Playing stealing behavior processing method and device, equipment, medium and product

By managing multiple content distribution networks through a centralized authentication server, the problems of log aggregation delay and outdated blocking policies in traditional architectures are solved, enabling rapid response and effective suppression of piracy.

CN121985158APending Publication Date: 2026-05-05BEIJING QIYI CENTURY SCI & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING QIYI CENTURY SCI & TECH CO LTD
Filing Date
2026-03-13
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

In existing technologies, it is difficult to prevent piracy on video playback platforms in real time. Traditional content distribution network architectures result in high log aggregation latency and lagging blocking strategies, which cannot effectively suppress the occurrence of piracy.

Method used

A centralized authentication server is used to manage multiple content delivery networks. The authentication server determines whether user information meets the preset blocking policy and intercepts file access requests from user terminals when the blocking policy is met.

Benefits of technology

It improves the real-time nature of piracy, enabling rapid identification and prohibition of user terminal access to files, effectively suppressing piracy and reducing the content distribution network bandwidth costs and copyright infringement of video platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121985158A_ABST
    Figure CN121985158A_ABST
Patent Text Reader

Abstract

The invention relates to a broadcast stealing behavior processing method and device, equipment, a medium and a product, the method is applied to a broadcast stealing behavior processing system, and the broadcast stealing behavior processing system comprises an authentication server and a plurality of content distribution networks connected with the authentication server; the method comprises the following steps: when any content distribution network receives a file access request sent by a user terminal, sending an authentication request carrying target user information to an authentication server; the authentication server judges whether the target user information in the authentication request meets a preset forbidding strategy or not; and under the condition that the forbidding strategy is met, the authentication server returns interception information representing that the multimedia file cannot be accessed to the content distribution network, and the content distribution network intercepts the file requested to be accessed by the user terminal. According to the method and the device, the real-time performance of the broadcast stealing prohibition behavior can be improved, and the broadcast stealing behavior can be effectively inhibited.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of video playback technology, and in particular to a method, apparatus, device, medium, and product for dealing with piracy. Background Technology

[0002] With the development of video playback technology, third-party terminals have been stealing multimedia files from target servers and providing them to users for playback, resulting in hotlinking. Currently, countermeasures against hotlinking largely rely on analyzing content delivery network (CDN) access logs and triggering blocking. However, this method suffers from high log aggregation latency and lagging blocking policies, resulting in poor real-time performance and failing to effectively prevent hotlinking. Summary of the Invention

[0003] To address the aforementioned technical problems, this disclosure provides a method, apparatus, equipment, medium, and product for handling piracy.

[0004] According to one aspect of this disclosure, a method for handling piracy is provided. The method is applied to a system for handling piracy, the system comprising: an authentication server and multiple content distribution networks connected to the authentication server; the method includes: When any of the content delivery networks receives a file access request from a user terminal, it sends an authentication request carrying the target user information to the authentication server. The authentication server determines whether the target user information in the authentication request meets the preset blocking policy; If the blocking policy is met, the authentication server will return blocking information indicating that the file cannot be accessed to the content delivery network, and the content delivery network will then block the file requested by the user terminal.

[0005] According to another aspect of this disclosure, an apparatus for processing piracy is also provided. The apparatus is applied to a system for processing piracy, the system comprising: an authentication server and multiple content distribution networks connected to the authentication server; the apparatus includes: The authentication request sending module is used to send an authentication request carrying target user information to the authentication server when any of the content delivery networks receives a file access request sent by a user terminal. The blocking judgment module is used by the authentication server to determine whether the target user information in the authentication request meets the preset blocking policy; The file interception module is used to, when the blocking policy is met, have the authentication server return interception information indicating that the file cannot be accessed to the content delivery network, so that the content delivery network can intercept the file requested by the user terminal.

[0006] According to another aspect of this disclosure, an electronic device is also provided, the electronic device comprising: processor; Memory used to store the processor's executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the above-mentioned method for handling piracy.

[0007] According to another aspect of this disclosure, a computer-readable storage medium is also provided, the storage medium storing a computer program for performing the above-described method for handling piracy.

[0008] According to another aspect of this disclosure, a computer program product is also provided, which, when run on a computer, enables the computer to perform the aforementioned method for handling piracy.

[0009] The technical solution provided in this disclosure has the following advantages compared with the prior art: The technical solution provided in this embodiment is applied to a system for handling piracy, which includes an authentication server and multiple content distribution networks connected to the authentication server. Therefore, this solution constructs a centralized authentication server to handle multiple content distribution networks. Based on the authentication server, after a user terminal initiates a file access request, it needs to first send an authentication request carrying the target user information to the authentication server through the content distribution networks. The authentication server has a preset blocking policy and determines whether the target user information in the authentication request meets the blocking policy; if it does, it returns interception information indicating that the file cannot be accessed to the content distribution networks, which then intercept the file requested by the user terminal. Based on this, this embodiment requires all file access requests from all content distribution networks to be authenticated and approved by the authentication server, effectively alleviating the contradiction between centralized control and the operation of distributed content distribution networks. Compared to distributed content delivery networks that first analyze logs before issuing blocking policies, this solution, based on a centralized authentication server, directly utilizes pre-defined blocking policies to quickly determine whether the target user's information meets the blocking policy requirements. If so, it prohibits the user's terminal from accessing the file. This improves the real-time performance of blocking piracy and effectively suppresses its occurrence. Attached Figure Description

[0010] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0011] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 This is a flowchart of the method for handling piracy as described in the embodiments of this disclosure; Figure 2 This is a schematic diagram of the system architecture described in the embodiments of this disclosure; Figure 3 This is a schematic diagram of the synchronization mode described in the embodiments of this disclosure; Figure 4 This is a schematic diagram of the asynchronous mode described in the embodiments of this disclosure; Figure 5 This is a schematic diagram of the structure of the device for processing piracy described in the embodiments of this disclosure; Figure 6 This is a schematic diagram of the structure of the electronic device described in an embodiment of this disclosure. Detailed Implementation

[0013] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0014] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.

