WO2014177108A1 - 一种家庭网络多媒体内容共享的访问控制方法和装置 - Google Patents

一种家庭网络多媒体内容共享的访问控制方法和装置 Download PDF

Info

Publication number
WO2014177108A1
WO2014177108A1 PCT/CN2014/079524 CN2014079524W WO2014177108A1 WO 2014177108 A1 WO2014177108 A1 WO 2014177108A1 CN 2014079524 W CN2014079524 W CN 2014079524W WO 2014177108 A1 WO2014177108 A1 WO 2014177108A1
Authority
WO
WIPO (PCT)
Prior art keywords
access
client device
content
user
directory
Prior art date
Application number
PCT/CN2014/079524
Other languages
English (en)
French (fr)
Inventor
吉锋
陆平
赵培
贾霞
吕强
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2014177108A1 publication Critical patent/WO2014177108A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2803Home automation networks
    • H04L12/2807Exchanging configuration information on appliance services in a home automation network
    • H04L12/2812Exchanging configuration information on appliance services in a home automation network describing content present in a home automation network, e.g. audio video content
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/60Network streaming of media packets
    • H04L65/61Network streaming of media packets for supporting one-way streaming services, e.g. Internet radio
    • H04L65/612Network streaming of media packets for supporting one-way streaming services, e.g. Internet radio for unicast
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/45Management operations performed by the client for facilitating the reception of or the interaction with the content or administrating data related to the end-user or to the client device itself, e.g. learning user preferences for recommending movies, resolving scheduling conflicts
    • H04N21/462Content or additional data management, e.g. creating a master electronic program guide from data received from the Internet and a Head-end, controlling the complexity of a video stream by scaling the resolution or bit-rate based on the client capabilities
    • H04N21/4627Rights management associated to the content
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/47End-user applications
    • H04N21/472End-user interface for requesting content, additional data or services; End-user interface for interacting with content, e.g. for content reservation or setting reminders, for requesting event notification, for manipulating displayed content
    • H04N21/47202End-user interface for requesting content, additional data or services; End-user interface for interacting with content, e.g. for content reservation or setting reminders, for requesting event notification, for manipulating displayed content for requesting content on demand, e.g. video on demand
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/80Generation or processing of content or additional data by content creator independently of the distribution process; Content per se
    • H04N21/83Generation or processing of protective or descriptive data associated with content; Content structuring
    • H04N21/835Generation of protective data, e.g. certificates
    • H04N21/8355Generation of protective data, e.g. certificates involving usage data, e.g. number of copies or viewings allowed
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2803Home automation networks
    • H04L2012/2847Home automation networks characterised by the type of home appliance used
    • H04L2012/2849Audio/video appliances

