WO2020114167A1 - 一种融合网关的usb设备安全共用方法及装置 - Google Patents

一种融合网关的usb设备安全共用方法及装置 Download PDF

Info

Publication number
WO2020114167A1
WO2020114167A1 PCT/CN2019/115229 CN2019115229W WO2020114167A1 WO 2020114167 A1 WO2020114167 A1 WO 2020114167A1 CN 2019115229 W CN2019115229 W CN 2019115229W WO 2020114167 A1 WO2020114167 A1 WO 2020114167A1
Authority
WO
WIPO (PCT)
Prior art keywords
shared
usb device
address
usb
gateway
Prior art date
Application number
PCT/CN2019/115229
Other languages
English (en)
French (fr)
Inventor
覃淑荣
柳丽春
刘媛
Original Assignee
青岛海信宽带多媒体技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 青岛海信宽带多媒体技术有限公司 filed Critical 青岛海信宽带多媒体技术有限公司
Publication of WO2020114167A1 publication Critical patent/WO2020114167A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/66Arrangements for connecting between networks having differing types of switching systems, e.g. gateways
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F13/00Interconnection of, or transfer of information or other signals between, memories, input/output devices or central processing units
    • G06F13/38Information transfer, e.g. on bus
    • G06F13/382Information transfer, e.g. on bus using universal interface adapter
    • G06F13/385Information transfer, e.g. on bus using universal interface adapter for adaptation of a particular data processing system to different peripheral devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/28Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
    • H04L12/2854Wide area networks, e.g. public data networks
    • H04L12/2856Access arrangements, e.g. Internet access
    • H04L12/2869Operational details of access network equipments
    • H04L12/2898Subscriber equipments
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/41Structure of client; Structure of client peripherals
    • H04N21/4104Peripherals receiving signals from specially adapted client devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/41Structure of client; Structure of client peripherals
    • H04N21/426Internal components of the client ; Characteristics thereof
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/43Processing of content or additional data, e.g. demultiplexing additional data from a digital video stream; Elementary client operations, e.g. monitoring of home network or synchronising decoder's clock; Client middleware
    • H04N21/442Monitoring of processes or resources, e.g. detecting the failure of a recording device, monitoring the downstream bandwidth, the number of times a movie has been viewed, the storage space available from the internal hard disk
    • H04N21/44231Monitoring of peripheral device or external card, e.g. to detect processing problems in a handheld device or the failure of an external recording device
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/43Processing of content or additional data, e.g. demultiplexing additional data from a digital video stream; Elementary client operations, e.g. monitoring of home network or synchronising decoder's clock; Client middleware
    • H04N21/443OS processes, e.g. booting an STB, implementing a Java virtual machine in an STB or power management in an STB
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2213/00Indexing scheme relating to interconnection of, or transfer of information or other signals between, memories, input/output devices or central processing units
    • G06F2213/0042Universal serial bus [USB]