[0015] Various video platforms accumulate a large number of proprietary files (such as videos, audio files, documents, and resource packages) through self-production or acquisition. These files are typically stored on the video platform's Content Delivery Network (CDN). Users access these files through the video platform, generating revenue for the platform.

[0016] However, in industry practice, third parties sometimes masquerade as legitimate users to obtain the actual streaming addresses of video platform files (commonly found in membership or paid content) on content distribution networks. These addresses are then illegally distributed to third-party websites, applications, or social media channels for hotlinking and playback; this behavior is known as piracy. Piracy severely infringes upon the content copyright and revenue of video platforms and increases the bandwidth costs of their content distribution networks due to the hotlinked traffic.

[0017] When a third party steals and distributes content delivery network (CDN) playback addresses, it leaves behind access log records with characteristics different from those of legitimate users. Therefore, a common solution to combat piracy relies on identifying CDN access logs. After identifying suspicious piracy activity in the logs, the video platform generates a blocking policy and distributes it to all CDN nodes to prevent further unauthorized access.

[0018] However, traditional content delivery networks (CDNs) employ a distributed architecture and typically involve numerous providers (such as Baidu Cloud, Tencent Cloud, and Alibaba Cloud), and even a large number of self-built or leased servers. The total number of CDNs is enormous, dispersed across the country to quickly serve users nationwide. Under this architecture, rapid user log collection and analysis within minutes, and the dissemination of blocking policies, are impossible. The main problems encountered are as follows: Dispersed logs: Content delivery networks (CDNs) have numerous nodes that span across vendors, carriers, and regions, making real-time aggregation of access logs from all nodes impossible. This results in a significant time delay between the occurrence of an action and the completion of analysis, typically exceeding one hour, and in complex cases, even reaching several hours or longer. For example, in time-sensitive scenarios such as newly released popular dramas, the anti-piracy window is extremely short, while the existing process of log identification and triggering blocking is too time-consuming. This delay creates a huge gap with the timeliness of popular dramas, causing blocking measures to be severely lagging behind, failing to effectively block users who have already started watching, and failing to achieve a good blocking and protection effect, still causing significant losses.

[0019] Delayed blocking policies: Synchronizing blocking policies requires interfacing with different interfaces of various content delivery network providers and necessitates node-by-node synchronization within the provider's internal network. This process is time-consuming, resulting in a delay of over thirty minutes for the policies to take effect across the entire network.

[0020] There is a global blind spot: the actual time taken for log synchronization and policy distribution is not uniform across different vendors and content delivery network nodes, making it difficult to perform analysis and processing uniformly at once. Furthermore, the fast log analysis and policy distribution of a single node or vendor, which are relatively fast, cannot identify hotlinking behavior across regions and vendors.

[0021] Due to the aforementioned technical deficiencies, the relevant anti-piracy solutions cannot effectively prevent piracy from occurring.

[0022] In this context, embodiments of this disclosure provide a method, apparatus, device, medium, and product for handling piracy. For ease of understanding, embodiments of this disclosure are described below.

[0023] Figure 1This flowchart illustrates a method for handling piracy provided in this embodiment of the disclosure. This method is applicable to anti-piracy situations in various fields such as online video, live sports broadcasts, and online education. The method can be applied to a system for handling piracy, which includes an authentication server and multiple content distribution networks connected to the authentication server.

[0024] To address the problem of large numbers of nodes in traditional distributed content delivery networks, making unified management difficult, refer to Figure 2 This embodiment employs a centralized authentication server to manage multiple content delivery networks. The authentication server can be a single server or a cluster of multiple servers, providing unified processing services for piracy, such as establishing blocking policies, authenticating user terminals, and sending interception or access information. This centralized authentication server ensures uniformity and a global perspective in handling piracy at the business logic level, effectively mitigating the conflict between centralized control and the operation of distributed content delivery networks.

[0025] like Figure 1 As shown, the system for handling piracy may include the following steps S102 to S106.

[0026] S102, when any content delivery network receives a file access request from a user terminal, it sends an authentication request carrying the target user information to the authentication server.

[0027] In this embodiment, users can access various files such as multimedia, documents, and resource packages on their user terminals (e.g., mobile phones, computers, smart TVs). When accessing a file, the user terminal constructs a file access request carrying the target user information and sends the file access request to the content delivery network with the best network quality (e.g., sufficient bandwidth and resources, and closest to the user); this content delivery network is any content delivery network that receives the file access request, as described below. The target user information may include: a file identifier representing the file to be accessed, the user identifier of the current user, the first IP address (Internet Protocol Address) of the current user when accessing the service interface (such as the broadcasting and authentication interface), the second IP address of the current user when accessing the content delivery network, the device identifier of the user terminal, and the client type applied on the user terminal, etc.

