WO2016050064A1 - 一种对获取加密内容的终端设备的权限管理装置及方法 - Google Patents

一种对获取加密内容的终端设备的权限管理装置及方法 Download PDF

Info

Publication number
WO2016050064A1
WO2016050064A1 PCT/CN2015/078221 CN2015078221W WO2016050064A1 WO 2016050064 A1 WO2016050064 A1 WO 2016050064A1 CN 2015078221 W CN2015078221 W CN 2015078221W WO 2016050064 A1 WO2016050064 A1 WO 2016050064A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal device
rights
logged
obtaining
encrypted content
Prior art date
Application number
PCT/CN2015/078221
Other languages
English (en)
French (fr)
Inventor
李加波
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2016050064A1 publication Critical patent/WO2016050064A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/20Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
    • H04N21/25Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
    • H04N21/258Client or end-user data management, e.g. managing client capabilities, user preferences or demographics, processing of multiple end-users preferences to derive collaborative data

Definitions

  • the present invention relates to the field of interactive network television IPTV, and more particularly to a rights management apparatus and method for a terminal device that acquires encrypted content.
  • the well-known encryption server equipment provider verimatix provides a set of content management and device management solutions, which are used in many operators' IPTV systems.
  • verimatix provides a set of content management and device management solutions, which are used in many operators' IPTV systems.
  • the terminal user In an IPTV system with an encrypted server, the terminal user needs to encrypt after logging in. A key is obtained from the server for decrypting the encrypted content.
  • verimatix sells an authorization for its device.
  • This authorization includes the number of users supported by the system. Of course, the more end users are supported, the higher the charge, and the terminal user needs to obtain the key successfully.
  • the encryption server can register and then obtain the key through the DRM authentication. However, the total number of registered devices cannot exceed the authorized device capacity. If the license is supported by the actual user data, the cost is relatively high. At the same time, if the number of users increases, the number of users exceeds the authorized device capacity, and the license upgrade is also required, which also increases the operating expenses. If a large amount of authorized capacity is reserved, and the actual users are insufficient, resources are wasted.
  • the embodiment of the invention provides a device and a method for managing the rights of the terminal device for acquiring the encrypted content, and can timely recover the rights of the terminal device that is not used, so as to achieve the requirement of reducing the cost.
  • an embodiment of the present invention provides a rights management apparatus for a terminal device that acquires encrypted content, which is applied to a network television system, and includes:
  • the statistic module is configured to obtain a system CDR from the network television system, and obtain a first terminal device that has not been logged into the system and is registered in the system according to the system CDR but has not been logged in for more than a preset time. a second terminal device that has been logged off;
  • a first information processing module configured to acquire a permission identifier acquired when the first terminal device and/or the second terminal device are registered in the system, and confirm the first terminal device and/or according to the permission identifier
  • the second terminal device does not currently log in to the system, the rights occupied by the first terminal device and/or the second terminal device in the system are recovered.
  • the system bill includes a logout record when the terminal device logs out of the system and a logout record of the terminal device account cancellation;
  • the statistics module includes:
  • a first obtaining submodule configured to acquire the system bill in the system
  • the first processing sub-module is configured to obtain, according to the logout record, a logout duration that is up to the current time, and determine that the terminal device whose logout duration exceeds the preset time is the first terminal device;
  • the second processing submodule is configured to determine the second terminal device according to the logout record.
  • the first information processing module includes:
  • a second obtaining submodule configured to acquire a permission identifier of the first terminal device and/or the second terminal device
  • Querying a sub-module configured to query, according to the permission identifier, whether the first terminal device and/or the second terminal device are currently logged into the system;
  • Recycling submodule configured to generate and send a reclaim message to the encryption server when the first terminal device and/or the second terminal device are not currently logged into the system, so that the encryption server deletes the first terminal device and/or Or the second terminal device reclaims the rights of the first terminal device and/or the second terminal device.
  • the query submodule includes:
  • a sending unit configured to send an online query message to the system, to enable the system to query whether the first terminal device and/or the second terminal device are currently logged into the system;
  • the receiving unit is configured to receive a feedback message of the system, where the feedback message includes whether the first terminal device and/or the second terminal device are currently logged into the system.
  • the privilege identifier is included in the registration information of the terminal device when the terminal device sends the registration request to the encryption server;
  • the device also includes:
  • Obtaining a module configured to periodically acquire a third terminal device that logs in for the first time in the system
  • the second information processing module is configured to add the authority of the third terminal device to the encryption server according to the permission identifier of the third terminal device, and complete registration of the third terminal device, so that the The third terminal device can then authenticate to the encryption server by using the permission identifier to obtain an encryption key.
  • the obtaining the system bill from the network television system is performed periodically.
  • an embodiment of the present invention further provides a method for managing rights of a terminal device that obtains encrypted content, which is applied to a network television system, and includes:
  • the system bill includes a logout record when the terminal device logs out of the system and a logout record of the terminal device account cancellation;
  • the rights occupied by the first terminal device and/or the second terminal device in the system are recovered, including:
  • the querying whether the first terminal device and/or the second terminal device are currently logged into the system according to the privilege identifier includes:
  • the feedback message including whether the first terminal device and/or the second terminal device are currently logged into the system.
  • the privilege identifier is included in the registration information of the terminal device when the terminal device sends the registration request to the encryption server;
  • the method further includes:
  • the obtaining the system bill from the network television system is performed periodically.
  • the statistic module determines the terminal device that is not used or temporarily used according to the system bill, so that the first information processing module acquires the terminal device when the system is registered in the system.
  • the obtained permission identifier can confirm that the terminal device does not currently log in to the system according to the permission identifier, and recover the rights occupied by the terminal device in the system.
  • the device rights are recovered in time, the system resources are released, and the number of devices accommodated by the license is fully utilized.
  • the license of the device capacity is as small as possible to support sufficient terminal devices, and the effective use of the device is effectively utilized. System resources reduce operating costs.
  • FIG. 1 is a schematic structural diagram of a rights management apparatus for a terminal device that acquires encrypted content according to an embodiment of the present invention
  • FIG. 2 is a schematic diagram showing an application structure of a rights management apparatus for a terminal device that acquires encrypted content according to an embodiment of the present invention
  • FIG. 3 is a schematic diagram showing an application in a situation in which a terminal device is sold
  • FIG. 4 is a schematic diagram showing an application in a case where the terminal device is offline for more than 7 days;
  • FIG. 5 is a schematic diagram of an application registered when a terminal device logs in for the first time
  • FIG. 6 is a schematic diagram showing an application of obtaining an encryption key after authentication of a terminal device after registration
  • FIG. 7 is a schematic flowchart diagram of a method for managing rights of a terminal device that acquires encrypted content according to an embodiment of the present invention.
  • the present invention is directed to the prior art, in which the terminal device still occupies the license capacity of the system after not logging in or logging out for a long time, and the number of terminal users exceeds the capacity of the device, and the user needs to upgrade the authority or reserve a large amount of permission capacity for normal use.
  • the utility model not only improves the cost but also causes waste of resources, and provides a right authority management device for the terminal device that obtains the encrypted content, and can timely recycle the unused terminal device to achieve the requirement of reducing the cost.
  • an apparatus for managing a terminal device for acquiring encrypted content in an embodiment of the present invention is applied to a network television system, and includes:
  • the statistic module 10 is configured to obtain a system CDR from the network television system, and obtain, according to the system CDR, a first terminal device that has been registered but has not logged into the system for more than a preset time and/or is in the system. a second terminal device that has been registered but has been logged out;
  • the first information processing module 20 is configured to acquire the permission identifier acquired when the first terminal device and/or the second terminal device are registered in the system, and confirm the first terminal device according to the permission identifier. / or second When the terminal device does not currently log in to the system, the rights occupied by the first terminal device and/or the second terminal device in the system are recovered.
  • the statistic module 10 obtains the system CDR from the network television system, and obtains the first terminal device that has not been logged into the system but has not been logged in for more than a preset time according to the system CDR and/or in the system.
  • the second terminal device that has been registered but has been logged out, so that the first information processing module 20 acquires the privilege identifier obtained when the first terminal device and/or the second terminal device are registered in the system, and confirms the privilege according to the privilege identifier.
  • the rights occupied by the first terminal device and/or the second terminal device in the system are recovered.
  • the rights are collected and cleaned up to avoid the resources being occupied by invalid terminals or inactive terminals, and the system resources are released for use by other devices.
  • the obtaining the system bill from the network television system is performed periodically.
  • the period can be preset and adjusted according to the usage status of the terminal device user.
  • the permission identifier deviceid is included in the registration information that the encryption server feeds back to the terminal device when the terminal device sends the registration request to the encryption server, and the permission identifier is the identity feature of the terminal device.
  • the system bill includes the logout record when the terminal device logs out of the system and the logout record of the terminal device account cancellation;
  • the statistics module includes:
  • a first obtaining submodule configured to acquire the system bill in the system
  • the first processing sub-module is configured to obtain, according to the logout record, a logout duration that is up to the current time, and determine that the terminal device whose logout duration exceeds the preset time is the first terminal device;
  • the second processing submodule is configured to determine the second terminal device according to the logout record.
  • the system bill includes the logout record when the terminal device logs out of the system and the logout record of the terminal device.
  • the first obtaining submodule can be based on the logout record (including the time of logout) when the terminal device logs out of the system. Therefore, the logout duration (the duration from the last logout to the current time) is obtained, and the logout duration is compared with the preset duration, and the terminal device whose logout duration exceeds the preset time is determined to be the first Terminal Equipment.
  • the second processing sub-module can determine the second terminal device that has been sold according to the logout record of the system bill.
  • the system bill does not necessarily complete the real-time update.
  • Some terminal devices may not log in to the system for a preset time before being displayed in the system bill record. However, the terminal device may log in at some time before the recycle.
  • the system information is not updated in time. If the terminal device is online, the rights recovery may affect the user service experience. Therefore, in the embodiment of the present invention, the first information processing module includes:
  • a second obtaining submodule configured to acquire a permission identifier of the first terminal device and/or the second terminal device
  • Querying a sub-module configured to query, according to the permission identifier, whether the first terminal device and/or the second terminal device are currently logged into the system;
  • Recycling submodule configured to generate and send a reclaim message to the encryption server when the first terminal device and/or the second terminal device are not currently logged into the system, so that the encryption server deletes the first terminal device and/or Or the second terminal device reclaims the rights of the first terminal device and/or the second terminal device.
  • the query sub-module can query whether the first terminal device and/or the second terminal device are currently logged in according to the permission identifier.
  • the system so that the recycling sub-module generates and sends a recycling message to the encryption server when the first terminal device and/or the second terminal device does not currently log in to the system, so that the encryption server deletes the first terminal device and/or the second
  • the terminal device reclaims the rights of the first terminal device and/or the second terminal device. This avoids the situation of deleting terminal devices that may be currently online.
  • the query submodule includes:
  • a sending unit configured to send an online query message to the system, to enable the system to query whether the first terminal device and/or the second terminal device are currently logged into the system;
  • the receiving unit is configured to receive a feedback message of the system, where the feedback message includes whether the first terminal device and/or the second terminal device are currently logged into the system.
  • the query module sends an online query message to the system through the sending unit, and the online query message received by the system searches for the first terminal device and/or the second terminal device to log in, and then passes the query result.
  • the feedback message is sent back, and the receiving unit receives the feedback message.
  • the query module can notify the recycling sub-module whether to recycle according to the feedback message.
  • the privilege identifier is included in the registration information of the terminal device when the terminal device sends the registration request to the encryption server;
  • the device also includes:
  • Obtaining a module configured to periodically acquire a third terminal device that logs in for the first time in the system
  • the second information processing module is configured to add the authority of the third terminal device to the encryption server according to the permission identifier of the third terminal device, and complete registration of the third terminal device, so that the The third terminal device can then authenticate to the encryption server by using the rights identifier to obtain an encryption key.
  • the terminal device When the terminal device logs in, it first sends a registration request to the encryption server, and receives the permission identifier deviceid fed back by the encryption server.
  • the terminal device that is logged in for the first time is recorded, including the rights of the terminal device.
  • Obtaining a module, periodically acquiring, acquiring a third terminal device that is first logged in the system, including related information, and the second information processing module may increase the authority of the third terminal device according to the deviceid of the third terminal device to In the encryption server DRM, the registration of the third terminal device is completed, so that the third terminal device can then authenticate to the encryption server DRM through the deviceid to obtain an encryption key.
  • the obtained deviceid is sent to the encryption server DRM, and the authentication is performed on the encryption server DRM. Since the registered terminal device in the DRM of the encryption server is completed according to the deviceid, the authentication is performed according to the deviceid. Whether the terminal device has been registered in the encryption server DRM, whether the deviceid is a valid deviceid on the encryption server DRM, and the assigned encryption key is obtained after the authentication is passed. After that, the terminal device obtains the encrypted streaming media file or file stream from the streaming media server CDN, and performs decryption processing by using the encryption key.
  • the application of the rights management device of the terminal device for acquiring the encrypted content in the embodiment of the present invention is described below with reference to FIG. 2-6, wherein some functions of the statistics module of the rights management device of the terminal device that obtains the encrypted content are used in the embodiment of the present invention.
  • the first terminal device that has been registered according to the system bill but has not logged in for more than one preset time is implemented by the STAT statistic module, and another part of the function, and the functions of the first information processing module, the acquisition module, and the second information processing module. It can be implemented by the IMP (Interface Message Processor) interface module:
  • FIG. 2 is a schematic diagram of an overall structure of an apparatus application according to an embodiment of the present invention.
  • a unique device permission identifier is obtained from the encryption server DRM 205.
  • the IPTV service system 203 records the terminal device that is logged in for the first time according to the deviceid, including the rights of the terminal device, and the IPTV service system 203 generates a privilege-increasing task, that is, adds a device task, and the IMP interface module
  • the device 202 acquires related information of the device, including adding a device task, and adds the terminal device to the encryption server 205 to obtain the right.
  • the system CDR can include the logout record when the terminal device logs out of the system and the logout record of the terminal device.
