Network authentication method and device, equipment, and storage medium
By adding a client to smart TVs to identify and encrypt authentication information, the problem of smart TVs not being universally compatible across different provinces was solved, achieving low-cost network access authentication and improving the applicability and user experience of smart TVs.
Patent Information
- Application Number
- CN202111300967.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-04
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2041-11-04
AI Technical Summary
Existing smart TVs cannot be universally used in all provinces across the country and require customization for each province, resulting in high costs and complex maintenance. They also cannot support dedicated network access based on broadband access.
By adding a client to the terminal device, the extended field of the current region is determined, the authentication information is obtained and encrypted before being sent to the system firmware, thereby realizing information interaction with the network authentication device and performing network access permission authentication.
It enables network access authentication in different regions, reducing the workload and cost of modification, and improving the versatility and user experience of smart TVs.
Smart Images

Figure CN116074032B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to network technology, and relates to but is not limited to a network authentication method and device, equipment and a storage medium. BACKGROUND
[0002] With the popularity and development of smart televisions, it is an inevitable trend to develop interactive network television (IPTV) services directly through smart televisions, and the IPTV service needs to use a private network for transmission. However, the ordinary smart televisions on the market cannot support private network access such as IP over Ethernet (IPOE) authentication. In the related art, the IPTV service is generally developed by the operator and the television manufacturer cooperating to develop customized machines with private network access (for example, IPOE) functions. However, such deeply customized smart televisions cannot be used in all provinces in China, and therefore the television manufacturers need to develop and maintain multiple models and versions in each province in China in a provincial customization manner, which is relatively high in cost. SUMMARY
[0003] Therefore, the network authentication method and device, equipment and storage medium provided by the present application have less modification workload and lower cost when implementing network access authentication of a terminal device in different regions.
[0004] According to an aspect of an embodiment of the present application, a network authentication method is provided, including: a client on a terminal device determining an extension field of a region where the terminal device is currently located from extension fields corresponding to each region respectively; the client obtaining authentication information corresponding to the extension field of the region where the terminal device is currently located; the client writing the authentication information into the extension field of the region where the terminal device is currently located to obtain extension information; and the client sending the extension information to system firmware of the terminal device, so that the system firmware performs information interaction with a network authentication device based on the extension information, thereby authenticating whether the terminal device has network access permission.
[0005] According to an aspect of an embodiment of the present application, a network authentication method is provided, including: system firmware of a terminal device receiving extension information sent by a client on the terminal device; wherein the extension information is obtained by the client determining an extension field of a region where the terminal device is currently located from extension fields corresponding to each region respectively, and obtaining authentication information corresponding to the extension field of the region where the terminal device is currently located, and writing the authentication information into the extension field of the region where the terminal device is currently located; and the system firmware performing information interaction with a network authentication device based on the extension information, thereby authenticating whether the terminal device has network access permission.
[0006] According to an aspect of the embodiments of the present application, a network authentication apparatus is provided, comprising: a determining module configured to determine an extension field of a current region of the terminal device from extension fields corresponding to respective regions; an obtaining module configured to obtain authentication information corresponding to the extension field of the current region; a writing module configured to write the authentication information into the extension field of the current region to obtain extension information; and a sending module configured to send the extension information to a system firmware of the terminal device, so that the system firmware performs information interaction with a network authentication device based on the extension information, thereby authenticating whether the terminal device has network access permission.
[0007] According to an aspect of the embodiments of the present application, a network authentication apparatus is provided, comprising: a receiving module configured to receive extension information sent by a client on a terminal device; wherein the extension information is obtained by the client by determining an extension field of a current region of the terminal device from extension fields corresponding to respective regions, and determining authentication information corresponding to the extension field of the current region, and writing the authentication information into the extension field of the current region; and an interaction module configured to perform information interaction with a network authentication device based on the extension information, thereby authenticating whether the terminal device has network access permission.
[0008] According to an aspect of the embodiments of the present application, a terminal device is provided, comprising a memory and a processor, wherein the memory stores a computer program capable of running on the processor, and the processor implements the method according to the embodiments of the present application when executing the program.
[0009] According to an aspect of the embodiments of the present application, a computer readable storage medium is provided, which stores a computer program capable of being executed by a processor to implement the method according to the embodiments of the present application.
[0010] In the embodiment of the present application, the client determines the extension field of the current region of the terminal device, writes the authentication information into the extension field corresponding to the current region, and obtains the extension information; and sends the extension information to the system firmware of the terminal device, so that the system firmware interacts with the network authentication device based on the extension information, thereby realizing the authentication of the network access permission of the terminal device. That is, in the embodiment of the present application, a client is added to the terminal device, which can process the authentication information of the terminal device in the current region according to the network access specifications of different regions, and then send the corresponding extension field to the system firmware. In other words, for different terminal devices, they only need to add a same client, so as to realize the network access authentication of different terminal devices in different regions, without the need of technicians to modify the system firmware of the terminal device according to the different regions of different terminal devices. The authentication method has small modification workload and low cost.
[0011] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF DRAWINGS
[0012] The drawings incorporated into the specification and forming part of the specification, show embodiments consistent with the present application, and together with the specification, serve to explain the technical solutions of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0013] The flowchart shown in the drawings is only exemplary, and does not necessarily include all contents and operations / steps, nor does it necessarily execute in the described order. For example, some operations / steps can be further divided, and some operations / steps can be combined or partially combined, so the actual execution order can be changed according to the actual situation.
