Method and apparatus for accessing video conference terminal across domains, electronic device and medium

By negotiating with the video network server of the domain to which the target video network terminal belongs, access authorization is determined and the terminal is added to the read-only operation list, thus resolving the security risks of cross-autonomous domain access and enabling secure access to video network terminals.

CN114760299BActive Publication Date: 2026-01-16VISIONVERA INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210278673.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-21
Publication Date
2026-01-16
Estimated Expiration
2042-03-21

AI Technical Summary

Technical Problem

Accessing video network terminals across autonomous regions poses security risks, and the current method of directly entering the video network number makes access insecure.

Method used

Secure access is achieved by negotiating with the video network server of the domain to which the target video network terminal belongs, determining access authorization, and adding the target video network terminal to the read-only operation list.

Benefits of technology

A secure authorization mechanism for cross-domain access to video network terminals is provided to ensure that cross-domain access to video network terminals is conducted legally and securely, thereby guaranteeing the secure processing of inter-domain video network services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114760299B_ABST
    Figure CN114760299B_ABST
Patent Text Reader

Abstract

The application provides a method and device for cross-domain access to a video live streaming terminal, electronic equipment and a medium. The method is applied to a first video live streaming server in a video live streaming service system. The video live streaming service system includes multiple video live streaming terminals and multiple levels of video live streaming servers. Each video live streaming terminal is directly connected to a video live streaming server. Each video live streaming server and all the video live streaming terminals directly connected thereto constitute a video live streaming domain. The method includes determining a target video live streaming terminal and a second video live streaming server in a video live streaming domain to which the target video live streaming terminal belongs, which need to be accessed across domains; sending an access authorization request for the target video live streaming terminal to the second video live streaming server; receiving terminal information of the target video live streaming terminal returned by the second video live streaming server after the access authorization is allowed; and adding the target video live streaming terminal to a read-only operation list according to the terminal information. The method realizes safe access to a video live streaming terminal across domains.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to a method and apparatus for cross-domain access to a video live streaming terminal, an electronic device, and a medium. BACKGROUND

[0002] Video live streaming is a kind of distributed centralized control network, and in the video live streaming, multiple autonomous domains are distributed by layers, and the overall network structure is formed by interconnection of multiple structural units called autonomous domains. At present, the management of core servers and terminal devices in a single autonomous domain has been realized, and the information of terminal devices in a single autonomous domain can be accessed and configured by the management device in the autonomous domain at any time. However, the access authorization management mechanism of terminal devices in a cross-autonomous domain scenario has not been reasonably defined, and in related technologies, a method of directly inputting a video live streaming number is commonly used to access terminal devices in a cross-autonomous domain. However, in this method, there are certain security risks in the access process of the video live streaming terminal in the cross-domain. SUMMARY

[0003] In view of the above problems, the present application provides a method and apparatus for cross-domain access to a video live streaming terminal, an electronic device, and a medium, which can realize safe access to a video live streaming terminal in a cross-domain.

[0004] The first aspect of the present application provides a method for cross-domain access to a video live streaming terminal, applied to a first video live streaming server in a video live streaming service system, wherein the video live streaming service system includes multiple video live streaming terminals and multiple levels of video live streaming servers, each video live streaming terminal is directly connected to a video live streaming server, each video live streaming server is used to manage all video live streaming terminals directly connected to the video live streaming server, and each video live streaming server and all video live streaming terminals directly connected thereto constitute a video live streaming domain; the method comprises the following steps:

[0005] determining a target video live streaming terminal that needs to be accessed across domains and a second video live streaming server in a video live streaming domain to which the target video live streaming terminal belongs;

[0006] sending an access authorization request for the target video live streaming terminal to the second video live streaming server;

[0007] receiving terminal information of the target video live streaming terminal returned by the second video live streaming server after allowing access authorization;

[0008] adding the target video live streaming terminal to a read-only operation list according to the terminal information, wherein each video live streaming terminal in the read-only operation list is a video live streaming terminal on which the video live streaming server can only perform read-only operations.

[0009] Optionally, after adding the target video live streaming terminal to the read-only operation list, the method further comprises the following steps:

[0010] adding the target in-room video conference terminal into the created in-room video conference.

[0011] Optionally, the access authorization request includes an operation identifier of the authorization request event; after adding the target in-room video conference terminal into the read-only operation list, the method further includes:

[0012] sending a request for changing authorized access to the second in-room video conference server, so as to make the second in-room video conference server modify terminal information of the target in-room video conference terminal corresponding to the operation identifier, or cancel the authorization request event corresponding to the operation identifier;

[0013] The method further includes:

[0014] receiving a processing result returned by the second in-room video conference server in response to the request for changing authorized access;

[0015] If the processing result is that the authorization request event corresponding to the operation identifier is successfully canceled, the target in-room video conference terminal is deleted from the read-only operation list.

[0016] Optionally, the terminal information of the target in-room video conference terminal includes a valid time period during which the first in-room video conference server accesses the target in-room video conference terminal;

[0017] receiving terminal information of the target in-room video conference terminal returned by the second in-room video conference server after the access authorization is allowed, including:

[0018] receiving first terminal information of the target in-room video conference terminal returned by the second in-room video conference server after the access authorization is allowed;

[0019] receiving second terminal information of the target in-room video conference terminal returned by the third in-room video conference server after the access authorization is allowed, the third in-room video conference server being a server designated by the second in-room video conference server and being available for cross-domain authorization management of in-room video conference terminals directly connected to the second in-room video conference server;

[0020] If there is a conflict in-room video conference terminal, the or operation is performed on the valid time period in the first terminal information and the valid time period in the second terminal information, and the obtained time period is used as the valid time period in the terminal information of the conflict in-room video conference terminal, the valid time period in the first terminal information of the conflict in-room video conference terminal being different from the valid time period in the second terminal information of the conflict in-room video conference terminal.

[0021] Optionally, determining the target in-room video conference terminal requiring cross-domain access and the second in-room video conference server in the in-room video conference domain to which the target in-room video conference terminal belongs includes:

[0022] determine a second vision networking server and a number of target vision networking terminals connected under the second vision networking server that need to be accessed across domains;

[0023] send an access authorization request for the target vision networking terminals to the second vision networking server, comprising:

[0024] send an access authorization request containing the number of target vision networking terminals to the second vision networking server, so that the second vision networking server selects target vision networking terminals meeting the number from a plurality of vision networking terminals directly connected with the first vision networking server.

[0025] Optionally, the terminal information of the target vision networking terminal contains a valid time period in which the second vision networking server authorizes the first vision networking server to access the target vision networking terminal; after adding the target vision networking terminal to the read-only operation list, the method further comprises:

[0026] when the invalid time corresponding to the valid time period is reached, delete the target vision networking terminal from the read-only operation list.