  • the STAT statistic module 201 can implement some functions of the statistic module and obtain the registration by acquiring the system CDR in the IPTV service system 203.
  • the STAT statistic module 201 transmits the terminal device list to the IMP interface module 202, and the IMP interface module 202 queries the current state of the terminal device through the IPTV service system 203, and performs device privilege recovery when the terminal device is offline.
  • the terminal device does not perform permission recovery.
  • the privilege deletion task that is, the deletion device task
  • the task may be recorded in the system CDR.
  • the IMP interface module 202 can also periodically acquire the task and perform rights recovery. In the case of terminal equipment sales, the specific steps are shown in Figure 3:
  • Step 301 when logging out, adding a device deletion task to the database in the IPTV service system 203, the device deletion task is based on the deviceid;
  • Step 302 The IMP interface module 202 periodically acquires a device deletion task.
  • Step 303 The IMP interface module 202 sends the deviceid of the terminal device to the encryption server 205, deletes the terminal device from the encryption server, and reclaims its authority.
  • Step 401 The STAT statistic module 201 calculates, according to the system bill, that the terminal device has not been logged in for more than 7 days, and generates a list file.
  • Step 402 The IMP interface module 202 acquires the unregistered device list file for 7 days, and recovers according to the recorded deviceid of the terminal device.
  • Step 403 Before the collection, the IMP interface module 202 sends an online query message to the IPTV service system 203 to confirm whether the device is online. After accepting the message, the IPTV service system 203 checks whether the device is online and returns the result to the IPTV service system 202.
  • IMP interface machine module 202 Before the collection, the IMP interface module 202 sends an online query message to the IPTV service system 203 to confirm whether the device is online. After accepting the message, the IPTV service system 203 checks whether the device is online and returns the result to the IPTV service system 202.
  • Step 404 If the device is online, it indicates that the device is being used at this time. If the device is recycled at this time, the terminal user cannot watch the video and other problems, and the user experience is poor, so in this case, the process ends and no recovery is performed;
  • Step 405 If the device is not online, normal recovery is performed, and the device is deleted from the encryption server 205, so that the device capacity of the encryption server license is increased by one.
  • the device rights are recovered in time, the system resources are released, and the number of devices accommodated by the license is fully utilized, and the license of the device capacity as small as possible is supported to support sufficient terminal devices. Effective use of system resources and reduced operating costs.
  • Step 501 the terminal device 204 logs in, sends a message to the encryption server 205, downloads a third-party plug-in, and obtains a unique deviceid through the plug-in;
  • Step 502 After obtaining the deviceid, the terminal device synchronizes the deviceid to the IPTV service system 203, and generates an adding device task in the database.
  • Step 503 The IMP interface module 202 periodically acquires an added device task from the IPTV service system 203.
  • step 504 the IMP interface module 202 adds a terminal device to the encryption server 205, and registers the terminal device in the encryption server.
  • the terminal device After registration, the terminal device can obtain the streaming media file encryption key through encryption server authentication, as shown in Figure 6:
  • Step 601 The terminal device 204 sends the deviceid obtained by the third-party plug-in to the encryption server 205, performs authentication on the encryption server, determines whether the terminal device is already registered in the encryption server, and whether the deviceid is valid on the encryption server DRM.
  • Deviceid the deviceid obtained by the third-party plug-in to the encryption server 205, performs authentication on the encryption server, determines whether the terminal device is already registered in the encryption server, and whether the deviceid is valid on the encryption server DRM.
  • Step 602 After receiving the deviceid of the terminal device, the encryption server 205 performs authentication in its own database to see whether the terminal device is already registered in the encryption server.
  • Step 603 if the device has been registered in the encryption server, the normally assigned encryption key key;
  • Step 604 if the device is not registered in the encryption server, the device is invalid, no key is assigned, and the registration is repeated;
  • Step 605 the terminal device passes the authentication, the encryption server 205 returns the key to the terminal device 204;
  • Step 606 After acquiring the key, the terminal device 204 obtains the encrypted streaming media file or file stream from the streaming media server CDN, and performs decryption processing.
  • the rights management apparatus for the terminal device that obtains the encrypted content in the embodiment of the present invention recovers the device rights in time when the terminal device is not used or temporarily used, releasing system resources, and fully utilizing the license.
  • the number of devices will be as small as possible for the capacity of the device to support enough terminal devices, effectively utilizing system resources and reducing operating costs.
  • the registered terminal device is assigned corresponding rights, so that it can implement normal services.
  • an embodiment of the present invention further provides a method for managing rights of a terminal device that obtains encrypted content, which is applied to a network television system, and includes:
  • Step 11 Obtain a system bill from the network television system, and obtain, according to the system bill, a first terminal device that has been registered but has not logged into the system for more than a preset time and/or is registered in the system.
  • Step 12 Acquire a permission identifier acquired when the first terminal device and/or the second terminal device are registered in the system, and confirm the first terminal device and/or the second terminal device according to the permission identifier.
  • the rights occupied by the first terminal device and/or the second terminal device in the system are recovered.
  • the system bill includes a logout record when the terminal device logs out of the system and a logout record of the terminal device account cancellation;
  • Step 11 comprising:
  • Step 111 Acquire the system bill in the system.
  • Step 112 According to the logout record, obtain a logout duration that is up to the current time, and determine that the terminal device whose logout duration exceeds the preset time is the first terminal device;
  • Step 113 Determine the second terminal device according to the logout record.
  • step 12 includes:
  • Step 121 Query whether the first terminal device and/or the second terminal device are currently logged into the system according to the permission identifier.
  • Step 122 When the first terminal device and/or the second terminal device are not currently logged into the system, generate and send a recycling message to the encryption server, so that the encryption server deletes the first terminal device and/or the second The terminal device reclaims the rights of the first terminal device and/or the second terminal device.
  • step 121 includes:
  • Step 1211 Send an online query message to the system, so that the system queries whether the first terminal device and/or the second terminal device are currently logged into the system.
  • Step 1212 Receive a feedback message of the system, where the feedback message includes whether the first terminal device and/or the second terminal device are currently logged into the system.
  • the privilege identifier is included in the registration information of the terminal device when the terminal device sends the registration request to the encryption server;
  • the method further includes:
  • Step 13 periodically acquire a third terminal device that is first logged in the system
  • Step 14 Add the authority of the third terminal device to the encryption server according to the permission identifier of the third terminal device, and complete registration of the third terminal device, so that the third terminal device is followed by Capable of authenticating to the encryption server by using the permission identifier to obtain an encryption key
  • the obtaining the system bill from the network television system is performed periodically.
  • the method for managing the rights of the terminal device for obtaining the encrypted content in the embodiment of the present invention when the terminal device is not used or temporarily used, the device rights are recovered in time, the system resources are released, and the number of devices accommodated by the license is fully utilized.
  • a small device capacity license supports enough terminal devices, effectively utilizing system resources and reducing operating costs.
  • the registered terminal device is assigned corresponding rights, so that it can implement normal services.
  • the method is applied to the foregoing method for managing a rights management device of a terminal device for acquiring encrypted content, and the implementation manner of the rights management device for the terminal device for acquiring the encrypted content is applicable to the method, and can also achieve the same Technical effects.
  • the apparatus and method for managing the rights of the terminal device for obtaining the encrypted content provided by the embodiment of the present invention have the following beneficial effects: when the terminal device is not used or temporarily used, the device authority is recovered in time, and the system resources are released. Fully utilize the number of devices accommodated by the license, and support the license of the device capacity as small as possible to support sufficient terminal equipment, effectively utilize system resources, and reduce operating costs.