[0014] Figure 1 An implementation flowchart of a network authentication method provided for the embodiment of the present application;
[0015] Figure 2 An implementation flowchart of a network authentication method provided for the embodiment of the present application;
[0016] Figure 3 An implementation flowchart of a network authentication method provided for the embodiment of the present application;
[0017] Figure 4 A network authentication scheme design framework provided for the embodiment of the present application;
[0018] Figure 5 A soft terminal initiated IPOE access flowchart provided for the embodiments of the present application;
[0019] Figure 6 A television system initiated IPOE access flowchart provided for the embodiments of the present application;
[0020] Figure 7 A structural schematic diagram of a network authentication device provided for the embodiments of the present application;
[0021] Figure 8 A structural schematic diagram of a network authentication device provided for the embodiments of the present application;
[0022] Figure 9 A structural schematic diagram of a terminal device provided for the embodiments of the present application. DETAILED DESCRIPTION
[0023] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the specific technical solutions of the present application will be further described in detail below with reference to the drawings in the embodiments of the present application. The following embodiments are used to illustrate the present application, but are not used to limit the scope of the present application.
[0024] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application, and are not intended to limit the present application.
[0025] In the following description, "some embodiments" are described, which describe a subset of all possible embodiments, but it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.
[0026] The embodiments of the present application provide a network authentication method, which is applied to a terminal device. The terminal device can be various types of devices with network authentication function in the implementation process, for example, the terminal device can include a television, a mobile phone or a tablet computer, etc. The function realized by the method can be realized by calling program code by a processor in the terminal device. Of course, the program code can be saved in a computer storage medium. It can be seen that the terminal device at least includes a processor and a storage medium.
[0027] Figure 1 An implementation flowchart of the network authentication method provided for the embodiments of the present application is shown in the figure, the method is applied to a client on a terminal device, as shown in the figure, the method can include the following steps 101 to step 105: Figure 1
[0028] At step 101, the client on the terminal device determines the extension field corresponding to the region where the terminal device is currently located from the extension fields corresponding to the regions respectively.
[0029] It can be understood that the network access specifications of different regions are different, for example, the network access specifications of different provinces are different. In some embodiments, different network access specifications means that the terminal device needs different extension fields when interacting with the network authentication device for information when accessing the network of different regions. The extension field can be used to store authentication information that is not in the normal protocol.
[0030] In some embodiments, the regions are different provinces, and accordingly, determining the region where the terminal device is currently located means determining the province where the terminal device is currently located. In other embodiments, the regions can also be different cities, and accordingly, determining the region where the terminal device is currently located means determining the city where the terminal device is currently located.
[0031] For example, when the terminal device accesses the network of province A (or city A), authentication based on the access specification of province A (or city A) (represented by A extension field) is needed; when the terminal device accesses the network of province B (or city B), authentication based on the access specification of province B (or city B) (represented by B extension field) is needed. The A extension field and the B extension field can be different or the same.
[0032] In some embodiments, the terminal device can include a smart television, a projector, a tablet computer, a notebook computer, a personal computer, and the like. The client on the terminal device can include an application (APP) installed on the television.
[0033] In the embodiments of the present application, the manner of determining the region where the terminal device is currently located is not limited. For example, the client on the terminal device can automatically determine the current region by positioning technology after running, and then determine the extension field corresponding to the region where the terminal device is currently located from the pre-stored extension fields corresponding to the regions respectively. Alternatively, the user can determine the region where the terminal device is currently located by manual selection.
[0034] At step 102, the client obtains authentication information corresponding to the extension field of the region where the terminal device is currently located.
[0035] In some embodiments, the authentication information can include a user account, a password, or a media access control address (MAC) address (such as a virtual MAC address or a physical MAC address) of the terminal device. Different regions can have different extension fields, and the authentication information corresponding to different extension fields can also be different.
[0036] For example, assuming that the extension field corresponding to A province (or city) is Option60, the authentication information corresponding to the extension field of A province can be a user account and / or a password; assuming that the extension field corresponding to B province (or city) is Option61, the authentication information corresponding to the extension field of B province can be a virtual MAC address of the terminal device.
[0037] In some embodiments, the client can provide a user interface for a user to input the account and / or password and the like after being run, so as to obtain the user information.
[0038] In step 103, the client writes the authentication information into the extension field of the current region, to obtain extension information.
[0039] In some embodiments, step 103 can be implemented by performing steps 1031 to 1032 as follows:
[0040] In step 1031, the client encrypts the authentication information according to the encryption rule of the current region of the terminal device, to obtain encrypted information.
[0041] It can be understood that the encryption rule of different regions for the same extension field is different, and the encryption rule of the same region for different extension fields is also different. In the embodiments of the present application, before the authentication information is written into the extension field, in order to ensure the security of the information, the authentication information needs to be encrypted according to the encryption rule corresponding to the current region, and then the encrypted information is written into the extension field. In this way, when the client sends the authentication information to the system firmware of the terminal device, the encrypted authentication information is sent, so as to effectively ensure the security and reliability of the information transmission.