Definitions

  • the present invention relates to the field of digital homes, and in particular, to a DLNAAJpnP-based access control method and apparatus for home network multimedia content sharing.
  • BACKGROUND With the rapid development of the Internet and digital home services, home users have various terminal devices, such as mobile phones, tablets, TV/set top boxes, home PCs, and NAS (Network-attached storage) devices. , home gateway, etc. Multi-screen sharing of multimedia content (audio/video/pictures) across multiple devices has become a must-have feature for current home entertainment.
  • DLNA Digital Living Network
  • an access control method for home network multimedia content sharing comprising the steps of: receiving an access request sent by a client device; determining whether the client device has access rights, When the client device has the access right, the client device displays the directory and content corresponding to the permission, and allows the client device to access the directory and the content.
  • the process of determining whether the client device has access rights is specifically: determining, according to the MAC address or the IP address of the client device, whether the client device has access rights.
  • the method further includes: performing authorization authentication on the access user, and acquiring the access right of the user.
  • the specific process of performing authorization authentication on the access user includes: prompting the client device to perform user authentication; determining whether the client device supports input of a username and a password, when the client device does not support the username and password When the input or the user chooses not to perform identity authentication, it is determined that the client device only has the right to access the content in the public directory and the public directory; when the client device supports the input of the username and password, receiving the The username and password entered by the client device, and obtaining the access authority of the user according to the username and password.
  • the process of obtaining the access right of the user according to the user name and the password specifically includes: determining whether the user name and/or password has an error, and when an error occurs, determining that the client device only has access to the public directory and the The authority of the content under the public directory; when no error occurs, determining that the client device has the right to access the public directory, the user's personal private directory, and the content under the directory; the content under the user's personal private directory includes the The user's personal content and content shared by other users to the user.
  • the client device accesses the content in the private directory of the user, it is determined whether the user has the right to play the content, and when the user does not have the right to play the content, the client is determined.
  • the embodiment of the present invention further provides an access control apparatus for sharing multimedia content in a home network, including: an access request receiving unit, configured to receive an access request sent by a client device; and an access authority processing unit configured to determine the Whether the client device has access rights, when the client device has access rights, presents the directory and content of the corresponding authority to the client device, and allows the client device to access the directory and content.
  • the access authority processing unit comprises: a content directory service unit, configured to store a public directory, a user personal private directory, and content under the directory thereof; and an authentication authorization management service unit configured to determine whether the client device that sends the access request is Have access.
  • the authentication and authorization management service unit includes a client device access authority determining sub-unit, and is configured to determine whether the client device has access rights according to the MAC address or the IP address of the client device.
  • the authentication and authorization management service unit further includes a user access right obtaining sub-unit, configured to perform authorization authentication on the access user according to the user name and the password, and obtain the access authority of the user.
  • the authentication and authorization management service unit further includes a content play permission judging subunit, and is configured to determine whether the user has the right to play the content when accessing the content in the private directory of the user.
  • FIG. 1 is a schematic structural diagram of a home network system according to an embodiment of the present invention
  • FIG. 2 is a schematic diagram of a scenario of a home network DLNA device sharing application according to an embodiment of the present invention
  • FIG. 3 is a schematic diagram of an embodiment of the present invention
  • FIG. 4 is a structural diagram of a storage content of a content directory service unit of the present embodiment
  • FIG. 5 is a diagram of a multimedia content sharing of a home network according to an embodiment of the present invention.
  • a flow chart of the access control method and
  • FIG. 6 is a flow chart for determining the authority of the DLNADMS content sharing in the embodiment of the present invention.
  • DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS In order to solve the problem that the prior art does not consider the rights control when the DLNA device is shared, the present invention provides an access control method and apparatus for home network multimedia content sharing, which are combined with the following figures and three implementations.
  • EXAMPLES The present invention is preferably described in detail. It is understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
  • Embodiment 1 A home network system according to an embodiment of the present invention includes a digital media server 11 and a client device 12 as shown in FIG. 1.
  • the digital media server 11 includes an access request receiving unit 113 and an access authority processing unit.
  • the access request receiving unit 113 is configured to receive an access request sent by the client device;
  • the access authority processing unit is configured to determine whether the client device has access rights, and when the client device has access rights, to the client
  • the end device displays the directory and content corresponding to the rights and allows the client device to access the directory and content.
  • the access authority processing unit includes a content directory service unit 111 and an authentication authority management service unit 112, and the content directory service unit 111 is configured to store a public directory, a user's personal private directory, and contents under the directory thereof, the authentication and authorization management service.
  • Unit 112 is arranged to determine if the client device 12 that sent the access request has access rights; the client device 12 includes a digital media controller, a digital media player, and/or a digital media renderer.
  • a home network DLNA device sharing application scenario of this embodiment is shown in FIG. 2, including one digital media server (DLNADMS server) and three client devices (DLNA DMC controller, DLNADMP player, and DLNA DMR renderer). ).
  • the DMS is a content sharing server
  • the CDS Content Directory Service
  • a DLNADMP device such as a TV, STB (Set Top Box) device
  • DMC Digital Media Renderer
  • Embodiment 2 The structure of an access control apparatus for home network multimedia content sharing according to an embodiment of the present invention is as shown in FIG. 3, and includes a content directory service unit 31 and an authentication authority management service unit 32.