Landscapes

  • Engineering & Computer Science (AREA)
  • Databases & Information Systems (AREA)
  • Computer Graphics (AREA)
  • Multimedia (AREA)
  • Signal Processing (AREA)
  • Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
  • Storage Device Security (AREA)

Abstract

一种对获取加密内容的终端设备的权限管理装置及方法,涉及交互式网络电视IPTV领域。该装置,应用于网络电视系统中,包括:统计模块(10),用于从网络电视系统中获取系统话单,并根据系统话单获取注册过但超过一预设时间没有登录系统的第一终端设备和/或在系统中注册过但已注销的第二终端设备;第一信息处理模块(20),用于获取第一终端设备和/或第二终端设备在系统中注册时获取的权限标识,并根据权限标识,确认第一终端设备和/或第二终端设备当前没有登录系统时,回收所述第一终端设备和/或第二终端设备在系统中占用的权限。该装置能够及时的将不使用的终端设备进行权限回收,以达到降低成本的要求。

Description

一种对获取加密内容的终端设备的权限管理装置及方法 技术领域
本发明涉及交互式网络电视IPTV领域,特别是指一种对获取加密内容的终端设备的权限管理装置及方法。
背景技术
著名的加密服务器设备提供商verimatix,提供了一套内容管理和设备管理的解决方案,在很多运营商的IPTV系统中都有运用,在有加密服务器的IPTV系统中,终端用户登录后需要到加密服务器中获取密钥,以用于解密加密内容。
现有技术中,verimatix对于其设备会出售一个授权,这个授权包括了系统支持的用户的数量,当然,支持终端用户数量越多,收费越高,终端用户要成功的获取密钥,需要先到加密服务器上进行注册,然后通过DRM的鉴权后才能获取密钥,但是总的注册设备的数量不能超过授权的设备容量,如果按照实际用户数据购买能支持该数量的授权license,费用相对较高,同时,如果用户数量增加后,用户数量超过授权的设备容量,还需要进行license的升级,也会增加运营费用,如果预留大量授权容量,而实际用户不足,又会造成资源浪费。
发明内容
本发明实施例提供了一种对获取加密内容的终端设备的权限管理装置及方法,能够及时的将不使用的终端设备进行权限的回收,以达到降低成本的要求。
为达到上述目的,本发明的实施例提供一种对获取加密内容的终端设备的权限管理装置,应用于网络电视系统中,包括:
统计模块,设置为从网络电视系统中获取系统话单,并根据所述系统话单获取注册过但超过一预设时间没有登录所述系统的第一终端设备和/或在所述系统中注册过但已注销的第二终端设备;
第一信息处理模块,设置为获取所述第一终端设备和/或第二终端设备在所述系统中注册时获取的权限标识,并根据所述权限标识,确认所述第一终端设备和/或第二终端设备当前没有登录所述系统时,回收所述第一终端设备和/或第二终端设备在所述系统中占用的权限。
其中,所述系统话单中包括终端设备登出所述系统时的登出记录和终端设备销户的注销记录;
所述统计模块包括:
第一获取子模块,设置为获取所述系统中的所述系统话单;
第一处理子模块,设置为根据所述登出记录,获得截止到当前时间的登出时长,确定登出时长超过所述预设时间的终端设备为第一终端设备;
第二处理子模块,设置为根据所述注销记录,确定所述第二终端设备。
其中,所述第一信息处理模块包括:
第二获取子模块,设置为获取所述第一终端设备和/或第二终端设备的权限标识;
查询子模块,设置为根据所述权限标识,查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
回收子模块,设置为在所述第一终端设备和/或第二终端设备当前没有登录所述系统时,生成并发送回收消息至加密服务器,以使加密服务器删除所述第一终端设备和/或第二终端设备,回收所述第一终端设备和/或第二终端设备的权限。
其中,所述查询子模块包括:
发送单元,设置为发送在线查询消息至所述系统,以使所述系统查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
接收单元,设置为接收所述系统的反馈消息,所述反馈消息包括所述第一终端设备和/或第二终端设备的当前是否登录所述系统。
其中,所述权限标识包括于终端设备发送注册请求至加密服务器时,所述加密服务器反馈至所述终端设备的注册信息中;
所述装置还包括:
获取模块,设置为周期性获取在所述系统中首次登录的第三终端设备;
第二信息处理模块,设置为根据所述第三终端设备的权限标识,将所述第三终端设备的权限增加到所述加密服务器中,完成所述第三终端设备的注册,以使所述第三终端设备之后能够通过所述权限标识到所述加密服务器进行鉴权,获得加密密钥
其中,所述从网络电视系统中获取系统话单是周期性地执行的。
为了达到上述目的,本发明的实施例还提供了一种对获取加密内容的终端设备的权限管理方法,应用于网络电视系统中,包括:
从网络电视系统中获取系统话单,并根据所述系统话单获取注册过但超过一预设时间没有登录所述系统的第一终端设备和/或在所述系统中注册过但已注销的第二终端设备;
获取所述第一终端设备和/或第二终端设备在所述系统中注册时获取的权限标识,并根据所述权限标识,确认所述第一终端设备和/或第二终端设备当前没有登录所述系统时,回收所述第一终端设备和/或第二终端设备在所述系统中占用的权限。
其中,所述系统话单中包括终端设备登出所述系统时的登出记录和终端设备销户的注销记录;
所述从网络电视系统中获取系统话单,并根据所述系统话单获取注册过但超过一预设时间没有登录所述系统的第一终端设备和/或在所述系统中注册过但已注销的第二终端设备,包括:
获取所述系统中的所述系统话单;
根据所述登出记录,获得截止到当前时间的登出时长,确定登出时长超过所述预设时间的终端设备为第一终端设备;
根据所述注销记录,确定所述第二终端设备。
其中,所述获取所述第一终端设备和/或第二终端设备在所述系统中注册时获取的权限标识,并根据所述权限标识,确认所述第一终端设备和/或第二终端设备当前没有登录所述系统时,回收所述第一终端设备和/或第二终端设备在所述系统中占用的权限,包括:
获取所述第一终端设备和/或第二终端设备的权限标识;
根据所述权限标识,查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
在所述第一终端设备和/或第二终端设备当前没有登录所述系统时,生成并发送回收消息至加密服务器,以使加密服务器删除所述第一终端设备和/或第二终端设备,回收所述第一终端设备和/或第二终端设备的权限。
其中,所述根据所述权限标识,查询所述第一终端设备和/或第二终端设备当前是否登录所述系统,包括:
发送在线查询消息至所述系统,以使所述系统查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
接收所述系统的反馈消息,所述反馈消息包括所述第一终端设备和/或第二终端设备的当前是否登录所述系统。
其中,所述权限标识包括于终端设备发送注册请求至加密服务器时,所述加密服务器反馈至所述终端设备的注册信息中;
所述方法还包括:
周期性获取在所述系统中首次登录的第三终端设备;
根据所述第三终端设备的权限标识,将所述第三终端设备的权限增加到所述加密服务器中,完成所述第三终端设备的注册,以使所述第三终端设备之后能够通过所述权限标识到所述加密服务器进行鉴权,获得加密密钥
其中,所述从网络电视系统中获取系统话单是周期性地执行的。
本发明的上述技术方案的有益效果如下:
本发明实施例的装置,统计模块从网络电视系统中获取系统话单后,根据该系统话单确定不用或者暂时不用的终端设备,以使第一信息处理模块获取这些终端设备在系统中注册时获取的权限标识,能够根据权限标识,确认终端设备当前没有登录该系统时,并回收这些终端设备在该系统中占用的权限。在终端设备不用或者暂时不用时,及时的进行设备权限的回收,释放系统资源,充分的利用license所容纳的设备数量,将尽量小的设备容量的license去支持足够的终端设备,有效的利用了系统资源,降低了运营成本。