[0028] Furthermore, it is understandable that, in order to reduce authentication costs, when a user requests access to a file that has no value for piracy, such as advertising audio or video, this embodiment does not need to authenticate the user accessing the file that has no value for piracy; or in other words, in the scenario where a user accesses a file that has no value for piracy, this embodiment does not need to perform authentication, and therefore does not need to implement a method for handling piracy behavior for the user and their behavior.

[0029] When any content delivery network receives a file access request, in order to prevent the file access request from coming from a third-party terminal that is illegally broadcasting the file, it can generate an authentication request carrying the target user information and send the authentication request to the authentication server. The authentication server then judges the legitimacy of the file access request from the user terminal.

[0030] In addition, in user terminals or content delivery networks, encryption methods such as generating digital signatures can be used to encrypt target user information to ensure the security and immutability of the target user information.

[0031] S104, the authentication server determines whether the target user information in the authentication request meets the preset blocking policy.

[0032] In this embodiment, the authentication server parses the received authentication request to obtain authentication parameter information, which may include: target user information and a first encrypted value corresponding to the target user information; the target user information is then encrypted to obtain a second encrypted value. If the first encrypted value and the second encrypted value are the same, the authentication request is deemed to have been successfully verified. Therefore, the target user information in the authentication request is parsed to prevent erroneous authentication caused by the target user information being tampered with by a third party engaging in unauthorized broadcasting, thus blocking legitimate users.

[0033] Then, the authentication server determines whether the target user information meets the preset blocking policy. The blocking policy is used to determine, based on the target user information, whether the multimedia playback behavior corresponding to the user terminal's file access request constitutes piracy. The blocking policy may include: blocked user information and the corresponding blocking time period; the blocked user information represents the blocked user information, which includes, but is not limited to, at least one of the following: user identifier, the user's first IP address when accessing the service interface, the user's second IP address when accessing the content delivery network, and device identifier.

[0034] For example, the blocking policy can be predetermined in the following way: the authentication server analyzes access logs from multiple content delivery networks to obtain several key fields. These key fields include: user identifier, device identifier, first IP address, and second IP address representing user information; file identifier representing access behavior information; the first ISP corresponding to the first IP address when accessing the service interface; the second ISP corresponding to the second IP address when accessing the content delivery network; and pingback delivery. The frequency of each key field is counted, and then combined with the combination of key fields and the corresponding frequency thresholds, to determine the user information to be blocked and the blocking time period; the blocked user information and the blocking time are then correlated to form the blocking policy.

[0035] Specifically, the blocking of user information includes, for example: when the number of times a user accesses the content delivery network from a second IP address under the same first IP address exceeds a preset threshold, the first IP address and its corresponding user identifier are identified as blocked user information; device identifiers whose file identifiers (especially VIP file identifiers) exceed a preset threshold are identified as blocked user information; and user identifiers whose counts of inconsistent counts between the first and second operators exceed a preset threshold are identified as blocked user information.

[0036] Based on the blocking policy, if the current time meets the blocking time period and at least one item of the target user information is included in the blocked user information, then the blocking policy is determined. For example, if the first user identifier in the target user information matches the second user identifier in the blocked user information, it means that the multimedia playback behavior corresponding to the first user identifier has previously involved piracy; and at the same time, the current time meets the blocking time period associated with the second user identifier. In this case, the blocking policy is determined to be met by the target user information, that is, it is determined that the multimedia playback behavior corresponding to the file access request of the user terminal involves piracy.

[0037] Based on the blocking policy, if the current time does not meet the blocking time period and / or any of the target user information is not included in the blocked user information, then it is determined that the target user information does not meet the blocking policy, that is, it is determined that the multimedia playback behavior corresponding to the file access request of the user terminal does not involve piracy.

[0038] S106, if the blocking policy is met, the authentication server returns the blocking information indicating that the file cannot be accessed to the content delivery network, and the content delivery network blocks the file requested by the user terminal.

[0039] According to the above embodiments, when it is determined that the blocking policy is met, it indicates that there is piracy and the user is prohibited from playing the video. At this time, the authentication server returns the blocking information indicating that the file cannot be accessed to the content delivery network. The content delivery network forwards the blocking information to the user terminal to block the user terminal's request to access the file and prohibit the user terminal from accessing the file, such as prohibiting the user terminal from playing audio, video and other multimedia, or prohibiting the user terminal from downloading documents.

[0040] The method for handling piracy provided in this embodiment is applied to a system for handling piracy, which includes an authentication server and multiple content distribution networks connected to the authentication server. Therefore, this embodiment constructs a centralized authentication server to handle multiple content distribution networks. Based on the authentication server, after a user terminal initiates a file access request, it needs to first send an authentication request carrying the target user information to the authentication server through the content distribution networks. The authentication server has a preset blocking policy and determines whether the target user information in the authentication request meets the blocking policy; if it does, it returns interception information indicating that the file cannot be accessed to the content distribution networks, which then intercept the file requested by the user terminal. Based on this, this embodiment requires all file access requests from all content distribution networks to be authenticated and approved by the authentication server, effectively alleviating the contradiction between centralized control and the operation of distributed content distribution networks. Compared to distributed content delivery networks that first analyze logs before issuing blocking policies, this solution, based on a centralized authentication server, directly utilizes pre-defined blocking policies to quickly determine whether the target user's information meets the blocking policy requirements. If so, it prohibits the user's terminal from accessing the file. This improves the real-time performance of blocking piracy and effectively suppresses its occurrence.