  • the content directory service unit 31 is configured to store content under the public directory, the user's personal private directory, and its directory, the content under the directory includes multimedia content such as audio, video, and/or picture; the authentication and authorization management service unit 32 is configured to determine to send Whether the client device accessing the request has access rights.
  • the authentication authority management service unit 32 includes a client device access authority determining sub-unit 321, a user access right obtaining sub-unit 322, and a content playing right judging sub-unit 323.
  • Client device access authority judge The unit 321 is configured to determine whether the client device has access rights according to the MAC address or the IP address of the client device.
  • the user access permission obtaining sub-unit 322 is configured to perform authorization authentication on the access user according to the user name and password.
  • the user's access authority; the content play permission judgment sub-unit 323 is configured to determine whether the user has the right to play the content when accessing the content in the user's personal private directory.
  • the access control device for the home network multimedia content sharing in this embodiment may employ a digital media server.
  • the organization structure of a storage content of the content directory service unit 31 of this embodiment is as shown in FIG. 4, wherein the contents of the music and video photo in the Public public directory are all open, and no permission control is performed;
  • Each of the externally shared content includes the function of sharing it to other users when setting the shared content.
  • the permission information of user 001 accessing content is as shown in Table 1: Table 1
  • the rights information of content sharing in its own private directory is as shown in Table 1 for 001/*.*; the content list information shared by other users to 001, such as 002 user sharing. Part of the content: all content under video; only l.jpg picture under photo directory; l.mp3 file under music, actually form a tree structure authorization information form.
  • Embodiment 3 An access control method for multimedia content sharing in a home network according to an embodiment of the present invention is as shown in FIG. 5. The method includes the following steps: Step S501: A client device sends an access request to a digital media server.
  • Step s502 The digital media server determines whether the client device has access rights, and if yes, proceeds to step s503, otherwise ends. In this embodiment, the digital media server determines whether the client device has access rights according to the MAC address or the IP address of the client device.
  • Step s503 The digital media server prompts the client device to perform user authentication.
  • Step S504 Determine whether the client device meets the following conditions: the client device supports input of a username and a password, and the user selects an identity.
  • Step S505 the client device receives the input username and password, and returns the username and password to the digital media server;
  • Step S506 the number
  • the media server obtains the access authority of the user according to the user name and password, and proceeds to step S508.
  • the embodiment specifically includes: determining whether the user name and/or password has an error, and if so, the digital media server Determining that the client device only has the right to access the content in the public directory and the public directory; otherwise, the digital media server determines that the client device has access to the public directory, the user's personal private directory, and the contents of the directory.
  • Step S507 The digital media server determines that the client device only has the right to access the content in the public directory and the public directory, and proceeds to step S508; Step S508: displaying the corresponding permission directory to the client device and Content and allowing the client device to access the directory and content.
  • Step S509 the client The device plays the multimedia content within the permission.
  • Steps s503 ⁇ s507 are processes in which the digital media server performs authorization authentication on the access user to obtain the access authority of the user.
  • the rights control is represented by a multimedia directory, a file presentation and a media play shared on the DLNA DMS, and the access to different DLNA DMC/DMP devices and users is solved.
  • Technical issues with different shared content include:
  • Privilege setting and control on DLNADMS setting two levels of privilege control: Based on the authorization control of access device type such as MAC address, IP address, etc., the device is not authorized (the MAC address uniquely identifies the access device) Cannot access specific content list; based on access user authentication and authorization control, different users on DMC or DMP access the shared content of DLNA DMS, and display different content in the corresponding directory according to different user rights.
  • the above permission setting and control module is implemented on the DLNADMS.
  • DLNADMS Content Sharing Server
  • Pubic and non-public content is divided into video/photo/music:
  • the -public directory is divided into private folders for individual users.
  • the rights management module on the DMS allows you to set permissions information for individual users: Open shared directories, including their own visible files, and files/folders they are willing to share with other users.
  • the DMS determines whether the MAC address of the client device is legal, and then displays the Public directory for the user who authenticates the legitimate user; DMP and DMC support the pop-up username/password input interface for verification.
  • DMP and DMC the user name/password interface is not supported (pop-up or inconvenient to input), but only the contents of the Public directory are displayed.
  • shared content shared with others.
  • the DMS will perform permission judgment according to the user request information such as the play URL, and prevent the user from playing the unauthorized content by traversing the enumeration mode (for example, the a.mp4 device in the a directory has permission to play, b.mp4 has no permission, but Change the a.mp4 play URL directly to b.mp4).
  • the user request information such as the play URL
  • the DMC/DMP device discovers the DMS device and requests the content on the DMS device.
  • the DMS first detects whether the device itself (such as MAC, IP address, etc.) has permission. 3) If there is no permission, it directly returns an unauthorized prompt, and cannot display any content. The process ends; if the device itself is successfully authenticated, return to the client. User password request is required
  • the client supports the user name, password input, presentation prompt box, and user input for authentication. 6) After the authentication recognition fails, only the public directory can be displayed, and the process ends.
  • the DMS CDS After the authentication is successful, the DMS CDS returns to the Public directory and the user's personal private directory. 8) The user does not have any control to access any content in the Public directory.
  • the DMS When the user selects a personal private directory, the DMS returns its personal shared content and other users' shared content (displays a virtual file or directory)
  • the present invention implements privilege control when DLNA device sharing (UPnP service call), including authentication of device access rights, and access rights control for whether shared content is visible to different users' public and non-public directories/contents. While the preferred embodiments of the present invention have been disclosed for purposes of illustration, those skilled in the art will recognize that various modifications, additions and substitutions are possible, and the scope of the invention should not be limited to the embodiments described above.