附图说明
图1表示本发明实施例的对获取加密内容的终端设备的权限管理装置的结构示意图;
图2表示本发明实施例的对获取加密内容的终端设备的权限管理装置的应用结构示意图;
图3表示在终端设备销户状况下的应用示意图;
图4表示在终端设备不在线时间超过7天的状况下的应用示意图;
图5表示终端设备首次登录时注册的应用示意图;
图6表示终端设备注册后鉴权获取加密密钥的应用示意图;
图7表示本发明实施例的对获取加密内容的终端设备的权限管理方法的流程示意图。
具体实施方式
为使本发明要解决的技术问题、技术方案和优点更加清楚,下面将结合附图及具体实施例进行详细描述。
本发明针对现有的技术中,终端设备长时间不登录或者注销后仍占有系统的权限license容量,造成终端用户数量超过权限的设备容量,而维持用户正常使用需升级权限或预留大量权限容量,不仅提高了成本还造成资源浪费等问题,提供了一种对获取加密内容的终端设备的权限管理装置,能够及时的将不使用的终端设备进行权限的回收,以达到降低成本的要求。
如图1所示,本发明实施例的一种对获取加密内容的终端设备的权限管理装置,应用于网络电视系统中,包括:
统计模块10,设置为从网络电视系统中获取系统话单,并根据所述系统话单获取注册过但超过一预设时间没有登录所述系统的第一终端设备和/或在所述系统中注册过但已注销的第二终端设备;
第一信息处理模块20,设置为获取所述第一终端设备和/或第二终端设备在所述系统中注册时获取的权限标识,并根据所述权限标识,确认所述第一终端设备和/或第二 终端设备当前没有登录所述系统时,回收所述第一终端设备和/或第二终端设备在所述系统中占用的权限。
应该了解的是,如果终端设备在网络电视系统中下线(即登出,退出登录)超过一定的时间,则说明该终端设备暂时处于不使用的状态,所以这种终端设备所占用的权限属于一种系统资源的浪费;终端用户注销(即销户)后,在该系统中已经不存在了,这种终端设备占用授权已经没有意义,需要对其权限进行收回。这样,通过上述装置,统计模块10从网络电视系统中获取系统话单,并根据该系统话单获取注册过但超过一预设时间没有登录该系统的第一终端设备和/或在该系统中注册过但已注销的第二终端设备,以使第一信息处理模块20获取第一终端设备和/或第二终端设备在所述系统中注册时获取的权限标识,并根据权限标识,确认第一终端设备和/或第二终端设备当前没有登录该系统时,回收第一终端设备和/或第二终端设备在该系统中占用的权限。对于销户和长时间不在线的终端设备及时的进行权限回收清理,避免了资源被无效终端或者不活跃终端占用,释放系统资源,以供其他设备使用。
其中,所述从网络电视系统中获取系统话单是周期性地执行的。
周期性地获取系统话单,找出其中注册过但超过一预设时间没有登录该系统的第一终端设备和/或在该系统中注册过但已注销的第二终端设备收回其权限,能够提高处理效率,更及时实现资源回收再利用。当然,该周期可以根据终端设备用户的使用状况进行预设置和调整。
其中,权限标识deviceid包括于终端设备发送注册请求至加密服务器时,加密服务器反馈至终端设备的注册信息中,权限标识是该终端设备的身份特征。
需要了解到是,要对终端设备的权限进行回收,正确找出待回收的终端设备是第一位的。在本发明实施例中,是通过系统话单中的信息来确定的,所述系统话单中包括终端设备登出所述系统时的登出记录和终端设备销户的注销记录;
所述统计模块包括:
第一获取子模块,设置为获取所述系统中的所述系统话单;
第一处理子模块,设置为根据所述登出记录,获得截止到当前时间的登出时长,确定登出时长超过所述预设时间的终端设备为第一终端设备;
第二处理子模块,设置为根据所述注销记录,确定所述第二终端设备。
系统话单中包括终端设备登出系统时的登出记录和终端设备的注销记录,如此,第一获取子模块就可根据终端设备登出系统时的登出记录(包括退出登录的时间),从而获得截止到当前时间的登出时长(从上一次退出登录到当前时间的时长),将该登出时长与预设时长比较,确定登出时长超过所述预设时间的终端设备为第一终端设备。而第二处理子模块,可根据系统话单的注销记录确定已经销户的第二终端设备。
然而,系统话单并不一定能完成实时更新,有些终端设备可能在系统话单记录中显示之前在预设时间内都未登录该系统,但是,终端设备可能在回收之前的某个时刻登录,系统话单没有及时更新,此时如果该终端设备在线,进行权限回收则会影响到用户业务体验,因此,在本发明实施例中,所述第一信息处理模块包括:
第二获取子模块,设置为获取所述第一终端设备和/或第二终端设备的权限标识;
查询子模块,设置为根据所述权限标识,查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
回收子模块,设置为在所述第一终端设备和/或第二终端设备当前没有登录所述系统时,生成并发送回收消息至加密服务器,以使加密服务器删除所述第一终端设备和/或第二终端设备,回收所述第一终端设备和/或第二终端设备的权限。
在第二获取子模块获取到第一终端设备和/或第二终端设备的权限标识后,查询子模块能够根据该权限标识,查询到该第一终端设备和/或第二终端设备当前是否登录系统,使得回收子模块在该第一终端设备和/或第二终端设备当前没有登录所述系统时,生成并发送回收消息至加密服务器,以使加密服务器删除第一终端设备和/或第二终端设备,回收该第一终端设备和/或第二终端设备的权限。从而就避免了删除可能当前在线的终端设备的情况。
其中,所述查询子模块包括:
发送单元,设置为发送在线查询消息至所述系统,以使所述系统查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
接收单元,设置为接收所述系统的反馈消息,所述反馈消息包括所述第一终端设备和/或第二终端设备的当前是否登录所述系统。
查询模块通过发送单元发送在线查询消息至系统,系统接收的该在线查询消息后就去查找该第一终端设备和/或第二终端设备当前是否登录,然后把查询到的结果通过 反馈消息传回,接收单元就会接收到该反馈消息。查询模块就可依据该反馈消息通知回收子模块是否进行回收。
其中,所述权限标识包括于终端设备发送注册请求至加密服务器时,所述加密服务器反馈至所述终端设备的注册信息中;
所述装置还包括:
获取模块,设置为周期性获取在所述系统中首次登录的第三终端设备;
第二信息处理模块,设置为根据所述第三终端设备的权限标识,将所述第三终端设备的权限增加到所述加密服务器中,完成所述第三终端设备的注册,以使所述第三终端设备之后能够通过所述权限标识到所述加密服务器进行鉴权,获得加密密钥。
在终端设备登录时,会先发送一注册请求至加密服务器,并收到加密服务器反馈的权限标识deviceid,在系统的中就会同步记录首次登录的该终端设备,包括该终端设备的权限等。获取模块,周期性地获取,会获取到在系统中首次登录的第三终端设备,包括其相关信息,第二信息处理模块可根据第三终端设备的deviceid,将第三终端设备的权限增加到加密服务器DRM中,完成所述第三终端设备的注册,以使第三终端设备之后能够通过deviceid到加密服务器DRM进行鉴权,获得加密密钥。
终端设备注册成功后,会将获取的deviceid发送到加密服务器DRM,在加密服务器DRM上进行鉴权,由于加密服务器DRM中注册终端设备是根据deviceid完成的,鉴权时会根据该deviceid进行查找,看是否该终端设备已在加密服务器DRM中注册,该deviceid在加密服务器DRM上是否为有效的deviceid,在鉴权通过后就可获得分配的加密密钥。之后,终端设备从流媒体服务器CDN上获取到加密后的流媒体文件或文件流,凭借该加密密钥进行解密处理。
下面结合图2-6说明本发明实施例的对获取加密内容的终端设备的权限管理装置的应用,其中,本发明实施例的对获取加密内容的终端设备的权限管理装置的统计模块的部分功能,根据系统话单获取注册过但超过一预设时间没有登录系统的第一终端设备是由STAT统计模块实现,另一部分功能、以及第一信息处理模块、获取模块、第二信息处理模块的功能均可由IMP(Interface Message Processor,接口信息处理)接口机模块实现:
如图2所示为本发明实施例的装置应用的整体结构示意图,终端设备204开始登录IPTV业务系统203后,会从加密服务器DRM 205中获取到唯一的设备权限标识 deviceid,IPTV业务系统203会根据该deviceid同步记录首次登录的该终端设备,包括该终端设备的权限等,具体实现在IPTV业务系统203中会生成有权限增加任务即增加设备任务,IMP接口机模块202通过定时获取该设备相关信息,包括增加设备任务,并将该终端设备增加到加密服务器205中,获得权限。系统话单可包括终端设备登出系统时的登出记录和终端设备销户的注销记录,STAT统计模块201能够实现统计模块的部分功能,通过获取IPTV业务系统203中的系统话单,获取注册过但超过一预设时间(如,7天)没有登录该系统的终端设备。STAT统计模块201将该些终端设备列表传给IMP接口机模块202,IMP接口机模块202再通过IPTV业务系统203查询终端设备当前状态,在终端设备不在线时,进行设备权限回收,对于在线的终端设备则不进行权限回收。
当然,终端设备注销时在IPTV业务系统203中,也可生成权限删除任务即删除设备任务,该任务是可记录在系统话单中的。IMP接口机模块202也可定时获取该任务,进行权限回收。在终端设备销户的情况下,具体的步骤如图3:
步骤301,注销时,向IPTV业务系统203中的数据库中增加了一个设备删除任务,该设备删除任务是根据deviceid;
步骤302,IMP接口机模块202定时获取设备删除任务;
步骤303,IMP接口机模块202将该终端设备的deviceid发送给加密服务器205,将该终端设备从加密服务器上删除,回收其权限。
在用户没有登录系统时间超过7天的情况下,需要进行设备权限回收,如图4所示:
步骤401,STAT统计模块201根据系统话单,统计出注册过但超过7天未登录终端设备,生成列表文件;
步骤402,IMP接口机模块202获取7天未登录设备列表文件,根据记录的终端设备的deviceid进行回收;
步骤403,IMP接口机模块202在回收前,向IPTV业务系统203发送在线查询消息,以确认该设备是否在线;IPTV业务系统203接受消息后,去查下该设备是否在线,并将结果返回给IMP接口机模块202;
步骤404,如果设备在线,说明设备此时正在使用,如果此时回收设备,将导致终端用户不能观看视频等问题,用户体验差,所以此种情况下就结束流程,不进行回收;
步骤405,如果设备不在线,则进行正常回收,将设备从加密服务器205中删除,这样加密服务器的license的设备容量增加1个。
上述的实施步骤在终端设备不用或者暂时不用时,及时的进行设备权限的回收,释放系统资源,充分的利用license所容纳的设备数量,将尽量小的设备容量的license去支持足够的终端设备,有效的利用了系统资源,降低了运营成本。
如图5所示,显示了终端在首次登录时,如何到加密服务器上注册的情况:
步骤501,终端设备204登录,发消息到加密服务器205,下载第三方插件,通过插件获取唯一的deviceid;
步骤502,终端设备获取到deviceid后,将该deviceid同步到IPTV业务系统203,在数据库中生成增加设备任务;
步骤503,IMP接口机模块202定时从IPTV业务系统203获取增加设备任务;
步骤504,IMP接口机模块202在加密服务器205增加终端设备,将该终端设备注册到加密服务器中。
注册后,终端设备可通过加密服务器鉴权来获取流媒体文件加密密钥,如图6所示:
步骤601,终端设备204将通过第三方插件获取的deviceid发送到加密服务器205,在加密服务器上进行鉴权,判断该终端设备是否在加密服务器中已经注册,该deviceid在加密服务器DRM上是否为有效的deviceid;
步骤602,加密服务器205收到终端设备的deviceid后,在其自身的数据库中进行鉴权,看该终端设备是否在加密服务器中已经注册;
步骤603,如果设备已经在加密服务器中注册,则正常分配的加密密钥key;
步骤604,如果设备没有在加密服务器中注册,则设备是无效的,不分配key,重复注册;
步骤605,终端设备通过鉴权,加密服务器205将key返回给终端设备204;
步骤606,终端设备204获取了key后,从流媒体服务器CDN上获取加密后的流媒体文件或文件流,进行解密处理。
综上所述,本发明实施例的对获取加密内容的终端设备的权限管理装置,在终端设备不用或者暂时不用时,及时的进行设备权限的回收,释放系统资源,充分的利用license所容纳的设备数量,将尽量小的设备容量的license去支持足够的终端设备,有效的利用了系统资源,降低了运营成本。同时对注册的终端设备分配对应的权限,使其能够实现正常业务。
如图7所示,本发明的实施例还提供了一种对获取加密内容的终端设备的权限管理方法,应用于网络电视系统中,包括:
步骤11,从网络电视系统中获取系统话单,并根据所述系统话单获取注册过但超过一预设时间没有登录所述系统的第一终端设备和/或在所述系统中注册过但已注销的第二终端设备;
步骤12,获取所述第一终端设备和/或第二终端设备在所述系统中注册时获取的权限标识,并根据所述权限标识,确认所述第一终端设备和/或第二终端设备当前没有登录所述系统时,回收所述第一终端设备和/或第二终端设备在所述系统中占用的权限。
其中,所述系统话单中包括终端设备登出所述系统时的登出记录和终端设备销户的注销记录;
步骤11,包括:
步骤111,获取所述系统中的所述系统话单;
步骤112,根据所述登出记录,获得截止到当前时间的登出时长,确定登出时长超过所述预设时间的终端设备为第一终端设备;
步骤113,根据所述注销记录,确定所述第二终端设备。
其中,步骤12,包括:
获取所述第一终端设备和/或第二终端设备的权限标识;
步骤121,根据所述权限标识,查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
步骤122,在所述第一终端设备和/或第二终端设备当前没有登录所述系统时,生成并发送回收消息至加密服务器,以使加密服务器删除所述第一终端设备和/或第二终端设备,回收所述第一终端设备和/或第二终端设备的权限。
其中,步骤121,包括:
步骤1211,发送在线查询消息至所述系统,以使所述系统查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
步骤1212,接收所述系统的反馈消息,所述反馈消息包括所述第一终端设备和/或第二终端设备的当前是否登录所述系统。
其中,所述权限标识包括于终端设备发送注册请求至加密服务器时,所述加密服务器反馈至所述终端设备的注册信息中;
所述方法还包括:
步骤13,周期性获取在所述系统中首次登录的第三终端设备;
步骤14,根据所述第三终端设备的权限标识,将所述第三终端设备的权限增加到所述加密服务器中,完成所述第三终端设备的注册,以使所述第三终端设备之后能够通过所述权限标识到所述加密服务器进行鉴权,获得加密密钥
其中,所述从网络电视系统中获取系统话单是周期性地执行的。
本发明实施例的对获取加密内容的终端设备的权限管理方法,在终端设备不用或者暂时不用时,及时的进行设备权限的回收,释放系统资源,充分的利用license所容纳的设备数量,将尽量小的设备容量的license去支持足够的终端设备,有效的利用了系统资源,降低了运营成本。同时对注册的终端设备分配对应的权限,使其能够实现正常业务。
需要说明的是,该方法是应用于上述对获取加密内容的终端设备的权限管理装置的方法,上述对获取加密内容的终端设备的权限管理装置的实现方式适用于该方法,也能达到相同的技术效果。
以上所述是本发明的优选实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本发明所述原理的前提下,还可以作出若干改进和润饰,这些改进和润饰也应视为本发明的保护范围。
工业实用性
如上所述,本发明实施例提供的一种对获取加密内容的终端设备的权限管理装置及方法具有以下有益效果:在终端设备不用或者暂时不用时,及时地进行设备权限的回收,释放系统资源,充分的利用license所容纳的设备数量,将尽量小的设备容量的license去支持足够的终端设备,有效地利用了系统资源,降低了运营成本。