Definitions

  • This application relates to the technical field of network multimedia terminals, in particular to a method and device for securely sharing USB devices of a fusion gateway.
  • This application relates to the technical field of network multimedia terminals, in particular to a method and device for securely sharing USB devices of a fusion gateway.
  • the converged gateway As a converged product with a large amount of gateway and network broadcast control functions, the converged gateway has begun to quickly enter the market. Because it reduces the number of home boxes and facilitates the promotion and maintenance of operators, it is bound to gradually replace the traditional single function. Set-top box. How each terminal manufacturer can ensure better performance and better experience of this converged product is the key to quickly occupying the market.
  • the fusion gateway achieves the integration of product functions, because the current chip market does not currently have a mature solution with two functions of gateway and IPTV media playback, the implementation of the technical solution still uses two independent chips, namely hardware When selecting a model, two functions of routing plus playing of the all-in-one will be realized through the 1+1 mode of routing chip plus playing chip.
  • Two main chips are used in the fusion gateway hardware, and dual systems are used in the software implementation, including the gateway system and the IPTV system.
  • the gateway uses the Linux system and the IPTV system uses the Android system.
  • the two systems have their own independent devices. Driver, respectively for their own external devices for device management.
  • This application provides a method and device for safely sharing USB devices of a fusion gateway and a fusion gateway.
  • an embodiment of the present application discloses a method for securely sharing USB devices of a fusion gateway.
  • the fusion gateway has at least two relatively independent first systems and second systems.
  • the method includes:
  • a private communication link connection is configured between the first system and the second system
  • the first system sends a USB operation request to the second system
  • the second system creates a shared message according to the network address and sends it to the first system
  • the first system accesses the USB device through the shared message.
  • an embodiment of the present application further discloses a USB device security sharing device of a fusion gateway, the fusion gateway having at least two relatively independent first systems and second systems, the device including:
  • a configuration unit configured to configure a private communication link connection between the first system and the second system
  • a sending unit configured to send a USB operation request to the second system by the first system
  • An obtaining unit configured to obtain the USB device directory when the second system detects that a USB device is connected, and map the USB device directory to a network address;
  • a creating unit used for the second system to create a shared message according to the network address, and send the shared message to the first system
  • the access unit is used for the first system to access the USB device through the shared message.
  • the embodiments of the application also disclose a converged gateway, including at least two relatively independent first systems and second systems, wherein,
  • the first system is used to perform: configure a private communication link with the second chip; send a USB operation request to the second system; receive a shared message sent by the second system; access through the shared message The USB device;
  • the second system is used to execute: connect with the first chip to configure a private communication link; receive a USB operation request sent by the first system; when the second system detects that a USB device is connected, acquire the A USB device directory, mapping the USB device directory to a network address; creating a shared message according to the network address and sending it to the first system.
  • Embodiments of the present application provide a method for securely sharing USB devices of a fusion gateway.
  • the fusion gateway has at least two relatively independent first systems and second systems.
  • the method includes: between the first system and the second system Configure a private communication link connection; the first system sends a USB operation request to the second system; when the second system detects that a USB device is connected, obtain a USB device directory and map the USB device directory to a network address;
  • the second system creates a shared message according to the network address and sends it to the first system; the first system accesses the USB device through the shared message.
  • the fusion gateway provided in this application has at least two relatively independent first systems and second systems, and only one USB interface is provided in one system, and the first system and the second system are connected by configuring a private communication link.
  • the first system sends a USB operation request to the second system through a private communication link.
  • the second system creates a shared message accessed by the USB device and feeds the shared message back to the first system.
  • the first The system can access the USB device according to the shared message, so that one USB interface can be shared between the two systems, which can reduce the USB interface in the fusion gateway, reduce the finished product, and ensure its safety.
  • the function of the fusion gateway system is deeply integrated to improve user experience.
  • Figure 1 is a schematic diagram of the current USB gateway management architecture of the converged gateway
  • FIG. 2 is a schematic diagram of a USB device management architecture of a converged gateway provided by this application;
  • FIG. 3 is a flowchart of a method for securely sharing USB devices of a fusion gateway provided by an embodiment of the present application
  • FIG. 4 is a detailed flowchart of S100 in a method for securely sharing USB devices of a fusion gateway according to an embodiment of the present application
  • FIG. 5 is a detailed flowchart of S400 in a method for securely sharing USB devices of a converged gateway according to an embodiment of the present application
  • FIG. 6 is a detailed flowchart of S500 in a method for securely sharing USB devices of a fusion gateway provided by an embodiment of the present application;
  • FIG. 7 is a schematic diagram of a method for securely sharing USB devices of a fusion gateway according to an embodiment of the present application.
  • FIG. 8 is a schematic structural diagram of a USB device security sharing device for a fusion gateway provided by an embodiment of this application;
  • the dual system of the fusion gateway cannot read across systems.
  • USB devices commonly used in the fusion gateway to meet the requirements of the two systems for the USB device, you must add USB interfaces to the two systems separately, which will inevitably lead to a product
  • the status of multiple USB interfaces, and users must also distinguish between them, which increases product cost and reduces user experience.
  • the dual-system solution adopted by the converged gateway includes a gateway system and an IPTV system.
  • the gateway system uses a Linux system and the IPTV system uses an Android system.
  • the two systems have their own independent device drivers. External device for device management.
  • the Android system is implemented based on the Linux kernel, so the two methods of operation for USB devices are basically the same.
  • the steps for operating the USB device are as follows:
  • the USB device driver When the USB device is connected to the system, the USB device driver recognizes the USB device and generates a logical device node;
  • the file system mounts the USB device as a target disk recognized by the upper-layer application according to the logical device node generated by the device driver;
  • USB devices commonly used in the converged gateway to meet the requirements of the two systems for USB devices, you must add USB interfaces to the two systems. It will inevitably lead to the status quo of multiple USB interfaces of a product, and users must distinguish between them when they use them, which not only increases the finished product, but also reduces the user experience.
  • the embodiments of the present application provide a method for securely sharing USB devices of a fusion gateway.
  • the fusion gateway has at least two relatively independent first systems and second systems.
  • the fusion gateway only needs to design a USB interface and a USB device.
  • multiple systems of the fusion gateway can access the USB device through this method, which realizes the common use of a USB interface and two systems, which not only reduces the product cost, but also improves the user experience.
  • the first system in the embodiment of the present application may be a gateway system of a converged gateway or an IPTV system of a converged gateway.
  • the second system is an IPTV system of a converged gateway or a gateway system of a converged gateway.
  • the USB device interface is provided by the IPTV system side of the second system, and the gateway system shared by the IPTV system to the first system is used as an example for description.
  • FIG. 2 is a schematic diagram of a USB device management architecture of a converged gateway provided by an embodiment of the present application
  • FIG. 3 is a flowchart of a method for securely sharing USB devices of a converged gateway provided by an embodiment of the present application.
  • the fusion gateway provided in this application only has a USB interface on the IPTV system side, and the USB device can be inserted into the USB interface.
  • the IPTV system and the gateway system can implement the USB device through the method for securely sharing USB devices provided in the embodiments of this application Sharing.
  • a method for securely sharing USB devices of a fusion gateway provided by an embodiment of the present application.
  • the fusion gateway has at least two relatively independent first systems and second systems.
  • the method includes:
  • a private communication link connection is configured between the first system and the second system.
  • this application uses a private communication protocol to negotiate the communication between the two, which mainly includes the establishment of a communication link and the formulation of an interactive protocol.
  • the communication link ensures that the two can communicate with each other, and the interactive protocol stipulates specific operation instructions between the two.
  • the establishment of communication link is shown in Figure 4.
  • S101 The first system and the second system respectively configure private communication addresses and private communication ports.
  • the gateway system of the converged gateway and the IPTV system on the same local area network.
  • the address does not affect the other network functions of the gateway system and the IPTV system, it is implemented by means of multiple IPs, that is, adding a network sub in the existing network configuration Interface, this sub-interface is only used for interaction between the two.
  • the private communication address of the gateway system is 192.168.68.8, and the private communication address of the IPTV system is 192.168.68.9, and the subnet mask of both is configured as 255.255.255.254, which ensures that the network segment includes only two Host address.
  • the private communication port is configured to 8888.
  • S102 Establish a communication link between the private communication address of the first system and the private communication address of the second system through the private communication port.
  • the gateway system After configuring the private communication address and the private communication port of the gateway system and the IPTV system separately, establish a private communication link connection between the private communication address of the IPTV system and the private communication address of the gateway system through the private communication port.
  • the communication between the IPTV system and the gateway system can be Transmission through a private communication link to achieve communication between the two.
  • S200 The first system sends a USB operation request to the second system.
  • the gateway system can send a USB operation request to the IPTV system through the private communication link, such as requesting to share a USB device, or turning off USB device sharing.
  • the communication interaction between the gateway system of the converged gateway and the IPTV system adopts a data message format
  • the data message adopts an XML data format
  • its main fields include: operation type, encrypted string, operation result, shared address, shared
  • the port, access account, and access password are expressed as: optype, encrystr, opresult, shareadd, shareport, account, password.
  • the optype field needs to be configured, where optype is defined as: open (open sharing), close (close sharing).
  • optype is defined as: open (open sharing), close (close sharing).
  • the gateway system configures the optype field to 1 (open sharing).
  • the gateway system in order to ensure the security of the interaction between the gateway system and the IPTV system, can configure the encrypted string at the same time when sending the USB operation request; the IPTV system can perform secure calibration on the encrypted string when receiving the request Test.
  • the encrypted string is generated by the encryption algorithm agreed between the gateway system and the IPTV system.
  • the specific algorithm is as follows: the encryption key agreed by both parties is the fusion gateway SN code, the encryption method uses 3DES, and the gateway MAC is encrypted by this method.
  • the private communication address 192.168.68.8 of the gateway system is created through the private port 8888 and the private communication address 192.168.68.9 of the IPTV system is connected.
  • the configured request message is sent to the IPTV system through the private communication link.
  • USB device accesses Only when the fusion gateway accesses the USB device can the IPTV system or the gateway system use the USB device. If there is a USB device connected, when it is detected that the IPTV system side of the fusion gateway successfully connects the USB device, the USB device directory of the connected USB device is obtained.
  • the USB device directory needs to be mapped to a network address.
  • the specific method is: the IPTV system queries the path of the USB device and maps the path to the network address , Where the network address includes the IP address and port information of the IPTV system or gateway system of the converged gateway.
  • the access account and access password of the USB device may be randomly generated, and the USB device can be accessed only through the access account and access password.