Landscapes

  • Engineering & Computer Science (AREA)
  • Multimedia (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Automation & Control Theory (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Security & Cryptography (AREA)
  • Human Computer Interaction (AREA)
  • Storage Device Security (AREA)
  • Information Transfer Between Computers (AREA)
  • Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)

Abstract

本发明公开了一种家庭网络多媒体内容共享的访问控制方法,所述方法包括以下步骤:接收客户端设备发送的访问请求;判断所述客户端设备是否有访问权限,当所述客户端设备有访问权限时,向所述客户端设备展示对应权限的目录和内容,并允许所述客户端设备访问所述目录和内容。本发明还公开了一种家庭网络多媒体内容共享的访问控制装置。本发明有效地解决了DLNA设备共享时的权限控制,包括对设备访问权限的鉴别、共享内容针对不同用户的public和non-public目录/内容是否可见的访问权限控制问题。

Description

一种家庭网络多媒体内容共享的访问控制方法和装置 技术领域 本发明涉及数字家庭领域, 特别是涉及一种基于 DLNAAJpnP的家庭网络多媒体 内容共享的访问控制方法和装置。 背景技术 随着互联网、 数字家庭业务的飞速发展, 家庭用户具备了各种各样的终端设备, 如手机、 平板电脑、 TV/机顶盒、 家庭 PC、 NAS (Network- Attached Storage, 网络附 加存储)设备、 家庭网关等。 多媒体内容(音频 /视频 /图片)在多种设备之间的多屏共 享, 已成为当前家庭娱乐的一个必备功能。 目前针对家庭网络多媒体内容的共享,业界主要有 DLNA (Digital Living Network
Alliance, 数字生活网络联盟) 的解决方案。 在 DLNA 的解决方案中, 通过 UPnP
(Universal Plug and Play, 通用即插即用) 完成局域网设备的相互发现及服务调用, 如 DMS (Digital Media Server, 数字媒体服务器)、 DMC (Digital Media Controller, 数 字媒体控制器)、 DMP (Digital Media Player, 数字媒体播放器) 等设备, 但 DLNA设 备之间通过 UPnP协议的内容共享与播放 (即调用 UPnP服务接口) 时, 并没有考虑 共享内容对某些设备以及设备上当前用户是否可见的问题, 即 DLNA设备共享(UPnP 服务调用) 时的权限控制问题, 包括对设备访问权限的鉴别、 共享内容针对不同用户 的 public和 non-public的目录 /内容是否可见的问题。 发明内容 本发明实施例提供了一种家庭网络多媒体内容共享的访问控制方法和装置, 用以 解决现有技术没有考虑在 DLNA设备共享时的权限控制的问题。 根据本发明的一方面, 提供了一种家庭网络多媒体内容共享的访问控制方法, 所 述方法包括以下步骤: 接收客户端设备发送的访问请求; 判断所述客户端设备是否有访问权限, 当所述客户端设备有访问权限时, 向所述 客户端设备展示对应权限的目录和内容,并允许所述客户端设备访问所述目录和内容。 优选地, 判断所述客户端设备是否有访问权限的过程具体为: 根据所述客户端设 备的 MAC地址或 IP地址, 判断所述客户端设备是否有访问权限。 优选地, 在判断所述客户端设备有访问权限之后, 还包括: 对访问用户进行授权 认证, 获取所述用户的访问权限。 优选地, 对访问用户进行授权认证的具体过程包括: 提示所述客户端设备需要进行用户认证; 判断所述客户端设备是否支持用户名和密码的输入, 当所述客户端设备不支持用 户名和密码的输入或用户选择不进行身份认证时, 判断所述客户端设备只具有访问公 共目录和所述公共目录下的内容的权限; 当所述客户端设备支持用户名和密码的输入时, 接收所述客户端设备输入的用户 名和密码, 并根据所述用户名和密码, 获取所述用户的访问权限。 优选地, 所述根据用户名和密码获取用户的访问权限的过程具体包括: 判断所述用户名和 /或密码是否出现错误, 当出现错误时, 判断所述客户端设备只 具有访问公共目录和所述公共目录下的内容的权限; 当没有出现错误时, 判断所述客户端设备具有访问公共目录、 用户个人私有目录 及其目录下的内容的权限; 所述用户个人私有目录下的内容包括所述用户的个人内容 和其他用户共享给所述用户的内容。 优选地, 当客户端设备访问所述用户个人私有目录下的内容时, 判断所述用户是 否具备播放所述内容的权限, 当所述用户不具备播放所述内容的权限时, 判断所述客 户端设备没有播放所述内容的权限。 另一方面, 本发明实施例还提供一种家庭网络多媒体内容共享的访问控制装置, 包括: 访问请求接收单元, 设置为接收客户端设备发送的访问请求; 访问权限处理单元, 设置为判断所述客户端设备是否有访问权限, 当所述客户端 设备有访问权限时, 向所述客户端设备展示对应权限的目录和内容, 并允许所述客户 端设备访问所述目录和内容。 