Claims (12)

  1. 一种对获取加密内容的终端设备的权限管理装置,应用于网络电视系统中,包括:
    统计模块,设置为从网络电视系统中获取系统话单,并根据所述系统话单获取注册过但超过一预设时间没有登录所述系统的第一终端设备和/或在所述系统中注册过但已注销的第二终端设备;
    第一信息处理模块,设置为获取所述第一终端设备和/或第二终端设备在所述系统中注册时获取的权限标识,并根据所述权限标识,确认所述第一终端设备和/或第二终端设备当前没有登录所述系统时,回收所述第一终端设备和/或第二终端设备在所述系统中占用的权限。
  2. 根据权利要求1所述的对获取加密内容的终端设备的权限管理装置,其中,所述系统话单中包括终端设备登出所述系统时的登出记录和终端设备销户的注销记录;
    所述统计模块包括:
    第一获取子模块,设置为获取所述系统中的所述系统话单;
    第一处理子模块,设置为根据所述登出记录,获得截止到当前时间的登出时长,确定登出时长超过所述预设时间的终端设备为第一终端设备;
    第二处理子模块,设置为根据所述注销记录,确定所述第二终端设备。
  3. 根据权利要求1或2所述的对获取加密内容的终端设备的权限管理装置,其中,所述第一信息处理模块包括:
    第二获取子模块,设置为获取所述第一终端设备和/或第二终端设备的权限标识;
    查询子模块,设置为根据所述权限标识,查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
    回收子模块,设置为在所述第一终端设备和/或第二终端设备当前没有登录所述系统时,生成并发送回收消息至加密服务器,以使加密服务器删除所述第一终端设备和/或第二终端设备,回收所述第一终端设备和/或第二终端设备的权限。
  4. 根据权利要求3所述的对获取加密内容的终端设备的权限管理装置,其中,所述查询子模块包括:
    发送单元,设置为发送在线查询消息至所述系统,以使所述系统查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
    接收单元,设置为接收所述系统的反馈消息,所述反馈消息包括所述第一终端设备和/或第二终端设备的当前是否登录所述系统。
  5. 根据权利要求1所述的对获取加密内容的终端设备的权限管理装置,其中,所述权限标识包括于终端设备发送注册请求至加密服务器时,所述加密服务器反馈至所述终端设备的注册信息中;
    所述装置还包括:
    获取模块,设置为周期性获取在所述系统中首次登录的第三终端设备;
    第二信息处理模块,设置为根据所述第三终端设备的权限标识,将所述第三终端设备的权限增加到所述加密服务器中,完成所述第三终端设备的注册,以使所述第三终端设备之后能够通过所述权限标识到所述加密服务器进行鉴权,获得加密密钥。
  6. 根据权利要求1所述的对获取加密内容的终端设备的权限管理装置,其中,所述从网络电视系统中获取系统话单是周期性地执行的。
  7. 一种对获取加密内容的终端设备的权限管理方法,应用于网络电视系统中,包括:
    从网络电视系统中获取系统话单,并根据所述系统话单获取注册过但超过一预设时间没有登录所述系统的第一终端设备和/或在所述系统中注册过但已注销的第二终端设备;
    获取所述第一终端设备和/或第二终端设备在所述系统中注册时获取的权限标识,并根据所述权限标识,确认所述第一终端设备和/或第二终端设备当前没有登录所述系统时,回收所述第一终端设备和/或第二终端设备在所述系统中占用的权限。
  8. 根据权利要求7所述的对获取加密内容的终端设备的权限管理方法,其中,所述系统话单中包括终端设备登出所述系统时的登出记录和终端设备销户的注销记录;
    所述从网络电视系统中获取系统话单,并根据所述系统话单获取注册过但超过一预设时间没有登录所述系统的第一终端设备和/或在所述系统中注册过但已注销的第二终端设备,包括:
    获取所述系统中的所述系统话单;
    根据所述登出记录,获得截止到当前时间的登出时长,确定登出时长超过所述预设时间的终端设备为第一终端设备;
    根据所述注销记录,确定所述第二终端设备。
  9. 根据权利要求7或8所述的对获取加密内容的终端设备的权限管理方法,其中,所述获取所述第一终端设备和/或第二终端设备在所述系统中注册时获取的权限标识,并根据所述权限标识,确认所述第一终端设备和/或第二终端设备当前没有登录所述系统时,回收所述第一终端设备和/或第二终端设备在所述系统中占用的权限,包括:
    获取所述第一终端设备和/或第二终端设备的权限标识;
    根据所述权限标识,查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
    在所述第一终端设备和/或第二终端设备当前没有登录所述系统时,生成并发送回收消息至加密服务器,以使加密服务器删除所述第一终端设备和/或第二终端设备,回收所述第一终端设备和/或第二终端设备的权限。
  10. 根据权利要求9所述的对获取加密内容的终端设备的权限管理方法,其中,所述根据所述权限标识,查询所述第一终端设备和/或第二终端设备当前是否登录所述系统,包括:
    发送在线查询消息至所述系统,以使所述系统查询所述第一终端设备和/或第二终端设备当前是否登录所述系统;
    接收所述系统的反馈消息,所述反馈消息包括所述第一终端设备和/或第二终端设备的当前是否登录所述系统。
  11. 根据权利要求7所述的对获取加密内容的终端设备的权限管理方法,其中,所述权限标识包括于终端设备发送注册请求至加密服务器时,所述加密服务器反馈至所述终端设备的注册信息中;
    所述方法还包括:
    周期性获取在所述系统中首次登录的第三终端设备;
    根据所述第三终端设备的权限标识,将所述第三终端设备的权限增加到所述加密服务器中,完成所述第三终端设备的注册,以使所述第三终端设备之后能够通过所述权限标识到所述加密服务器进行鉴权,获得加密密钥
  12. 根据权利要求7所述的对获取加密内容的终端设备的权限管理方法,其中,所述从网络电视系统中获取系统话单是周期性地执行的。
PCT/CN2015/078221 2014-09-30 2015-05-04 一种对获取加密内容的终端设备的权限管理装置及方法 WO2016050064A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410522327.5 2014-09-30
CN201410522327.5A CN105530524A (zh) 2014-09-30 2014-09-30 一种对获取加密内容的终端设备的权限管理装置及方法

