Playback request authentication method and apparatus, and computing device cluster
By setting authentication metrics and conditions in the service node cluster, analyzing the global playback status of clients, and dynamically identifying users who steal links, the problem of live streaming theft is solved, and the security of live streaming and the reliability of legitimate access are improved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2025-08-26
- Publication Date
- 2026-07-23
Smart Images

Figure CN2025117052_23072026_PF_FP_ABST
Abstract
Description
Playback request authentication methods, devices and computing device clusters
[0001] This application claims priority to Chinese Patent Application No. 202510072066.X, filed on January 16, 2025, entitled “Playback Request Authentication Method, Apparatus and Computing Device Cluster”, the entire contents of which are incorporated herein by reference. Technical Field
[0002] This invention relates to the field of video anti-piracy technology, specifically to a method, apparatus, and computing device cluster based on playback request authentication. Background Technology
[0003] Live streaming hotlinking significantly increases the live streaming costs for affected clients, damages the security and reputation of live streaming cloud services, and infringes on clients' copyrights. Therefore, live streaming anti-hotlinking technology is needed to reduce the probability of hotlinking. This technology checks the legitimacy of viewers' playback requests, ensuring that only designated pages or applications can access the live streaming content.
[0004] However, there is currently a lack of effective technical solutions to prevent live streams from being stolen. Summary of the Invention
[0005] This invention provides a playback request authentication method, apparatus, and computing device cluster. It sets authentication indicators and conditions to measure the global playback security of a service node cluster, obtains the authentication indicator values for clients to measure the global playback status of clients for playback domains within the service node cluster, and then determines whether the authentication indicator values meet the set authentication conditions. This allows for analysis of whether there are any anomalies in the global playback status of clients for playback domains within the service node cluster, thereby dynamically identifying users who engage in hotlinking and reducing the possibility of large-scale hotlinking.
[0006] In a first aspect, embodiments of the present invention provide a playback request authentication method, the method comprising:
[0007] First, the authentication data from the playback request is obtained. This data includes the playback domain name and the client's identifier. The playback request is sent by the client to the service node, which is located in a service node cluster. Next, the authentication rules corresponding to the playback domain name are obtained. These rules include authentication metrics and corresponding authentication conditions. The authentication metrics are used to measure the security of global playback for the playback domain name. After obtaining the authentication rules, the metric values are obtained based on the client's identifier. These values indicate the client's global playback status for the playback domain name within the service node cluster. Finally, it is determined whether the metric values meet the authentication conditions to obtain the authentication result.
[0008] In this solution, authentication metrics and conditions are set to measure the security of global playback on the service node cluster. The metric values for the client are obtained to measure the global playback status of the client for the playback domain name in the service node cluster. Subsequently, it is determined whether the metric values of the authentication metrics meet the set authentication conditions to analyze whether there are any anomalies in the global playback status of the client for the playback domain name in the service node cluster. This allows for the dynamic identification of users who engage in hotlinking and reduces the possibility of large-scale hotlinking.
[0009] In one possible implementation, the authentication condition is less than or equal to a preset threshold.
[0010] Determine whether the indicator value meets the authentication conditions to obtain the authentication result, including: if the indicator value is less than or equal to a preset threshold, determine the authentication result to indicate that the authentication is successful; if the indicator value is greater than the preset threshold, determine the authentication result to indicate that the client is an abnormal client.
[0011] In this solution, the presence of anomalies in the client is determined by comparing indicator values and thresholds.
[0012] In one possible implementation, the authentication rules also include the statistical period of the authentication metrics;
[0013] Based on the client's identifier, obtain the authentication indicator values, including: determining the data period based on the statistical period; and obtaining the authentication indicator values for the data period based on the client's identifier and the playback domain name.
[0014] In this solution, by designing a statistical period, it is possible to analyze users who engage in large-scale hotlinking within a short period of time.
[0015] In one possible implementation, the client's identifier includes the token used by the client and the client's address; the authentication metrics include a first metric and a second metric.
[0016] Based on the client's identifier, obtain the corresponding indicator value of the authentication indicator, including: based on the token and the playback domain name, determine the first indicator value of the first indicator, which is used to indicate the number of times the token is used globally for the playback domain name in the service node cluster; based on the client's address and the playback domain name, determine the second indicator value of the second indicator, which is used to indicate the number of times the client plays the playback domain name globally or the global playback duration in the service node cluster.
[0017] In this solution, the combination of token, global playback count, and / or global playback duration can accurately measure the global playback status of the client for the playback domain name in the service node cluster. Subsequently, judging whether the value of the authentication indicator meets the set authentication conditions can more accurately analyze whether there are any anomalies in the global playback status of the client for the playback domain name in the service node cluster.
[0018] In one possible implementation, global playback includes at least one or more of the following:
[0019] Total playback duration of the client, total number of playbacks of the client, average playback duration of the client, number of concurrent playbacks of the client, and average concurrent playback duration of the client.
[0020] In one possible implementation, the authentication index values are obtained based on the client's identifier and the playback domain name, including: obtaining global playback data based on the client's identifier, which is used to instruct the service node cluster to process data during the client's historical playback requests for the playback domain name; and determining the authentication index values based on the global playback data.
[0021] In this solution, the data from the historical playback requests of the client for the playback domain name is processed by the integrated service node cluster. By analyzing the global playback status of the client for the playback domain name in the service node cluster, the authentication index value can be obtained more accurately.
[0022] In one possible implementation, the method further includes: sending an authentication result to the service node, so that the service node, after the authentication result indicates that the authentication is successful, responds to the playback request by sending playback content to the client.
[0023] In one possible implementation, obtaining the authentication rules corresponding to the playback domain name includes: obtaining the authentication rules corresponding to the playback domain name input by the user.
[0024] In this solution, users can configure authentication rules according to their actual needs.
[0025] Secondly, embodiments of the present invention provide a playback request authentication device, which includes several modules. Each module is used to execute various steps in the playback request authentication method provided in the first aspect of the present invention. The division of modules is not limited here. For the specific functions performed by each module of this playback request authentication device and the beneficial effects achieved, please refer to the functions of each step in the playback request authentication method provided in the first aspect of the present invention; further details will not be repeated here.
[0026] For example, the playback request authentication device includes:
[0027] The authentication module is used to obtain authentication data from the playback request. The authentication data includes the playback domain name and the client's identifier. The playback request is sent by the client to the service node, which is located in the service node cluster.
[0028] The rule acquisition module is used to acquire the authentication rules corresponding to the playback domain name. The authentication rules include authentication indicators and authentication conditions corresponding to the authentication indicators. The authentication indicators are used to measure the security of global playback for the playback domain name.
[0029] The indicator value acquisition module is used to obtain the indicator value of the authentication indicator based on the client's identifier. The indicator value is used to indicate the global playback status of the client for the playback domain name in the service node cluster.
[0030] The authentication module is used to determine whether the indicator value meets the authentication conditions in order to obtain the authentication result.
[0031] In one possible implementation, the authentication condition is less than or equal to a preset threshold.
[0032] The authentication module is used to determine the authentication result when the indicator value is less than or equal to a preset threshold, indicating that the authentication has passed; and to determine the authentication result when the indicator value is greater than the preset threshold, indicating that the client is an abnormal client.
[0033] In one possible implementation, the authentication rules also include the statistical period of the authentication metrics;
[0034] The indicator value acquisition module is used to determine the data period based on the statistical period; and to obtain the authentication indicator values for the data period based on the client's identifier and playback domain name.
[0035] In one possible implementation, the client's identifier includes the token used by the client and the client's address; the authentication metrics include a first metric and a second metric.
[0036] The indicator value acquisition module is used to determine the first indicator value of the first indicator based on the token and the playback domain name. The first indicator value is used to indicate the number of times the token is used globally for the playback domain name in the service node cluster. Based on the client's address and the playback domain name, the module determines the second indicator value of the second indicator. The second indicator value is used to indicate the number of times the client plays the playback domain name globally or the global playback duration in the service node cluster.
[0037] In one possible implementation, global playback includes at least one or more of the following:
[0038] Total playback duration of the client, total number of playbacks of the client, average playback duration of the client, number of concurrent playbacks of the client, and average concurrent playback duration of the client.
[0039] In one possible implementation, the indicator value acquisition module is used to acquire global playback data based on the client's identifier. The global playback data is used to indicate the data in the process of the service node cluster processing the client's historical playback requests. Based on the global playback data, the indicator value of the authentication indicator is determined.
[0040] In one possible implementation, the device further includes:
[0041] The sending module is used to send the authentication result to the service node, so that the service node can send the playback content to the client in response to the playback request after the authentication result indicates that the authentication is successful.
[0042] In one possible implementation, the rule acquisition module is used to acquire the authentication rules corresponding to the playback domain name input by the user.
[0043] Thirdly, embodiments of the present invention provide a playback request authentication device, comprising: at least one memory for storing a program; and at least one processor for executing the program stored in the memory, wherein when the program stored in the memory is executed, the processor is used to execute the method provided in the first aspect.
[0044] Fourthly, embodiments of the present invention provide a playback request authentication device, which executes computer program instructions to perform the method provided in the first aspect. Exemplarily, the device may be a chip or a processor.
[0045] In one example, the device may include a processor that can be coupled to memory, read instructions from the memory, and execute the methods provided in the first aspect according to those instructions. The memory may be integrated into the chip or processor, or it may be independent of the chip or processor.
[0046] Fifthly, embodiments of the present invention provide a service node, comprising: at least one memory for storing a program; and at least one processor for executing the program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to execute the method provided in the first aspect.