优选地, 所述访问权限处理单元包括: 内容目录服务单元, 设置为存储公共目录、用户个人私有目录及其目录下的内容; 认证授权管理服务单元,设置为判断发送访问请求的客户端设备是否有访问权限。 优选地, 所述认证授权管理服务单元包括客户端设备访问权限判断子单元, 设置 为根据所述客户端设备的 MAC地址或 IP地址,判断所述客户端设备是否有访问权限。 优选地, 所述认证授权管理服务单元还包括用户访问权限获取子单元, 设置为根 据用户名和密码, 对访问用户进行授权认证, 获取所述用户的访问权限。 优选地, 所述认证授权管理服务单元还包括内容播放权限判断子单元, 设置为当 访问所述用户个人私有目录下的内容时,判断所述用户是否具备播放所述内容的权限。 本发明实施例有益效果如下: 在本发明的上述实施例中, 实现了 DLNA设备共享 (UPnP服务调用) 时的权限 控制, 包括对设备访问权限的鉴别、 共享内容针对不同用户的 public和 non-public 目 录 /内容是否可见的访问权限控制。 附图说明 图 1 是本发明实施例的一种家庭网络系统的结构示意图; 图 2 是本发明实施例的一种家庭网络 DLNA设备共享应用的场景示意图; 图 3 是本发明实施例的一种家庭网络多媒体内容共享的访问控制装置的结构图; 图 4 是本实施例的内容目录服务单元的一种存储内容的组织结构图; 图 5 是本发明实施例的一种家庭网络多媒体内容共享的访问控制方法的流程图; 以及 图 6 是本发明实施例中 DLNADMS内容共享的权限判断流程图。 具体实施方式 为了解决现有技术没有考虑在 DLNA设备共享时的权限控制的问题,本发明提供 了一种家庭网络多媒体内容共享的访问控制方法和装置, 以下结合附图以及三个实施 例, 对本发明进行优选地详细说明。 应当理解, 此处所描述的具体实施例仅仅用以解 释本发明, 并不限定本发明。 实施例 1 本发明实施例的一种家庭网络系统如图 1所示, 包括数字媒体服务器 11、 客户端 设备 12; 所述数字媒体服务器 11包括访问请求接收单元 113和访问权限处理单元; 所述访问请求接收单元 113设置为接收客户端设备发送的访问请求; 所述访问权限处 理单元设置为判断所述客户端设备是否有访问权限,当所述客户端设备有访问权限时, 向所述客户端设备展示对应权限的目录和内容, 并允许所述客户端设备访问所述目录 和内容。 所述访问权限处理单元包括内容目录服务单元 111和认证授权管理服务单元 112, 所述内容目录服务单元 111设置为存储公共目录、 用户个人私有目录及其目录下的内 容,所述认证授权管理服务单元 112设置为判断发送访问请求的客户端设备 12是否有 访问权限; 所述客户端设备 12包括数字媒体控制器、 数字媒体播放器和 /或数字媒体 呈现器。 本实施例的一种家庭网络 DLNA设备共享应用的场景如图 2所示,包括 1个数字 媒体服务器 (DLNADMS服务器)和 3个客户端设备(DLNA DMC控制器、 DLNADMP 播放器和 DLNA DMR呈现器)。该场景中, DMS是内容共享 Server,其中 CDS ( Content Directory Service)是标准的内容目录服务器; DLNADMP设备(如 TV、 STB ( Set Top Box, 机顶盒)设备)可以自己发现 DMS服务器并访问其中的内容; 通常的, 可以使 用手机、 平板电脑等移动设备作为 DMC控制器, 可发现局域网中的 DMS服务器、 DMR (Digital Media Renderer,数字媒体呈现器)(如 TV、 STB), DMC负责展示 DMS 的内容并最终控制内容在 DMR设备的播放。 实施例 2 本发明实施例的一种家庭网络多媒体内容共享的访问控制装置的结构如图 3 所 示, 包括内容目录服务单元 31和认证授权管理服务单元 32。 内容目录服务单元 31设 置为存储公共目录、 用户个人私有目录及其目录下的内容, 所述目录下的内容包括音 频、 视频和 /或图片等多媒体内容; 认证授权管理服务单元 32设置为判断发送访问请 求的客户端设备是否有访问权限。 所述认证授权管理服务单元 32包括客户端设备访问权限判断子单元 321、用户访 问权限获取子单元 322和内容播放权限判断子单元 323。 客户端设备访问权限判断子 单元 321设置为根据所述客户端设备的 MAC地址或 IP地址, 判断所述客户端设备是 否有访问权限; 用户访问权限获取子单元 322设置为根据用户名和密码, 对访问用户 进行授权认证, 获取所述用户的访问权限; 内容播放权限判断子单元 323设置为当访 问所述用户个人私有目录下的内容时, 判断所述用户是否具备播放所述内容的权限。 本实施例中的家庭网络多媒体内容共享的访问控制装置可以采用数字媒体服务 器。 本实施例的内容目录服务单元 31 的一种存储内容的组织结构如图 4所示, 其中 Public公共目录下 music、 video photo中内容是全部开放的, 不做任何权限控制; 另 外每个用户设置各自的对外共享内容,设置共享内容时包括其共享给其他用户的功能。 例如, 用户 001访问内容的权限信息如表 1所示: 表 1
Figure imgf000007_0001