[0027] Optionally, the method further comprises:

[0028] when the terminal information of the target vision networking terminal returned by the second vision networking server after allowing access authorization is not received, receive the vision networking terminals that can be accessed returned by the second vision networking server;

[0029] determine one or more vision networking terminals from the vision networking terminals that can be accessed in response to the operation of the user, and send an access authorization request for the determined vision networking terminals to the second vision networking server.

[0030] Optionally, the method further comprises:

[0031] receive an access authorization request for the vision networking terminals under the first vision networking server sent by the second vision networking server;

[0032] determine a vision networking terminal to be accessed, and if the second vision networking server is allowed to access the vision networking terminal to be accessed, return terminal information of the vision networking terminal to be accessed to the second vision networking server, so that the second vision networking server adds the vision networking terminal to be accessed to a read-only operation list according to the terminal information.

[0033] The second aspect of the application provides a device for cross-domain access to a video conferencing terminal, applied to a first video conferencing server in a video conferencing service system, wherein the video conferencing service system comprises a plurality of video conferencing terminals and a plurality of levels of video conferencing servers, each video conferencing terminal is directly connected to a video conferencing server, each video conferencing server is used for managing all video conferencing terminals directly connected to the video conferencing server, and each video conferencing server and all video conferencing terminals directly connected thereto constitute a video conferencing domain; the device comprises:

[0034] A determination module is configured to determine a target video conferencing terminal requiring cross-domain access and a second video conferencing server in a video conferencing domain to which the target video conferencing terminal belongs;

[0035] A first sending module is configured to send an access authorization request for the target video conferencing terminal to the second video conferencing server;

[0036] A first receiving module is configured to receive terminal information of the target video conferencing terminal returned by the second video conferencing server after the second video conferencing server allows the access authorization;

[0037] A first adding module is configured to add the target video conferencing terminal to a read-only operation list according to the terminal information, and each video conferencing terminal in the read-only operation list is a video conferencing terminal on which the video conferencing server can only perform read-only operations.

[0038] Optionally, the device further comprises:

[0039] A second adding module is configured to add the target video conferencing terminal to a created video conferencing video conference.

[0040] Optionally, the access authorization request comprises an operation identifier of an authorization request event; and the device further comprises:

[0041] A second sending module is configured to send a request for changing authorized access containing the operation identifier to the second video conferencing server, so that the second video conferencing server modifies terminal information of a target video conferencing terminal corresponding to the operation identifier or cancels the authorization request event corresponding to the operation identifier;

[0042] The device further comprises:

[0043] A second receiving module is configured to receive a processing result returned by the second video conferencing server in response to the request for changing authorized access;

[0044] A first deleting module is configured to delete the target video conferencing terminal from the read-only operation list if the processing result is successful cancellation of the authorization request event corresponding to the operation identifier.

[0045] Optionally, the terminal information of the target visual internet server includes an effective time period in which the first visual internet server is allowed to access the target visual internet server; and the first receiving module includes:

[0046] a first receiving sub-module, configured to receive first terminal information of the target visual internet server returned by the second visual internet server after the access authorization is allowed;

[0047] a second receiving sub-module, configured to receive second terminal information of the target visual internet server returned by the third visual internet server after the access authorization is allowed, the third visual internet server being a server designated by the second visual internet server and being available for cross-domain authorization management of visual internet servers directly connected to the second visual internet server;

[0048] an operation sub-module, configured to, if there is a conflict visual internet server, perform an OR operation on the effective time period in the first terminal information and the effective time period in the second terminal information, and re-set the obtained time period as the effective time period in the terminal information of the conflict visual internet server, the effective time period in the first terminal information of the conflict visual internet server being different from the effective time period in the second terminal information of the conflict visual internet server.

[0049] Optionally, the determining module includes:

[0050] a determining sub-module, configured to determine the second visual internet server and the number of target visual internet servers connected to the second visual internet server and needing cross-domain access;

[0051] the first sending module includes:

[0052] a sending sub-module, configured to send, to the second visual internet server, an access authorization request including the number of target visual internet servers, so that the second visual internet server selects target visual internet servers meeting the number from a plurality of visual internet servers directly connected to the visual internet server.

[0053] Optionally, the terminal information of the target visual internet server includes an effective time period in which the second visual internet server authorizes the first visual internet server to access the target visual internet server; and the apparatus further includes:

[0054] a second deleting module, configured to delete the target visual internet server from the read-only operation list when an invalid time corresponding to the effective time period is reached.

[0055] Optionally, the apparatus further includes:

[0056] The third receiving module is configured to receive the view internet server accessible terminal returned by the second view internet server when the terminal information of the target view internet terminal returned by the second view internet server after the access authorization is allowed is not received.

[0057] The third sending module is configured to, in response to a user operation, determine one or more view internet terminals from the view internet server accessible terminals, and send an access authorization request for the determined view internet terminals to the second view internet server.

[0058] Optionally, the apparatus further comprises:

[0059] The fourth receiving module is configured to receive an access authorization request for the view internet terminals under the first view internet server sent by the second view internet server.

[0060] The fourth sending module is configured to determine a view internet terminal to be accessed, and if the second view internet server is allowed to access the view internet terminal to be accessed, return terminal information of the view internet terminal to be accessed to the second view internet server, so that the second view internet server adds the view internet terminal to be accessed to the read-only operation list according to the terminal information.

[0061] The third aspect of the present application provides an electronic device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the method for cross-domain access to a view internet terminal according to the first aspect of the present application.

[0062] The fourth aspect of the present application provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to implement the steps of the method for cross-domain access to a view internet terminal according to the first aspect of the present application.

[0063] The method for cross-domain access to a WebRTC terminal provided in the application first determines a target WebRTC terminal that needs to be accessed cross-domain and a second WebRTC server in the WebRTC domain to which the target WebRTC terminal belongs. Then, an access authorization request for the target WebRTC terminal is sent to the second WebRTC server, and terminal information of the target WebRTC terminal returned by the second WebRTC server after the access authorization is allowed is received. Next, the target WebRTC terminal is added to a read-only operation list according to the terminal information, and subsequent read-only operations on the target WebRTC terminal can be performed. The application provides a security authorization mechanism for cross-domain access to a WebRTC terminal. When a WebRTC terminal is accessed cross-domain, negotiation is performed with a WebRTC server in the WebRTC domain to which the WebRTC terminal belongs, and the WebRTC server decides whether to authorize the access (for example, the WebRTC server can authorize the access only when the WebRTC terminal is secure and legal), thereby realizing secure access to a cross-domain WebRTC terminal and providing a guarantee for security processing of inter-domain WebRTC services. BRIEF DESCRIPTION OF DRAWINGS

[0064] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the application.