[0041] According to the above embodiments, if it is determined that the blocking policy is not met, it indicates that there is no piracy. At this time, the first pass information indicating that multimedia playback is allowed is returned to the content delivery network. The content delivery network obtains the target file corresponding to the file identifier in the file access request based on the first pass information and sends the target file to the user terminal, so that the user terminal can play the target file normally.

[0042] To better understand the solution, the following embodiments provide a detailed description of the methods for handling the aforementioned piracy.

[0043] In order to directly use the blocking policy, the blocking policy needs to be established in advance. This embodiment provides a process for determining the blocking policy, referring to steps 1 to 6.

[0044] Step 1: The authentication server obtains access logs from multiple content delivery networks within a preset statistical time range.

[0045] In practical applications, the multimedia playback link mainly involves: the start-up and authentication interface (also known as the business interface), the scheduling interface, the content distribution network, and Pingback delivery.

[0046] The broadcasting interface is used to obtain the user's initial IP address when multimedia content is broadcast. The authentication interface provides authentication services for VIP users or paid videos when multimedia content is broadcast; however, in some scenarios, the authentication service can be directly provided within the broadcasting interface itself, meaning the broadcasting and authentication interfaces are unified into a single business interface. The scheduling interface directs users to a content delivery network with sufficient bandwidth and resources. The content delivery network is the node that provides multimedia data to the user, determined by the scheduling interface. Pingback delivery records the client's behavior on the user's terminal, including the playback status of the multimedia content, such as start time, end time, buffering time, and playback duration.

[0047] Based on the above video playback chain, in a specific embodiment of obtaining access logs from multiple content delivery networks within a preset statistical duration range, access logs within the preset statistical duration range can be collected from the content delivery networks through interfaces such as launch interface, authentication interface, scheduling interface, content delivery network, and Pingback delivery. The statistical duration range can have multiple dimensions, such as five minutes, one hour, and one day.

[0048] In one approach, the content delivery network (CDN) generates and packages access logs into compressed files at small time-granularity collection intervals (e.g., one or five minutes), and sends these compressed files to the authentication server. These compressed files are quickly aggregated and collected by the authentication server; the authentication server then decompresses the access log files and imports them into a large data cluster such as an Iceberg data lake or Hive tables. Subsequently, leveraging the powerful computing capabilities of the authentication server, field extraction and statistical analysis are performed on all access logs within the statistical timeframe.

[0049] In another approach, the content delivery network (CDN) simultaneously generates access logs and sends them in real-time as messages to high-performance message queues such as Kafka, storing them in an in-memory database on the authentication server, such as a local Redis instance or a centralized Redis cluster. Subsequently, the access logs in message format are consumed directly from the in-memory database, and field extraction and statistical analysis are performed on all access logs within the statistical timeframe. This method minimizes the time required for access log statistics, achieving faster processing speeds.

[0050] Step 2: Extract key fields from the access logs; these key fields include: statistical dimension fields representing user information and key behavior fields representing access behavior information and used as data to be analyzed.

[0051] After obtaining access logs from multiple content delivery networks within a preset statistical timeframe, key fields are extracted from the access logs. These key fields may include statistical dimension fields representing user information, such as user identifier, first IP address, second IP address, and device identifier. Key fields may also include key behavioral fields representing access behavior information and used as data to be analyzed, such as file identifier, client type used on the user's terminal, authentication behavior, the first ISP corresponding to the first IP address, and the second ISP corresponding to the second IP address.

[0052] In real-world scenarios, a single operator (such as China Mobile) has users nationwide. A third party engaging in piracy might distribute file access addresses to users in different provinces who belong to the same operator. Therefore, in this embodiment, both the first and second operators are internet service providers carrying geographic information. Geographic information includes, for example, province information and city information.

[0053] Step 3: Based on the statistical dimension fields, aggregate and statistically analyze the key behavioral fields to obtain the statistical results.

[0054] In this embodiment, the user identifier, first IP address, second IP address, and device identifier are each treated as an independent core statistical dimension. Based on these multiple core statistical dimensions, statistical analysis is performed on key behavioral fields within different statistical timeframes.

[0055] This embodiment may include: performing aggregate statistics on key behavioral fields under each statistical dimension field to obtain a first statistical result.

[0056] Specifically, taking user identifiers as an example, the statistical dimension fields are aggregated and statistically analyzed for the quantity of each key behavioral field within different statistical timeframes, such as five minutes, one hour, and one day. For instance, within a five-minute statistical timeframe, the number of times a second IP address appears after deduplication is counted.

[0057] Under normal circumstances, users will use the same IP address to access the business interface and the content delivery network to obtain files. In this case, the first IP address when the user accesses the business interface and the second IP address when accessing the content delivery network are the same IP address.