[0047] In a sixth aspect, embodiments of the present invention provide an authentication node, comprising: at least one memory for storing a program; and at least one processor for executing the program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to execute the method provided in the first aspect.
[0048] In a seventh aspect, embodiments of the present invention provide a computing device cluster, the computing device cluster including at least one computing device, each computing device including a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster performs the method provided in the first aspect.
[0049] Eighthly, embodiments of the present invention provide a computer storage medium storing instructions that, when executed on a computer, cause the computer to perform the method provided in the first aspect.
[0050] In a ninth aspect, embodiments of the present invention provide a computer program product containing instructions that, when executed on a computer, cause the computer to perform the method provided in the first aspect. Attached Figure Description
[0051] Figure 1a is an architecture diagram of a playback system provided in an embodiment of the present invention;
[0052] Figure 1b is a schematic diagram of the authentication and data analysis scenario provided in an embodiment of the present invention;
[0053] Figure 1c is an architecture diagram of another playback system provided in an embodiment of the present invention;
[0054] Figure 2a is a schematic diagram of the service deployment scheme in Figure 1a;
[0055] Figure 2b is a schematic diagram of the service deployment scheme in Figure 1a;
[0056] Figure 2c is a schematic diagram of the service deployment scheme in Figure 1a.
[0057] Figure 3a is a schematic diagram of the cloud deployment of the playback system shown in Figure 1b;
[0058] Figure 3b is a schematic diagram of the cloud deployment of the playback system shown in Figure 1b;
[0059] Figure 4a is a schematic diagram of the Refer anti-hotlinking principle in related technologies;
[0060] Figure 4b is a schematic diagram of the attack methods of Refer anti-hotlinking in related technologies;
[0061] Figure 4c is a schematic diagram of the Key anti-leeching principle in related technologies;
[0062] Figure 4d is a schematic diagram of the attack methods of Key anti-hotlinking in related technologies;
[0063] Figure 4e is a schematic diagram of a large-scale hotlinking identification scenario provided by an embodiment of the present invention;
[0064] Figure 5 is a flowchart illustrating the playback request authentication method in the Refer anti-leeching scenario provided by an embodiment of the present invention;
[0065] Figure 6 is a flowchart illustrating a playback request authentication method in a Key anti-leeching scenario provided by an embodiment of the present invention;
[0066] Figure 7 is a flowchart illustrating another playback request authentication method in the Key anti-leeching scenario provided by an embodiment of the present invention;
[0067] Figure 8 is a schematic diagram of querying global playback data of the client provided in an embodiment of the present invention;
[0068] Figure 9 is a flowchart illustrating the playback request authentication method under the playback system provided in Figure 2a;
[0069] Figure 10 is a flowchart illustrating the playback request authentication method under the playback system provided in Figures 2b and 2c;
[0070] Figure 11 is a communication diagram of the playback request authentication method provided in an embodiment of the present invention;
[0071] Figure 12 is a schematic diagram of the playback request authentication device provided in an embodiment of the present invention;
[0072] Figure 13 is a schematic diagram of the structure of the computing device provided in an embodiment of the present invention;
[0073] Figure 14 is a schematic diagram of the structure of the computing device cluster provided in an embodiment of the present invention;
[0074] Figure 15 is a schematic diagram of computing devices in a computer cluster connected via a network according to an embodiment of the present invention. Detailed Implementation
[0075] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be described below with reference to the accompanying drawings.
[0076] In the description of the embodiments of the present invention, the words "exemplary," "for example," or "for instance" are used to indicate that they are examples, illustrations, or descriptions. Any embodiment or design that is described as "exemplary," "for example," or "for instance" in the embodiments of the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the use of the words "exemplary," "for example," or "for instance" is intended to present the relevant concepts in a specific manner.
[0077] In the description of the embodiments of this invention, the term "and / or" is merely a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, B existing alone, and A and B existing simultaneously. Furthermore, unless otherwise stated, the term "multiple" means two or more. For example, multiple systems refer to two or more systems, and multiple terminals refer to two or more terminals.
[0078] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and their variations all mean "including but not limited to," unless otherwise specifically emphasized.
[0079] The following explanations cover some of the terms used in this embodiment. It should be noted that these explanations are for the convenience of those skilled in the art and are not intended to limit the scope of protection claimed by this invention.
[0080] Hotlinking refers to obtaining content such as videos through links without the permission of the original website.
[0081] Authentication refers to verifying whether a user or request has the right to access the system.
[0082] Internet Protocol (IP) is a network layer protocol in the TCP / IP architecture. The purpose of IP is to improve network scalability: firstly, to solve internet problems and achieve interconnection of large-scale, heterogeneous networks; and secondly, to separate the coupling between top-level network applications and underlying network technologies, facilitating their independent development. Based on end-to-end design principles, IP provides only one connectionless, unreliable, best-effort packet transmission service to hosts.
[0083] A domain name is the name of a computer or group of computers on the Internet, used to identify the computer's electronic location (and sometimes its geographical location) during data transmission. A domain name consists of a string of names separated by dots, usually including the organization name, and always includes a two- or three-letter suffix to indicate the type of organization or the country or region where the domain is located.
[0084] Playback domain name: Used to describe the domain name related to playback.
[0085] Authentication metrics: These are various quantitative indicators that measure the security of global playback for a given domain.
[0086] The value of the authentication index refers to the specific value of the authentication index.
[0087] A token is a string generated by the server to serve as a token for the client to make requests. After the first login, the server generates a token and returns it to the client. In subsequent logins, the client only needs to use this token to request data, without having to use the username and password again.
[0088] Average concurrent playback duration: Total viewing time / Number of concurrent users. Calculation steps: First, calculate the total viewing time for all users. Then, determine the number of concurrent users, i.e., the number of users watching online simultaneously. Finally, divide the total viewing time by the number of concurrent users to obtain the average concurrent playback duration.
[0089] Software (application, APP): Primarily refers to software installed on smartphones, used to improve upon the shortcomings of the original system and for personalization. Enhancing the functionality of the phone is a primary means of providing users with a richer user experience. Mobile software requires a corresponding mobile operating system to run, which can include Apple's iOS, Google's Android, and Huawei's HarmonyOS.
[0090] Content Delivery Network (CDN): A smart virtual network built on top of the existing internet infrastructure, consisting of node servers placed throughout the network. A CDN system can redirect user requests to the nearest service node in real time based on comprehensive information such as network traffic, the connectivity and load of each node, distance to the user, and response time. Its purpose is to allow users to obtain the content they need from the nearest location, alleviating internet congestion and improving website response speed.
[0091] Acceleration Node: A server node in the CDN network responsible for storing cached content and providing a fast response when a user requests it.
[0092] Cloud: A software platform that uses application virtualization technology, integrating multiple functions such as software search, download, use, management, and backup.
[0093] Media files: These typically refer to audio, video, and image files stored on computers, mobile devices, or other storage devices.
[0094] A Uniform Resource Locator (URL) is a string used to identify and locate resources on the Internet. A URL consists of several parts, including the protocol, server location, and resource path, and is used to locate and access resources on the network.
[0095] Resource path: This refers to the part of the URL used to locate the resource, excluding the resource name. It specifies the resource's exact location on the server, typically similar to a file system path.
[0096] First, the playback system to which the method provided in the embodiments of the present invention may be applied will be described. Figure 1 is a schematic diagram of the architecture of a playback system provided in an embodiment of the present invention.
[0097] As shown in Figure 1a, the system includes a client 101, a service platform 102, a media service 103, an authentication service 104, and a data analysis service 105.
[0098] In this embodiment, client 101 is used to access media service 103 to obtain playback content according to the playback domain name. Optionally, client 101 can be a browser, which accesses the playback website through the browser. The playback website can be a hotlinking website or a legitimate website. Optionally, client 101 can be an APP, which accesses media service 103 through the APP. Optionally, as shown in FIG1a, accessing media service 103 to obtain playback content may include: client 101 sending a playback request of playback domain name to media service 103, media service 103 sending playback content to client 101, and client 101 playing the playback content. Optionally, as shown in FIG1a, client 101 can run on terminal 110, which can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. Exemplary embodiments of the terminal involved in this solution include, but are not limited to, electronic devices running iOS, Android, Windows, Harmony OS, or other operating systems. This embodiment of the invention does not specifically limit the type of terminal 110.
[0099] The service platform 102 provides the function of configuring authentication rules. Subsequently, the authentication rules of the playback domain configured by the service provider of the playback domain (the party providing the playback content) can be distributed to the authentication service 104. In this embodiment of the invention, the service platform 102 can run on a single node or distributed across multiple nodes. The nodes in this embodiment of the invention can be physical servers, virtual servers embedded in a virtualization environment, or various possible computing resources such as containers. This embodiment of the invention does not impose specific limitations.
[0100] Media service 103 stores playback content accessed by users. When a user accesses the content, it requests authentication from authentication service 104 and sends playback data (e.g., client 101's IP address, playback start time, playback duration, and the token used) to data analysis service 105. As shown in Figure 1a, media service 103 can run on a service node cluster, which includes multiple service nodes 120, each running media service 103. Service nodes 120 can be physical servers, virtual servers embedded in a virtualization environment, containers, or other possible computing resources. Optionally, the service node cluster can be a CDN, and service nodes 120 can be acceleration nodes. The CDN distributes media files to service nodes 120 physically close to the user, allowing the user to obtain the required playback content from the nearest location. In some optional embodiments, clients 101 in different regions can send playback requests to different service nodes 120 when they need media files. As shown in Figure 1b, client 1 in region 1 sends playback request 1 to service node 1, client 2 in region 2 sends playback request 2 to service node 2, and client 3 in region 3 sends playback request 3 to service node 3.