  • S400 The second system creates a shared message according to the network address and sends it to the first system.
  • the IPTV system needs to send the information such as the address of the USB device to the gateway system, and in order to facilitate the transmission of the information to the gateway system, the information such as the address of the USB device is encapsulated into a shared message (data message) , And then transmit the data message to the gateway system.
  • the specific method for creating data messages is shown in Figure 5.
  • S401 The second system separately configures the shared address and shared port of the shared message according to the IP address and port information.
  • the IPTV system After obtaining the IP address and port information corresponding to the USB device, the IPTV system configures the shareadd (shared address) and shareport (shared port) fields of the shared message according to the IP address and port information, respectively.
  • the opresult field After configuring the shareadd and shareport fields of the shared message, you can configure the opresult field according to whether the USB device is connected to the IPTV system side. For example, if the USB device is connected to the IPTV system side, set the opresult to 1; if the IPTV system side is not connected If you enter a USB device, configure opresult to 0.
  • the account (access account) and password (access password) fields of the shared message can also be configured according to the generated access account and access password, and only through this access Only the account number and access password can access the USB device.
  • S402 Send the shared message to the first system through the private communication link.
  • the USB operation request sent by the gateway system can be safely verified to ensure the communication security between the gateway system and the IPTV system.
  • the specific method is: the IPTV system parses the USB operation request message sent by the gateway system to obtain the encrystr (encrypted string) in the request message, and the IPTV system decrypts the encrystr field in the communication request message according to the agreed encryption and decryption algorithm to obtain The MAC address of the encrypted string.
  • the gateway MAC address of the private partition of the IPTV system (the gateway MAC of the private partition and the fusion gateway SN are written at the factory, that is, during production, the gateway MAC and SN information are written to the private partition of the IPTV system synchronously to ensure For consistency with the gateway system), compare the MAC address obtained after decryption with the MAC address read to determine whether they are consistent.
  • the IPTV system is consistent with The gateway system can interact, and the IPTV system can return a shared message corresponding to the communication request message; if the MAC address obtained by decryption is inconsistent with the read MAC address, it means that the IPTV system and the gateway system cannot interact, and the gateway system cannot access the USB device .
  • the IPTV system After performing security verification, the IPTV system obtains the optype (operation type) in the parsed request message, and detects the value of the optype. If the optype is 1, the gateway system requests to open sharing; if the optype is 0, the gateway system Request to close sharing. The corresponding shared message is returned according to the value of optype.
  • S500 The first system accesses the USB device through the shared message.
  • the gateway system After the gateway system receives the shared message returned by the IPTV system, the gateway system can access the USB device according to the returned shared message to realize the sharing of the USB device.
  • the specific method is shown in Figure 6:
  • S501 The first system parses the shared message sent by the second system.
  • the gateway system and the IPTV system have agreed on the format of the data message between the two through an interactive protocol.
  • the shared message returned by the IPTV system includes but does not include the following fields: opresult, shareadd, shareport, account, password. Through this interactive protocol, the shared message is parsed.
  • S502 The first system reads the shared address and shared port of the shared message.
  • the opresult, account, and password fields in the shared message must also be read.
  • the operation result opresult in the shared message returned by the IPTV system is 1 indicates that the request was successful; when the USB device is not connected to the IPTV system side, the shared message returned by the IPTV system The operation result opresult is 0, indicating that the request failed. Therefore, after parsing the shared message according to the interactive protocol, it is necessary to check the value of the operation result to understand whether the IPTV system is connected to the USB device.
  • S503 The first system accesses the USB device through the shared address and the shared port, and performs read and write operations on the USB device.
  • the method for securely sharing USB devices of a converged gateway implements cross-system operation of a USB device through gateway system request sharing and IPTV system configuration sharing, and realizes the gateway system and IPTV by configuring a private communication link
  • the interaction of the system realizes the sharing of the USB device interface through the interaction protocol, and ensures the security of the system interaction through the encryption and decryption algorithm.
  • the above embodiment is an implementation method of the gateway system requesting the IPTV system to share the USB device.
  • the gateway system can notify the IPTV to close the USB device sharing by requesting the sharing.
  • the specific method is similar to the request sharing.
  • the gateway system only needs to be configured
  • the Opresult in the communication message is 0.
  • the IPTV system recognizes that the sharing request is closed, and performs the sharing close operation. The operation returns the operation result successfully.
  • the converged gateway is provided with a USB interface on the IPTV system side, and the gateway system implements cross-system use of the USB device through the USB device security sharing method.
  • a USB interface can also be provided on the gateway system side of the fusion gateway, and the IPTV system can share the USB device through the USB device security sharing method.
  • the USB device safety sharing method of the fusion gateway creates a connection between the gateway system and the IPTV system by configuring a private communication link, and realizes the interaction between the two.
  • the gateway system sends a USB operation request to the IPTV system through the private communication link.
  • the IPTV system system returns the corresponding shared message according to the USB operation request, and the gateway system creates a connection with the USB device according to the shared message returned by the IPTV system, thereby enabling the gateway system to operate the USB device across systems.
  • the sharing of USB devices in the fusion gateway is realized, that is, the dual systems share the same USB interface, reducing the USB interface in the fusion gateway, saving hardware costs, and its secure communication mechanism also avoids the existence of private devices for network sharing. Hidden security risks, ensuring its security, deeply integrating the functions of the fusion gateway system, and improving the user experience. This solution is also applicable to all dual-system converged terminal products, which is convenient for transplantation.
  • embodiments of the present application further provide a USB device security sharing device of the fusion gateway, the fusion gateway having at least two relatively independent first systems and a second system system.
  • the USB device security sharing device provided by the embodiment of the present application includes:
  • the configuration unit 100 is configured to configure a private communication link connection between the first system and the second system.
  • the communication between the gateway system and the IPTV system is realized through the configured private communication link.
  • the configuration unit 100 includes a first configuration module 101 and a establishment module 102, wherein,
  • the first configuration module 101 configured to separately configure the private communication address and the private communication port of the first system and the second system.
  • Configure the private communication address of the gateway system as 192.168.68.8, configure the private communication address of the IPTV system as 192.168.68.9, and configure the private communication port as 8888.
  • the subnet mask of both the gateway system and the IPTV system is configured as 255.255.255.254, which ensures that the network segment includes only two host addresses.
  • Establishment module 102 used to supervise the communication link between the private communication address of the first system and the private communication address of the second system through the private communication port, and establish a private communication link connection between the gateway system and the IPTV system.
  • Sending unit 200 used by the first system to send a USB operation request to the second system.
  • the gateway system may send a USB operation request to the IPTV system through a private communication link.
  • the USB operation request may be a request to share a USB device or a request to turn off USB device sharing.
  • the obtaining unit 300 is used to obtain a USB device directory when the second system detects the access of a USB device, and map the USB device directory to a network address.
  • the obtaining unit obtains the path of the USB device, maps the path to a network address, and obtains the address information of the USB device.
  • Creation unit 400 used by the second system to create a shared message according to the network address and send the shared message to the first system.
  • the creation unit on the IPTV system side creates a shared message according to the network address of the USB device and sends it to the gateway system.
  • the creating unit 400 includes a second configuration module 401 and a sending module 402, where,
  • Second configuration module 401 used by the second system to configure the shared address and shared port of the shared message according to the IP address and port information, respectively. After obtaining the network address (IP address and port information) of the USB device, configure the shareadd (shared address) and shareport (shared port) fields of the shared message according to its configuration.
  • Sending module 402 used to send the shared message to the first system through a private communication link. After configuring the shared message according to the network address information of the USB device, the IPTV system sends it to the gateway system through a private communication link, and responds to the USB operation request sent by the gateway system.
  • Access unit 500 used by the first system to access the USB device through the shared message.
  • the gateway system receives the shared message fed back by the IPTV system, and accesses the USB device according to the shared message.
  • the access unit 500 includes a parsing module 501, a reading module 502, and an operation module 503, where,
  • Parsing module 501 used by the first system to parse the shared message sent by the second system. After receiving the shared message sent by the IPTV system, the gateway system analyzes it through the analysis module.
  • Reading module 502 used to read the shared address and shared port of the shared message. After getting the parsed shared message, read the shareadd (shared address) and shareport (shared port) fields.
  • Operation module 503 used by the first system to access the USB device through the shared address and the shared port, and perform read and write operations on the USB device. After obtaining the shareadd (shared address) and shareport (shared port) fields, access the USB device through it, and perform read and write operations on the USB device.
  • the USB device security sharing device of the fusion gateway implements a private communication link through the configuration unit to realize the communication connection between the gateway system and the IPTV system; the transmission unit implements the gateway system to send the USB operation request to the IPTV system; and the acquisition unit Obtain the address information of the USB device connected to the IPTV system; create a shared message based on the address information of the USB device through the creation unit and send it to the gateway system; receive the shared message returned by the IPTV system through the access unit, and according to the shared report Access USB devices on the IPTV system side.
  • the sharing of USB devices in the fusion gateway is realized, that is, the dual systems share the same USB interface, the USB interface in the fusion gateway is reduced, and the hardware cost is saved.
  • the application embodiment also provides a converged gateway, including a first system 910 and a second system 920, where,
  • the first system 910 is configured to perform: configure a private communication link connection with the second system 920; send a USB operation request to the second system 920; receive a shared message sent by the second system 920; Sharing the message to access the USB device;
  • the second system 920 is configured to perform: configure a private communication link connection with the first system 910; receive a USB operation request sent by the first system 910; when the second system detects that a USB device is accessed, Obtain the USB device directory and map the USB device directory to a network address; create a shared message according to the network address and send it to the first system 910.
  • the USB operation request includes an operation type, where the operation type includes opening sharing and closing sharing.
  • acquiring the USB device directory and mapping the USB device directory to a network address includes: the second system querying the A path of a USB device, and mapping the path to a network address, where the network address includes the IP address and port information of the first system 910 or the second system 920.
  • the second system 920 creates a shared message according to the network address and sends it to the first system 910, including: separately configuring the shared message according to the IP address and the port information Shared address and shared port; and send the shared message to the first system 910 through the private communication link.
  • the first system 910 accessing the USB device through the shared message includes: parsing the shared message sent by the second system 920; reading the shared address of the shared message and Shared port; access the USB device through the shared address and shared port, and perform read and write operations on the USB device.