[0042] In step 1032, the client writes the encrypted information into the extension field of the current region, to obtain the extension information.
[0043] In step 104, the client sends the extension information to the system firmware of the terminal device.
[0044] In step 105, the system firmware performs information interaction with the network authentication device based on the extension information, so as to authenticate whether the terminal device has network access permission.
[0045] It should be noted that, in some embodiments, in order to enable different terminal devices to successfully access the network in different regions, the system firmware on the terminal device needs to be modified in each region according to the corresponding extension field type of each region in a region-specific manner. In this way, even for different individual terminal devices of the same model, when they are located in different regions, the system firmware on them needs to be modified according to the access specification of the current region in order to enable them to access the network in the current region. This access method has a large amount of modification work, high cost, and high maintenance cost.
[0046] In the embodiments of the present application, a client is added to the terminal device. The client can process the authentication information of the terminal device in the current region according to the network access specification of different regions, obtain the corresponding extension field, and then send it to the system firmware. In other words, for different terminal devices, they only need to add a same client to realize the network access authentication of different terminal devices in different regions, without the need for technicians to modify the system firmware on the terminal device according to the different regions where different terminal devices are located. This authentication method has small amount of modification work, low cost, and strong universality.
[0047] Figure 2 The implementation flowchart of the network authentication method provided in the embodiments of the present application is shown in FIG. 1. Figure 2 The method can include the following steps 201 to 207.
[0048] Step 201, the client on the terminal device determines the extension field of the region where the terminal device is currently located from the extension fields corresponding to each region respectively.
[0049] Step 202, the client obtains authentication information corresponding to the extension field of the current region.
[0050] Step 203, the client writes the authentication information into the extension field of the current region to obtain extension information.
[0051] Step 204, the client sends the extension information to the system firmware of the terminal device.
[0052] In some embodiments, an interface can be added to the underlying application of the terminal device. The client sends the extension information to the system firmware through the newly added interface, and receives the network authentication result returned by the system firmware through the newly added interface. This novel data interaction method enables the client and the system firmware to have corresponding answering parties when transmitting information, avoiding the loss of information and increasing the security and reliability of information transmission.
[0053] In step 205, the system firmware sends the extended information to the network authentication device, so that the network authentication device performs network access authentication on the terminal device based on the extended information, and obtains a network authentication result.
[0054] In the embodiments of the present application, when the network authentication device performs network access authentication on the terminal device based on the extended information, the following two cases can exist: (1) the network authentication device determines that the terminal device carrying the extended information is a legal device, and the authentication is successful, allowing the terminal device to access the corresponding network; (2) the network authentication device determines that the terminal device carrying the extended information is an illegal device, and the authentication fails, not allowing the terminal device to access the corresponding network.
[0055] In some embodiments, when the network authentication device authenticates whether the terminal device is a legal device, the network authentication device can query its own database to authenticate the terminal device based on the user account, password or virtual MAC address carried in the extended information. If the network authentication device can find data matching the authentication information carried in the extended information in its own database, the network authentication device determines that the terminal device is a legal device; if the network authentication device cannot find data matching the authentication information carried in the extended information in its own database, the network authentication device determines that the terminal device is an illegal device.
[0056] In step 206, the system firmware receives the network authentication result sent by the network authentication device, and determines that the terminal device has network access permission in the case that the network authentication result is network authentication success; and determines that the terminal device does not have network access permission in the case that the network authentication result is network authentication failure.
[0057] In some embodiments, the network access permission includes permission to access a dedicated network for providing a specific service, and the specific service includes an Internet television service; and the network access authentication includes IPOE authentication.
[0058] In step 207, the client receives the network authentication result sent by the system firmware, and performs corresponding processing based on the network authentication result.
[0059] In some embodiments, when the system firmware determines that the terminal device has network access permission, the client performs the following steps 2071 to 2073:
[0060] In step 2071, the client receives the network access address sent by the system firmware.
[0061] The network access address is an address allocated by the network authentication device to the terminal device when the terminal device is determined to have network access permission, and sent to the system firmware.
[0062] In some embodiments, the network access address is the Internet Protocol (IP) address assigned to the terminal device by the network authentication device.
[0063] Step 2072: The client authenticates the network authentication device based on the network access address and obtains the authentication result.
[0064] In some embodiments, in order to prevent conflicts caused by the network access address assigned to a terminal device by the network authentication device having already been assigned to another terminal device, the network access address can also be authenticated, thereby making the process of the terminal device accessing the corresponding network more secure and reliable.
[0065] Step 2073: If the authentication result is successful, the client accesses the corresponding network through the network access address.
[0066] In some embodiments, after accessing the corresponding network, in order for the terminal device to display the specific services it has subscribed to, the client can also interact with the IPTV service platform. The IPTV service platform authenticates and authorizes the terminal device based on authentication information, so that the terminal device can display the subscribed electronic program guide (EPG) for the user to access.
[0067] In some embodiments, when the system firmware determines that the terminal device does not have network access permissions, the client performs the following steps 2074 to 2075:
[0068] Step 2074: The client receives the network authentication failure result sent by the system firmware;
[0069] Step 2075: Based on the network authentication failure result, the client reminds the user to re-authenticate.