Publications (1)

Publication Number Publication Date
WO2016050064A1 true WO2016050064A1 (zh) 2016-04-07

Family

ID=55629395

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/078221 WO2016050064A1 (zh) 2014-09-30 2015-05-04 一种对获取加密内容的终端设备的权限管理装置及方法

Country Status (2)

Country Link
CN (1) CN105530524A (zh)
WO (1) WO2016050064A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108764607A (zh) * 2018-04-09 2018-11-06 中国平安人寿保险股份有限公司 用户月数据复检方法、装置、设备及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102457763A (zh) * 2010-10-22 2012-05-16 深圳Tcl新技术有限公司 一种许可证书回收系统以及回收方法
US20130031578A1 (en) * 2011-07-27 2013-01-31 Telefonaktiebolaget L M Ericsson (Publ) System and method for control of iptv multimedia content distribution
CN103297272A (zh) * 2013-05-29 2013-09-11 华为软件技术有限公司 设备绑定、解绑定方法和设备缓冲回收池实体设备
CN103346880A (zh) * 2013-06-03 2013-10-09 上海众人网络安全技术有限公司 一种手机令牌自动回收系统及方法
CN103561128A (zh) * 2013-11-04 2014-02-05 福建星网锐捷网络有限公司 光纤通道身份标识回收处理方法及网络设备

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100539516C (zh) * 2006-12-31 2009-09-09 华为技术有限公司 网络许可证管理方法、系统及许可证服务器和客户端
CN101631331B (zh) * 2009-08-10 2012-11-21 华为技术有限公司 一种终端管理方法和设备
CN102467624B (zh) * 2010-11-10 2014-04-02 金蝶软件(中国)有限公司 一种软件许可回收与自动重新申请的方法及系统
CN102521530A (zh) * 2011-10-21 2012-06-27 张国 一种许可证回收方法及系统

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102457763A (zh) * 2010-10-22 2012-05-16 深圳Tcl新技术有限公司 一种许可证书回收系统以及回收方法
US20130031578A1 (en) * 2011-07-27 2013-01-31 Telefonaktiebolaget L M Ericsson (Publ) System and method for control of iptv multimedia content distribution
CN103297272A (zh) * 2013-05-29 2013-09-11 华为软件技术有限公司 设备绑定、解绑定方法和设备缓冲回收池实体设备
CN103346880A (zh) * 2013-06-03 2013-10-09 上海众人网络安全技术有限公司 一种手机令牌自动回收系统及方法
CN103561128A (zh) * 2013-11-04 2014-02-05 福建星网锐捷网络有限公司 光纤通道身份标识回收处理方法及网络设备

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108764607A (zh) * 2018-04-09 2018-11-06 中国平安人寿保险股份有限公司 用户月数据复检方法、装置、设备及存储介质
CN108764607B (zh) * 2018-04-09 2022-04-15 中国平安人寿保险股份有限公司 用户月数据复检方法、装置、设备及存储介质

Also Published As

Publication number Publication date
CN105530524A (zh) 2016-04-27

Similar Documents

Publication Publication Date Title
KR100939430B1 (ko) 브로드캐스트/멀티캐스트 서비스에서 디지털 저작권관리방법
KR100753181B1 (ko) 사용자 및 디바이스 기반의 도메인 시스템의 도메인 관리방법 및 도메인 콘텍스트
US9038191B2 (en) Method and apparatus for providing DRM service
CN102281300B (zh) 数字版权管理许可证分发方法和系统、服务器及终端
CN101247192B (zh) 通信系统、信息处理设备和信息处理方法
WO2008040201A1 (fr) Procédé d'obtention d'une clé à long terme (ltk) et serveur de gestion d'abonnement associé
US8984270B2 (en) Data file decryption method, decryption device and data broadcasting system
CN105530266B (zh) 一种许可证书管理方法、装置及系统
WO2007121632A1 (fr) Procédé pour recevoir un service télédiffusion numérique, terminal maître et terminal esclave associés
CN101699819A (zh) 数字版权管理方法和系统
CN101425112B (zh) 数字许可证书发送系统以及数字作品解密运行方法
EP2157527A1 (en) The method, device and system for forwarding the license
US11258601B1 (en) Systems and methods for distributed digital rights management with decentralized key management
WO2013013581A1 (zh) 一种文档权限管理方法、装置及系统
AU2009252121A1 (en) Method and apparatus for managing tokens for digital rights management
US20100161974A1 (en) Master terminal capable of registering and managing terminals of personal use scope, and method and system using the same
CN108063748B (zh) 一种用户认证方法、装置及系统
CN113472722A (zh) 数据传输方法、存储介质、电子设备及自动售检票系统
US11570192B2 (en) Methods, systems, and devices for detecting over-the-top piracy
JP2004302817A (ja) ライセンス管理システム
WO2016050064A1 (zh) 一种对获取加密内容的终端设备的权限管理装置及方法
US20120284797A1 (en) Drm service providing method, apparatus and drm service receiving method in user terminal
CN100454320C (zh) 数字版权管理中的密钥管理方法及装置
KR20090065399A (ko) 복제된 보안 모듈을 갖는 다운로더블 제한 수신 호스트를감지하는 방법 및 그 장치
CN102123390B (zh) 业务密钥处理的方法、装置及终端

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15847906

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15847906

Country of ref document: EP

Kind code of ref document: A1