Landscapes

  • Engineering & Computer Science (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Multimedia (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Computing Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • Databases & Information Systems (AREA)
  • Automation & Control Theory (AREA)
  • Power Engineering (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本申请公开了一种融合网关,具有至少两个相对独立的第一系统和第二系统,第一系统和第二系统之间配置私有通信链路连接;第一系统向第二系统发送USB操作请求;当第二系统检测到有USB设备接入时,获取USB设备目录,将USB设备目录映射为网络地址;第二系统根据网络地址创建共享报文并发送给第一系统;第一系统通过共享报文访问USB设备。

Description

一种融合网关的USB设备安全共用方法及装置
本公开要求在2018年12月7日提交中国专利局、申请日为201811496581.7、申请名称为“一种融合网关的USB设备安全共用方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本公开中。
技术领域
本申请涉及网络多媒体终端技术领域,尤其涉及一种融合网关的USB设备安全共用方法及装置。
背景技术
本申请涉及网络多媒体终端技术领域,尤其涉及一种融合网关的USB设备安全共用方法及装置。
背景技术
融合网关作为一款具备网关和网络播控量大功能的融合性产品,已经开始迅速步入市场,由于其减少了家庭盒子数量,也方便了运营商推广及维护,势必逐渐取代传统的功能单一的机顶盒。各终端厂商如何能够保证这种融合性产品更好的性能以及更好的体验,是迅速占领市场的关键。
融合网关虽然实现了产品功能的整合,但由于目前芯片市场暂不具备方案成熟的具有网关及IPTV媒体播放两大功能的芯片,因此技术方案的实现上还是采用了独立的两款芯片,即硬件选型的时候,会通过路由芯片加播放芯片这种1+1的模式来实现一体机的路由加播放两个功能。融合网关硬件上采用了两款 主芯片,软件的实现上也采用了双系统,包括网关系统和IPTV系统两个系统,网关采用Linux系统,IPTV系统采用Android系统,两个系统有自己独立的设备驱动,分别对于自己的外接设备进行设备管理。
但是,融合网关的双系统无法跨系统进行读取操作,对用户使用造成不便。
发明内容
本申请提供了一种融合网关的USB设备安全共用方法、装置及融合网关。
第一方面,本申请实施例公开了一种融合网关的USB设备安全共用方法,所述融合网关具有至少两个相对独立的第一系统和第二系统,所述方法包括:
所述第一系统和所述第二系统之间配置私有通信链路连接;
所述第一系统向所述第二系统发送USB操作请求;
当所述第二系统检测到有USB设备接入时,获取所述USB设备目录,将所述USB设备目录映射为网络地址;
所述第二系统根据所述网络地址创建共享报文并发送给所述第一系统;
所述第一系统通过所述共享报文访问所述USB设备。
第二方面,本申请实施例还公开了一种融合网关的USB设备安全共用装置,所述融合网关具有至少两个相对独立的第一系统和第二系统,所述装置包括:
配置单元,用于在所述第一系统和所述第二系统之间配置私有通信链路连接;
发送单元,用于所述第一系统向所述第二系统发送USB操作请求;
获取单元,用于当所述第二系统检测到有USB设备接入时,获取所述USB设备目录,将所述USB设备目录映射为网络地址;
创建单元,用于所述第二系统根据所述网络地址创建共享报文,并将所述共享报文发送给所述第一系统;
访问单元,用于所述第一系统通过所述共享报文访问所述USB设备。
第三方面,申请实施例还公开了一种融合网关,包括至少两个相对独立的第一系统和第二系统,其中,
所述第一系统用于执行:与所述第二芯片配置私有通信链路连接;向所述第二系统发送USB操作请求;接收第二系统发送的共享报文;通过所述共享报文访问所述USB设备;
所述第二系统用于执行:与所述第一芯片配置私有通信链路连接;接收第一系统发送的USB操作请求;当所述第二系统检测到有USB设备接入时,获取所述USB设备目录,将所述USB设备目录映射为网络地址;根据所述网络地址创建共享报文并发送给所述第一系统。
与现有技术相比,本申请的有益效果为:
本申请实施例提供了一种融合网关的USB设备安全共用方法,所述融合网关具有至少两个相对独立的第一系统和第二系统,所述方法包括:第一系统和第二系统之间配置私有通信链路连接;第一系统向第二系统发送USB操作请求;当所述第二系统检测到有USB设备接入时,获取USB设备目录,将USB设备目录映射为网络地址;所述第二系统根据网络地址创建共享报文并发送给第一系统;第一系统通过共享报文访问USB设备。本申请提供的融合网关具有至少两个相对独立的第一系统和第二系统,且只在一个系统设置一个USB接口,通过配置私有通信链路连接第一系统和第二系统,当第一系统要使用USB设备时,第一系统通过私有通信链路向第二系统发送USB操作请求,第二系统创建有 USB设备接入的共享报文,并将共享报文反馈至第一系统,第一系统可根据该共享报文访问USB设备,从而能够实现一个USB接口两个系统共用,能够减少融合网关中USB接口,降低产品成品,并保证其安全性,将融合网关系统功能进行深度融合,提高用户体验。
应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本申请。以上是本公开的简单概述,已解释申请的某些方面。该概述不是对申请及其各个方面、实例和/或配置的全面或详细的概述。其目的既不是确定申请的主要或关键元件,也不描述申请的范围,而是简要的介绍申请的某些概念,作为对下文详细描述的介绍。应该理解,本披露文件的其他方面、实例和/或配置可以单独或组合利用上文陈述或下文详述的一个或多个特征。
附图说明
为了更清楚地说明本申请的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,显而易见地,对于本领域普通技术人员而言,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为目前融合网关的USB设备管理架构示意图;
图2为本申请提供的融合网关的USB设备管理架构示意图;
图3为本申请实施例提供的一种融合网关的USB设备安全共用方法的流程图;
图4为本申请实施例提供的融合网关的USB设备安全共用方法中S100的详细流程图;
图5为本申请实施例提供的融合网关的USB设备安全共用方法中S400的 详细流程图;
图6为本申请实施例提供的融合网关的USB设备安全共用方法中S500的详细流程图;
图7为本申请实施例提供的融合网关的USB设备安全共用方法的示意图;
图8为本申请实施例提供的一种融合网关的USB设备安全共用装置的结构示意图;
图9为本申请实施例提供的一种融合网关。
通过上述附图,已示出本申请明确的实施例,后文中将有更详细的描述。这些附图和文字描述并不是为了通过任何方式限制本申请构思的范围,而是通过参考特定实施例为本领域技术人员说明本申请的概念。
具体实施方式
为了使本技术领域的人员更好地理解本申请中的技术方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本申请保护的范围。
融合网关的双系统无法跨系统进行读取操作,对于融合网关中常用到的USB设备,要满足两个系统对于USB设备的需求,则必须为两个系统分别增加USB接口,这必然导致一个产品多个USB接口的现状,而用户使用时,也必须进行区分,增加了产品成本,降低了用户体验。
如图1所示,融合网关采用的双系统方案,包括网关系统和IPTV系统两个系统,网关系统采用Linux系统,IPTV系统采用Android系统,两个系统有自己独立的设备驱动,分别对于自己的外接设备进行设备管理。Android系统基于Linux内核实现,所以,二者对于USB设备的操作方法基本一致,其操作USB设备的步骤如下:
1)USB设备接入系统时,USB设备驱动识别USB设备,并生成一个逻辑设备节点;
2)文件系统根据设备驱动生成的逻辑设备节点将该USB设备挂载成上层应用可以识别的一个目标盘;
3)USB设备挂载成功后,便可以对USB设备进行读写操作了。
但是,融合网关的双系统无法跨系统进行读取操作,所以,对于融合网关中常用到的USB设备,要满足两个系统对于USB设备的需求,则必须为两个系统分别增加USB接口,这必然导致一个产品多个USB接口的现状,而用户使用时,也必须进行区分,不仅增加了产品成品,则降低了用户体验。