[0058] However, third parties engaging in piracy do not follow the above scenario. Instead, they use a centralized server's primary IP address to access the service interface. After obtaining the video playback address, the third party distributes it to malicious websites or apps, resulting in a large number of users accessing the content delivery network (CDN) separately. In this case, the secondary IP address accessing the CDN is not the same as the primary IP address accessing the service interface, and there will be a significant number of these secondary IP addresses. Based on this, we can count the number of times the secondary IP address appears after deduplication; if the number of occurrences exceeds a certain threshold (e.g., 3 times), it can be considered that piracy has occurred.

[0059] This embodiment may also include: performing aggregate statistics on key behavioral fields under a combined dimension field that includes at least two statistical dimension fields to obtain a second statistical result.

[0060] In a specific embodiment, the field representing the first IP address when a user accesses the service interface and the field representing the user identifier in the statistical dimension are determined as a combined dimension field; under the combined dimension field, the operator field is aggregated and statistically analyzed to obtain the second statistical result corresponding to the operator field; wherein, the operator field is used to represent: the Internet service provider carrying regional information corresponding to the second IP address when a user accesses the content delivery network.

[0061] This embodiment combines the first IP address and the user identifier to form a combined dimension field with finer statistical granularity. Under the same set of first IP address and user identifier, it counts the number of provincial operators accessing the second IP address.

[0062] For individual users engaging in normal streaming activities, their secondary IP address typically comes from only one or two carriers (e.g., when switching between Wi-Fi and mobile data). If too many different carriers are associated with the same primary IP address and user identifier, it strongly suggests that the streaming address is being distributed in a heterogeneous network environment. This is a typical characteristic of centralized distribution in piracy, and thus can be used to identify piracy.

[0063] This statistical analysis method, which employs multiple core dimensions and statistical time ranges, is key to discovering complex piracy and automating anti-piracy measures.

[0064] If it is a local Redis statistics, it is also necessary to perform an additional aggregation statistics on the Redis of all authentication servers. During this process, statistics with very low access frequency can be discarded to speed up the process. This can reduce the time to obtain statistics to the second level.

[0065] Step 4: If the statistical results meet the preset abnormal behavior conditions, then mark the user information represented by the statistical dimension field as banned user information.

[0066] In this embodiment, a preset detection model (such as an ML model) can be used to detect whether the statistical results meet preset abnormal behavior conditions. If the statistical results meet the preset abnormal behavior conditions, the original user information is marked as blocked user information, which may include: Determine whether the statistical results meet at least one preset abnormal behavior condition, and if so, mark the original user information as blocked user information; wherein, the abnormal behavior condition includes: the number of occurrences of at least one access behavior information is greater than a preset first number threshold.

[0067] In some example scenarios, there are VIP authentication attempts exceeding a certain threshold within the statistical duration. An abnormally high number of authentication attempts may indicate verification of a stolen member account, which is inconsistent with normal user behavior. Accessing a large number of different file identifiers within the statistical duration is also inconsistent with normal user behavior. For multimedia playback duration phrases with preset duration values, extremely short playback durations may indicate that the video stream is being captured rather than watched.

[0068] Determine whether the behavior statistics results meet the abnormal behavior conditions in the above scenario, and if so, mark the user information represented by the statistical dimension field as banned user information.

[0069] Step 5: Determine the blocking period for user information based on the statistical results.

[0070] The ban period refers to the time period during which a user's information is banned from hotlinking and playing content. The period can be divided into several forms such as 1 day, 1 week, or permanent ban. If it is 1 day, hotlinking and playing content is prohibited for that day. If it is 1 week, hotlinking and playing content is prohibited for that week. Permanent ban means that the user is permanently prohibited from hotlinking and playing content.

[0071] Step 6: Associate the blocked user information with the blocked time period to form a blocking policy.

[0072] The blocking policy can be stored in a blocking pool. This embodiment can also scan the blocking pool at a preset period (e.g., every minute) and delete blocked user information such as user identifiers, user IP addresses, and device identifiers that have exceeded the blocking period from the blocking pool.

[0073] Any batch of changes to the blocking pool will trigger an update and distribution logic simultaneously, immediately updating the anti-leeching blocking policy configuration and distributing it to the broadcasting interface, VIP member authentication interface, scheduling interface, and authentication server. When a blocked user starts broadcasting or requests the next multimedia segment, an interception error will be triggered immediately, thereby protecting the company's rights and preventing theft.

[0074] In this embodiment, the user terminal initiates a file access request to the content delivery network (CDN). The CDN generates an authentication request based on the file access request and sends the authentication request to the authentication server. The CDN can send the authentication request to the authentication server in either synchronous or asynchronous mode in the specific implementation.

[0075] In synchronous mode, when any content delivery network receives a file access request from a user terminal, it sends an authentication request carrying the target user information to the authentication server.

[0076] Among them, reference Figure 3 In synchronous mode, the user terminal initiates a file access request to the content delivery network (CDN). This file access request may specifically be a request for a video resource URL (Uniform Resource Locator). The CDN generates an authentication request carrying the target user's information based on the file access request and sends the request directly to the authentication server. The authentication server then determines whether the target user information in the authentication request meets the preset blocking policy.

[0077] If the authentication server successfully authenticates the user, it returns a first pass message to the content delivery network (CDN), which may be a 200 OK status code. After receiving the first pass message, the CDN then returns the target file to the user terminal.