[0070] After receiving the network authentication failure result sent by the system firmware, the client can return to the user interface so that the user can re-enter information and re-authenticate.
[0071] In this embodiment, the initiator of the network authentication method can be either a client on the terminal device or the system firmware on the terminal device. In actual use, any initiation method can be selected according to the actual application scenario, providing high flexibility.
[0072] Figure 3 This is a schematic diagram illustrating the implementation process of the network authentication method provided in this application embodiment. The method is applied to the system firmware on the terminal device, such as... Figure 3 As shown, the method may include the following steps 301 to 302:
[0073] At step 301, the system firmware of the terminal device receives the extension information sent by the client on the terminal device.
[0074] The extension information is obtained by the client determining an extension field corresponding to the current region of the terminal device from the extension fields corresponding to the respective regions, and obtaining the authentication information corresponding to the extension field of the current region and writing the authentication information into the extension field of the current region.
[0075] In some embodiments, the system firmware can receive the extension information sent by the client in the following manner: a user clicks into the network device module of the terminal device to establish a connection with the client, so that the extension information sent by the client is received after the client is started.
[0076] At step 302, the system firmware performs information interaction with the network authentication device based on the extension information, so as to authenticate whether the terminal device has network access permission.
[0077] In some embodiments, the system firmware can authenticate whether the terminal device has network access permission by performing steps 3021 to 3022 as follows:
[0078] At step 3021, the system firmware performs information interaction with the network authentication device based on the extension information to obtain a network access result.
[0079] At step 3022, the system firmware receives the network authentication result sent by the network authentication device, and determines that the terminal device has network access permission in the case where the network authentication result is network authentication success, and determines that the terminal device does not have network access permission in the case where the network authentication result is network authentication failure.
[0080] In some embodiments, in the case where the network access result is network access success, the system firmware obtains the network access address allocated by the network authentication device for the terminal device; the system firmware sends the network access address to the client, so that the client performs authentication on the network authentication device based on the network access address, and determines that the terminal device has network access permission in the case where the authentication result is authentication success.
[0081] In some embodiments, in the case where the network access result is network access failure, the system firmware sends the network access failure result to the client, so that the client reminds the user to re-access.
[0082] IPTV is a kind of Internet TV technology which uses broadband network, integrates Internet, multimedia, communication and other technologies, and provides interactive services including digital TV to home users. In order to ensure the security of the service and the fluency of the user watching, the bearer network of IPTV service is always transmission based on access authentication. Common access authentication methods include "DHCP+Web method", "DHCP+client method" and "DHCP+Option extension field" authentication method.
[0083] The DHCP+Option extension field authentication method, also known as IPoE, is a broadband access authentication system which takes Dynamic Host Configuration Protocol (DHCP) technology as the core. The Option fields used for DHCP extension are mainly Option60 and Option82, and the information of each field is generally encrypted. IPOE technology closely combines the common Remote Authentication Dial In User Service (RADIUS) to realize Internet Protocol (IP) user session mechanism, IP data flow grading mechanism, IP session authentication and management mechanism.
[0084] Magic and is an Internet TV service currently promoted by operators in the whole network. According to research, 90% of provinces in China use IPOE network access authentication method for Magic and IPTV service. IPOE network access authentication system mainly includes user terminal, Service Router (SR) equipment, DHCP server and Authentication, Authorization, Accounting (AAA) platform. The user terminal performs authentication interaction with the SR equipment through the DHCP DISCOVER message, and the authentication message needs to contain the DHCP extension field. At present, the IPTV user terminal equipment in the whole network uses IP set-top box. Due to the differences in the message fields and encryption methods of the authentication specifications of each province, the set-top box manufacturers develop the software and hardware versions of the set-top box in each province through the way of provincial customization.
[0085] With the popularization and development of smart TVs, the popularization rate of smart TVs is getting higher and higher, and ordinary TVs are gradually eliminated. In addition, the software and hardware performance of smart TVs is gradually improved, which can completely replace IP set-top boxes and carry more IPTV business scenarios in the 5th Generation Mobile Communication Technology (5G) era. The IPTV business in the form of traditional set-top box + TV as user terminal has exposed many drawbacks. 1. For users, there is already a smart TV at home, and additional installation of a set-top box is required to handle IPTV services, which affects the appearance of wiring and use experience. 2. For operators, hardware procurement and warehouse management of set-top boxes increase the complexity of business operation and management, and increase the cost of business development.
[0086] Therefore, it is an inevitable trend to develop IPTV services directly through smart TVs. Since IPTV services need to use a private network for transmission, ordinary smart TVs on the market do not support private network access based on IPOE authentication. The solution in some embodiments is to develop a customized machine with IPOE private network access function through cooperation between operators and TV manufacturers to develop IPIV services. However, this solution has obvious defects. At present, there are differences in IPOE access specifications in various provinces in China, and the Option extension field has Option60, Option82 and Option125, and the encryption method of the Option extension field is also different. This leads to the fact that this deeply customized smart TV cannot be used universally in all provinces in China, and TV manufacturers need to develop and maintain multiple models and versions in a provincial customization manner in all provinces in China.