[0065] Figure 1 is a structural schematic diagram of a WebRTC service system according to an embodiment of the application;

[0066] Figure 2 is a flowchart of a method for cross-domain access to a WebRTC terminal according to an embodiment of the application;

[0067] Figure 3 is a structural block diagram of an apparatus for cross-domain access to a WebRTC terminal according to an embodiment of the application. DETAILED DESCRIPTION

[0068] The technical solutions in the embodiments of the application will be described clearly and completely below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are some of the embodiments of the application, but not all the embodiments of the application. Based on the embodiments in the application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the application.

[0069] Figure 1 is a structural schematic diagram of a WebRTC service system according to an embodiment of the application. In Figure 1In the video live streaming service system, three levels of video live streaming servers are included. The first level of video live streaming server is video live streaming server G0. The second level of video live streaming server includes video live streaming server A0, video live streaming server B0 and video live streaming server C0. The third level of video live streaming server includes video live streaming server A1, video live streaming server A2, video live streaming server A3, video live streaming server B1, video live streaming server C1, video live streaming server C2 and video live streaming server C3. The video live streaming servers of multiple levels are connected in a tree structure. A video live streaming server can be connected with a video live streaming terminal or not directly connected with a video live streaming terminal. One video live streaming terminal is directly connected to one video live streaming server. Video live streaming terminal A01-video live streaming terminal A03 are directly connected to video live streaming server A0. Video live streaming terminal A11-video live streaming terminal A13 are directly connected to video live streaming server A1. Video live streaming terminal A31-video live streaming terminal A32 are directly connected to video live streaming server A3. Video live streaming terminal C01-video live streaming terminal C03 are directly connected to video live streaming server C0. Video live streaming terminal C31-video live streaming terminal C32 are directly connected to video live streaming server C3. Of course, the specific structure of the video live streaming service system can also be set according to actual needs. Figure 1 Only as an example.

[0070] In combination Figure 1 , one video live streaming server and multiple video live streaming terminals directly connected under the video live streaming server constitute an autonomous domain of video live streaming. For example, video live streaming server A0 and video live streaming terminal A01-video live streaming terminal A03 directly connected under the video live streaming server A0 constitute an autonomous domain corresponding to the video live streaming server A0. For another example, video live streaming server A1 and video live streaming terminal A11-video live streaming terminal A13 directly connected under the video live streaming server A1 constitute an autonomous domain corresponding to the video live streaming server A1.

[0071] One video live streaming server is only responsible for managing each video live streaming terminal directly connected under the video live streaming server. Here, the management mainly refers to the modification of configuration information and the like. One video live streaming server cannot manage the video live streaming terminals directly connected under other video live streaming servers. However, in some business scenarios, the video live streaming server needs to perform cross-domain operations, such as inviting video live streaming terminals in other video live streaming domains to join a video live streaming conference under the video live streaming server. The operations of the video live streaming server on the video live streaming terminals in other video live streaming domains due to business needs are mainly read-only operations, that is, only the joining of the conference, the transmission of data and the like can be invited, and the modification of the configuration information cannot be realized.

[0072] The method for cross-domain access to a video live streaming terminal of the present application is applied to Figure 1 the video live streaming server. Figure 2 is a flowchart of a method for cross-domain access to a video live streaming terminal according to an embodiment of the present application. Referring to Figure 2The method for cross-domain access to a video conference terminal according to the present application can comprise the following steps:

[0073] Step S21: determining a target video conference terminal requiring cross-domain access, and a second video conference server in a video conference domain to which the target video conference terminal belongs.

[0074] In the present embodiment, the first video conference server is any one of the video conference servers in the video conference service system, and the video conference domain is a video conference autonomous domain.

[0075] The target video conference terminal can be determined according to user operation or automatically determined by the first video conference server according to business requirements.

[0076] Each video conference terminal belongs to only one video conference autonomous domain and is connected to only one video conference server. Therefore, after the target video conference terminal requiring cross-domain access is determined, the second video conference server in the autonomous domain to which the target video conference terminal belongs can be determined.

[0077] The method for cross-domain access to a video conference terminal according to the present application can be applied to at least two scenarios: 1. a communication scenario between video conference terminals in different autonomous domains; and 2. a video conference scenario among multiple video conference terminals in different autonomous domains.

[0078] For the first scenario, for example, if terminal X under the first video calling server wants to have a video call with terminal Y under the second video calling server, terminal X can send a video call request with terminal Y to the first video calling server. At this time, the first video calling server can determine that the target video calling terminal that needs to be accessed across domains is terminal Y, and terminal Y belongs to the second video calling server according to the video call request. If active sending of a video call request by a terminal is not supported in this scenario (that is, active control by the first video calling server of which two terminals to have a video call), when the first video calling server determines that terminal X under the first video calling server and terminal Y under the second video calling server need to have a video call, the first video calling server can determine that the target video calling terminal that needs to be accessed across domains is terminal Y, and terminal Y belongs to the second video calling server. For the second scenario, for example, if terminal X under the first video calling server wants to start a video conference, a conference initiation request (the list of participants in the conference initiation request includes terminal X, terminal Y and terminal Z under the second video calling server) can be sent to the first video calling server. Then, the first video calling server can determine that terminal Y and terminal Z are target video calling terminals that need to be accessed across domains, and terminal Y and terminal Z belong to the second video calling server. If active sending of a conference initiation request by a terminal is not supported (that is, active control by the first video calling server of which terminals to have a video conference), when the first video calling server determines that terminal X under the first video calling server, terminal Y and terminal Z under the second video calling server need to have a video conference, the first video calling server can determine that the target video calling terminals that need to be accessed across domains are terminal Y and terminal Z, and terminal Y and terminal Z belong to the second video calling server.

[0079] Step S22: Send an access authorization request for the target video calling terminal to the second video calling server.

[0080] In this embodiment, the access authorization request contains the identification (for example, a video calling number) of the target video calling terminal, and the purpose of sending the access authorization request to the second video calling server is to make the second video calling server grant the first video calling server the right to access the target video calling terminal.

[0081] Step S23: Receive terminal information of the target video calling terminal returned by the second video calling server after allowing access authorization.

[0082] In this embodiment, after receiving the access authorization request for the target video calling terminal, the second video calling server can choose to grant the first video calling server the right to access the target video calling terminal, or refuse to grant the first video calling server the right to access the target video calling terminal.

[0083] If the second vision network server grants the first vision network server the right to access the target vision network terminal, the terminal information of the target vision network terminal is returned to the first vision network server. The terminal information mainly includes basic information of the target vision network terminal, such as the duration of the granted right, the effective time of the right, the invalid time of the right, the vision network number, the terminal type, etc. The terminal information can be set according to actual needs, and this embodiment does not make a specific limitation.

[0084] If the second vision network server refuses to grant the first vision network server the right to access the target vision network terminal, a message of authorization failure can be returned to the first vision network server.

[0085] Step S24: According to the terminal information, the target vision network terminal is added to the read-only operation list. Each vision network terminal in the read-only operation list is a vision network terminal on which the vision network server can only perform read-only operations.

