账号中查找所述用户账号, 并在找到所述用户账号时,将所述用户账号和所述用户令牌发送至 IPTV服 务器; IPTV服务器利用所述用户账号和所述用户令牌, 对用户进行鉴权, 并将鉴权结果发送至桌面云服务器, 由桌面云服务器根据鉴权结果进行相 应处理。 通过本发明实施例的技术方案, 提高了用户体验, 减少了维护工
作量, 降低了运维成本。
Claims
1、 一种基于交互式网络电视 IPTV的桌面云系统鉴权的方法, 包括: 当用户启动桌面云客户端时, 桌面云客户端自动生成包含用户账号和 用户令牌的用户鉴权请求, 并发送至桌面云服务器;
桌面云服务器在自身保存的所有用户账号中查找所述用户鉴权请求包 含的用户账号, 并在查找到所述用户账号时, 将所述用户账号和所述用户 令牌发送至 IPTV服务器, 其中, 桌面云服务器在自身保存的所有用户账号 中包含 IPTV服务器中需要使用桌面云服务器的用户账号;
IPTV服务器利用所述用户账号和所述用户令牌, 对用户进行鉴权, 并 将鉴权结果发送至桌面云服务器。
2、 根据权利要求 1所述的方法, 其中, 所述方法还包括:
桌面云服务器向 IPTV服务器发送用于用户账号同步的请求;
IPTV服务器收到所述请求后, 将所有需要使用桌面云服务器的用户账 号发送至桌面云服务器;
桌面云服务器保存所收到的用户账号。
3、 根据权利要求 2所述的方法, 其中, 所述桌面云客户端自动生成包 含用户账号和用户令牌的用户鉴权请求, 包括:
当用户启动桌面云客户端时, 桌面云客户端从与桌面云客户端融合的 IPTV机顶盒中获取用户账号和用户令牌, 并生成包含所述用户账号和用户 令牌的用户鉴权请求。
4、 根据权利要求 3所述的方法, 其中, 所述桌面云客户端从与其融合 的 IPTV机顶盒中获取用户账号和用户令牌之前, 所述方法还包括:
IPTV机顶盒向 IPTV服务器发送用于请求用户令牌的认证请求, 并接 收所述服务器响应所述认证请求的加密令牌;
IPTV机顶盒对所述用户账号、 所述加密令牌、 IPTV机顶盒账号、 桌
面云客户端的网际协议 IP地址和媒体接入控制 MAC地址进行加密处理, 生成加密字符串, 并发送至 IPTV服务器;
IPTV服务器对所述加密字符串进行认证, 并在认证成功时, 将包含用 户令牌的认证成功消息发送至 IPTV机顶盒。
5、 根据权利要求 4所述的方法, 其中, 所述方法还包括:
当桌面云服务器在自身保存的所有用户账号中未查找到所述用户账号 时, 生成鉴权失败的消息, 并发送至桌面云客户端。
6、 根据权利要求 5所述的方法, 其中, 所述 IPTV服务器利用所述用 户账号和所述用户令牌对用户进行鉴权, 包括:
IPTV服务器在自身保存的所有用户账号中查找所述用户账号, 并确定 所述用户令牌的有效性;
若能够找到所述用户账号, 且所述用户令牌有效, 则生成鉴权成功的 消息, 并发送至桌面云服务器, 否则生成鉴权失败的消息, 并发送至桌面 云服务器。
7、 根据权利要求 6所述的方法, 其中, 所述方法还包括:
当桌面云服务器收到鉴权成功的消息时, 将包含虚拟桌面信息的鉴权 成功消息发送至桌面云客户端, 所述虚拟桌面信息为桌面云客户端接入云 桌面所使用的信息。
8、 根据权利要求 7所述的方法, 其中, 所述方法还包括:
当桌面云服务器收到鉴权失败的消息时, 将包含错误信息的鉴权失败 消息发送至桌面云客户端,以便桌面云客户端根据所述错误信息,通知 IPTV 机顶盒向 IPTV服务器重新请求有效的用户令牌。
9、 一种基于 IPTV的桌面云系统鉴权的系统, 包括:
桌面云客户端, 配置为当用户启动桌面云客户端时, 自动生成包含用 户账号和用户令牌的用户鉴权请求, 并发送至桌面云服务器;
桌面云服务器,配置为保存交互式网络电视 IPTV服务器中需要使用桌 面云服务器的用户账号, 并在收到用户鉴权请求时, 在自身保存的所有用 户账号中查找所述用户鉴权请求包含的用户账号, 当查找到所述用户账号 时, 将所述用户账号和所述用户令牌发送至 IPTV服务器, 其中, 桌面云服 务器在自身保存的所有用户账号中包含 IPTV服务器中需要使用桌面云服 务器的用户账号;
IPTV服务器, 配置为利用所述用户账号和所述用户令牌, 对用户进行 鉴权, 并将鉴权结果发送至桌面云服务器。
10、 根据权利要求 9所述的系统, 其中, 所述系统还包括:
IPTV机顶盒, 配置为当用户启动融合在 IPTV机顶盒内桌面云客户端 时, 将用户账号和用户令牌传递给桌面云客户端。
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201310081751.6 | 2013-03-14 | ||
CN201310081751.6A CN104052719B (zh) | 2013-03-14 | 2013-03-14 | 一种基于iptv的桌面云系统鉴权的方法及系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
WO2013189392A2 true WO2013189392A2 (zh) | 2013-12-27 |
WO2013189392A3 WO2013189392A3 (zh) | 2014-02-13 |
Family
ID=49769538
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CN2013/081915 WO2013189392A2 (zh) | 2013-03-14 | 2013-08-20 | 基于交互式网络电视的桌面云系统鉴权的方法及系统 |
Country Status (2)
Country | Link |
---|---|
CN (1) | CN104052719B (zh) |
WO (1) | WO2013189392A2 (zh) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20220046017A1 (en) * | 2014-09-25 | 2022-02-10 | Google Llc | Systems, methods, and media for authenticating multiple devices |
Families Citing this family (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107645658A (zh) * | 2016-07-22 | 2018-01-30 | 南京中兴新软件有限责任公司 | 交互式网络电视iptv平台的鉴权方法、装置及系统 |
CN107241435A (zh) * | 2017-07-18 | 2017-10-10 | 贵阳动视云科技有限公司 | 软件云服务的授权验证方法及云计算平台 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20070143831A1 (en) * | 2005-12-21 | 2007-06-21 | Sbc Knowledge Ventures, Lp | System and method of authentication |
CN101888529A (zh) * | 2010-06-28 | 2010-11-17 | 中兴通讯股份有限公司 | 基于交互式电视的多媒体终端信息机的管理方法及系统 |