[0078] If the authentication server fails authentication, it returns an interception message to the content delivery network (CDN), which may be an error code such as 403, 405, or 401. Accordingly, in synchronous mode, the CDN prohibits the return of the target file to the user terminal. In a specific example, after receiving the interception message, the CDN forwards the interception message to the user terminal and prohibits the return of the target file to the user terminal.

[0079] In asynchronous mode, when any content delivery network receives a file access request from a user terminal, it sends a file fragment from the target file corresponding to the file identifier to the user terminal based on the file identifier carried in the file access request, and sends an authentication request carrying the target user information to the authentication server.

[0080] Reference Figure 4In asynchronous mode, the user terminal initiates a file access request to the content delivery network (CDN). On one hand, upon receiving the request, the CDN, without waiting for authentication from the authentication server, immediately sends the file fragment corresponding to the target file in the file access request to the user terminal, based on the file identifier carried in the request, to improve the user's first-screen loading speed. On the other hand, the CDN generates an authentication request carrying the target user information based on the file access request and asynchronously sends the authentication request to the authentication server. The authentication server then determines whether the target user information in the authentication request meets the preset blocking policy.

[0081] The specific implementation methods for a content delivery network to send file fragments from a target file corresponding to a file identifier to a user terminal include, but are not limited to, the following: Example 1: The content delivery network sends one or more standard slices to the user terminal in the order of transmission of the target file (such as a video stream), usually the file fragment corresponding to the first image group, to ensure that the user terminal can decode and play the picture immediately.

[0082] Example 2: The content delivery network (CDN) extracts a file segment of a specified duration from the beginning of the target file based on a preset time threshold (e.g., the first 5 or 10 seconds) and sends it to the user terminal. If no authentication success message is received after the specified duration of the file segment has been sent, the transmission of the remaining content of the target file is stopped.

[0083] Example 3: A content delivery network sends a fixed-size (e.g., the first 1MB) file fragment to a user terminal to cover the needs of files with different bitrates during the initial buffering phase.

[0084] Subsequently, if the authentication server passes the authentication, it returns a first pass message to the content delivery network, which then returns the target file to the user terminal.

[0085] If the authentication server fails to authenticate the file, the content delivery network (CDN) will intercept the file request from the user terminal. Specifically, in asynchronous mode, the CDN may interrupt the transmission of file fragments to the user terminal and prevent the return of the target file. In short, if authentication fails, the CDN immediately interrupts the currently transmitted file fragment and does not return the target file.

[0086] In this embodiment, after receiving the authentication request, the authentication server determines whether the target user information meets the preset blocking policy, as shown below.

[0087] The authentication server obtains the blocked user information and the blocking time period from the blocking policy; wherein, the blocked user information is used to represent the information of the blocked user, and the user information includes at least one of the following: user identifier, first IP address, second IP address and device identifier; If the current time meets the blocking period and at least one item of the target user information is included in the blocked user information, then the target user information is determined to meet the blocking policy.

[0088] Subsequently, if the blocking policy is met, the authentication server returns interception information indicating that the file cannot be accessed to the content delivery network. Conversely, if the blocking policy is not met, a first pass message is generated and returned to the content delivery network.

[0089] This embodiment may further include: when the content delivery network receives non-blocking information returned by the authentication server, or when it does not receive return information from the authentication server within a preset response time range, it sends the target file corresponding to the file identifier carried in the file access request to the user terminal; wherein, when the authentication server determines that the target user information does not meet the blocking policy, it returns non-blocking information to the content delivery network.

[0090] In one embodiment, the authentication server returns non-interception information to the content delivery network (CDN), enabling the CDN to send the target file corresponding to the file identifier carried in the file access request to the user terminal. The non-interception information includes a first pass message generated when the target user information does not meet the blocking policy. Furthermore, in special circumstances such as unpaid fees, network disconnection, or CDN parsing errors, authentication requests may be hijacked; in this case, the CDN can generate a second pass message.

[0091] Specifically, authentication servers typically only return the aforementioned status codes indicating successful or unsuccessful authentication. However, in real-world scenarios, authentication requests may be hijacked, in which case the authentication server may return status codes other than those mentioned above to the content delivery network.

[0092] For a content delivery network, if other status codes are received, it is considered that the authentication request has been hijacked. In this case, a downgrade process is performed, and the target file corresponding to the file identifier is sent directly to the user terminal.

[0093] In another embodiment, if the content delivery network does not receive a return message from the authentication server within a preset response time range (e.g., 200ms), it considers the request to have timed out and performs a degradation process, sending the target file corresponding to the file identifier to the user terminal based on the file identifier carried in the file access request.

[0094] In summary, traditional content delivery networks (CDNs), characterized by multiple vendors, numerous nodes, and geographical dispersion, generally suffer from pain points in areas such as rapid log collection, real-time statistical analysis, and second / minute-level distribution of network-wide policies. To address these pain points, this disclosure effectively improves the governance challenges of distributed content delivery networks through a centralized authentication server, including: Real-time / near real-time aggregation of end-to-end logs: All access requests (regardless of which content delivery network node they ultimately reach) first pass through the central service, thus the logs are naturally centralized.