[0101] The data analysis service 105 is used to acquire playback data from client 101 sent by each service node 120, and then perform data analysis, such as aggregating playback data from the same client 101 and playback domain name, to obtain the global playback data corresponding to client 101. Referring again to Figure 1b, client 1 in region 1 sends playback request 1 to service node 1, client 2 in region 2 sends playback request 2 to service node 2, and client 3 in region 3 sends playback request 3 to service node 3. Service nodes 1, 2, and 3 send playback data from clients 1, 2, and 3 to the data analysis service 105. The data analysis service 105 can run on a single node or distributed across multiple nodes. Nodes can be physical servers, virtual servers embedded in a virtualization environment, containers, or various other possible computing resources.
[0102] The authentication service 104, when media service 103 requests authentication, queries data such as the global playback data corresponding to client 101 according to the configured authentication rules of the playback domain name to obtain the basic data required by the authentication rules, and determines whether the playback request is legitimate based on the basic data. Referring to Figure 1b, client 1 in region 1 sends playback request 1 to service node 1, client 2 in region 2 sends playback request 2 to service node 2, and client 3 in region 3 sends playback request 3 to service node 3. Service nodes 1, 2, and 3 send authentication requests to authentication service 104. It should be noted that authentication service 104 can run on a single node or distributed across multiple nodes. Nodes can be physical servers, virtual servers embedded in a virtualization environment, containers, or various other possible computing resources.
[0103] In summary, this solution designs authentication rules based on the client's global playback data, obtains the basic data required for analyzing the authentication rules based on the client's global playback status, thereby dynamically identifying users who engage in hotlinking and reducing the possibility of large-scale hotlinking.
[0104] In some optional embodiments, as shown in Figure 1c, the playback system may further include a database 106. The database 106 is used to store authentication rules and global playback data corresponding to different clients 101. It should be noted that the database 106 can run on a single node or distributed across multiple nodes. Nodes can be various possible computing resources such as physical servers, virtual servers embedded in a virtualization environment, or containers.
[0105] Optionally, the service platform 102 may store the authentication rules configured by the service provider (the party providing the playback content) in the database 106.
[0106] Optionally, the data analysis service 105 stores the global playback data corresponding to the client 101 in the database 106.
[0107] It should be noted that authentication service 104 and data analysis service 105 can run on the same node or on different nodes. The specific deployment of authentication service 104 and data analysis service 105 can be designed according to the actual situation. Authentication service 104 and media service 120 can also run on the same node or on different nodes. The specific operation of authentication service 104 and media service 120 can be designed according to the actual situation.
[0108] In some optional embodiments, as shown in Figure 2a, authentication service 104 and media service 120 run on each service node 120 in the service node cluster, and data analysis service 105 runs on aggregation node 140. Each service node 120 runs authentication service 104 and media service 120, implementing the functions of authentication service 104 and media service 120.
[0109] In some optional embodiments, as shown in Figure 2b, authentication service 104 and media service 120 run on different nodes, while authentication service 104 and data analysis service 105 can run on the same node, such as authentication node 130. Authentication node 130 runs authentication service 104 and data analysis service 105, implementing the functions of authentication service 104 and data analysis service 105.
[0110] In some optional embodiments, as shown in FIG2c, the authentication service 104 and the data analysis service 105 can run on different nodes. For example, the authentication service 104 runs on the authentication node 130, and the data analysis service 105 runs on the aggregation node 140. The authentication node 130 runs the authentication service 104 to implement the function of the authentication service 104, and the aggregation node 140 runs the data analysis service 105 to implement the function of the data analysis service 105.
[0111] In some possible scenarios, service platform 102, media service 103, authentication service 104, data analysis service 105, and database 106 can be deployed in the cloud.
[0112] As shown in Figure 3a, the cloud includes a cloud management platform and a data center. The data center can include a server cluster consisting of multiple physical servers. The server cluster provides infrastructure, which includes various nodes such as physical servers, virtual servers (e.g., virtual machines), and containers. There can be multiple data centers, such as Data Center A and Data Center B. Data Center A is located away from the user, while Data Center B is located closer to the user. In this embodiment of the invention, the cloud management platform can deploy the service platform 102, authentication service 104, data analysis service 105, and database 106 on the nodes provided by Data Center A, and deploy the media service 103 on the service node 120 provided by Data Center B.
[0113] As shown in Figure 3b, the cloud management platform can deploy the service platform 102, data analysis service 105, and database 106 on the nodes provided by data center A, and deploy the media service 103 and authentication service 104 on the service node 120 provided by data center B.
[0114] Terminal 110 can be connected to service platform 102 and service node cluster 130 via a network. Service node cluster 130 can be connected to aggregation node 140 and authentication node 130 via a network. Aggregation node 140 and authentication node 130 can be connected to database 106 via a network. The network can be a wired network or a wireless network. For example, the wired network can be a cable network, fiber optic network, Digital Data Network (DDN), etc., and the wireless network can be a telecommunications network, intranet, Internet, Local Area Network (LAN), Wide Area Network (WAN), Wireless Local Area Network (WLAN), Metropolitan Area Network (MAN), ZigBee, Global System for Mobile Communications (GSM), CDMA (Code Division Multiple Access) network, CPRS (General Packet Radio Service) network, etc., or any combination thereof. It is understood that a network can use any known network communication protocol to achieve communication. The aforementioned network communication protocol can be various wired or wireless communication protocols, such as Ethernet, Universal Serial Bus (USB) and other communication protocols or any combination thereof.
[0115] The following is an exemplary description of attack scenarios that may be applied to the embodiments of the present invention.
[0116] 1) Referer Hotlinking Prevention: This is a protection mechanism in internet technology to prevent resource theft, primarily used to protect files or content on a server from being referenced by unauthorized websites. In the HTTP protocol, the referer (also written as referer) is part of the request header, telling the server the URL of the webpage making the request. The webpage URL can contain a website domain name or IP address. Media service 103 checks this referer field to determine the legitimacy of the request: only when the referer source of the request is an allowed domain name or IP address will media service 103 return the requested resource for playback; otherwise, it will refuse to provide service. For example, in one scenario: a website A stores a large number of image resources. To prevent other unauthorized websites B from directly hotlinking these images, website A can set up referer hotlinking prevention, allowing only requests originating from website A's own domain to access the image resources, thereby protecting the resources.
[0117] Refer anti-hotlinking measures apply to browser-based playback scenarios and rely on browser playback standards. Viewers sending playback requests via their browsers will by default include a Referer field, the value of which is the website domain. Browsers do not allow viewers to modify this field's value. Various media scenarios support configuring a Referer whitelist in the backend, allowing only specified Referers to access specific content. For example, as shown in Figure 4a, a viewer accesses a client website using a browser. The client website sends a playback request to media service 103, including a Referer field containing the address of the source page of the currently requested page: abc.fun.com. Media service 103 verifies whether the Referer field is on the Referer whitelist.
[0118] Attack methods may include: the hotlinking website deploying a proxy server to intercept the browser's playback request and tamper with the Referer field value of the playback request to a legitimate website domain. For example, as shown in Figure 4b, the hotlinking website's domain is steal.com. The hotlinking website sends a playback request to media service 103, and the playback request includes a Referer field of steal.com. The proxy server intercepts the playback request and modifies the Referer field in the playback request to abc.fun.com.
[0119] 2) Key anti-hotlinking
[0120] As shown in Figure 4c, the tenant configures the authentication key and encryption algorithm on the media service 103 through the service platform 102. Simultaneously, the client needs to record this key and encryption algorithm policy in their own authentication server. When the client plays content, the client website first obtains a token from the client's authentication server. This token is generated by the client's authentication server based on the encryption algorithm policy, key, resource path in the playback request, and expiration time. The token is then passed as a parameter of the playback request to the media service 103. The media service 103 uses the client's configured algorithm policy and private key to verify the token's validity. For example, the media service 103 generates a token using the client's configured encryption algorithm policy, key, expiration time, and resource path in the playback request. If this token matches the one in the playback request, the token is considered valid.
[0121] As shown in Figure 4d, the attack method may include: 1. The hotlinking party registers and logs into the client's website normally; 2. The client generates a playback request over the network; 3. The playback request is intercepted to obtain the token from the playback request; 4. This token is sent to the proxy server of the hotlinking website (used to add the token), and the proxy server is the backend of an illegitimate website; 5. The hotlinking website generates a playback request and sends it to the proxy server; 6. The proxy server adds the token to the playback request to access media service 103.
[0122] In some optional large-scale hotlinking scenarios, as shown in Figure 4e, a large number of users, such as User 1, User 2, etc., will access the client (hotlinking website). The client (hotlinking website) will send a large number of playback requests (including playback domain names) from the same client (hotlinking website) to the service node cluster. These playback requests will be sent to different service nodes in the service node cluster for processing. Subsequently, each service node in the service node cluster reports the client's playback status to the data analysis service 105. The data analysis service 105 analyzes the global playback status of the client for the playback domain name in the service node cluster. Subsequently, each service node in the service node cluster can send an authentication request to the authentication service 104. The authentication service 104 can analyze whether there is a client (hotlinking website) engaging in large-scale hotlinking based on the global playback status of the client for the playback domain name in the service node cluster, thereby improving playback security.
[0123] Next, a playback request authentication method provided by an embodiment of the present invention will be described in detail. The present invention will use a playback system as an example to illustrate the solution.