[0086] In this embodiment, the vision network server is provided with an operable terminal list. The operable terminal list can be divided into a configurable list and a read-only operation list. Each vision network terminal in the configurable list is a terminal on which the vision network server can modify the configuration information. Each vision network terminal in the read-only operation list is a vision network terminal on which the vision network server cannot modify the configuration information and can only perform read-only operations.

[0087] Since the target vision network terminal is not a terminal in the vision network domain to which the first vision network server belongs, the first vision network server can only perform read-only operations on the target vision network terminal. Therefore, the first vision network server can add the target vision network terminal to the read-only operation list according to the terminal information (such as the vision network number) of the target vision network terminal.

[0088] After adding the target vision network terminal to the read-only operation list, the first vision network server can perform read-only operations on the target vision network terminal according to actual business.

[0089] For example, in combination with Figure 1 The vision network server A0 determines the target vision network terminal C31 that needs to be accessed across domains, and sends an access authorization request for the vision network terminal C31 to the vision network server C3. After receiving the access authorization request, if the vision network server C3 allows the vision network server A0 to access the vision network terminal C31, the vision network server C3 returns the terminal information of the vision network terminal C31 to the vision network server A0. Then, the vision network server A0 adds the vision network terminal C31 to the read-only operation list, and can subsequently perform read-only operations on the vision network terminal C31.

[0090] In this embodiment, when the first vision network server accesses the target vision network terminal under the second vision network server across domains, the second vision network server decides whether to authorize the first vision network server to access the target vision network terminal through negotiation with the second vision network server. Since the second vision network server will detect the information of the target vision network terminal before deciding to authorize, it is determined that the target vision network terminal is legal and safe. Only when the target vision network terminal is legal and safe, the first vision network server is authorized to access the target vision network terminal. Compared with the method in the related art that the first vision network server directly accesses the target vision network terminal through the vision network number of the target vision network terminal, the method can realize the safe access of the first vision network server to the vision network terminal across domains.

[0091] The method for accessing the vision network terminal across domains provided in the present application first determines the target vision network terminal that needs to be accessed across domains and the second vision network server in the vision network domain to which the target vision network terminal belongs. Then, an access authorization request for the target vision network terminal is sent to the second vision network server, and terminal information of the target vision network terminal returned by the second vision network server after allowing access authorization is received. Next, according to the terminal information, the target vision network terminal is added to the read-only operation list, and subsequent read-only operations can be performed on the target vision network terminal. The present application provides a secure authorization mechanism for accessing the vision network terminal across domains. When accessing the vision network terminal across domains, the vision network server of the vision network domain to which the vision network terminal to be accessed belongs is negotiated, and the vision network server decides whether to authorize access (for example, the vision network server can authorize when the vision network terminal is safe and legal), thereby realizing the safe access to the vision network terminal across domains and providing protection for the security of the inter-domain vision network service.

[0092] In combination with the above embodiments, in an implementation manner, determining the target vision network terminal that needs to be accessed across domains and the second vision network server in the vision network domain to which the target vision network terminal belongs can specifically include:

[0093] Determining the second vision network server and the number of target vision network terminals connected under the second vision network server that need to be accessed across domains.

[0094] On this basis, sending an access authorization request for the target vision network terminal to the second vision network server can specifically include:

[0095] Sending an access authorization request containing the number of target vision network terminals to the second vision network server, so that the second vision network server selects target vision network terminals meeting the number from the plurality of vision network terminals directly connected to the first vision network server.

[0096] In the embodiment, the first vision network server can either actively specify the target vision network terminal that needs to be accessed across domains, or only determine the second vision network server and the number of target vision network terminals that the second vision network server needs to provide, and the second vision network server automatically selects the terminals meeting the number from the vision network terminals directly connected thereto as the target vision network terminals and returns them to the first vision network server according to its own situation.

[0097] In some implementation scenarios, the first vision network server only needs to use a preset number of vision network terminals under a specified vision network server, but does not limit a specific part of the vision network terminals, at this time, the first vision network server can take the specified vision network server as the second vision network server, and send an access authorization request containing the number of target vision network terminals to the second vision network server. After the second vision network server receives the access authorization request, it is detected that the vision network number of the specified target vision network terminal is not given, but the number of the target vision network terminal required is given, so the accessible vision network terminals (the accessible vision network terminals generally refer to the safe and legal vision network terminals) meeting the number are selected from the vision network terminals directly connected to itself as the target vision network terminals. Then, the second vision network server returns the terminal information of the target vision network terminal to the second vision network server.

[0098] In the embodiment, if the access authorization request sent by the first vision network server does not give the specified target vision network terminal, the second vision network server can actively select the accessible vision network terminal meeting the number requirement in the access authorization request as the target vision network terminal according to its own situation, thereby improving the flexibility of the cross-domain access of the vision network terminal.

[0099] In combination with the above embodiments, in an implementation, after adding the target vision network terminal to the read-only operation list, the cross-domain access method of the vision network terminal of the present application can further include:

[0100] adding the target vision network terminal to the created vision network video conference.

[0101] In the embodiment, the cross-domain access method of the vision network terminal can be applied to the scenario of cross-domain establishment of the vision network video conference.

[0102] For example, in combination with the above embodiments, in an implementation, the cross-domain access method of the vision network terminal of the present application can further include: Figure 1For example, taking inviting all the WebRTC terminals under WebRTC server C3 to participate in the WebRTC video conference created on WebRTC server A0 as an example, WebRTC server A0 sends a conference invitation to WebRTC server C3, where the number of participating WebRTC terminals (all the WebRTC terminals under WebRTC server C3) and conference information (conference number, start time, end time, etc.) are carried. WebRTC server C3 allows WebRTC terminal C31 and WebRTC terminal C32 to participate in the conference, and returns the terminal information of WebRTC terminal C31 and WebRTC terminal C32 to WebRTC server A0 respectively. WebRTC server A0 adds WebRTC terminal C31 and WebRTC terminal C32 to the read-only operation list, and only when WebRTC terminal C31 and WebRTC terminal C32 are both in the read-only operation list, WebRTC server A0 can perform read-only operation on them. After reaching the start time of the conference, WebRTC server A0 actively pulls WebRTC terminal C31 and WebRTC terminal C32 into the video conference.

[0103] Through the embodiment, the WebRTC terminal can join the cross-domain WebRTC video conference, which enriches the WebRTC function and better meets the business needs of users.

[0104] In combination with the above embodiments, in an implementation, the terminal information of the target WebRTC terminal includes an effective time period in which the second WebRTC server authorizes the first WebRTC server to access the target WebRTC terminal. On this basis, after adding the target WebRTC terminal to the read-only operation list, the method for the cross-domain access WebRTC terminal of the application can include:

[0105] When the invalid time corresponding to the effective time period is reached, the target WebRTC terminal is deleted from the read-only operation list.