为了解决上述问题,本申请实施例提供了一种融合网关的USB设备安全共用方法,融合网关具有至少两个相对独立的第一系统和第二系统,融合网关只需设计一个USB接口,USB设备接入USB接口时,通过该方法融合网关的多个系统均可访问USB设备,实现了一个USB接口两个系统共用,不仅降低了产品成本,也提高了用户体验。
本申请实施例中的第一系统可为融合网关的网关系统,也可为融合网关的IPTV系统,相应地,第二系统为融合网关的IPTV系统,或者为融合网关的网关系统。本申请实施例以USB设备接口由第二系统的IPTV系统侧提供,通过 IPTV系统共享给第一系统的网关系统使用为例进行说明。
参见图2、图3,图2为本申请实施例提供的一种融合网关的USB设备管理架构示意图;图3为本申请实施例提供的一种融合网关的USB设备安全共用方法的流程图。
如图2所示,本申请提供的融合网关只在IPTV系统侧设有USB接口,USB设备可插入USB接口,IPTV系统与网关系统可通过本申请实施例提供的USB设备安全共用方法实现USB设备的共享。
如图3所示,本申请实施例提供的融合网关的USB设备安全共用方法,融合网关具有至少两个相对独立的第一系统和第二系统,所述方法包括:
S100:第一系统和第二系统之间配置私有通信链路连接。
为保证网关系统与IPTV系统之间可以通信与交互,本申请通过私有通信协议协定二者之间的通信,其主要包括通信链路的建立及交互协议的制定。通信链路保证二者之间可以互通,交互协议约定二者之间的具体操作指令。通信链路的建立方法如图4所示。
S101:第一系统和第二系统分别配置私有通信地址与私有通信端口。
将融合网关的网关系统与IPTV系统配置在同一局域网,为保证该地址不影响网关系统和IPTV系统的其他网络功能,通过多IP的方式来实现,即在现有的网络配置下增加一个网络子接口,该子接口仅用于二者之间的交互。具体而言,配置网关系统私有通信地址为192.168.68.8,配置IPTV系统私有通信地址为192.168.68.9,二者的子网掩码均配置为255.255.255.254,其保证了该网段仅包括两个主机地址。私有通信端口配置为8888。
S102:通过私有通信端口建立第一系统私有通信地址与第二系统私有通信 地址的通信链路。
分别配置网关系统和IPTV系统的私有通信地址与私有通信端口后,通过私有通信端口建立IPTV系统私有通信地址与网关系统的私有通信地址间的私有通信链路连接,IPTV系统与网关系统的通信可通过私有通信链路进行传输,实现二者之间的通信。
S200:第一系统向第二系统发送USB操作请求。
融合网关的IPTV系统通过私有通信链路与网关系统连接成功后,网关系统可通过私有通信链路向IPTV系统发送USB操作请求,例如请求共享USB设备,或是关闭USB设备共享。
具体地,融合网关的网关系统与IPTV系统二者之间的通信交互采用数据报文格式,数据报文采用XML数据格式,其主要字段包括:操作类型、加密串、操作结果、共享地址、共享端口、访问帐号、访问密码,分别表示为:optype、encrystr、opresult、shareadd、shareport、account、password。
网关端发送USB操作请求时,需要配置optype字段,其中,optype定义为:open(打开共享)、close(关闭共享)。当网关系统要操作USB设备时,网关系统配置optype字段为1(打开共享)。
在一些实施例中,为了保证网关系统与IPTV系统二者交互的安全性,网关系统在发送USB操作请求时,可同时配置加密串;IPTV系统在接收到请求时,可对加密串进行安全校验。
加密串是通过网关系统与IPTV系统二者之间约定的加密算法来生成的,具体算法如下:双方约定加密密钥为融合网关SN码,加密方法采用3DES,通过该方法对网关MAC进行加密,生成加密串;生成加密串后,根据加密串配置 USB操作请求报文中的encrystr字段。
生成请求报文后,通过私有端口8888创建网关系统私有通信地址192.168.68.8与IPTV系统私有通信地址192.168.68.9连接,连接成功后,通过私有通信链路向IPTV系统发送配置好的请求报文。发送通信请求报文时,设置超时时间为10秒,并等待IPTV系统的数据返回。
S300:当第二系统检测到有USB设备接入时,获取USB设备目录,将USB设备目录映射为网络地址。
在通过共用方法访问USB设备之前,需要检测融合网关是否有USB设备接入,只有在融合网关接入USB设备的前提下,IPTV系统或网关系统才能使用USB设备。如果有USB设备接入,当检测到融合网关的IPTV系统侧成功接入USB设备后,获取接入USB设备的USB设备目录。
在一些实施例中,为方便融合网关的IPTV系统或网关系统访问USB设备,需要将USB设备目录映射为网络地址,具体方法为:IPTV系统查询USB设备的路径,将所述路径映射为网络地址,其中,网络地址包括融合网关的IPTV系统或网关系统的IP地址和端口信息。
在一些实施例中,为了保证融合网关的IPTV系统与网关系统的交互安全性,还可随机生成USB设备的访问账号及访问密码,通过该访问账号及访问密码才能访问USB设备。
S400:第二系统根据网络地址创建共享报文并发送给第一系统。
为方便网关系统访问USB设备,IPTV系统需要将USB设备的地址等信息发送至网关系统,而为了便于将信息发送至网关系统,将USB设备的地址等信息封装为共享报文(数据报文),再将数据报文传输至网关系统。数据报文的具 体创建方法如图5所示。
S401:第二系统根据IP地址与端口信息分别配置共享报文的共享地址与共享端口。
获得USB设备对应的IP地址与端口信息后,IPTV系统根据IP地址与端口信息分别配置共享报文的shareadd(共享地址)、shareport(共享端口)字段。
配置完共享报文的shareadd、shareport字段后,可根据IPTV系统侧是否接入USB设备配置opresult字段,例如,如果IPTV系统侧接入了USB设备,则配置opresult为1;如果IPTV系统侧未接入USB设备,则配置opresult为0。
在一些实施例中,为了保证共享报文的安全性,还可根据所涉及生成的访问账号及访问密码配置共享报文的account(访问账号)、password(访问密码)字段,只能通过该访问账号及访问密码才能访问USB设备。
S402:将共享报文通过私有通信链路发送给第一系统。
将配置好的opresult、shareadd、shareport、account、password字段封装为共享报文,并通过私有通信链路将共享报文由IPTV系统发送至网关系统。
在封装共享报文前,可对网关系统发送的USB操作请求进行安全校验,以保证网关系统与IPTV系统的通信安全性。具体方法为:IPTV系统解析网关系统发送的USB操作请求报文,获取请求报文中的encrystr(加密串),IPTV系统按照约定的加解密算法对通信请求报文中的encrystr字段进行解密,获得加密串的MAC地址。
读取IPTV系统私有分区的网关MAC地址(私有分区的网关MAC与融合 网关SN由出厂时写入,即生产时,将该网关MAC及SN信息同步写入到IPTV系统的私有分区,以此保证了与网关系统的一致性),将解密后得到的MAC地址与读取的MAC地址进行比较,判断二者是否一致,如果解密获得的MAC地址与读取的MAC地址一致,则说明IPTV系统与网关系统能够交互,IPTV系统可返回与通信请求报文相应的共享报文;如果解密获得的MAC地址与读取的MAC地址不一致,则说明IPTV系统与网关系统不能交互,网关系统不能访问USB设备。
IPTV系统在进行安全校验之后,获取解析后请求报文中的optype(操作类型),检测optype的数值,如果optype为1,则说明网关系统请求打开共享;如果optype为0,则说明网关系统请求关闭共享。根据optype数值返回相应的共享报文。
S500:第一系统通过共享报文访问USB设备。
网关系统接收到IPTV系统返回的共享报文后,网关系统可根据返回的共享报文访问USB设备,实现USB设备的共享。具体方法如图6所示:
S501:第一系统解析第二系统发送的共享报文。
网关系统与IPTV系统通过交互协议约定了二者之间的数据报文格式,IPTV系统返回的共享报文包括但不全包括以下字段:opresult、shareadd、shareport、account、password。通过该交互协议解析共享报文。
S502:第一系统读取共享报文的共享地址与共享端口。
对共享报文进行解析处理后,读取共享报文中的shareadd、shareport字段,获取USB设备的共享地址与共享端口。
在一些实施例中,为了网关系统与IPTV系统的通信安全性,除了读取共享 报文中的shareadd、shareport字段外,还需读取共享报文中的opresult、account、password字段。其中,当IPTV系统侧接入USB设备时,IPTV系统返回的共享报文中的操作结果opresult为1则表明请求成功;当IPTV系统侧未接入USB设备时,IPTV系统返回的共享报文中的操作结果opresult为0,表明请求失败。因此,按照交互协议解析共享报文后,需要检测操作结果的数值,以此了解IPTV系统是否接入USB设备。