[0124] In the context of referral anti-hotlinking, the playback request authentication method provided in this embodiment of the invention may include: aggregating playback data of any client from the service node cluster during the current time period, such as 1 minute, to obtain global playback data corresponding to different clients 101; subsequently, based on authentication rules, querying the global playback data corresponding to client 101 to obtain the data required for analyzing the authentication rules, thereby facilitating subsequent hotlinking identification, identifying clients currently experiencing large-scale hotlinking, and subsequently, hotlinking processing such as blocking can be carried out on clients experiencing large-scale hotlinking.
[0125] In the context of Refer anti-hotlinking, the authentication service 104 needs to perform Refer anti-hotlinking verification, such as whether the value of the Refer field is in the whitelist. Only after the Refer anti-hotlinking verification is passed will it proceed to anti-hotlinking identification based on authentication rules.
[0126] In some optional embodiments of the present invention, as shown in FIG5, the playback request authentication method provided by the embodiments of the present invention may include the following:
[0127] Configure anti-leeching process:
[0128] Step 501. The provider of the playback domain A accesses the service platform 102 and configures the authentication rule A: playback domain A, statistical period A, authentication index A, authentication condition A (used to indicate the conditions that authentication index A needs to meet).
[0129] In this embodiment of the invention, for the development of authentication rule A for playback domain A, service platform 102 provides a development environment. The development environment provides a graphical editing environment for editing (or arranging) authentication rule A. Optionally, authentication rule A can be stored in script form.
[0130] In this embodiment of the invention, authentication rule A comprises three elements: target, condition, and period. The target can be one or more playback domains. The condition indicates the authentication conditions that the authentication index must meet. For example, the condition may include authentication index A and authentication condition A. Authentication condition A indicates the relationship between authentication index A and a preset threshold, such as authentication index A being less than or equal to the preset threshold. The preset threshold can be flexibly designed based on actual circumstances. The period indicates the duration for calculating authentication index A, such as 1 minute. In this embodiment, the period corresponding to authentication index A is called the statistical period A. It should be noted that by reasonably designing the statistical period A, it is possible to analyze clients experiencing large-scale hotlinking within a short period, such as 1 minute. Authentication index A is used to measure the security of playback domain A for global playback. There can be one or more authentication indices A, which may include one or more of the following:
[0131] The total playback duration of a single client (can be denoted as duration_sum, in seconds), the total number of playbacks of a single client (can be denoted as session_count), the average playback duration of a single client (can be denoted as duration_avg, in seconds; calculation formula: duration_sum / session_count), the average concurrent playback duration of a single client (can be denoted as duration_concurrency, in seconds), the number of concurrent playbacks of a single client (can be denoted as session_cocurrency), and the total number of times the token is used globally by a single client (can be denoted as token_count, used to indicate the total number of times the same token is used by a single client when key anti-hotlinking is enabled).
[0132] The above authentication indicators are merely examples and do not constitute specific limitations. More or fewer authentication indicators can be set according to actual needs.
[0133] It should be noted that authentication rule A may include several authentication metrics A, a statistical period A corresponding to each authentication metric A, and an authentication condition A corresponding to each authentication metric A. For example, authentication metric A is the number of concurrent playbacks on a single client, the statistical period A is 1 minute, and the authentication condition A is that the number of concurrent playbacks on a single client is less than or equal to 2.
[0134] Step 502. Service platform 102 issues authentication rule A to authentication service 104.
[0135] Sampling and reporting process:
[0136] Step 503. Each service node 102 in the service node cluster 104 reports the playback data of the sampling period to the data analysis service 105. The playback data includes the playback domain name, client IP address, playback time, and playback duration.
[0137] In this embodiment, service node 102 collects playback data according to a preset sampling period. Optionally, the playback data may include the following:
[0138] IP: The IP address of the client that initiated the playback request;
[0139] session: A unique identifier for this playback session;
[0140] sample_time: The time of this data collection;
[0141] start_time: Playback start time;
[0142] duration_time: The playback duration within the sampling period, which can be in milliseconds.
[0143] It should be noted that the sampling period is less than or equal to the statistical period A. For example, it can be 1 second or 2 seconds. The specific design can be based on the actual situation.
[0144] Step 504. Data analysis service 105 aggregates playback data to obtain global playback data corresponding to different clients 101. Global playback data includes playback domain name, client IP address, sampling period, and aggregated data.
[0145] In this embodiment, the data analysis service 140 aggregates, for example, adds up, the playback data of the same client IP address and playback domain name based on the client IP address and playback domain name in the playback data to obtain and store the global playback data corresponding to different clients 101.
[0146] Here, global playback data can be stored in a table. The table entries are playback domain name, client IP address, sampling period, and aggregated data, thus establishing the correspondence between playback domain name, client IP address, sampling period, and aggregated data, which facilitates subsequent queries. The aggregated data is used to indicate the global playback status of the same client under a certain playback domain name for a certain sampling period in the service node cluster.
[0147] Optionally, the aggregated data may include the values of authentication metrics. For example, authentication metrics may be the total playback duration (duration_sum) of a single client, the total number of playbacks of a single client (session_count), the average playback duration of a single client (duration_avg), the average concurrent playback duration of a single client (duration_concurrency), the number of concurrent playbacks of a single client (session_cocurrency), or the number of times a single client's token is used globally.
[0148] Optionally, the aggregated data may include other data required to calculate the authentication metric, which is the global usage count of the token across the service node cluster, and the related data is the global usage count of the token for each single client within the sampling period.
[0149] Authentication and playback process:
[0150] Step 505. Client 101A sends a playback request to service node 120A in the service node cluster. The playback request includes playback domain name A and client IP address A. The playback domain name A is the value of the referer field.
[0151] Among them, the playback domain name A is used to indicate the address of the website used by client 101A.
[0152] Among them, the client IP address A is one of the identifiers of client 101A, which is used to uniquely identify client 101A and can indicate the location of client 101A.
[0153] In addition, playback requests can also include resource paths.
[0154] Step 506. Service node 120A sends an authentication request to authentication service 104. The authentication request includes the playback domain name A and the client IP address A.
[0155] Step 507. If the Refer anti-hotlinking verification is successful, the authentication service 104 sends a query request to the data analysis service 105. The query request includes the playback domain name A, the client IP address A, the statistical period A, and the authentication index A.
[0156] The Referer anti-hotlinking verification passed is used to indicate that the authentication request has passed the anti-hotlinking verification. For example, Referer anti-hotlinking verification passed means that the playback domain A is legitimate.
[0157] In some optional implementations of this embodiment, the Refer anti-hotlinking verification may include the authentication service 104 obtaining the referrer whitelist, determining whether the playback domain name A is in the referrer whitelist, and if so, determining that the playback domain name A is legitimate.
[0158] In some optional implementations of this embodiment, the authentication service 104 searches for authentication rules based on the playback domain name A to obtain authentication rule A. Authentication rule A includes the playback domain name A, statistical period A, authentication index A, and authentication rule A. At this point, it can be concluded that the Refer anti-hotlinking verification is successful and the playback domain name A is legitimate. Subsequently, a query request can be obtained based on authentication rule A and the client IP address.
[0159] It should be noted that the above query request is merely an example and does not constitute a specific limitation; in some optional implementations of this embodiment, the query request may only include the client IP address A and the statistical period A.
[0160] Step 508. Data analysis service 105 sends the query results to authentication service 104.
[0161] In some optional implementations of this embodiment, the data analysis service 105 responds to the query request and, for each authentication index A, determines the data time period to be queried based on the statistical period A corresponding to the authentication index A. For example, if the statistical period A is 1 minute, then the data time period to be queried is the most recent 1 minute. It can query all index values of the authentication index A corresponding to the client IP address A and the playback domain name A in the data time period from the global playback data corresponding to different clients 101 that have been stored, such as the index values of each of the multiple sampling periods, and use them as the query results.
[0162] In some optional implementations of this embodiment, the data analysis service 105 responds to the query request and, for each authentication index A, determines the data period to be queried based on the statistical period A corresponding to authentication index A. For example, if the statistical period A is 1 minute, then the data period to be queried is the most recent 1 minute. From the stored global playback data corresponding to different client IP addresses, it queries all index values of authentication index A corresponding to client IP address A and playback domain name A in the data period, such as the index values of each of multiple sampling periods. It then aggregates, for example, adds, all index values of authentication index A for the data period to obtain the index value of authentication index A for statistical period A as the query result.
[0163] It is worth noting that there are multiple authentication indicators A. You can query one authentication indicator A at a time, or you can query multiple authentication indicators A at a time.
[0164] Step 509. Authentication Service 104 determines the authentication result based on authentication condition A and the query result.
[0165] In some optional implementations of this embodiment, there may be one or more authentication indicators A. For each authentication indicator A, there is an authentication condition A. The authentication condition indicates the conditions that the authentication indicator A needs to meet. Correspondingly, the authentication service 104 can determine the indicator value of each authentication indicator A based on the query results. If the indicator value of each authentication indicator A meets the corresponding authentication condition A, the authentication is determined to be successful; otherwise, the authentication fails.
[0166] Step 510. Authentication service 104 sends the authentication result to service node 120A.
[0167] Step 511. When the authentication result indicates that the authentication is successful, the service node 120A sends the playback content to the client 101A.
[0168] Step 512. Service node 120A sends playback data to data analysis service 105. The playback data includes client IP address A, playback time, and playback duration.
[0169] In this embodiment, the service node 120A collects the playback data corresponding to the client 101A based on the time when the playback content is sent.
[0170] In summary, the playback request authentication method provided in this embodiment of the invention consists of three processes: configuring anti-leeching, authenticating playback, and sampling and reporting. The authentication playback and sampling and reporting processes do not have a specific order and can occur simultaneously.