[0106] In the embodiment, the effective time period in which the first WebRTC server accesses the target WebRTC terminal is set by the second WebRTC server. The effective time period includes an effective time and an invalid time, and the length of the effective time period is an effective length. The first WebRTC server can only perform read-only operation on the target WebRTC terminal within the effective length, and when the invalid time is reached, the first WebRTC server will automatically delete the target WebRTC terminal in the read-only operation list.

[0107] For example, WebRTC server C3 grants WebRTC server A0 to access WebRTC terminal C31, the effective time is 10:00:00 of the day, and the invalid time is 12:00:00 of the day. Then, WebRTC server A0 can add WebRTC terminal C31 to the read-only operation list

[0108] between 10:00:00 and 12:00:00 of the day, pull WebRTC terminal C31 into the created video conference, and when 12:00:00 is reached, automatically delete WebRTC terminal C31 in the read-only operation list.

[0109] Delete the video call terminal C31 from the read-only operation list.

[0110] Through the embodiment, the video call server can strictly manage each cross-domain video call terminal, and provides a guarantee for the security processing of inter-domain video call services.

[0111] In combination with the above embodiments, in an implementation, the method for accessing a video call terminal across domains of the application can further include:

[0112] When the terminal information of the target video call terminal returned by the second video call server after the access authorization is allowed is not received, the video call terminal that can be allowed to access returned by the second video call server is received.

[0113] In response to the operation of the user, one or more video call terminals are determined from the video call terminals that can be allowed to access, and an access authorization request for the determined video call terminals is sent to the second video call server.

[0114] In the embodiment, after receiving the access authorization request sent by the first video call server, if the first video call server is refused to be granted the right to access the target video call terminal, in addition to returning a message of authorization failure to the first video call server, the second video call server can also return the video call terminals that can be allowed to be authorized to access except the target video call terminal to the first video call server.

[0115] In this way, the first video call server can select one or more video call terminals from all the returned video call terminals that can be allowed to access according to the operation of the user, and then send an access authorization request to the second video call server again, taking the selected video call terminals as target video call terminals. Of course, the first video call server can also select one or more video call terminals from the remaining video call terminals except the returned video call terminals that can be allowed to access according to the operation of the user, and take the selected video call terminals as target video call terminals.

[0116] In the embodiment, after the second video call server refuses to grant the first video call server the right to access the target video call terminal, the second video call server can return the video call terminals that can be allowed to be authorized to access except the target video call terminal to the first video call server, so as to facilitate the selection of the first video call server, and provide convenience for the first video call server to access the video call terminals under the second video call server across domains.

[0117] In combination with the above embodiments, in an implementation, the operation identifier of the current authorization request event is included in the access authorization request. After the target video call terminal is added to the read-only operation list, the method for accessing a video call terminal across domains of the application can further include:

[0118] The second video call server is sent a request for changing authorized access containing the operation identifier, so that the second video call server modifies terminal information of the target video call terminal corresponding to the operation identifier, or cancels the authorization request event corresponding to the operation identifier.

[0119] In this embodiment, the first video call server generates an operation identifier each time it generates an access authorization request, and the operation identifier uniquely corresponds to the authorization request event. In other words, the operation identifier can be understood as a unique number of an authorization request event, and can be used to distinguish other authorization request events.

[0120] The first video call server sends an access authorization request to the second video call server for the first time, and the access authorization request contains an operation identifier. The second video call server stores the operation identifier in the access authorization request.

[0121] In the subsequent process, the first video call server can also send a request for changing authorized access containing the operation identifier to the second video call server for the authorization request event that has been processed and authorized. The request for changing authorized access can be of two types: modifying terminal information of the target video call terminal and canceling the authorization request event.

[0122] For the request of the type of modifying terminal information of the target video call terminal, the content in the request generally includes: the field to be changed and the changed content, etc. The second video call server can determine the authorization request event according to the operation identifier, and then modify the terminal information of the target video call terminal based on the content in the request for changing authorized access.

[0123] For the request of the type of canceling the authorization request event, the second video call server can determine the authorization request event according to the operation identifier, and then cancel the authorization request event.

[0124] On this basis, the method for cross-domain access to a video call terminal of the present application can further include:

[0125] A processing result returned by the second video call server in response to the request for changing authorized access is received.

[0126] If the processing result is that the authorization request event corresponding to the operation identifier is successfully canceled, the target video call terminal is deleted from the read-only operation list.

[0127] In this embodiment, if the first vision networking server sends a cancel authorization request event type request to the second vision networking server, upon receiving the processing result returned by the second vision networking server that successfully cancels the authorization request event corresponding to the operation identifier, the first vision networking server deletes the target vision networking terminal from the read-only operation list. Conversely, if the processing result returned by the second vision networking server that fails to successfully cancel the authorization request event corresponding to the operation identifier is received, the first vision networking server does not process the target vision networking terminal in the read-only operation list.

[0128] For example, in combination with Figure 1 If the vision networking server A0 sends an access authorization request (creates an authorization request event) to the vision networking server C3 at 10:00:00 on October 1, the content in the access authorization request is mainly: requesting the vision networking server C3 to grant the vision networking server A0 the right to invite the vision networking terminal C31 to participate in the video conference X from 14:00:00 on October 1 to 16:00:00 on October 1. The operation identifier in the access authorization request is YYY (the operation identifier can usually be generated according to the initiation time, for example, can be generated according to 10:00:00 on October 1), the vision networking server C3 receives the access authorization request, processes the access authorization request, and stores the operation identifier YYY.

[0129] If the vision networking server C3 allows this authorization, the terminal information of the vision networking terminal C31 is returned to the first vision networking server, and the operation identifier YYY is stored corresponding to the terminal information. The terminal information includes: the effective time period is from 14:00:00 on October 1 to 16:00:00 on October 1, the effective time is 14:00:00 on October 1, the invalid time is 16:00:00 on October 1, the valid duration is 2 hours, the vision networking number CBDEU595 of the vision networking terminal C31, and the like. In this way, the first vision networking server can add the vision networking terminal C31 to the read-only operation list between 14:00:00 on October 1 and 16:00:00 on October 1, and pull the vision networking terminal C31 into the video conference X.

[0130] If the first video conference server cancels the video conference X at 13:00:00 on October 1st, and schedules the video conference X to 14:00:00 on October 2nd, that is, the terminal information of the target video conference terminal in the authorization request event corresponding to the operation identifier YYY needs to be modified, the first video conference server sends a request for changing the authorization access to the second video conference server, and the type is to modify the terminal information of the target video conference terminal. The content of the request is mainly that the access authorization request corresponding to the operation identifier YYY has been changed, and after the change, it is requested that the video conference server C3 grants the video conference server A0 the right to invite the video conference terminal C31 to participate in the video conference X from 14:00:00 on October 2nd to 16:00:00 on October 2nd. The second video conference server re-returns the changed terminal information of the video conference terminal C31 to the first video conference server according to the changed access authorization request. The terminal information includes: the valid time period is from 14:00:00 on October 2nd to 16:00:00 on October 2nd, the valid time is 14:00:00 on October 2nd, the invalid time is 16:00:00 on October 2nd, the valid time is 2 hours, the video conference number CBDEU595 of the video conference terminal C31, and the like.