通过表 1可以看出, 该信息主要分为两类: 自身私有目录下内容共享的权限信息 如表 1中 001/*.*表示全部; 其他用户共享给 001的内容列表信息, 如 002用户共享了 部分内容: video下所有内容; 只有 photo目录下的 l .jpg图片; 音乐下的 l .mp3文件, 实际上形成一个树形结构的授权信息表格。 实施例 3 本发明实施例的一种家庭网络多媒体内容共享的访问控制方法如图 5所示, 所述 方法包括以下步骤: 步骤 S501 : 客户端设备向数字媒体服务器发送访问请求。 步骤 s502: 所述数字媒体服务器判断所述客户端设备是否有访问权限, 如果是, 则转步骤 s503, 否则结束。 本实施例中具体包括: 所述数字媒体服务器根据所述客户 端设备的 MAC地址或 IP地址, 判断所述客户端设备是否有访问权限。 步骤 s503 : 所述数字媒体服务器提示所述客户端设备需要进行用户认证; 步骤 S504 : 判断所述客户端设备是否符合以下条件: 所述客户端设备支持用户名 和密码的输入, 且用户选择进行身份认证, 如果是, 则转步骤 s505, 否则转步骤 s507; 步骤 S505 : 所述客户端设备接收输入的用户名和密码, 并将所述用户名和密码返 回所述数字媒体服务器; 步骤 S506 : 所述数字媒体服务器根据所述用户名和密码, 获取所述用户的访问权 限, 并转步骤 S508 ; 本实施例中具体包括: 判断所述用户名和 /或密码是否出现错误, 如果是, 则所述数字媒体服务器判断所述客户端设备只具有访问公共目录和所述公共 目录下的内容的权限; 否则所述数字媒体服务器判断所述客户端设备具有访问公共目 录、 用户个人私有目录及其目录下的内容的权限; 所述用户个人私有目录下的内容包 括所述用户的个人内容和其他用户共享给所述用户的内容。 步骤 S507 : 所述数字媒体服务器判断所述客户端设备只具有访问公共目录和所述 公共目录下的内容的权限, 并转步骤 S508 ; 步骤 S508 : 向所述客户端设备展示对应权限的目录和内容, 并允许所述客户端设 备访问所述目录和内容。 当访问所述用户个人私有目录下的内容时, 还判断所述用户 是否具备播放所述内容的权限, 如果否, 则判断所述用户没有播放所述内容的权限; 步骤 S509 : 所述客户端设备对权限内的多媒体内容进行播放。 其中步骤 s503~s507为数字媒体服务器对访问用户进行授权认证, 获取所述用户 的访问权限的过程。 在本发明实施例的家庭网络多媒体内容共享的访问控制方法中, 权限控制表现在 对 DLNA DMS 上共享的多媒体目录、 文件的展现与媒体播放, 解决了针对不同的 DLNA DMC/DMP设备及用户访问不同共享内容的技术问题。 具体实现的技术方法包 括:
1 ) DLNADMS上进行权限的设置与控制, 设定了两个层面的权限控制: 基于访问设备类型如 MAC地址、 IP地址等的授权控制,设备没有被授权(以 MAC 地址唯一标识访问设备), 不能访问具体的内容列表; 基于访问用户进行认证授权控制, DMC或 DMP上不同的用户访问 DLNA DMS 的共享内容, 根据用户权限不同, 展示相应目录下的不同内容。 以上权限的设置与控制模块在 DLNADMS上实现。
2) DLNADMS (内容共享服务端) 内容组织上分为 pubic和 non-public两大类内 容 (内容分为 video/photo/music三类): 对于 public目录下, 任何用户都可以访问; 而对应 non-public 目录下分为各个用 户的私有文件夹。 通过 DMS 上权限管理模块可以设置各个用户的权限信息: 开放共 享的目录, 包括自己可见, 以及其愿意共享给其他用户的文件 /文件夹。
3 ) DLNA客户端如 DMP、 DMC通过 UPnP方式访问 DMS内容时: 首先 DMS判断客户端设备的 MAC地址是否合法,然后对于验证合法的用户显示 Public 目录; 对于其他个人共享目录提示需要授权。 DMP、 DMC支持弹出用户名 /密 码输入界面进行校验, 对于 DMP、 DMC不支持 (弹出或不方便输入)用户名 /密码界 面的, 只是显示 Public目录下内容。 对于成功认证用户名、 密码终端的设备, 当用户选择私有子目录内容时, 需显示 两部分内容: 自己共享和别人共享的内容。 最终进行内容播放时, DMS 会根据播放 URL等用户请求信息进行权限判断, 防止用户通过遍历枚举方式播放未授权内容(例 如 a目录下 a.mp4设备有权限播放、 b.mp4没有权限, 但直接将 a.mp4播放 URL改为 b.mp4)。
DLNADMS内容共享的权限判断流程如图 6所示, 包括以下步骤:
1 ) DMC/DMP设备发现 DMS设备, 请求 DMS设备上的内容
2) DMS首先检测设备本身 (如可根据 MAC、 IP地址等) 是否有权限 3 )若没有权限, 直接返回未授权的提示, 不能展示任何内容, 流程结束; 若设备 本身认证成功, 返回客户端需要进行用户密码请求
4)若 DMP、 DMC客户端不支持或不方便进行输入, 则忽略此响应消息; 按标准 UPnP消息请求根 CDS目录, 只展示 Public目录内容
5 ) 客户端支持用户名、 密码输入, 展现提示框、 用户输入后进行认证 6) 认证识别失败后, 只能展示 Public目录, 流程结束
7) 认证成功后, DMS CDS返回 Public目录和用户个人私有目录 8) 用户访问 Public目录下任何内容不做任何控制
9) 用户选择个人私有目录时, DMS上返回其个人共享的内容和其他用户共享的 内容 (显示一个虚拟的文件或目录)
10) 用户选择私有目录下具体内容播放时, 仍然进行内容的权限判断, 防止用户 通过遍历枚举方式播放未授权内容。 本发明实现了 DLNA设备共享 (UPnP服务调用) 时的权限控制, 包括对设备访 问权限的鉴别、 共享内容针对不同用户的 public和 non-public目录 /内容是否可见的访 问权限控制。 尽管为示例目的, 已经公开了本发明的优选实施例, 本领域的技术人员将意识到 各种改进、 增加和取代也是可能的, 因此, 本发明的范围应当不限于上述实施例。