[0087] Understandably, when the smart TV is shipped, the message sent by the smart TV when it is authenticated with the network authentication device does not contain the Option extension field, and the extension field will not be encrypted, but IPOE network authentication needs to be authenticated. Therefore, in the embodiments of the present application, the encryption and transmission of the extension field can be realized through a soft terminal APP, and then transmitted to the TV system ROM, so that the extension field is sent to the network authentication device when interacting with the network authentication device. If the message does not carry the extension field, it is only a network authentication at the DHCP level, that is, it can only access the public network and cannot access the IPOE private network.
[0088] To solve the above problems, the embodiment of the present application proposes an IPOE network access scheme for an Android smart TV (an example of a terminal device): on the basis of maintaining the network access and authentication system at the provincial side unchanged, the soft terminal APP (an example of a client on a terminal device) is combined with the TV system ROM (an example of system firmware), the message field (an example of an extension field) content of each province (an example of each region) is realized by the soft terminal APP differentiation, and then the content is synchronized to the TV system ROM. The TV system ROM can realize the message interaction between the network authentication equipment of each province by using a unified modification scheme. The above method can support the IPTV private network for the smart TV under the condition of supporting public network access, and can also make the modified smart TV universal in each province.
[0089] It should be noted that the TV system ROM in the embodiment of the present application refers to the bottom firmware of the TV system, and the system firmware can send the DHCP message and interact with the network authentication equipment.
[0090] The scheme in the embodiment of the present application is aimed at the defects and deficiencies in some embodiments, and realizes a unified solution for the smart TV to access the IPOE authentication private network by combining the soft terminal APP with the TV system ROM without changing the nationwide IPTV service private network infrastructure and specifications.
[0091] Figure 4 A scheme design framework diagram is given:
[0092] (1) The soft terminal APP provides a UI interface for inputting the IPTV service username and password;
[0093] (2) The soft terminal APP encrypts the username and password according to the Option60 rule, and encrypts the soft terminal virtual mac according to the Option61 rule;
[0094] (3) The soft terminal APP sends the encrypted Option60, Option61 or Option125 content (i.e. encrypted information) to the TV system ROM through the EthernetManager class of frameworks;
[0095] (4) The TV system ROM receives the authentication message carrying the Option60, Option61 or Option125 field content and performs IPOE authentication; after the authentication is completed, the TV system ROM feeds back the authentication result to the soft terminal APP, and returns the Option125 to the soft terminal APP.
[0096] As shown in Figure 5 , it is an IPOE access flowchart initiated by the soft terminal APP, and the steps are as follows:
[0097] Step 501, after the soft terminal APP is installed, manually input the account password, and the soft terminal writes the account password and other information into the cache;
[0098] Step 502, the soft terminal encapsulates and encrypts the information of the user account, password, and virtual mac according to the specifications of each province, generates corresponding Option60, Option61, or Option125 fields, and the like.
[0099] Step 503, manually click the 'network connection' button, and the soft terminal pulls up the television IPOE network connection module;
[0100] Step 504, the soft terminal APP synchronizes the contents of the Option60, Option61, and Option125 fields to the television system ROM;
[0101] Step 505, the television system ROM interacts with the intermediate network authentication device (carrying the corresponding field information in the message), completes access authentication, and obtains an IP address;
[0102] Step 506, finally, the television system ROM feeds back the network access result to the soft terminal provincial APP, if the network access is successful, the soft terminal performs authentication and authorization and pulls up the broadcast EPG process; otherwise, returns to the IPOE network access interface, and prompts the user to re-access.
[0103] As shown in Figure 6 , it is an IPOE access flowchart initiated by the television system ROM, as shown in the following steps 601 to 605:
[0104] Step 601, the user enters the network setting module of the television, and opens the IPOE network connection;
[0105] Step 602, the television system ROM pulls up the soft terminal APP, and the soft terminal enters the network connection interface after starting;
[0106] Step 603, the soft terminal APP synchronizes the authentication message and other information (Option60, Option61, Option125) in the cache to the television system ROM;
[0107] Step 604, after the television system ROM obtains the corresponding message field, it interacts with the intermediate network device through the message, and obtains the network IP;
[0108] Step 605, finally, the television system ROM feeds back the network access result to the soft terminal provincial APP, if the network access is successful, the soft terminal APP performs authentication and authorization and pulls up the broadcast EPG process; otherwise, returns to the IPOE network access interface, and prompts the user to re-access.
[0109] The soft terminal APP and the smart television system ROM share and interact data through the EthernetManager class of frameworks.
[0110] Two methods are added in the EthernetManager class of frameworks:
[0111] (1) Configure Option parameter
[0112] public void setIPOEOptionPara(String strOptionName, byte[] OptionParam, int iNum, String strOptionMD5 String strExtra);
[0113] OptionName = {"Option60", "Option61", "Option125"};
[0114] OptionParam: encrypted parameter, array
[0115] iNum: parameter length, indicating the byte length of the parameter
[0116] strOptionMD5: calculate the MD5 value of the OptionParam parameter, used for bottom layer MD5 inspection, to judge whether the parameter is correct. Calculate the MD5 value of the OptionParam parameter, used for bottom layer MD5 inspection, strExtra: extension parameter public void setCallback(Connection
[0117] (2) Callback registration function
[0118] public void setCallback(ConnectionCallBack*callback);
[0119] Function description: the upper soft terminal APP calls setCallback() to register the callback function. After the upper soft terminal APP initiates connection, if the bottom layer DHCP module is connected successfully, the callback function is used to directly notify the upper soft terminal APP of the connection success result, and the connection result parameter contains the IP address and other related information. If the connection is not successful, the callback function is used to notify the upper soft terminal APP of the connection failure result, and the connection result parameter contains the related information of the connection failure.