S503:第一系统通过共享地址与共享端口访问USB设备,对USB设备进行读写操作。
读取到共享报文中的shareadd(共享地址)、shareport(共享端口)、account(访问账号)、password(访问密码)后,通过shareadd、shareport、account、password创建与USB设备的连接,连接成功后,对USB设备进行读写操作。
如图7所示,本申请实施例提供的融合网关的USB设备安全共用方法通过网关系统请求共享、IPTV系统配置共享实现了USB设备的跨系统操作,通过配置私有通信链路实现网关系统与IPTV系统的交互,通过交互协议实现了USB设备接口的共享,通过加解密算法保证了系统交互的安全性。
上述实施例为网关系统请求IPTV系统共享USB设备的实现方法,当共享需求结束后,网关系统可通过请求共享来通知IPTV关闭USB设备的共享,其具体方法与请求共享类似,网关系统仅需要配置通信报文中的Opresult为0,IPTV系统收到请求后,识别为关闭共享请求时,进行共享关闭操作,操作成功返回操作结果。
在一些实施例中,融合网关在IPTV系统侧设置一个USB接口,网关系统通过USB设备安全共用方法实现对USB设备的跨系统使用。同理,也可在融 合网关的网关系统侧设置一个USB接口,IPTV系统可通过该USB设备安全共用方法共享USB设备。
本申请实施例提供的融合网关的USB设备安全共用方法通过配置私有通信链路创建网关系统与IPTV系统的连接,实现二者的交互,网关系统通过私有通信链路向IPTV系统发送USB操作请求,IPTV系统系统根据USB操作请求返回与之对应的共享报文,网关系统根据IPTV系统返回的共享报文创建与USB设备的连接,实现了网关系统跨系统操作USB设备。由此,实现了融合网关中USB设备的共用,即双系统共用同一个USB接口,减少了融合网关中的USB接口,节省了硬件成本,其安全通信机制也规避了私有设备进行网络共享时存在的安全隐患,保证了其安全性,将融合网关系统功能进行深度融合,提高了用户体验。该方案也适用于所有的双系统的融合性终端产品,方便移植。
基于上述实施例所述的融合网关的USB设备安全共用方法,本申请实施例还提供了一种融合网关的USB设备安全共用装置,该融合网关具有至少两个相对独立的第一系统和第二系统。
如图8所示,本申请实施例提供的融合网关的USB设备安全共用装置包括:
配置单元100,用于在第一系统和第二系统之间配置私有通信链路连接。通过配置的私有通信链路实现网关系统和IPTV系统的通信。配置单元100包括第一配置模块101与建立模块102,其中,
第一配置模块101:用于分别配置第一系统和第二系统的私有通信地址与私有通信端口。配置网关系统私有通信地址为192.168.68.8,配置IPTV系统私有通信地址为192.168.68.9,配置私有通信端口为8888。网关系统与IPTV系统二者的子网掩码均配置为255.255.255.254,其保证了该网段仅包括两个主机 地址。
建立模块102:用于通过私有通信端口监理第一系统私有通信地址与第二系统私有通信地址的通信链路,建立网关系统与IPTV系统的私有通信链路连接。
发送单元200:用于第一系统向第二系统发送USB操作请求。网关系统可通过私有通信链路向IPTV系统发送USB操作请求,USB操作请求可为共享USB设备的请求,也可为关闭USB设备共享的请求。
获取单元300:用于当第二系统检测到USB设备接入时,获取USB设备目录,将USB设备目录映射为网络地址。当IPTV系统检测到有USB设备接入时,获取单元就获取USB设备的路径,并将路径映射为网络地址,获取USB设备的地址信息。
创建单元400:用于第二系统根据网络地址创建共享报文,并将共享报文发送给第一系统。IPTV系统侧的创建单元根据USB设备的网络地址创建共享报文,并发送至网关系统。创建单元400包括第二配置模块401与发送模块402,其中,
第二配置模块401:用于第二系统根据IP地址与端口信息分别配置共享报文的共享地址与共享端口。获得USB设备的网络地址(IP地址与端口信息)后,根据其配置共享报文的shareadd(共享地址)、shareport(共享端口)字段。
发送模块402:用于将共享报文通过私有通信链路发送给第一系统。IPTV系统根据USB设备的网络地址信息配置好共享报文后,通过私有通信链路将其发送给网关系统,对网关系统发送的USB操作请求作出响应。
访问单元500:用于第一系统通过共享报文访问USB设备。网关系统接收到IPTV系统反馈的共享报文,并根据该共享报文访问USB设备。访问单元500 包括解析模块501、读取模块502与操作模块503,其中,
解析模块501:用于第一系统解析第二系统发送的共享报文。网关系统接收到IPTV系统发送的共享报文后,通过解析模块对其进行解析处理。
读取模块502:用于读取共享报文的共享地址与共享端口。得到解析后的共享报文后,读取其中的shareadd(共享地址)、shareport(共享端口)字段。
操作模块503:用于第一系统通过共享地址与共享端口访问USB设备,对USB设备进行读写操作。得到shareadd(共享地址)、shareport(共享端口)字段后,通过其访问USB设备,对USB设备进行读写操作。
本申请实施例提供的融合网关的USB设备安全共用装置通过配置单元配置私有通信链路来实现网关系统与IPTV系统的通信连接;通过发送单元实现网关系统向IPTV系统发送USB操作请求;通过获取单元得到IPTV系统接入的USB设备的地址信息;通过创建单元根据USB设备的地址信息创建共享报文,并将其发送给网关系统;通过访问单元接收IPTV系统返回的共享报文,并根据共享报文访问IPTV系统侧的USB设备。由此,实现了融合网关中USB设备的共用,即双系统共用同一个USB接口,减少了融合网关中的USB接口,节省了硬件成本。
参见图9,嗯申请实施例还提供一种融合网关,包括第一系统910和第二系统920,其中,
所述第一系统910用于执行:与所述第二系统920配置私有通信链路连接;向所述第二系统920发送USB操作请求;接收第二系统920发送的共享报文;通过所述共享报文访问所述USB设备;
所述第二系统920用于执行:与所述第一系统910配置私有通信链路连接; 接收第一系统910发送的USB操作请求;当所述第二系统检测到有USB设备接入时,获取所述USB设备目录,将所述USB设备目录映射为网络地址;根据所述网络地址创建共享报文并发送给所述第一系统910。
在一些实施例中,所述USB操作请求包括操作类型,其中,所述操作类型包括打开共享与关闭共享。
在一些实施例中,当所述第二系统920检测到有USB设备接入时,获取所述USB设备目录,将所述USB设备目录映射为网络地址,包括:所述第二系统查询所述USB设备的路径,并将所述路径映射为网络地址,其中,所述网络地址包括所述第一系统910或所述第二系统920的IP地址和端口信息。
在一些实施例中,所述第二系统920根据所述网络地址创建共享报文并发送给所述第一系统910,包括:根据所述IP地址与所述端口信息分别配置所述共享报文的共享地址与共享端口;将所述共享报文通过所述私有通信链路发送给所述第一系统910。
在一些实施例中,所述第一系统910通过所述共享报文访问所述USB设备,包括:解析所述第二系统920发送的共享报文;读取所述共享报文的共享地址与共享端口;通过所述共享地址与共享端口访问所述USB设备,对所述USB设备进行读写操作。
由于以上实施方式均是在其他方式之上引用结合进行说明,不同实施例之间均具有相同的部分,本说明书中各个实施例之间相同、相似的部分互相参见即可。在此不再详细阐述。
需要说明的是,在本说明书中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的电路结构、物品或者 设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种电路结构、物品或者设备所固有的要素。在没有更多限制的情况下,有语句“包括一个……”限定的要素,并不排除在包括所述要素的电路结构、物品或者设备中还存在另外的相同要素。
本领域技术人员在考虑说明书及实践这里发明的公开后,将容易想到本申请的其他实施方案。本申请旨在涵盖本发明的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本申请的一般性原理并包括本申请未公开的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的,本申请的真正范围和精神由权利要求的内容指出。
以上所述的本申请实施方式并不构成对本申请保护范围的限定。