Claims

权 利 要 求 书 、 一种家庭网络多媒体内容共享的访问控制方法, 包括:
接收客户端设备发送的访问请求;
判断所述客户端设备是否有访问权限, 当所述客户端设备有访问权限时, 向所述客户端设备展示对应权限的目录和内容, 并允许所述客户端设备访问所 述目录和内容。 、 如权利要求 1所述的家庭网络多媒体内容共享的访问控制方法, 其中, 判断所 述客户端设备是否有访问权限的过程具体为: 根据所述客户端设备的 MAC地 址或 IP地址, 判断所述客户端设备是否有访问权限。 、 如权利要求 1所述的家庭网络多媒体内容共享的访问控制方法, 其中, 在判断 所述客户端设备有访问权限之后, 还包括: 对访问用户进行授权认证, 获取所 述用户的访问权限。 、 如权利要求 3所述的家庭网络多媒体内容共享的访问控制方法, 其中, 对访问 用户进行授权认证的具体过程包括:
提示所述客户端设备需要进行用户认证;
判断所述客户端设备是否支持用户名和密码的输入, 当所述客户端设备不 支持用户名和密码的输入或用户选择不进行身份认证时, 判断所述客户端设备 只具有访问公共目录和所述公共目录下的内容的权限;
当所述客户端设备支持用户名和密码的输入时, 接收所述客户端设备输入 的用户名和密码, 并根据所述用户名和密码, 获取所述用户的访问权限。 、 如权利要求 4所述的家庭网络多媒体内容共享的访问控制方法, 其中, 所述根 据用户名和密码获取用户的访问权限的过程具体包括:
判断所述用户名和 /或密码是否出现错误, 当出现错误时, 判断所述客户端 设备只具有访问公共目录和所述公共目录下的内容的权限;
当没有出现错误时, 判断所述客户端设备具有访问公共目录、 用户个人私 有目录及其目录下的内容的权限; 所述用户个人私有目录下的内容包括所述用 户的个人内容和其他用户共享给所述用户的内容。 、 如权利要求 5所述的家庭网络多媒体内容共享的访问控制方法, 其中, 当客户 端设备访问所述用户个人私有目录下的内容时, 判断所述用户是否具备播放所 述内容的权限, 当所述用户不具备播放所述内容的权限时, 判断所述客户端设 备没有播放所述内容的权限。 、 一种家庭网络多媒体内容共享的访问控制装置, 包括:
访问请求接收单元, 设置为接收客户端设备发送的访问请求; 访问权限处理单元, 设置为判断所述客户端设备是否有访问权限, 当所述 客户端设备有访问权限时, 向所述客户端设备展示对应权限的目录和内容, 并 允许所述客户端设备访问所述目录和内容。 、 如权利要求 7所述的家庭网络多媒体内容共享的访问控制装置, 其中, 所述访 问权限处理单元包括:
内容目录服务单元, 设置为存储公共目录、 用户个人私有目录及其目录下 的内容;
认证授权管理服务单元, 设置为判断发送访问请求的客户端设备是否有访 问权限。 、 如权利要求 8所述的家庭网络多媒体内容共享的访问控制装置, 其中, 所述认 证授权管理服务单元包括客户端设备访问权限判断子单元, 设置为根据所述客 户端设备的 MAC地址或 IP地址, 判断所述客户端设备是否有访问权限。 0、 如权利要求 9所述的家庭网络多媒体内容共享的访问控制装置, 其中, 所述认 证授权管理服务单元还包括用户访问权限获取子单元, 设置为根据用户名和密 码, 对访问用户进行授权认证, 获取所述用户的访问权限。 1、 如权利要求 10所述的家庭网络多媒体内容共享的访问控制装置,其中,所述认 证授权管理服务单元还包括内容播放权限判断子单元, 设置为当访问所述用户 个人私有目录下的内容时, 判断所述用户是否具备播放所述内容的权限。
PCT/CN2014/079524 2013-12-03 2014-06-09 一种家庭网络多媒体内容共享的访问控制方法和装置 WO2014177108A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310645572.0 2013-12-03
CN201310645572.0A CN104683320A (zh) 2013-12-03 2013-12-03 一种家庭网络多媒体内容共享的访问控制方法和装置

Publications (1)

Publication Number Publication Date
WO2014177108A1 true WO2014177108A1 (zh) 2014-11-06

Family

ID=51843182

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/079524 WO2014177108A1 (zh) 2013-12-03 2014-06-09 一种家庭网络多媒体内容共享的访问控制方法和装置

Country Status (2)

Country Link
CN (1) CN104683320A (zh)
WO (1) WO2014177108A1 (zh)