[0171] In this solution, authentication metrics and conditions are set to measure the security of global playback on the service node cluster. The metric values for the client are obtained to measure the global playback status of the client for the playback domain name in the service node cluster. Subsequently, it is determined whether the metric values of the authentication metrics meet the set authentication conditions to analyze whether there are any anomalies in the global playback status of the client for the playback domain name in the service node cluster. This allows for the dynamic identification of users who engage in hotlinking and reduces the possibility of large-scale hotlinking.
[0172] It should be noted that the "A" in authentication rule A, playback domain name A, statistical period A, authentication index A, and authentication condition A does not have any special meaning; it is merely for ease of description and distinction.
[0173] Based on the playback request authentication method provided above, the specific application of this method will be explained. In some possible scenarios, the specific content includes:
[0174] 1) Authentication rule A obtained by service platform 102:
[0175] The above authentication rules are used to indicate that for a live domain name A, the same IP can only play a maximum of 2 live channels at the same time within a 1-minute statistical period A.
[0176] The authentication service 104 has identified authentication rule A. Playback is only allowed if authentication rule A is met.
[0177] 2) Each service node 120 in the service node cluster reports the playback data of client 101 per second to the data analysis service 105. The playback data includes the playback domain name, client IP address, data collection time, playback start time, and playback duration.
[0178] 3) Data analysis service 105 merges the playback start time and playback duration of the same client IP address and the same playback domain name per second to obtain the total playback duration (duration_sum), total number of playbacks (session_count), average playback duration (duration_avg), average concurrent playback duration (duration_concurrency), and number of concurrent playbacks (session_cocurrency) per second for the client IP address and playback domain name.
[0179] 4) When client 101A plays the live stream, it accesses the nearest service node 120 and sends a playback request to service node 120. The playback request includes the client's IP address A and the playback domain name A.
[0180] 5) Service node 120 requests authentication from authentication service 104.
[0181] 6) The authentication service 104 queries the data analysis service 105 for the number of concurrent playbacks of client IP address A for playback domain A within 1 minute, based on the authentication rules corresponding to playback domain A. If the number of concurrent playbacks of client IP address A for playback domain A is less than or equal to 2, the authentication is confirmed to be successful, and the service node 120 is notified that the authentication is successful.
[0182] 7) Service node 120 provides live streaming service to client 101A, sends live streaming content to client 101A, collects the playback data of client 101A per second, and reports the playback data of client 101A to data distribution service 105.
[0183] In the context of key-based hotlinking prevention, it is necessary to aggregate playback data (including tokens) from clients in the service node cluster during the current time period, such as 1 minute, to obtain global playback data corresponding to different clients 101. Subsequently, based on authentication rules, the global playback data corresponding to client 101 is queried to obtain the data required for analyzing the authentication rules, thereby facilitating subsequent hotlinking identification and identifying clients currently experiencing large-scale hotlinking. Subsequently, hotlinking processing, such as blocking, can be carried out on clients experiencing large-scale hotlinking.
[0184] In the embodiment, in the key anti-leeching scenario, the playback request includes a token. The authentication service 104 needs to perform key anti-leeching verification, such as verifying the token. Only after the key anti-leeching verification is passed, such as the token verification is passed, will the anti-leeching identification based on the authentication rules be further performed.
[0185] Optionally, in some embodiments, the data analysis service 140 may count the global usage frequency of the token. In a scenario where the authentication service 104 is deployed on the service node 120, the authentication service 104 needs to report the token to the data analysis service 140.
[0186] As shown in Figure 6, the playback request authentication method provided in this embodiment of the invention may include the following:
[0187] Configure anti-leeching process:
[0188] Step 601. The provider of the playback domain A access service platform 102 configures authentication rules A: playback domain A, statistical period A, authentication index A and authentication conditions A.
[0189] For example, the playback domain name is playback domain name A, the statistical period A is 1 minute, the authentication index A is the global usage count of the token of the service node cluster, and the authentication condition A is that the global usage count of the token of the service node cluster is less than or equal to 10.
[0190] For example, the playback domain name is playback domain name A. There are two authentication metrics A: the global usage count of the token of the service node cluster and the playback concurrency of a single client. The statistical period A for each of the two authentication metrics A is 1 minute. There are two authentication conditions A: the global usage count of the token of the service node cluster is less than or equal to 10 and the playback concurrency of a single client is less than or equal to 2.
[0191] Step 602. Service platform 102 issues authentication rule A to authentication service 104.
[0192] Sampling and reporting process:
[0193] Step 603. Each service node 102 in the service node cluster 104 reports the playback data of the sampling period to the data analysis service 105. The playback data includes the playback domain name, client IP address, playback time, playback duration, and token.
[0194] Step 604. Data analysis service 105 aggregates playback data to obtain global playback data corresponding to different clients 101. Global playback data includes playback domain name, client IP address, sampling period, and aggregated data.
[0195] In this embodiment, the playback data includes a token, and the aggregated data includes the global usage count of the token by client 101. Optionally, the data analysis service 140 may sum the token usage counts for the same client IP address and playback domain name during the sampling period to obtain the global usage count of the token by client 101.
[0196] Authentication and playback process:
[0197] Step 605. Client 101A sends a playback request to service node 120A in the service node cluster. The playback request includes domain name A, client IP address A, and token A.
[0198] In this embodiment, the client 101 first obtains tokenA from the client's authentication server and uses tokenA as a parameter for the playback request.
[0199] Step 606. Service node 120A sends an authentication request to authentication service 104. The authentication request includes playback domain name A, client IP address A, and token A.
[0200] Step 607. If the Key anti-hotlinking verification is successful, the authentication service 104 sends a query request to the data analysis service 105. The query request includes the playback domain name A, the client IP address A, the statistical period A, and the authentication index A.
[0201] The Key anti-hotlinking verification passed is used to indicate that tokenA has passed verification.
[0202] In some possible implementations of this embodiment, the Key anti-hotlinking verification may include: the authentication service 104 uses the algorithm strategy and private key configured by the customer to verify whether token A is valid. For example, the token is generated using the encryption algorithm strategy, private key, expiration time and resource path in the playback request configured by the customer. If the token is the same as token A, it means that token A is valid and the Key anti-hotlinking verification passes.
[0203] Step 608. Data analysis service 105 sends the query results to authentication service 104.
[0204] For details, please refer to the description of step 508 above, which will not be repeated here.
[0205] In some optional implementations of this embodiment, authentication index A is the global usage count of the token of the service node cluster. For each sampling period, data analysis service 105 counts the global usage count of the same token for each client 101 with the same playback domain name in that sampling period, thus obtaining the global usage count of the token of the service node cluster in each sampling period. Subsequently, data analysis service 105 can respond to query requests, determine the data period to be queried based on the statistical period A corresponding to authentication index A, and query the multiple global usage counts of the service node cluster for token A corresponding to the playback domain name and client IP address A within the data period. For example, the multiple global usage counts of the service node cluster for token A in each sampling period within the data period can be used to obtain the query result. Alternatively, the multiple global usage counts of the service node cluster for token A within the data period can be aggregated, for example, added together, to obtain the global usage count of the service node cluster for token A within the statistical period A as the query result.
[0206] In some optional implementations of this embodiment, when the authentication index A is the global usage count of the token in the service node cluster, the data analysis service 105 responds to the query request, determines the data period to be queried based on the statistical period A corresponding to the authentication index A, queries the global playback data corresponding to different clients 101 in the stored data period for the multiple global usage counts of the client 101A corresponding to the playback domain A for the token A, and obtains the query results. For example, the query results may include the client IP address A and multiple global usage counts.
[0207] In some optional implementations of this embodiment, when the authentication index A is the global usage count of the token of the service node cluster, the data analysis service 105 responds to the query request, determines the data period to be queried, queries the global playback data corresponding to different clients 101 in the stored data period for the multiple global usage counts of the client 101A corresponding to the playback domain A for the token A, adds the multiple global usage counts together, and obtains the global usage count of the service node cluster for the token A within the statistical period A as the query result. For example, the query result may include the identifier of the service node cluster and a single global usage count.
[0208] Step 609. Authentication Service 104 determines the authentication result based on authentication condition A and the query result.
[0209] For details, please refer to the description of step 509 above, which will not be repeated here.
[0210] If authentication metric A represents the global usage count of the token in the service node cluster, and the query result indicates the multiple global usage counts of client 101A for token A within the statistical period A, then authentication service 104 can aggregate, for example, add up, the multiple global usage counts in the query result to obtain the global usage count of the service node cluster for token A within the statistical period A. Subsequently, if the authentication condition A corresponding to authentication metric A is less than or equal to 10, authentication service 104 determines whether the global usage count of the service node cluster for token A is less than or equal to 10. If it is, it indicates that the global usage count of the token in the service node cluster is normal; otherwise, it indicates that client 101 is abnormal.
[0211] Step 610. Authentication service 104 sends the authentication result to service node 120A.
[0212] Step 611. When the authentication is successful, the service node 120A sends the playback content to the client 101A.
[0213] Step 612. Service node 120A sends playback data to data analysis service 105. The playback data includes client IP address A, playback time, and playback duration.
[0214] It should be noted that the "A" in tokenA has no special meaning; it is merely for ease of description and distinction.
[0215] Based on the playback request authentication method provided above, the specific application of this method will be explained. In some possible scenarios, the specific content includes:
[0216] 1) Authentication rule A obtained by service platform 102:
[0217] The above authentication rules are used to indicate that for live domain A, the same IP can only play a maximum of 2 live channels at the same time within a 1-minute statistical period. If traditional key anti-leeching is enabled, the same key anti-leeching token can only be used a maximum of 10 times.