[0131] If the first video conference server cancels the video conference X at 13:00:00 on October 1st, the first video conference server sends a request for changing the authorization access to the second video conference server, and the type is to cancel the authorization request event. The second video conference server determines the authorization request event corresponding to the operation identifier YYY according to the request for changing the authorization access, and then cancels the authorization request event. The canceled authorization request event does not exist from the beginning. After the second video conference server sends the first video conference server a successful cancellation of the authorization request event corresponding to the operation identifier YYY, the second video conference server deletes the video conference terminal C31 from the read-only operation list.

[0132] The method for changing the processed authorization request event provided in this embodiment makes the cross-domain access of the video conference terminal more flexible, and provides convenience for the first video conference server to cross-domain access the video conference terminal under the second video conference server.

[0133] In combination with the above embodiments, in an implementation, the terminal information of the target video conference terminal includes a valid time period of the first video conference server accessing the target video conference terminal. On this basis, receiving the terminal information of the target video conference terminal returned by the second video conference server after allowing the access authorization can specifically include the following steps:

[0134] Receiving the first terminal information of the target video conference terminal returned by the second video conference server after allowing the access authorization;

[0135] receive the second terminal information of the target vision net terminal returned by the third vision net server after the access authorization is allowed, the third vision net server being designated by the second vision net server and being a server that can be used to perform cross-domain authorization management on the vision net terminals directly connected to the second vision net server;

[0136] If there is a conflict vision net terminal, the or operation is performed on the effective time period in the first terminal information and the effective time period in the second terminal information, and the obtained time period is used as the effective time period in the terminal information of the conflict vision net terminal again, the effective time period in the first terminal information of the conflict vision net terminal being different from the effective time period in the second terminal information of the conflict vision net terminal.

[0137] In the embodiment, if the second vision net server is a subordinate vision net server of the third vision net server, the second vision net server can grant the third vision net server the right to perform cross-domain authorization management on the vision net terminals directly connected to the second vision net server when the third vision net server is in the default state.

[0138] After the second vision net server grants the third vision net server the right to perform cross-domain authorization management on the vision net terminals directly connected to the second vision net server, the second vision net server still has the right to perform cross-domain authorization management on the vision net terminals directly connected to the second vision net server, and the right will not disappear because of the assignment of the authorization.

[0139] For example, in the Figure 1 , the vision net server C3 can grant the vision net server C0 the right to perform cross-domain authorization management on the vision net terminals C31-C32 directly connected to the vision net server C3, at this time, the vision net server C0 can grant the vision net server A0 the right to access the vision net terminal C31, or can grant the vision net server A0 the right to access the vision net terminal C32.

[0140] Therefore, in actual implementation, after the first vision net server sends the access authorization request for the target vision net terminal to the second vision net server, if the second vision net server grants the third vision net server the right to perform cross-domain authorization management on the vision net terminals directly connected to the second vision net server, the first vision net server will receive the first terminal information of the target vision net terminal returned by the second vision net server after the access authorization is allowed, and the second terminal information of the target vision net terminal returned by the third vision net server after the access authorization is allowed.

[0141] For example, the WebRTC server C3 grants the WebRTC server C0 the right to perform cross-domain authorization management on the WebRTC terminals directly connected under the WebRTC server C3, and then the WebRTC server A0 sends an access authorization request to the WebRTC server C3 for the WebRTC terminal C31, and can receive the first terminal information of the WebRTC terminal C31 returned by the WebRTC server C3 and the second terminal information of the WebRTC terminal C31 returned by the WebRTC server C0.

[0142] According to the first terminal information and the second terminal information, if the effective time period in the first terminal information and the effective time period in the second terminal information are different for the same WebRTC terminal, the WebRTC terminal is a conflict WebRTC terminal. For example, the target WebRTC terminal is the WebRTC terminal C31, the effective time period in the first terminal information of the WebRTC terminal C31 is 10:00:00, October 1-12:00:00, October 1, and the effective time period in the second terminal information of the WebRTC terminal C31 is 10:00:00, October 1-13:00:00, October 1, so the WebRTC terminal C31 is a conflict WebRTC terminal, and then the or operation is performed on 10:00:00, October 1-12:00:00, October 1 and 10:00:00, October 1-13:00:00, October 1 to obtain the time period 10:00:00, October 1-13:00:00, October 1, and then 10:00:00, October 1-13:00:00, October 1 is re-set as the effective time period of the WebRTC terminal C31.

[0143] If there are multiple target WebRTC terminals and only one of them is a conflict WebRTC terminal, only the effective time period in the first terminal information and the effective time period in the second terminal information of the conflict WebRTC terminal need to be or operated to obtain a new effective time period.

[0144] In this embodiment, when the first WebRTC server detects the existence of a conflict WebRTC terminal, it can also send a prompt of the authorization conflict to the second WebRTC server and the third WebRTC server respectively to prompt the second WebRTC server to re-set the cross-domain authorization management right of the third WebRTC server.

[0145] In this embodiment, the second WebRTC server can grant the third WebRTC server the right to perform cross-domain authorization management on the WebRTC terminals directly connected under the second WebRTC server, so that when the second WebRTC server fails, the first WebRTC server can also access the WebRTC terminals directly connected under the second WebRTC server through the access right granted by the third WebRTC server, realize cross-domain access of the WebRTC terminals, and improve the convenience of cross-domain access of the WebRTC terminals.

[0146] In an implementation form, the method of the present application can further comprise:

[0147] receiving the access authorization request sent by the second visual internet server for the visual internet terminal under the first visual internet server;

[0148] determining a visual internet terminal to be accessed, and if the second visual internet server is allowed to access the visual internet terminal to be accessed, returning terminal information of the visual internet terminal to be accessed to the second visual internet server, so that the second visual internet server adds the visual internet terminal to be accessed to the read-only operation list according to the terminal information.

[0149] In the embodiment, the first visual internet server can also receive the access authorization request sent by other visual internet servers for the visual internet terminal under the first visual internet server and process it. After the first visual internet server authorizes, other visual internet servers can also perform read-only operation on the visual internet terminal under the first visual internet server, and the process is the same as the process principle of the second visual internet server processing the access authorization request described above. Therefore, it is not described here.

[0150] It should be noted that, for the method embodiments, in order to simply describe, they are all described as a series of action combinations, but those skilled in the art should know that the embodiments of the present application are not limited to the order of the described actions, because according to the embodiments of the present application, certain steps can be performed in other order or at the same time. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions involved are not necessarily the necessary of the embodiments of the present application.