[0095] Instant / rapid network-wide effect of unified policies: After the blocking policy is decided by the central service, it can immediately take effect on all subsequent requests (regardless of which content delivery network node the request points to), solving the problem of synchronization delay (hours or even days) of traditional content delivery network policies.

[0096] Global perspective anomaly analysis: The central service has a global view of all requests, making it possible to analyze user behavior across content delivery network nodes and across regions.

[0097] Figure 5 This is a schematic diagram of a device for processing piracy provided in an embodiment of this disclosure. This device can be applied to a system for processing piracy, which includes an authentication server and multiple content distribution networks connected to the authentication server. (Refer to...) Figure 5 The device for handling piracy may include the following modules: The authentication request sending module 202 is used to send an authentication request carrying target user information to the authentication server when any of the content delivery networks receives a file access request sent by a user terminal. The blocking judgment module 204 is used by the authentication server to determine whether the target user information in the authentication request meets the preset blocking policy; The file interception module 206 is used to, when the blocking policy is met, have the authentication server return interception information indicating that the file cannot be accessed to the content delivery network, so that the content delivery network can intercept the file requested by the user terminal.

[0098] In this embodiment, the blocking determination module 204 is further configured to: The authentication server obtains the blocked user information and the blocked time period from the blocking policy; wherein, the blocked user information is used to represent the blocked user information, and the user information includes at least one of the following: user identifier, device identifier, first network protocol IP address when the user accesses the service interface, and second IP address when the user accesses the content delivery network; If the current time meets the blocking time period and at least one of the target user information is included in the blocked user information, then the target user information is determined to meet the blocking policy.

[0099] In this embodiment, the device further includes a strategy determination module, which is used for: The authentication server obtains access logs from multiple content delivery networks within a preset statistical time range; Extract key fields from the access logs; wherein, the key fields include: statistical dimension fields representing user information and key behavior fields representing access behavior information and used as data to be analyzed; Based on the statistical dimension fields, the key behavioral fields are aggregated and statistically analyzed to obtain statistical results; If the statistical results meet the preset abnormal behavior conditions, the user information represented by the statistical dimension field will be marked as banned user information; The time period for blocking user information is determined based on the statistical results. The blocked user information and the blocked time period are associated to form a blocking policy.

[0100] In this embodiment, the strategy determination module is further configured to: Under each of the aforementioned statistical dimension fields, the key behavioral fields are aggregated and statistically analyzed to obtain the first statistical result; Under a combined dimension field that includes at least two of the aforementioned statistical dimension fields, aggregate statistics are performed on the key behavior fields to obtain a second statistical result.

[0101] In this embodiment, the strategy determination module is further configured to: The field representing the first IP address when a user accesses the business interface and the field representing the user identifier in the statistical dimension are determined as the combined dimension field; Under the combined dimension fields, the operator field is aggregated and statistically analyzed to obtain the second statistical result corresponding to the operator field; wherein, the operator field is used to represent: the Internet service provider carrying regional information corresponding to the second IP address when the user accesses the content delivery network.

[0102] In this embodiment, the authentication request sending module 202 is further configured to: In synchronous mode, when any of the content delivery networks receives a file access request from a user terminal, it sends an authentication request carrying the target user information to the authentication server. Alternatively, in asynchronous mode, when any of the content delivery networks receives a file access request from a user terminal, it sends a file fragment from the target file corresponding to the file identifier carried in the file access request to the user terminal, and sends an authentication request carrying the target user information to the authentication server.

[0103] In this embodiment, the file interception module 206 is further configured to: In the synchronization mode, the content delivery network is prohibited from returning the target file to the user terminal; In the asynchronous mode, the content delivery network interrupts sending the file fragment to the user terminal and prohibits returning the target file to the user terminal.

[0104] In this embodiment, the device further includes a file sending module, which is used for: When the content delivery network receives non-interception information returned by the authentication server, or when it does not receive return information from the authentication server within a preset response time range, it sends the target file corresponding to the file identifier carried in the file access request to the user terminal. If the authentication server determines that the target user information does not meet the blocking policy, it returns non-blocking information to the content delivery network.

[0105] The device for handling piracy in a content delivery network provided in this embodiment has the same implementation principle and technical effect as the aforementioned method for handling piracy in an authentication server. For the sake of brevity, any parts not mentioned in this embodiment can be referred to the corresponding content in the aforementioned method embodiment.

[0106] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Figure 6 As shown, the electronic device 300 includes one or more processors 301 and memory 302.

[0107] The processor 301 may be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 300 to perform desired functions.

[0108] The memory 302 may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, and the processor 301 may execute the program instructions to implement the method for handling piracy described in the embodiments of this disclosure above, and / or other desired functions. Various contents such as input signals, signal components, and noise components may also be stored in the computer-readable storage medium.

[0109] In one example, the electronic device 300 may also include an input device 303 and an output device 304, which are interconnected via a bus system and / or other forms of connection mechanism (not shown).

[0110] In addition, the input device 303 may also include, for example, a keyboard, a mouse, etc.

[0111] The output device 304 can output various information to the outside, including determined distance information, direction information, etc. The output device 304 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, etc.

[0112] Of course, for the sake of simplicity, Figure 6 Only some of the components of the electronic device 300 relevant to this disclosure are shown, omitting components such as buses, input / output interfaces, etc. In addition, the electronic device 300 may include any other suitable components depending on the specific application.