[0218] The authentication service 104 has identified authentication rule A. Playback is only allowed if authentication rule A is met.
[0219] 2) Each service node 120 in the service node cluster reports the token per second and the playback data of client 101 to the data analysis service 105. The playback data includes the client IP address, data collection time, playback start time, and playback duration.
[0220] 3) Data analysis service 105 merges the playback start time, playback duration, and token for the same client IP address and playback domain name every second to obtain the total playback duration (duration_sum), total number of playbacks (session_count), average playback duration (duration_avg), average concurrent playback duration (duration_concurrency), playback concurrency (session_cocurrency), and global usage count of the token for the client IP address and playback domain name every second; merges the global usage count (token_count) of the same token for different client IP addresses of the same playback domain name every second to obtain the global usage count of the token for the service node cluster.
[0221] 4) When client 101A plays the live stream, it accesses the nearest service node 120 and sends a playback request to service node 120. The playback request includes client IP address A, playback domain name A, and token A.
[0222] 5) Service node 120 requests authentication from authentication service 104.
[0223] 6) The authentication service 104 queries the data analysis service 105 based on the authentication rules corresponding to the playback domain A, and queries the client IP address A for the playback domain A concurrent playback count within 1 minute, and the service node cluster for the global usage count of token A within 1 minute. If the client IP address A for the playback domain A concurrent playback count is less than or equal to 2, and the service node cluster for the global usage count of token A is less than or equal to 10, then the authentication is confirmed to be successful, and the authentication is reported to the service node 120.
[0224] 7) Service node 120 provides live streaming service to client 101A, sends live streaming content to client 101A, collects playback data from client 101A, and reports the playback data from client 101A to data distribution service 105.
[0225] Alternatively, in some other embodiments, when the authentication service 104 is used to implement authentication of the service node cluster, the authentication service 104 can count the global usage count of the token.
[0226] As shown in Figure 7, the playback request authentication method provided in this embodiment of the invention may include the following:
[0227] Configure anti-leeching process:
[0228] Step 701. The provider of the playback domain A accesses the service platform 102 and configures authentication rules A: playback domain A, global usage count of single client token A1, statistical period A1, playback metric A2, statistical period A2, global usage count condition A1, playback metric condition A2.
[0229] For example, the data analysis service 105 merges the playback start time and playback duration of the same client IP address to obtain playback metrics A2: total playback duration of a single client (duration_sum), total number of playbacks of a single client (session_count), average playback duration of a single client (duration_avg), average concurrent playback duration of a single client (duration_concurrency), and number of concurrent playbacks of a single client (session_cocurrency).
[0230] Among them, the playback metric A2 condition is used to indicate the conditions that the playback metric A2 needs to meet, and the token global usage count condition A1 is used to indicate the upper limit of the token global usage count A1 for a single client.
[0231] For example, the playback domain name is playback domain name A. There are two authentication metrics A: the global usage count of the token by a single client A1 and the playback metric A2. The statistical period A1 corresponding to the global usage count of the token by a single client is 1 minute, and the statistical period A2 corresponding to the playback metric A2 is 1 minute. The condition for the global usage count of the token A1 is that the global usage count of the token A by the client 101A is less than or equal to 10. The condition for the playback metric A2 is that the playback concurrency of a single client is less than or equal to 2.
[0232] Step 702. Service platform 102 issues authentication rule A to authentication service 104.
[0233] Sampling and reporting process:
[0234] Step 703. Each service node 102 in the service node cluster 104 reports the playback data of the sampling period to the data analysis service 105. The playback data includes the playback domain name, client IP address, playback time, and playback duration.
[0235] Step 704. Data analysis service 105 aggregates playback data to obtain global playback data corresponding to different clients 101. Global playback data includes playback domain name, client IP address, sampling period, and aggregated data.
[0236] In this embodiment, the data analysis service 140 does not need to obtain tokens sent by multiple clients 101.
[0237] Authentication and playback process:
[0238] Step 705. Client 101A sends a playback request to service node 120A in the service node cluster. The playback request includes domain name A, client IP address A, and token A.
[0239] In this embodiment, the client 101 first obtains tokenA from the client's authentication server and uses tokenA as a parameter for the playback request.
[0240] Step 706. Service node 120A sends an authentication request to authentication service 104. The authentication request includes playback domain name A, client IP address A, and token A.
[0241] Step 707. If the Key anti-hotlinking verification is successful, the authentication service 104 sends a query request to the data analysis service 105. The query request includes the playback domain name A, the client IP address A, the statistical period A, and the playback metric A2.
[0242] For details, please refer to the description of step 607, which will not be repeated here.
[0243] Step 708. Data analysis service 105 sends the query results to authentication service 104.
[0244] Step 709. The authentication service 104 determines the authentication result based on the query results, the global usage count of token A by client 101A, the global usage count condition A1, and the playback metric condition A2.
[0245] In some optional implementations of this embodiment, the authentication service 104 can determine the value of the playback indicator A2 based on the query results. If the value of the playback indicator A2 meets the conditions of the playback indicator A2, the client 101A determines that the global usage count of token A meets the global usage count condition A1. For example, if the global usage count condition A1 is less than or equal to the upper limit of the global usage count of the token, the authentication is confirmed to be successful; otherwise, the authentication fails.
[0246] Step 710. Authentication service 104 sends the authentication result to service node 120A.
[0247] Step 711. When the authentication is successful, the service node 120A sends the playback content to the client 101A.
[0248] Step 712. Service node 120A sends playback data to data analysis service 105. The playback data includes client IP address A, playback time, and playback duration.
[0249] It should be noted that if database 106 as shown in Figure 1c is used, for the technical solutions described in Figures 5, 6, and 7 above, service platform 102 can store the authentication rule A input by the provider of playback domain name A into database 106, and data analysis service 105 can store the global playback data corresponding to client 101 into database 106. As shown in Figure 8, after receiving the authentication request sent by service node 120, authentication service 104 can obtain authentication rule A from database 106 based on playback domain name A, and send a query request to database 106 to obtain the query result returned by database 106; based on the query result, the index value of authentication index A is obtained. The query request and query result are described in the relevant descriptions in Figures 5 to 7, and will not be repeated here.
[0250] The above describes the interaction process between client 101, service platform 102, media service 103, authentication service 104, and data analysis service 105. The following describes the technical solutions for various deployment methods of media service 103, authentication service 104, and data analysis service 105 (such as Figures 2a to 2c).
[0251] In some optional embodiments, as shown in Figure 2a, authentication service 104 and media service 120 run on each service node 120 in the service node cluster, and data analysis service 105 runs on aggregation node 140. Each service node 120 runs authentication service 104 and media service 120, implementing the functions of authentication service 104 and media service 120.
[0252] As shown in Figure 9, the playback request authentication method provided in this embodiment of the invention includes at least the following steps:
[0253] Step 901: Client 101A sends a playback request to service node 120A. The playback request includes the playback domain name A and the identifier of client 101A, which is the client IP address A and / or token A.
[0254] It should be noted that client IP address A and token A are examples of client 101A identifiers and do not constitute specific limitations; other identifiers can be designed in other possible scenarios. Client IP address A is the same throughout the service node cluster and will not change. In practical applications, a client 101A identifier can also be designed to replace client IP address A.
[0255] Step 902: Service node 120A obtains the authentication data in the playback request. The authentication data includes the playback domain name A and the identifier of client 101A, which is the client IP address A and / or token A.
[0256] Step 903: Service node 120A obtains the authentication rule A corresponding to the playback domain name A. The authentication rule A includes authentication index A and authentication condition A corresponding to authentication index A.
[0257] In this embodiment, the authentication service 104 may also include verification of Key hotlinking (i.e., token verification) or referrer hotlinking (referer field verification). If the Key hotlinking or referrer hotlinking verification is successful, step 903 is executed.
[0258] In some possible scenarios, when the playback request includes tokenA, service node 120A uses Key anti-hotlinking to verify tokenA. After successful verification, step 903 is executed. TokenA verification may include using a client-configured algorithm strategy and private key to verify tokenA's validity. For example, a token may be generated using the client-configured encryption algorithm strategy, key, expiration time, and resource path in the playback request. If this token matches tokenA, then tokenA is considered valid. Optionally, service node 120A may also send tokenA to the node where data analysis service 105 resides, facilitating the node where data analysis service 105 resides to count the global usage count of tokenA.
[0259] In other possible scenarios, when the playback request includes a Referer field indicating playback domain A, service node 120A uses referrer-based hotlinking prevention to determine if playback domain A is legitimate. If playback domain A is legitimate, step 903 is executed. Optionally, determining the legitimacy of playback domain A may include: obtaining a referrer whitelist, determining whether playback domain A is on the referrer whitelist, and if so, determining that playback domain A is legitimate.
[0260] In some possible implementations of this embodiment, the service center 102 sends authentication rule A to the service node 120A. The service node 120A queries the local storage based on the playback domain name A to obtain the authentication rule A corresponding to the playback domain name A.
[0261] In some other possible implementations of this embodiment, the service center 102 stores the authentication rule A in the database 106, and the service node 120A queries the database 106 based on the playback domain name A to obtain the authentication rule A corresponding to the playback domain name A returned by the database 106.
[0262] Among them, authentication rule A may include playback domain name A, several authentication indicators A, authentication conditions A corresponding to each authentication indicator A, and statistical period A corresponding to each authentication indicator A.
[0263] For example, the playback domain name is playback domain name A, the statistical period A is 1 minute, the authentication index A is the global usage count of the token of the service node cluster, and the authentication condition A is that the global usage count of the token of the service node cluster is less than or equal to 10.