[0151] Based on the same inventive concept, the present application provides a device 300 for cross-domain access to a visual internet terminal, applied to a first visual internet server in a visual internet service system, the visual internet service system comprising a plurality of visual internet terminals and a plurality of levels of visual internet servers, the plurality of levels of visual internet servers being connected in a tree structure, each visual internet terminal being directly connected to a visual internet server, each visual internet server being used to manage all visual internet terminals directly connected to the visual internet server, each visual internet server and all visual internet terminals directly connected thereto constituting a visual internet domain. Figure 3 is a structural block diagram of a device for cross-domain access to a visual internet terminal according to an embodiment of the present application. Referring to Figure 3 , the device 300 of the present application can comprise:

[0152] a determination module 301, configured to determine a target visual internet terminal to be accessed and a second visual internet server in a visual internet domain to which the target visual internet terminal belongs;

[0153] The first sending module 302 is configured to send, to the second Live Streaming Network server, an access authorization request for the target Live Streaming Network terminal;

[0154] The first receiving module 303 is configured to receive terminal information of the target Live Streaming Network terminal returned by the second Live Streaming Network server after allowing the access authorization;

[0155] The first adding module 304 is configured to add the target Live Streaming Network terminal to a read-only operation list according to the terminal information, and each Live Streaming Network terminal in the read-only operation list is a Live Streaming Network terminal on which the target Live Streaming Network server can only perform read-only operation.

[0156] Optionally, the apparatus 300 further includes:

[0157] The second adding module is configured to add the target Live Streaming Network terminal to the created Live Streaming Network video conference.

[0158] Optionally, the access authorization request includes an operation identifier of an authorization request event; and the apparatus 300 further includes:

[0159] The second sending module is configured to send, to the second Live Streaming Network server, a request for changing authorized access containing the operation identifier, so that the second Live Streaming Network server modifies terminal information of a target Live Streaming Network terminal corresponding to the operation identifier or cancels the authorization request event corresponding to the operation identifier;

[0160] The apparatus 300 further includes:

[0161] The second receiving module is configured to receive a processing result returned by the second Live Streaming Network server in response to the request for changing authorized access;

[0162] The first deleting module is configured to delete the target Live Streaming Network terminal from the read-only operation list if the processing result is successful cancellation of the authorization request event corresponding to the operation identifier.

[0163] Optionally, the terminal information of the target Live Streaming Network terminal includes a valid time period during which the first Live Streaming Network server accesses the target Live Streaming Network terminal; and the first receiving module 303 includes:

[0164] The first receiving submodule is configured to receive first terminal information of the target Live Streaming Network terminal returned by the second Live Streaming Network server after allowing the access authorization;

[0165] The second receiving submodule is used to receive the second terminal information of the target video network terminal returned by the third video network server after access authorization is granted. The third video network server is designated by the second video network server and can be used to perform cross-domain authorization management of video network terminals directly connected to the second video network server.

[0166] The calculation submodule is used to perform an OR operation on the effective time period in the first terminal information and the effective time period in the second terminal information if there are conflicting video network terminals, and use the resulting time period as the effective time period in the terminal information of the conflicting video network terminals. The effective time period in the first terminal information of the conflicting video network terminals is different from the effective time period in the second terminal information of the conflicting video network terminals.

[0167] Optionally, the determining module 301 includes:

[0168] The determination submodule is used to determine the second video network server and the number of target video network terminals connected to the second video network server that need to be accessed across domains;

[0169] The first sending module 302 includes:

[0170] The sending submodule is used to send an access authorization request containing the number of target video network terminals to the second video network server, so that the second video network server can select the target video network terminal that meets the number from multiple video network terminals directly connected to the video network server.

[0171] Optionally, the terminal information of the target video network terminal includes the effective time period for the second video network server to authorize the first video network server to access the target video network terminal; the device 300 further includes:

[0172] The second deletion module is used to delete the target video network terminal from the read-only operation list when the expiration time corresponding to the effective time period is reached.

[0173] Optionally, the device 300 further includes:

[0174] The third receiving module is used to receive the accessible video network terminal returned by the second video network server when the terminal information of the target video network terminal returned by the second video network server after the access authorization is not received.

[0175] The third sending module is used to respond to the user's operation, determine one or more video network terminals from the allowed video network terminals, and send an access authorization request for the determined video network terminals to the second video network server.

[0176] Optionally, the apparatus further comprises:

[0177] a fourth receiving module, configured to receive an access authorization request for the first in-room intercom server sent by the second in-room intercom server;

[0178] a fourth sending module, configured to determine a to-be-accessed in-room intercom terminal, and if the second in-room intercom server is allowed to access the to-be-accessed in-room intercom terminal, return terminal information of the to-be-accessed in-room intercom terminal to the second in-room intercom server, so that the second in-room intercom server adds the to-be-accessed in-room intercom terminal to the read-only operation list according to the terminal information.

[0179] Based on the same inventive concept, the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the steps in the method for cross-domain access to in-room intercom terminals according to any of the embodiments of the present application.

[0180] Based on the same inventive concept, the present application provides a computer readable storage medium having a computer program stored thereon, and the program, when executed by a processor, implements the steps in the method for cross-domain access to in-room intercom terminals according to any of the embodiments of the present application.

[0181] For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts are described in the part of the method embodiments.

[0182] Each of the embodiments in the specification is described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The same and similar parts between the embodiments can be referred to each other.

[0183] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, device, or computer program product. Therefore, the embodiments of the present application can be in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.

[0184] The embodiments of the present application are described with reference to the flowchart illustrations and / or block diagrams of the methods, terminal devices (systems) and computer program products according to the embodiments of the present application. It is understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing terminal devices to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal devices, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0185] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal devices to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions means which implement the function specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0186] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal devices, such that a series of operational steps are performed on the computer or other programmable terminal devices to create a computer implemented process so that the instructions executed on the computer or other programmable terminal devices provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0187] Finally, it should also be noted that, in the present text, the relationship terms such as first and second, and the like are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, so that processes, methods, articles or terminal devices including a series of elements not only include those elements, but also include other elements not explicitly listed, or further include elements inherent in such processes, methods, articles or terminal devices. Without more limitations, the element defined by the phrase "comprising a" does not exclude the presence of additional identical elements in the process, method, article or terminal device including the said element.

[0188] The above describes in detail the method, device, electronic equipment and medium for cross-domain access to a videoconferencing terminal provided by the present application. The principles and implementation manners of the present application are described by using specific examples in this paper. The above description of the examples is only used to help understand the method of the present application and its core idea. Meanwhile, for those skilled in the art, there will be changes in the specific implementation manners and application scopes according to the idea of the present application. In conclusion, the content of the specification should not be understood as a limitation of the present application.