[0113] Furthermore, this embodiment also provides a computer-readable storage medium storing a computer program for executing the above-described method for handling piracy.

[0114] The present disclosure provides a computer program product for processing piracy activities, including a method, apparatus, electronic device, and medium. The program product includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the methods described in the preceding method embodiments. For specific implementation details, please refer to the method embodiments, which will not be repeated here.

[0115] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0116] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for handling piracy, characterized in that, The method is applied to a system for handling piracy, the system comprising: an authentication server and multiple content distribution networks connected to the authentication server; the method comprising: When any of the content delivery networks receives a file access request from a user terminal, it sends an authentication request carrying the target user information to the authentication server. The authentication server determines whether the target user information in the authentication request meets the preset blocking policy; If the blocking policy is met, the authentication server will return blocking information indicating that the file cannot be accessed to the content delivery network, and the content delivery network will then block the file requested by the user terminal.

2. The method according to claim 1, characterized in that, The step of the authentication server determining whether the target user information in the authentication request meets the preset blocking policy includes: The authentication server obtains the blocked user information and the blocked time period from the blocking policy; wherein, the blocked user information is used to represent the blocked user information, and the user information includes at least one of the following: user identifier, device identifier, first network protocol IP address when the user accesses the service interface, and second IP address when the user accesses the content delivery network; If the current time meets the blocking time period and at least one of the target user information is included in the blocked user information, then the target user information is determined to meet the blocking policy.

3. The method according to claim 1, characterized in that, The process of determining the blocking strategy includes: The authentication server obtains access logs from multiple content delivery networks within a preset statistical time range; Extract key fields from the access logs; wherein, the key fields include: statistical dimension fields representing user information and key behavior fields representing access behavior information and used as data to be analyzed; Based on the statistical dimension fields, the key behavioral fields are aggregated and statistically analyzed to obtain statistical results; If the statistical results meet the preset abnormal behavior conditions, the user information represented by the statistical dimension field will be marked as banned user information; The time period for blocking user information is determined based on the statistical results. The blocked user information and the blocked time period are associated to form a blocking policy.

4. The method according to claim 3, characterized in that, Based on the statistical dimension fields, the key behavioral fields are aggregated and statistically analyzed to obtain the statistical results, including: Under each of the aforementioned statistical dimension fields, the key behavioral fields are aggregated and statistically analyzed to obtain the first statistical result; Under a combined dimension field that includes at least two of the aforementioned statistical dimension fields, aggregate statistics are performed on the key behavior fields to obtain a second statistical result.

5. The method according to claim 4, characterized in that, The step of aggregating and statistically analyzing the key behavior field under a combined dimension field containing at least two of the aforementioned statistical dimension fields to obtain a second statistical result includes: The field representing the first IP address when a user accesses the business interface and the field representing the user identifier in the statistical dimension are determined as the combined dimension field; Under the combined dimension fields, the operator field is aggregated and statistically analyzed to obtain the second statistical result corresponding to the operator field; wherein, the operator field is used to represent: the Internet service provider carrying regional information corresponding to the second IP address when the user accesses the content delivery network.

6. The method according to claim 1, characterized in that, When any of the content delivery networks receives a file access request from a user terminal, it sends an authentication request carrying target user information to the authentication server, including: In synchronous mode, when any of the content delivery networks receives a file access request from a user terminal, it sends an authentication request carrying the target user information to the authentication server. Alternatively, in asynchronous mode, when any of the content delivery networks receives a file access request from a user terminal, it sends a file fragment from the target file corresponding to the file identifier carried in the file access request to the user terminal, and sends an authentication request carrying the target user information to the authentication server.

7. The method according to claim 6, characterized in that, The file requested for access by the user terminal by the content delivery network includes: In the synchronization mode, the content delivery network is prohibited from returning the target file to the user terminal; In the asynchronous mode, the content delivery network interrupts sending the file fragment to the user terminal and prohibits returning the target file to the user terminal.

8. The method according to claim 1, characterized in that, The method further includes: When the content delivery network receives non-interception information returned by the authentication server, or when it does not receive return information from the authentication server within a preset response time range, it sends the target file corresponding to the file identifier carried in the file access request to the user terminal. If the authentication server determines that the target user information does not meet the blocking policy, it returns non-blocking information to the content delivery network.

9. A device for processing piracy, characterized in that, The device is used in a system for processing piracy, the system comprising: an authentication server and multiple content distribution networks connected to the authentication server; the device comprises: The authentication request sending module is used to send an authentication request carrying target user information to the authentication server when any of the content delivery networks receives a file access request sent by a user terminal. The blocking judgment module is used by the authentication server to determine whether the target user information in the authentication request meets the preset blocking policy; The file interception module is used to, when the blocking policy is met, have the authentication server return interception information indicating that the file cannot be accessed to the content delivery network, so that the content delivery network can intercept the file requested by the user terminal.

10. An electronic device, characterized in that, The electronic device includes: processor; Memory used to store the processor's executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method for handling piracy as described in any one of claims 1-8.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a terminal device, cause the terminal device to implement the method for handling piracy as described in any one of claims 1-8.

12. A computer program product, characterized in that, When the computer program product is run on a computer, the computer implements the method for handling piracy as described in any one of claims 1-8.