[0264] For example, the playback domain name is playback domain name A. There are two authentication metrics A: the global usage count of the token of the service node cluster and the playback concurrency of a single client. The statistical period A corresponding to each of the two authentication metrics A is 1 minute. There are two authentication conditions A: the global usage count of the token of the service node cluster is less than or equal to 10 and the playback concurrency of a single client is less than or equal to 2.
[0265] Step 904: Service node 120A obtains the value of authentication index A based on the identifier and playback domain name of client 101. The index value is used to indicate the global playback status of client 101A for playback domain name A in the service node cluster.
[0266] In optional case A of this embodiment, each service node 120 in the service node cluster reports playback data for the sampling period to the aggregation node 140, thereby enabling the aggregation node 140 to aggregate playback data for the same sampling period and obtain the global playback data corresponding to client 101, which is stored locally or in database 106. It should be noted that when the authentication index A is the global usage count of the token in the service node cluster, the aggregation node 140 needs to aggregate, for example, add the global usage counts of the same token for different clients 101 within each sampling period to obtain the global usage count of the token in the service node cluster within the sampling period.
[0267] It should be noted that there can be one or more authentication indicators A. The method of obtaining the indicator value of each authentication indicator A is similar. The following description of the technical solution takes one authentication indicator A and the corresponding statistical period A as an example.
[0268] In one implementation A1 of this scenario, for each authentication index A, the service node 120 determines the query request based on the client IP address A and the authentication index A, and sends the query request to the aggregation node 140; then, the aggregation node 140 responds to the query request, performs a query from the local machine or the database 106, obtains the query result, and sends the query result to the service node 120, and the service node 120 obtains the index value of the authentication index A based on the query result.
[0269] In some optional scenarios, the query result can be the value of authentication metric A for statistical period A. The query request can include the playback domain A, statistical period A, the identifier of client 101A (e.g., client IP address or token A), and authentication metric A. For example, when authentication metric A is a playback metric A2, such as the total playback duration (duration_sum), total playback count (session_count), average playback duration (duration_avg), average concurrent playback duration (duration_concurrency), or concurrent playback count (session_cocurrency) for a single client, the query request includes the client IP address. Similarly, when authentication metric A is a token-related metric, such as the global token usage count for a single client or the global token usage count for the service node cluster, the query request includes token A.
[0270] For details, please refer to the description of step 508, which will not be repeated here.
[0271] Optionally, in an example A11, the aggregation node 140 responds to the query request and obtains the query result, which may include: determining the data period to be queried based on the statistical period A, for example, if the statistical period A is 1 minute, then the data period to be queried is the most recent 1 minute; then, based on the authentication index A, querying from the local machine or database 106 all index values of the authentication index A corresponding to the client IP address A and the playback domain name A in the data period, and aggregating, for example, adding, all index values of the authentication index A for the data period to obtain the index value of the authentication index A for the statistical period A as the query result.
[0272] Optionally, in another example A12, the aggregation node 140 responds to the query request and obtains the query results, which may include: determining the data period to be queried based on the statistical period A, for example, if the statistical period A is 1 minute, then the data period to be queried is the most recent 1 minute; then, based on the authentication index A, querying from the local machine or database 106 all index values of the authentication index A corresponding to the client IP address A and the playback domain name A during the data period, and using these as the query results. For example, the authentication index A includes the total playback duration (duration_sum) of a single client, the total number of playbacks of a single client (session_count), the average playback duration of a single client (duration_avg), the average concurrent playback duration of a single client (duration_concurrency), the number of concurrent playbacks of a single client (session_cocurrency), and the number of times the token is used globally by a single client.
[0273] Based on the query results, service node 120 can obtain the value of authentication index A by aggregating, for example, all the values of authentication index A in the query results and adding them together to obtain the value of authentication index A for the statistical period A.
[0274] It should be noted that the above query results are merely examples. In other possible scenarios, the query results could be data related to authentication indicator A for statistical period A. The query request is used to request data related to authentication indicator A from client 101A within statistical period A. This query request could include the playback domain A, statistical period A, the identifier of client 101A (e.g., token A), and authentication indicator A. Subsequently, service node 120A performs calculations on the relevant data for authentication indicator A within statistical period A to obtain the value of authentication indicator A.
[0275] For details, please refer to examples A11 and A12 above. The difference is:
[0276] Replace the sampling period's value for authentication index A with relevant data for authentication index A; authentication index A can be the global usage count of the token in the service node cluster; service node 120A needs to perform calculations on the relevant data of authentication index A for each sampling period within statistical period A to obtain the value of authentication index A for each sampling period within statistical period A, and then aggregate, for example, add, the values of authentication index A for each sampling period within statistical period A to obtain the value of authentication index A for statistical period A.
[0277] For example, authentication metric A is the global usage count of the token in the service node cluster, and the query result is the global usage count of each client IP address A in each sampling period within the statistical period A.
[0278] In optional scenario B of this embodiment, the service node cluster can send a query request to database 106. For details, refer to the section on the response of aggregation node 140 to query requests; the difference is that aggregation node 140 can be replaced with database 106.
[0279] It is worth noting that when there are multiple authentication indicators A, one authentication indicator A can be queried at a time, or multiple authentication indicators A can be queried at a time. In the scenario of querying multiple authentication indicators A at a time, the query results can be the indicator value of each authentication indicator A for the statistical period A, or the indicator values of some authentication indicators A for the statistical period A, and the relevant data of other authentication indicators A for the statistical period A.
[0280] Step 905: Service node 120A determines whether the value of authentication index A meets authentication condition A in order to obtain the authentication result.
[0281] There can be one or more authentication indicators A. For each authentication indicator A, the authentication rule A can include the authentication condition A corresponding to the authentication indicator A. The authentication condition A is used to indicate the conditions that the authentication indicator A needs to meet. In some optional implementations of this embodiment, the service node 120 determines whether the indicator value of each authentication indicator A meets the corresponding authentication condition A. If it does, the authentication is successful; otherwise, the authentication fails, indicating that the client 101A is abnormal.
[0282] Optionally, authentication condition A includes a preset threshold, authentication index A, and the relationship between the preset threshold and the value of the index, such as being less than or equal to the preset threshold. Correspondingly, determining whether the value of authentication index A satisfies the corresponding authentication condition A may include: judging whether the relationship between the value of authentication index A and the preset threshold in the authentication condition A corresponding to authentication index A satisfies authentication condition A. If it is satisfied, it means that the authentication index passes normally; otherwise, authentication fails, indicating that client 101A is abnormal.
[0283] Step 906: After the authentication result indicates that the authentication is successful, service node 120A responds to the playback request and determines the playback content.
[0284] In practice, service node 120A can pre-cache the playback content. If it is not cached, it can request playback content from other service nodes 120A or storage resource servers.
[0285] Step 907: Service node 120A sends playback content to client 101A.
[0286] Step 908: Service node 120 collects playback data from client 101A.
[0287] The playback data may include the client IP address A, data collection time, playback start time, and playback duration.
[0288] Subsequently, service node 120 can send the playback data of client 101A to the node where data analysis service 105 is located.
[0289] In this solution, authentication metrics and conditions are set to measure the security of global playback on the service node cluster. The metric values for the client are obtained to measure the global playback status of the client for the playback domain name in the service node cluster. Subsequently, it is determined whether the metric values of the authentication metrics meet the set authentication conditions to analyze whether there are any anomalies in the global playback status of the client for the playback domain name in the service node cluster. This allows for the dynamic identification of users who engage in hotlinking and reduces the possibility of large-scale hotlinking.
[0290] In some optional embodiments, as shown in Figures 2b and 2c, the authentication service 104 and the media service 120 run on different nodes. Each service node 120 runs the media service 120 and implements the functions of the media service 120. The authentication node 130 runs at least the authentication service 104 and implements at least the functions of the authentication service 104.
[0291] As shown in FIG10, in one feasible implementation of the present invention, the playback request authentication method provided by the present invention includes at least the following steps:
[0292] Step 1001: Client 101A sends a playback request to service node 120A. The playback request includes the playback domain name A and the identifier of client 101A, which is the client IP address A and / or token A.
[0293] Step 1002: Service node 120A determines the authentication request based on the playback request. The authentication request includes the playback domain name A and the client IP address A.
[0294] In some optional implementations of this embodiment, some functions of the authentication service 104, such as Key anti-hotlinking (i.e., token verification) or referrer anti-hotlinking (referer field verification), can be implemented by the service node 120A.
[0295] In some possible scenarios, when the playback request includes tokenA, service node 120A uses Key anti-hotlinking to verify tokenA. After successful verification, step 903 is executed. TokenA verification may include using a client-configured algorithm strategy and private key to verify tokenA's validity. For example, a token may be generated using the client-configured encryption algorithm strategy, key, expiration time, and resource path in the playback request. If this token matches tokenA, then tokenA is considered valid. Optionally, service node 120A may also send tokenA to the node where data analysis service 105 resides, facilitating the node where data analysis service 105 resides to count the global usage count of tokenA.
[0296] In other possible scenarios, when the playback request includes a Referer field indicating playback domain A, service node 120A uses referrer-based hotlinking prevention to determine if playback domain A is legitimate. If playback domain A is legitimate, step 903 is executed. Optionally, determining the legitimacy of playback domain A may include: obtaining a referrer whitelist, determining whether playback domain A is on the referrer whitelist, and if so, determining that playback domain A is legitimate.
[0297] Step 1003: Service node 120A sends an authentication request to authentication node 130. The authentication request includes the playback domain name A and the identifier of client 101A, which is the client IP address A and / or token A.