Claims

1. A method for cross-domain access to a video network terminal, characterized in that, The first vision networking server applied to a vision networking service system, the vision networking service system comprising a plurality of vision networking terminals and a plurality of levels of vision networking servers, each vision networking terminal being directly connected with a vision networking server, each vision networking server being used for managing all vision networking terminals directly connected with the vision networking server, each vision networking server and all vision networking terminals directly connected with the vision networking server constituting a vision networking domain; the method comprises: determining a target vision networking terminal requiring cross-domain access and a second vision networking server in a vision networking domain to which the target vision networking terminal belongs; sending an access authorization request for the target vision networking terminal to the second vision networking server; receiving terminal information of the target vision networking terminal returned by the second vision networking server after allowing the access authorization; adding the target vision networking terminal to a read-only operation list according to the terminal information, each vision networking terminal in the read-only operation list being a vision networking terminal for which the vision networking server can only perform read-only operations; the terminal information of the target vision networking terminal comprising an effective time period for the first vision networking server to access the target vision networking terminal; receiving the terminal information of the target vision networking terminal returned by the second vision networking server after allowing the access authorization, comprising: receiving first terminal information of the target vision networking terminal returned by the second vision networking server after allowing the access authorization; receiving second terminal information of the target vision networking terminal returned by a third vision networking server after allowing the access authorization, the third vision networking server being specified by the second vision networking server and being a server that can be used for cross-domain authorization management of vision networking terminals directly connected with the second vision networking server; if there is a conflict vision networking terminal, performing an or operation on the effective time period in the first terminal information and the effective time period in the second terminal information, and taking the obtained time period as an effective time period in terminal information of the conflict vision networking terminal, the effective time period in the first terminal information of the conflict vision networking terminal being different from the effective time period in the second terminal information of the conflict vision networking terminal.

2. The method of claim 1, wherein, after adding the target vision networking terminal to the read-only operation list, the method further comprising: adding the target vision networking terminal to a created vision networking video conference.

3. The method of claim 1, wherein, the access authorization request comprising an operation identifier of an authorization request event; after adding the target vision networking terminal to the read-only operation list, the method further comprising: sending a request for changing authorized access containing the operation identifier to the second vision networking server, so that the second vision networking server modifies terminal information of a target vision networking terminal corresponding to the operation identifier or cancels an authorization request event corresponding to the operation identifier; the method further comprising: receiving a processing result returned by the second vision networking server in response to the request for changing authorized access; if the processing result is successful in canceling the authorization request event corresponding to the operation identifier, deleting the target vision networking terminal from the read-only operation list.

4. The method of claim 1, wherein, determine a target videoconferencing terminal requiring cross-domain access and a second videoconferencing server in a videoconferencing domain to which the target videoconferencing terminal belongs, including: determine a second videoconferencing server and a number of target videoconferencing terminals connected under the second videoconferencing server requiring cross-domain access; send an access authorization request for the target videoconferencing terminal to the second videoconferencing server, including: send an access authorization request containing the number of target videoconferencing terminals to the second videoconferencing server, so that the second videoconferencing server selects target videoconferencing terminals meeting the number from a plurality of videoconferencing terminals directly connected to the first videoconferencing server.

5. The method of claim 1, wherein, The terminal information of the target videoconferencing terminal contains a valid time period in which the second videoconferencing server authorizes the first videoconferencing server to access the target videoconferencing terminal; after adding the target videoconferencing terminal to the read-only operation list, the method further includes: When the invalid time corresponding to the valid time period is reached, delete the target videoconferencing terminal from the read-only operation list.

6. The method of claim 1, wherein, The method further includes: When the terminal information of the target videoconferencing terminal returned by the second videoconferencing server after allowing access authorization is not received, receive the videoconferencing terminals allowed to access returned by the second videoconferencing server; In response to the operation of the user, determine one or more videoconferencing terminals from the videoconferencing terminals allowed to access, and send an access authorization request for the determined videoconferencing terminals to the second videoconferencing server.

7. The method of claim 1, wherein, The method further includes: Receive the access authorization request for the videoconferencing terminals under the first videoconferencing server sent by the second videoconferencing server; Determine a videoconferencing terminal to be accessed, and if the second videoconferencing server is allowed to access the videoconferencing terminal to be accessed, return the terminal information of the videoconferencing terminal to be accessed to the second videoconferencing server, so that the second videoconferencing server adds the videoconferencing terminal to be accessed to a read-only operation list according to the terminal information.

8. A device for cross-domain access to a video network terminal, characterized in that, A first videoconferencing server applied to a videoconferencing service system, the videoconferencing service system including a plurality of videoconferencing terminals and a plurality of levels of videoconferencing servers, each videoconferencing terminal being directly connected to a videoconferencing server, each videoconferencing server being used to manage all videoconferencing terminals directly connected thereto, and each videoconferencing server and all videoconferencing terminals directly connected thereto constituting a videoconferencing domain; the device includes: A determination module for determining a target videoconferencing terminal requiring cross-domain access and a second videoconferencing server in a videoconferencing domain to which the target videoconferencing terminal belongs; A first sending module for sending an access authorization request for the target videoconferencing terminal to the second videoconferencing server; A first receiving module for receiving terminal information of the target videoconferencing terminal returned by the second videoconferencing server after allowing access authorization; The first adding module is configured to add the target in-room terminal into a read-only operation list according to the terminal information, and each in-room terminal in the read-only operation list is an in-room terminal on which the in-room server can only perform a read-only operation. The terminal information of the target in-room terminal includes a valid time period during which the first in-room server accesses the target in-room terminal; and the first receiving module includes: A first receiving sub-module, configured to receive first terminal information of the target in-room terminal returned by a second in-room server after authorization of access is allowed; A second receiving sub-module, configured to receive second terminal information of the target in-room terminal returned by a third in-room server after authorization of access is allowed, the third in-room server being specified by the second in-room server and being a server that can be used to perform cross-domain authorization management on in-room terminals directly connected to the second in-room server; An operation sub-module, configured to, if there is a conflict in-room terminal, perform an OR operation on the valid time period in the first terminal information and the valid time period in the second terminal information, and use the obtained time period as the valid time period in the terminal information of the conflict in-room terminal, the valid time period in the first terminal information of the conflict in-room terminal being different from the valid time period in the second terminal information of the conflict in-room terminal.

9. A computer readable storage medium having stored thereon a computer program, characterized in that, The program, when executed by a processor, implements the steps in the method for cross-domain access to an in-room terminal according to any one of claims 1-7.

10. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor, when executed, implements the steps in the method for cross-domain access to an in-room terminal according to any one of claims 1-7.

Citation Information

Patent Citations

  • A processing method and a system of a video conference

    CN109005378A

  • Cross-domain equipment access control method and device, computer equipment and storage medium

    CN112702315A