[0120] The definitions of various interfaces are given below, as shown in Table 1 for authentication field parameters, and as shown in Table 2 for authentication result parameters:
[0121] Table 1
[0122]
[0123] Table 2
[0124] Parameter name Type Description state Int authentication result state: 0: success; 1: failure msg String authentication result description ip String IP address mask String subnet mask dns String DNS server extra String extended parameters
[0125] The example code is given below:
[0126]
[0127] strConnectionStatusType={"ipoe","pppoe","dhcp","manu","wifi");
[0128] strResult: is a json string parameter, and stores the authentication result: authentication result state, authentication result description, IP address, subnet mask, DNS server, and extended parameters.
[0129] strResult
[0130] {
[0131] “state”:"0",
[0132] “msg”:"failure",
[0133] “ip”:"0.0.0.0",
[0134] “mask”:"0.0.0.0",
[0135] “dns”:"0,0,0,0",
[0136] “extra”:"null",
[0137] }
[0138] In the embodiments of the present application, (1) the television system ROM is innovatively used in cooperation with the top-layer application soft terminal APP to realize network access based on IPOE authentication, compatible with different IPOE networks in authentication message field, with strong universality and small reconstruction workload of the television system ROM; (2) a novel and reliable data transmission and information sharing method between the television system ROM and the top-layer application soft terminal APP ensures the reliability of message data transmission; and (3) the initiator of the IOPE network authentication is flexible and variable, and can be selected according to the actual scene to be initiated by the television system ROM or the top-layer application soft terminal APP.
[0139] Accordingly, the following technical effects can be obtained: (1) the intelligent television reformed by the method provided in the application can access the IPTV private network of a plurality of provinces where differences exist in IPOE specifications. (2) Compared with the technology of realizing IPTV private network access in the manner of customizing a machine in some embodiments, the ROM of the television system is less changed in the application, and the implementation is more flexible. (3) The development of IPTV services by using the method provided in the application can not only improve user experience, but also reduce the cost of service development and operation.
[0140] It should be noted that although the steps of the method in the application are described in a specific order in the accompanying drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired result. In addition or alternatively, some steps can be omitted, a plurality of steps can be combined into one step, and / or one step can be divided into a plurality of steps, etc.
[0141] Based on the foregoing embodiments, the embodiments of the application provide a network authentication device, which comprises the modules included therein and the units included in the modules, and can be implemented by a processor; of course, it can also be implemented by a specific logic circuit; in the implementation process, the processor can be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP), or a field programmable gate array (FPGA), etc.
[0142] Figure 7 The structure of the network authentication device of the embodiments of the application is shown in the schematic diagram, and the network authentication device can be a client on a terminal device, such as Figure 7 As shown in the figure, the device 700 comprises a determination module 701, an acquisition module 702, a writing module 703, and a sending module 704, wherein:
[0143] The determination module 701 is configured to determine an extension field of a region where the terminal device is currently located from the extension fields corresponding to the respective regions; the acquisition module 702 is configured to acquire authentication information corresponding to the extension field of the current region; the writing module 703 is configured to write the authentication information into the extension field of the current region to obtain extension information; and the sending module 704 is configured to send the extension information to the system firmware of the terminal device, so that the system firmware performs information interaction with a network authentication device based on the extension information, thereby authenticating whether the terminal device has network access authority.
[0144] In some embodiments, the apparatus 700 further comprises an encryption module configured to encrypt the authentication information according to an encryption rule of a region where the terminal device is currently located, to obtain encrypted information; and a writing module 703 configured to write the encrypted information into an extension field of the region where the terminal device is currently located, to obtain the extension information.
[0145] In some embodiments, the apparatus 700 further comprises a receiving module, a sending module 704 configured to send the extension information to the network authentication device, so that the network authentication device performs network access authentication on the terminal device based on the extension information, to obtain a network authentication result; the receiving module is configured to receive the network authentication result sent by the network authentication device, and determine that the terminal device has network access permission in a case where the network authentication result is network authentication success, and determine that the terminal device does not have network access permission in a case where the network authentication result is network authentication failure.
[0146] In some embodiments, the apparatus 700 further comprises an authentication module and an access module, the receiving module is configured to receive a network access address sent by the system firmware; wherein the network access address is an address allocated by the network authentication device to the terminal device and sent to the system firmware when the network authentication device authenticates that the terminal device has network access permission; the authentication module is configured to authenticate the network authentication device based on the network access address, to obtain an authentication result; and the access module is configured to access a corresponding network through the network access address in a case where the authentication result is authentication success.
[0147] In some embodiments, the apparatus 700 further comprises a reminding module, the receiving module is configured to receive a result of network authentication failure sent by the system firmware; and the reminding module is configured to remind a user to re-authenticate based on the result of network authentication failure.