US20110099616A1 (en) * | 2009-10-23 | 2011-04-28 | Microsoft Corporation | Authenticating Using Cloud Authentication |
CN102739708A (zh) * | 2011-04-07 | 2012-10-17 | 腾讯科技(深圳)有限公司 | 一种基于云平台访问第三方应用的系统及方法 |
Family Cites Families (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101174952B (zh) * | 2006-10-31 | 2010-05-19 | 中兴通讯股份有限公司 | Iptv业务自动认证方法及装置 |
CN101202626A (zh) * | 2006-12-13 | 2008-06-18 | 中兴通讯股份有限公司 | Iptv业务认证装置 |
KR101463608B1 (ko) * | 2008-02-12 | 2014-12-05 | 삼성전자 주식회사 | Iptv서비스에서 광고 제공 시스템 및 방법 |
-
2013
- 2013-03-14 CN CN201310081751.6A patent/CN104052719B/zh active Active
- 2013-08-20 WO PCT/CN2013/081915 patent/WO2013189392A2/zh active Application Filing
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20070143831A1 (en) * | 2005-12-21 | 2007-06-21 | Sbc Knowledge Ventures, Lp | System and method of authentication |
US20110099616A1 (en) * | 2009-10-23 | 2011-04-28 | Microsoft Corporation | Authenticating Using Cloud Authentication |
CN101888529A (zh) * | 2010-06-28 | 2010-11-17 | 中兴通讯股份有限公司 | 基于交互式电视的多媒体终端信息机的管理方法及系统 |
CN102739708A (zh) * | 2011-04-07 | 2012-10-17 | 腾讯科技(深圳)有限公司 | 一种基于云平台访问第三方应用的系统及方法 |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20220046017A1 (en) * | 2014-09-25 | 2022-02-10 | Google Llc | Systems, methods, and media for authenticating multiple devices |
US11637829B2 (en) * | 2014-09-25 | 2023-04-25 | Google Llc | Systems, methods, and media for authenticating multiple devices |
Also Published As
Publication number | Publication date |
---|---|
CN104052719B (zh) | 2018-06-26 |
WO2013189392A3 (zh) | 2014-02-13 |
CN104052719A (zh) | 2014-09-17 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
EP3525415B1 (en) | Information processing system and control method therefor | |
KR102362456B1 (ko) | 권한 위양 시스템, 그 제어 방법 및 저장 매체 | |
WO2017186005A1 (zh) | 一种云桌面认证的方法、服务器及终端 | |
WO2018036314A1 (zh) | 一种单点登录认证方法及装置、存储介质 | |
WO2017028804A1 (zh) | 一种Web实时通信平台鉴权接入方法及装置 | |
CN102201915B (zh) | 一种基于单点登录的终端认证方法和装置 | |
EP2963884B1 (en) | Bidirectional authorization system, client and method | |
JP5694344B2 (ja) | クラウド認証を使用する認証 | |
WO2018219056A1 (zh) | 鉴权方法、装置、系统和存储介质 | |
JP6929181B2 (ja) | デバイスと、その制御方法とプログラム | |
CN102624720B (zh) | 一种身份认证的方法、装置和系统 | |
US9805185B2 (en) | Disposition engine for single sign on (SSO) requests | |
CN107347068A (zh) | 单点登录方法及系统、电子设备 | |
US7318234B1 (en) | Request persistence during session authentication | |
US20140237580A1 (en) | Server system and control method | |
WO2016078419A1 (zh) | 一种开放授权方法、装置及开放平台 | |
JP2007310512A (ja) | 通信システム、サービス提供サーバおよびユーザ認証サーバ | |
WO2016155220A1 (zh) | 一种单点登录的方法、系统以及终端 | |
US20200076797A1 (en) | System and data processing method | |
WO2011144081A2 (zh) | 用户业务鉴权方法、系统及服务器 | |
WO2018045798A1 (zh) | 网络认证方法、相关装置 | |
JP7100561B2 (ja) | 認証システム、認証サーバおよび認証方法 | |
US11251951B2 (en) | Remote authentication for accessing on-premises network devices | |
CN112929388B (zh) | 网络身份跨设备应用快速认证方法和系统、用户代理设备 | |
WO2013189392A2 (zh) | 基于交互式网络电视的桌面云系统鉴权的方法及系统 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
122 | Ep: pct application non-entry in european phase |
Ref document number: 13807167 Country of ref document: EP Kind code of ref document: A2 |