Claims (16)

  1. 一种融合网关,包括:
    至少两个相对独立的第一系统和第二系统,其中,
    所述第一系统用于执行:与所述第二芯片配置私有通信链路连接;向所述第二系统发送USB操作请求;接收第二系统发送的共享报文;通过所述共享报文访问所述USB设备;
    所述第二系统用于执行:与所述第一芯片配置私有通信链路连接;接收第一系统发送的USB操作请求;当所述第二系统检测到有USB设备接入时,获取所述USB设备目录,将所述USB设备目录映射为网络地址;根据所述网络地址创建共享报文并发送给所述第一系统。
  2. 根据权利要求1所述的融合网关,所述USB操作请求包括操作类型,其中,所述操作类型包括打开共享与关闭共享。
  3. 根据权利要求1所述的融合网关,当所述第二系统检测到有USB设备接入时,获取所述USB设备目录,将所述USB设备目录映射为网络地址,包括:
    所述第二系统查询所述USB设备的路径,并将所述路径映射为网络地址,其中,所述网络地址包括所述第一系统或所述第二系统的IP地址和端口信息。
  4. 根据权利要求3所述的方法,其特征在于,所述第二系统根据所述网络地址创建共享报文并发送给所述第一系统,包括:
    根据所述IP地址与所述端口信息分别配置所述共享报文的共享地址与共享端口;
    将所述共享报文通过所述私有通信链路发送给所述第一系统。
  5. 根据权利要求1所述的方法,其特征在于,所述第一系统通过所述共享报 文访问所述USB设备,包括:
    解析所述第二系统发送的共享报文;
    读取所述共享报文的共享地址与共享端口;
    通过所述共享地址与共享端口访问所述USB设备,对所述USB设备进行读写操作。
  6. 一种融合网关的USB设备安全共用方法,所述融合网关具有至少两个相对独立的第一系统和第二系统,其特征在于,所述方法包括:
    所述第一系统和所述第二系统之间配置私有通信链路连接;
    所述第一系统向所述第二系统发送USB操作请求;
    当所述第二系统检测到有USB设备接入时,获取所述USB设备目录,将所述USB设备目录映射为网络地址;
    所述第二系统根据所述网络地址创建共享报文并发送给所述第一系统;
    所述第一系统通过所述共享报文访问所述USB设备。
  7. 根据权利要求6所述的方法,其特征在于,所述第一系统和所述第二系统之间配置私有通信链路连接,包括:
    所述第一系统和所述第二系统分别配置私有通信地址与私有通信端口;
    通过所述私有通信端口建立所述第一系统私有通信地址与所述第二系统私有通信地址的通信链路。
  8. 根据权利要求6所述的方法,其特征在于,所述第一系统向所述第二系统发送USB操作请求,包括:
    所述第一系统向所述第二系统发送操作类型,其中,所述操作类型包括打开共享与关闭共享。
  9. 根据权利要求6所述的方法,其特征在于,当所述第二系统检测到有USB设备接入时,获取所述USB设备目录,将所述USB设备目录映射为网络地址,包括:
    所述第二系统查询所述USB设备的路径,并将所述路径映射为网络地址,其中,所述网络地址包括所述第一系统或所述第二系统的IP地址和端口信息。
  10. 根据权利要求9所述的方法,其特征在于,所述第二系统根据所述网络地址创建共享报文并发送给所述第一系统,包括:
    所述第二系统根据所述IP地址与所述端口信息分别配置所述共享报文的共享地址与共享端口;
    将所述共享报文通过所述私有通信链路发送给所述第一系统。
  11. 根据权利要求6所述的方法,其特征在于,所述第一系统通过所述共享报文访问所述USB设备,包括:
    所述第一系统解析所述第二系统发送的共享报文;
    所述第一系统读取所述共享报文的共享地址与共享端口;
    所述第一系统通过所述共享地址与共享端口访问所述USB设备,对所述USB设备进行读写操作。
  12. 一种融合网关的USB设备安全共用装置,所述融合网关具有至少两个相对独立的第一系统和第二系统,其特征在于,所述装置包括:
    配置单元,用于在所述第一系统和所述第二系统之间配置私有通信链路连接;
    发送单元,用于所述第一系统向所述第二系统发送USB操作请求;
    获取单元,用于当所述第二系统检测到有USB设备接入时,获取所述USB 设备目录,将所述USB设备目录映射为网络地址;
    创建单元,用于所述第二系统根据所述网络地址创建共享报文,并将所述共享报文发送给所述第一系统;
    访问单元,用于所述第一系统通过所述共享报文访问所述USB设备。
  13. 根据权利要求12所述的装置,其特征在于,所述配置单元包括:
    第一配置模块,用于分别配置所述第一系统和所述第二系统的私有通信地址与私有通信端口;
    建立模块,用于通过所述私有通信端口建立所述第一系统私有通信地址与所述第二系统私有通信地址的通信链路。
  14. 根据权利要求12所述的装置,其特征在于,所述创建单元包括:
    第二配置模块,用于所述第二系统根据IP地址与端口信息分别配置所述共享报文的共享地址与共享端口;
    发送模块,用于将所述共享报文通过所述私有通信链路发送给所述第一系统。
  15. 根据权利要求12所述的装置,其特征在于,所述访问单元包括:
    解析模块,用于所述第一系统解析所述第二系统发送的共享报文;
    读取模块,用于读取所述共享报文的共享地址与共享端口;
    操作模块,用于所述第一系统通过所述共享地址与共享端口访问所述USB设备,对所述USB设备进行读写操作。
  16. 根据权利要求12所述的装置,其特征在于,所述访问单元包括:
    解析模块,用于所述第一系统解析所述第二系统发送的共享报文;
    读取模块,用于读取所述共享报文的共享地址与共享端口;
    操作模块,用于所述第一系统通过所述共享地址与共享端口访问所述USB设备,对所述USB设备进行读写操作。
PCT/CN2019/115229 2018-12-07 2019-11-04 一种融合网关的usb设备安全共用方法及装置 WO2020114167A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201811496581.7 2018-12-07
CN201811496581.7A CN109450785B (zh) 2018-12-07 2018-12-07 一种融合网关的usb设备安全共用方法及装置