[0148] Figure 8 FIG. 8 is a structural schematic diagram of a network authentication device according to an embodiment of the present application. The network authentication device can be a system firmware on a terminal device, for example. As shown in FIG. 8, the apparatus 800 comprises a receiving module 801 and an interaction module 802, wherein: Figure 8
[0149] The receiving module 801 is used to receive extended information sent by a client on a terminal device; wherein the extended information is obtained by the client determining the extended field of the current region of the terminal device from the extended fields corresponding to each region, determining the authentication information corresponding to the extended field of the current region, and writing the authentication information into the extended field of the current region; the interaction module 802 is used to enable the system firmware to interact with the network authentication device based on the extended information, thereby authenticating whether the terminal device has network access permission.
[0150] In some embodiments, the device 800 further includes a determining module and an interaction module 802, which is further configured to interact with the network authentication device based on extended information to obtain a network access result; the determining module is configured to receive the network authentication result sent by the network authentication device, and if the network authentication result is successful, determine that the terminal device has network access permission; and if the network authentication result is unsuccessful, determine that the terminal device does not have network access permission.
[0151] In some embodiments, the device 800 further includes an acquisition module and a sending module. The acquisition module is used to acquire the network access address assigned to the terminal device by the network authentication device when the network access result is successful. The sending module is used to send the network access address to the client so that the client can authenticate the network authentication device based on the network access address, thereby determining that the terminal device has network access permission when the authentication result is successful.
[0152] In some embodiments, the sending module is further configured to send the network access failure result to the client if the network access result is a network access failure, so that the client can remind the user to reconnect.
[0153] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0154] It should be noted that, in the embodiments of this application... Figure 7 and Figure 8 The module division of the network authentication device shown is illustrative and represents only one logical functional division; in actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, exist as separate physical units, or be integrated into one unit by two or more units. The integrated units can be implemented in hardware, as software functional units, or a combination of both.
[0155] It should be noted that, in the embodiments of the present application, if the above-mentioned method is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, and includes a plurality of instructions for causing a terminal device to execute all or part of the methods described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a magnetic disk or an optical disk, and various media that can store program codes. Thus, the embodiments of the present application are not limited to any specific combination of hardware and software.
[0156] The embodiments of the present application provide a terminal device, Figure 9 A hardware entity diagram of the terminal device of the embodiments of the present application is shown in Figure 9 The terminal device 900 includes a memory 901 and a processor 902, the memory 901 stores a computer program executable on the processor 902, and the processor 902 implements the steps in the method provided in the above-mentioned embodiments when executing the program.
[0157] It should be noted that the memory 901 is configured to store instructions and applications executable by the processor 902, and can also buffer data (for example, image data, audio data, voice communication data and video communication data) to be processed or having been processed in the processor 902 and the modules of the terminal device 900, which can be realized by a flash memory (FLASH) or a random access memory (RAM).
[0158] The embodiments of the present application provide a computer-readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps in the method provided in the above-mentioned embodiments.
[0159] The embodiments of the present application provide a computer program product containing instructions, which, when executed on a computer, cause the computer to perform the steps in the method provided in the above-mentioned method embodiments.
[0160] It should be noted that the above description of the storage medium and device embodiments is similar to the description of the above-mentioned method embodiments, and has similar beneficial effects to the method embodiments. For technical details not disclosed in the storage medium, storage medium and device embodiments of the present application, please refer to the description of the method embodiments of the present application.
[0161] It should be understood that the term "one embodiment" or "an embodiment" or "some embodiments" as used herein means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. Therefore, the appearances of the phrase "in one embodiment" or "in an embodiment" or "in some embodiments" in various places throughout the specification are not necessarily referring to the same embodiment. Furthermore, the particular features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that the sequence of steps in the above-described processes does not necessarily mean that the steps are executed in the order described, and the execution order of the steps should be determined according to their functions and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the application. The sequence numbers of the above-described embodiments of the application are only for description, and do not represent the advantages or disadvantages of the embodiments. The above description of each embodiment tends to emphasize the differences between the embodiments, and the same or similar parts can be mutually referred to, and are not described herein for the sake of brevity.
[0162] The term "and / or", as used herein, merely describes association between associated objects, and can mean that three relationships exist, for example, object A and / or object B can mean that object A exists alone, object A and object B exist together, and object B exists alone.
[0163] It should be noted that the terms "comprising", "including", or any other variant are intended to cover a non-exclusive inclusion, such that processes, methods, articles, or devices that comprise a list of elements are not limited to those elements, but can also include other elements not expressly listed, or inherent to such processes, methods, articles, or devices. Without more limitations, the element defined by the sentence "comprising a" does not exclude the presence of additional identical elements in the process, method, article, or device including the element.
[0164] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The above-described embodiments are merely illustrative, for example, the division of the modules is only a logical function division, and actual implementation can have another division manner, such as: multiple modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed components can be indirect coupling or communication connection through some interfaces, devices or modules, which can be electrical, mechanical or other forms.
[0165] The modules described above as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules; they can be located in one place or distributed on multiple network units; and part or all of the modules can be selected as needed to achieve the purposes of the embodiments.
[0166] In addition, all the functional modules in the embodiments of the present application can be integrated in one processing unit, or each module can be a separate unit, or two or more modules can be integrated in one unit; the integrated modules can be realized in the form of hardware or in the form of hardware plus software functional units.