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106254407B (zh) * 2015-06-15 2020-09-25 南京中兴软件有限责任公司 一种家庭网络服务共享的方法及装置
CN107239239A (zh) * 2016-03-28 2017-10-10 平安科技(深圳)有限公司 数据传输方法和系统
CN105827636B (zh) * 2016-05-09 2019-04-16 Oppo广东移动通信有限公司 一种共享媒体服务的方法和装置
CN106650468B (zh) * 2016-10-09 2019-05-17 Oppo广东移动通信有限公司 控制移动终端的方法、移动终端及音箱
CN106534102A (zh) * 2016-10-31 2017-03-22 北京小米移动软件有限公司 设备访问的方法及装置、电子设备
CN107038388B (zh) * 2017-02-23 2021-03-05 深圳市先河系统技术有限公司 一种多用户操作系统运行方法、装置及计算机设备
US10349134B2 (en) * 2017-05-10 2019-07-09 Accenture Global Solutions Limited Analyzing multimedia content using knowledge graph embeddings
CN110909313A (zh) * 2019-09-18 2020-03-24 龙建春 一种基于家庭数字网络的数字版权管理系统
CN112131588A (zh) * 2020-09-25 2020-12-25 北京锐安科技有限公司 应用访问方法、装置、电子设备和存储介质
CN113051240A (zh) * 2021-04-15 2021-06-29 深圳市椰壳信息科技有限公司 一种应用于nas设备之间的文件共享方法及装置

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1759564A (zh) * 2003-03-10 2006-04-12 索尼株式会社 访问控制处理方法
CN101969407A (zh) * 2010-11-03 2011-02-09 中国电信股份有限公司 基于家庭网关的存储服务方法和存储服务装置
CN102075534A (zh) * 2011-01-06 2011-05-25 中国联合网络通信集团有限公司 家庭网关数据共享的方法和系统
CN102882923A (zh) * 2012-07-25 2013-01-16 北京亿赛通科技发展有限责任公司 移动终端安全存储系统及方法
CN103188284A (zh) * 2011-12-27 2013-07-03 华为终端有限公司 一种家庭网络间媒体资源信息共享的方法及设备

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103001803A (zh) * 2012-12-10 2013-03-27 上海斐讯数据通信技术有限公司 一种网络管理中实现权限管理的方法和系统

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1759564A (zh) * 2003-03-10 2006-04-12 索尼株式会社 访问控制处理方法
CN101969407A (zh) * 2010-11-03 2011-02-09 中国电信股份有限公司 基于家庭网关的存储服务方法和存储服务装置
CN102075534A (zh) * 2011-01-06 2011-05-25 中国联合网络通信集团有限公司 家庭网关数据共享的方法和系统
CN103188284A (zh) * 2011-12-27 2013-07-03 华为终端有限公司 一种家庭网络间媒体资源信息共享的方法及设备
CN102882923A (zh) * 2012-07-25 2013-01-16 北京亿赛通科技发展有限责任公司 移动终端安全存储系统及方法

Also Published As

Publication number Publication date
CN104683320A (zh) 2015-06-03

Similar Documents

Publication Publication Date Title
WO2014177108A1 (zh) 一种家庭网络多媒体内容共享的访问控制方法和装置
US9848024B1 (en) Multiple media device infrastructure
KR101548574B1 (ko) 통신 네트워크들에 대한 네트워크 접속된 미디어 게이트웨이
US20200267432A1 (en) Method of integrating remote content with hospitality media system and media system thereof
US8185949B2 (en) UPnP CDS user profile
US11178131B2 (en) Systems and methods related to establishing a temporary trust relationship between a network-based media service and a digital media renderer
US8655343B2 (en) Server connection method, server, and remote control system
US20040117650A1 (en) Secure media peripheral association in a media exchange network
JP2007534046A (ja) サーバ装置、クライアント装置およびネットワークシステム
WO2013177734A1 (zh) 局域网中媒体资源播放列表的处理方法、装置和系统
US8931059B2 (en) Method and apparatus for cross DRM domain registration
JP2008098708A (ja) コンテンツ配信サーバ、コンテンツ提供サーバ、コンテンツ配信システム、コンテンツ配信方法、コンテンツ提供方法、および、制御プログラム
JP4161791B2 (ja) 機器間認証システム及び機器間認証方法、通信装置、並びにコンピュータ・プログラム
JP6296253B2 (ja) セキュリティ更新可能性のために配布されるホワイトリスト
WO2014071818A1 (zh) 处理媒体内容的方法、控制设备、媒体服务器和媒体播放器
WO2013007154A1 (zh) 媒体资源访问控制方法和设备
WO2013086836A1 (zh) 一种数字移动网络联盟权限控制方法及装置
EP1624622A1 (en) Inter-device authentication system, inter-device authentication method, communication device, and computer program
WO2013013529A1 (zh) 一种UPnP访问控制方法、服务器和客户端
WO2014176970A1 (zh) 一种数据同步的方法及数字媒体服务器
WO2016095434A1 (zh) 播放多媒体资源方法及其装置、存储介质
KR20120094350A (ko) Dlna 기반 홈 네트워크 시스템에서 제한된 컨텐츠 리스트를 제공하기 위한 방법, 이를 수행하기 위한 디지털 미디어 서버 및 디지털 미디어 플레이어
WO2011039179A1 (en) Service contracting by means of upnp
TWI502987B (zh) 影音播放字幕之系統和方法
TW201308943A (zh) 數位生活網路聯盟(dlna)封包傳送方法和系統

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14791039

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14791039

Country of ref document: EP

Kind code of ref document: A1