Publications (1)

Publication Number Publication Date
WO2020114167A1 true WO2020114167A1 (zh) 2020-06-11

Family

ID=65557091

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2019/115229 WO2020114167A1 (zh) 2018-12-07 2019-11-04 一种融合网关的usb设备安全共用方法及装置

Country Status (2)

Country Link
CN (1) CN109450785B (zh)
WO (1) WO2020114167A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023184559A1 (zh) * 2022-04-02 2023-10-05 Oppo广东移动通信有限公司 设备共享方法、装置、设备、存储介质及程序产品

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109450785B (zh) * 2018-12-07 2022-01-07 青岛海信宽带多媒体技术有限公司 一种融合网关的usb设备安全共用方法及装置

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20150365237A1 (en) * 2014-06-17 2015-12-17 High Sec Labs Ltd. Usb security gateway
CN105391652A (zh) * 2015-12-03 2016-03-09 武汉噢易云计算有限公司 基于usb重定向实现usb设备网络共享的系统及方法
EP2428897B1 (en) * 2010-09-14 2016-10-19 Samsung Electronics Co., Ltd. Server device connecting with usb device and device sharing method
CN205693692U (zh) * 2016-06-23 2016-11-16 北京云易时代技术有限公司 共用usb的智能网关
CN109450785A (zh) * 2018-12-07 2019-03-08 青岛海信宽带多媒体技术有限公司 一种融合网关的usb设备安全共用方法及装置

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101599970A (zh) * 2009-07-14 2009-12-09 中国联合网络通信集团有限公司 家庭网关共享存储实现方法及装置
JP6098251B2 (ja) * 2013-03-14 2017-03-22 日本電気株式会社 二重化システム
CN103546200A (zh) * 2013-08-26 2014-01-29 深圳Tcl新技术有限公司 一种基于近场通讯的数据传输方法和系统
CN105704190A (zh) * 2014-11-28 2016-06-22 宇龙计算机通信科技(深圳)有限公司 一种共享数据的方法、装置及终端
CN106878976B (zh) * 2016-01-27 2020-08-21 努比亚技术有限公司 移动终端及双系统的数据共享方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP2428897B1 (en) * 2010-09-14 2016-10-19 Samsung Electronics Co., Ltd. Server device connecting with usb device and device sharing method
US20150365237A1 (en) * 2014-06-17 2015-12-17 High Sec Labs Ltd. Usb security gateway
CN105391652A (zh) * 2015-12-03 2016-03-09 武汉噢易云计算有限公司 基于usb重定向实现usb设备网络共享的系统及方法
CN205693692U (zh) * 2016-06-23 2016-11-16 北京云易时代技术有限公司 共用usb的智能网关
CN109450785A (zh) * 2018-12-07 2019-03-08 青岛海信宽带多媒体技术有限公司 一种融合网关的usb设备安全共用方法及装置

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2023184559A1 (zh) * 2022-04-02 2023-10-05 Oppo广东移动通信有限公司 设备共享方法、装置、设备、存储介质及程序产品

Also Published As

Publication number Publication date
CN109450785B (zh) 2022-01-07
CN109450785A (zh) 2019-03-08

Similar Documents

Publication Publication Date Title
US10237253B2 (en) Private cloud routing server, private network service and smart device client architecture without utilizing a public cloud based routing server
US9203807B2 (en) Private cloud server and client architecture without utilizing a routing server
US9219638B2 (en) Apparatus and method for applying network policy at a network device
US8561147B2 (en) Method and apparatus for controlling of remote access to a local network
US9794237B2 (en) Secured networks and endpoints applying internet protocol security
US7925693B2 (en) NAT access control with IPSec
US9935930B2 (en) Private and secure communication architecture without utilizing a public cloud based routing server
US20100095027A1 (en) Secure communication port redirector
US20150163213A1 (en) Private and secure communication architecture without utilizing a public cloud based routing server
RU2004117065A (ru) Архитектура для подключения удаленного клиента к рабочему столу локального клиента
JP2005518117A (ja) ファイアウォールとnatとを介してコネクションを開始する方法
WO2020114167A1 (zh) 一种融合网关的usb设备安全共用方法及装置
US20100011375A1 (en) Zero-install IP security
TWI632465B (zh) 利用公有雲端網路的方法、私有雲端路由伺服器及智慧型裝置客戶端
TWI537744B (zh) 不利用公用雲端型路由伺服器之私有雲端路由伺服器、私有網路服務及智慧型裝置客戶端架構
WO2015188331A1 (zh) 转发控制方法、驱动器及sdn网络
TWI629598B (zh) 利用公有雲端網路的方法、私有雲端路由伺服器及智慧型裝置客戶端
CN103888288A (zh) 一种注册方法、管理器、注册器与系统
WO2013185696A2 (zh) 一种数据处理的方法与设备
JP6990647B2 (ja) ReNAT通信環境を提供するシステム及び方法
GB2496380A (en) Private cloud server and client architecture using e-mail/SMS to establish communication
Cisco Configuring Dynamic Port VLAN Membership with VMPS
Cisco Configuring Dynamic Port VLAN Membership with VMPS
Cisco Configuring Dynamic Port VLAN Membership with VMPS
Cisco Configuring Dynamic Port VLAN Membership with VMPS

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19893603

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19893603

Country of ref document: EP

Kind code of ref document: A1