[0167] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware, and the above-mentioned program can be stored in a computer readable storage medium, and the program executes the steps including the above-mentioned method embodiments when executed; and the above-mentioned storage medium includes mobile storage equipment, read only memory (Read Only Memory, ROM), magnetic disc or optical disc and various storage program codes.
[0168] Alternatively, the integrated units of the present application, if implemented in the form of software functional modules and sold or used as independent products, can also be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of software products, which are stored in a storage medium and include a number of instructions for causing terminal devices to execute all or part of the methods described in the embodiments of the present application. The above-mentioned storage medium includes mobile storage equipment, ROM, magnetic disc or optical disc and various storage program codes.
[0169] The methods disclosed in the several method embodiments of the present application can be combined arbitrarily without conflict to obtain new method embodiments.
[0170] The features disclosed in the several product embodiments of the present application can be combined arbitrarily without conflict to obtain new product embodiments.
[0171] The features disclosed in the several method or device embodiments of the present application can be combined arbitrarily without conflict to obtain new method or device embodiments.
[0172] The above merely provides the implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of the change or replacement within the technical range disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A network authentication method characterized by, The method is applied to an IPTV service, and the method comprises: A client on a terminal device determines an extension field of a region where the terminal device is currently located from an extension field corresponding to each region; The client acquires authentication information corresponding to the extension field of the region where the terminal device is currently located; The client writes the authentication information into the extension field of the region where the terminal device is currently located to obtain extension information; The client sends the extension information to a system firmware of the terminal device, so that the system firmware interacts with a network authentication device based on the extension information to authenticate whether the terminal device has network access authority.
2. The method of claim 1, wherein, The writing of the authentication information into the extension field of the region where the terminal device is currently located to obtain extension information comprises: The client encrypts the authentication information according to an encryption rule of the region where the terminal device is currently located to obtain encrypted information; The client writes the encrypted information into the extension field of the region where the terminal device is currently located to obtain the extension information.
3. The method of claim 1, wherein, The interaction of the system firmware with the network authentication device based on the extension information to authenticate whether the terminal device has network access authority comprises: The system firmware sends the extension information to the network authentication device, so that the network authentication device performs network access authentication on the terminal device based on the extension information to obtain a network authentication result; The system firmware receives the network authentication result sent by the network authentication device, and determines that the terminal device has network access authority in a case where the network authentication result is network authentication success; and The system firmware determines that the terminal device does not have network access authority in a case where the network authentication result is network authentication failure.
4. The method of claim 3, wherein, The method further comprises: The client receives a network access address sent by the system firmware; wherein the network access address is an address allocated by the network authentication device to the terminal device and sent to the system firmware when the terminal device is authenticated to have network access authority; The client authenticates the network authentication device based on the network access address to obtain an authentication result; The client accesses a corresponding network through the network access address in a case where the authentication result is authentication success.
5. The method of claim 3, wherein, The method further comprises: The client receives a network authentication failure result sent by the system firmware; wherein the network authentication failure result is sent to the client by the system firmware when the terminal device is determined to not have network access authority; The client reminds a user to re-authenticate based on the network authentication failure result.
6. The method according to any one of claims 3 to 5, characterized in that, The network access authority comprises an authority to access a dedicated network for providing a specific service, and the specific service comprises an Internet TV service; and the network access authentication comprises an IPOE.
7. A network authentication method characterized by, The method is applied to an IPTV service, and the method comprises: The system firmware of the terminal device receives extended information sent by a client on the terminal device; wherein the extended information is obtained by the client as follows: determining an extension field of a current region of the terminal device from extension fields corresponding to respective regions, obtaining authentication information corresponding to the extension field of the current region, and writing the authentication information into the extension field of the current region. The system firmware performs information interaction with a network authentication device based on the extended information, thereby authenticating whether the terminal device has network access authority.
8. A network authentication apparatus characterized by comprising: The apparatus is applied to an interactive network television (IPTV) service, and comprises: a determining module configured to determine an extension field of a current region of a terminal device from extension fields corresponding to respective regions; an obtaining module configured to obtain authentication information corresponding to the extension field of the current region; a writing module configured to write the authentication information into the extension field of the current region to obtain extended information; a sending module configured to send the extended information to system firmware of the terminal device, so that the system firmware performs information interaction with a network authentication device based on the extended information, thereby authenticating whether the terminal device has network access authority.
9. A network authentication apparatus characterized by comprising: The apparatus is applied to an interactive network television (IPTV) service, and comprises: a receiving module configured to receive, by system firmware, extended information sent by a client on a terminal device; wherein the extended information is obtained by the client as follows: determining an extension field of a current region of the terminal device from extension fields corresponding to respective regions, obtaining authentication information corresponding to the extension field of the current region, and writing the authentication information into the extension field of the current region. an interacting module configured to perform information interaction, by the system firmware, with a network authentication device based on the extended information, thereby authenticating whether the terminal device has network access authority. 10.A terminal device, comprising a memory and a processor, the memory storing a computer program capable of running on the processor, characterized in that, The processor implements the method of any one of claims 1 to 7 when executing the program.
11. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program implements the method of any one of claims 1 to 7 when executed by the processor.
Citation Information
Patent Citations
Network roaming method and device, terminal and storage medium
CN112449339A