[0298] Step 1004: Authentication node 130 obtains the authentication rule A corresponding to the playback domain name A. The authentication rule A includes authentication index A and authentication condition A corresponding to authentication index A.
[0299] In some optional implementations of this embodiment, all functions of the authentication service 104 can also be implemented by the authentication node 130. The full functionality of the authentication service 104 includes authentication rule A, key hotlinking prevention (i.e., token verification), and referrer hotlinking prevention (referer field verification). For details on key hotlinking prevention (i.e., token verification) and referrer hotlinking prevention (referer field verification), please refer to the description in step 1002, which will not be repeated here.
[0300] For details on obtaining the authentication rule A corresponding to the playback domain A, please refer to the description in step 903, which will not be repeated here.
[0301] Step 1005: The authentication node 130 obtains the value of the authentication index A based on the identifier of client 101 and the playback domain name. The index value is used to indicate the global playback status of client 101A for playback domain name A in the service node cluster.
[0302] In the scenario shown in Figure 2b, authentication service 104 and data analysis service 105 can run on the same node, such as authentication node 130. In this case, authentication node 130 can obtain the value of authentication indicator A without interacting with aggregation node 140. For details, please refer to the description of step 904, which will not be repeated here. The difference is that no query request needs to be sent to aggregation node 140, and aggregation node 140 does not need to respond to the query request to obtain the query results.
[0303] In the scenario shown in Figure 2c, the authentication service 104 and the data analysis service 105 can run on different nodes. For example, the authentication service 104 runs on the authentication node 130, and the data analysis service 105 runs on the aggregation node 140. The authentication node 130 needs to interact with the aggregation node 140, for example, by sending a query request to the aggregation node 140, in order to obtain the value of the authentication indicator A. See step 904 for details, which will not be repeated here.
[0304] In the scenario where database 106 is used, authentication node 130 needs to interact with database 106, such as sending a query request to database 106, in order to obtain the value of authentication indicator A.
[0305] Additionally, it is worth noting that if the authentication request includes tokenA, the authentication metric A is the global usage count of the token for a single client or the global usage count of the token for the service node cluster. In the scenario shown in Figure 2c, the authentication service 104 and the data analysis service 105 can run on different nodes. In this case, the authentication service 104 is used to perform global authentication on the service node cluster. The authentication node 130 can then obtain the global usage count of the tokenA for client 101A or the global usage count of the tokenA for the service node cluster. Correspondingly, the authentication node 130 can query the aggregation node 140 for other authentication metrics A to obtain the metric values or related data of other authentication metrics A.
[0306] Step 1006: Authentication node 130 determines whether the value of authentication index A meets authentication condition A in order to obtain the authentication result.
[0307] For details, please refer to the description of step 905, which will not be repeated here.
[0308] Step 1007: Authentication node 130 sends the authentication result to service node 120A.
[0309] Step 1008: After the authentication result indicates that the authentication is successful, service node 120A responds to the playback request and determines the playback content.
[0310] Step 1009: Service node 120A sends playback content to client 101A.
[0311] Step 1010: Service node 120 collects playback data from client 101A.
[0312] The playback data may include the client IP address A, data collection time, playback start time, and playback duration.
[0313] Subsequently, service node 120 can send the playback data of client 101A to the node where data analysis service 105 is located.
[0314] In this solution, authentication rules are designed based on the client's global playback data. Based on the client's global playback status, the system obtains the values of the authentication indicators required for analyzing the authentication rules, thereby dynamically identifying users who engage in hotlinking and reducing the possibility of large-scale hotlinking.
[0315] This embodiment, based on the aforementioned embodiments, provides another playback request authentication method. This method can be applied to service node 120 or authentication node 130. As shown in Figure 11, the playback request authentication method provided in this embodiment of the invention may include:
[0316] Step 1101: Obtain the authentication data in the playback request. The authentication data includes the playback domain name A and the identifier of client 101A. The playback request is sent by client 101A to service node 120. Service node 120 is located in the service node cluster.
[0317] The identifier for client 101A can be the address of client 101A and / or tokenA. The address of client 101A can be an IP address, which can be referred to as the client IP address described above.
[0318] In some feasible implementations of this embodiment, the execution subject is the service node 120. After receiving the playback request, the service node 120 can extract the authentication data from the playback request.
[0319] In some feasible implementations of this embodiment, the execution subject is the authentication node 130. After receiving the authentication request sent by the target service node, the authentication node 130 can obtain the authentication data from the authentication request.
[0320] Step 1102: Obtain the authentication rules corresponding to the playback domain A. The authentication rules include authentication indicators and authentication conditions corresponding to the authentication indicators. The authentication indicators are used to measure the security of global playback for the playback domain A.
[0321] In this embodiment, the authentication index may include one or more indexes, and the authentication conditions are used to describe the conditions that each index in the authentication index needs to meet. For details, please refer to the description of steps 903 and 1004, which will not be repeated here.
[0322] For example, authentication metrics may include any one or more of the following:
[0323] The total playback duration (duration_sum) for a single client, the total number of playbacks for a single client (session_count), the average playback duration (duration_avg) for a single client, the average concurrent playback duration (duration_concurrency) for a single client, the number of concurrent playbacks for a single client (session_cocurrency), the global usage count of tokenA for a single client, and the global usage count of tokenA for the service node cluster.
[0324] Step 1103: Based on the identifier of client 101A and the playback domain name A, obtain the indicator value of the authentication indicator. The indicator value is used to indicate the global playback status of client 101A for playback domain name A in the service node cluster.
[0325] Optionally, global playback status may include any one or more of the following:
[0326] The total playback duration (duration_sum), total number of playbacks (session_count), average playback duration (duration_avg), average concurrent playback duration (duration_concurrency), and concurrent playback count (session_cocurrency) of client 101A.
[0327] Some feasible implementation methods of this embodiment include authentication rules including the statistical period of authentication indicators; correspondingly, based on the client's identifier and playback domain name A, obtaining the indicator value of the authentication indicator may include: determining the data time period based on the statistical period, for example, if the statistical period is 1 minute, then the data time period to be queried is the most recent 1 minute; obtaining the indicator value of the authentication indicator for the data time period based on the identifier of client 101A and playback domain name A, for details please refer to the description of step 905 or step 1005, which will not be repeated here.
[0328] In some feasible implementations of this embodiment, the identifier of client 101A includes the token used by client 101A (which can be referred to as tokenA for ease of description and distinction) and the address of client 101A, such as its IP address. Global playback status can include the number of times client 101A uses tokenA globally and / or the number of times the service node cluster uses tokenA globally.
[0329] Correspondingly, the authentication metrics can include a first metric and a second metric. The first metric can be the number of times tokenA is used globally in the service node cluster, and the second metric can be the playback metric A2 mentioned above, such as the total playback duration (duration_sum) of a single client, the total number of playbacks of a single client (session_count), the average playback duration of a single client (duration_avg), the average concurrent playback duration of a single client (duration_concurrency), and the number of concurrent playbacks of a single client (session_cocurrency).
[0330] Correspondingly, based on the client's identifier, the corresponding indicator value for the authentication indicator can include: determining a first indicator value for a first indicator based on tokenA and playback domain A, the first indicator value indicating the global usage count of tokenA for playback domain A in the service node cluster; and determining a second indicator value for a second indicator based on the client's address and playback domain A, the second indicator value indicating the global playback count or global playback duration of the client for playback domain A in the service node cluster. The global playback count can be represented by the total playback count of client 101A (session_count) and / or the concurrent playback count of client 101A (session_cocurrency), and the global playback duration can be represented by the total playback duration of client 101A (duration_sum), the average playback duration of client 101A (duration_avg), and / or the average concurrent playback duration of client 101A (duration_concurrency).
[0331] The process of determining the first indicator value of the first metric based on tokenA and playback domain A may include: service node 120 determining a query request based on tokenA and playback domain A, and sending the query request to aggregation node 140; then, aggregation node 140 responding to the query request, obtaining the query result, and sending the query result back to service node 120; service node 120 determining the first indicator value of the first metric based on the query result. Optionally, the query request includes tokenA and the statistical period corresponding to the first metric; the query result can be the global usage count of tokenA by the service node cluster; the query result can also be multiple global usage counts of tokenA by the service node cluster, such as multiple global usage counts in multiple sampling periods within the statistical period corresponding to the first metric; subsequently, the multiple global usage counts in the query result are aggregated, for example, added together, to obtain the first indicator value of the first metric.
[0332] It should be noted that the first indicator value, used to indicate the global usage count of tokenA for playback domain A in the service node cluster, is merely an example. In other possible cases, the first indicator value is used to indicate the global usage count of tokenA for client 101A in the service node cluster. Optionally, the query request includes playback domain A, the address of client 101A, tokenA, and the statistical period corresponding to the first indicator. The query result is multiple global usage counts of client 101A for tokenA, such as multiple global usage counts in multiple sampling periods within the statistical period corresponding to the first indicator. Subsequently, the multiple global usage counts of client 101A for tokenA in the query result are aggregated, for example, added together, to obtain the first indicator value of the first indicator.
[0333] The process of determining the second indicator value based on the address of client 101A can include: service node 120 determining a query request based on the address of client 101A and playback domain name A, and sending the query request to aggregation node 140; then, aggregation node 140 responding to the query request, obtaining the query result, and sending the query result back to service node 120; service node 120 determining the second indicator value based on the query result. Optionally, the query request includes playback domain name A, the address of client 101A, the statistical period corresponding to the second indicator, and the second indicator; the query result is multiple indicator values of client 101A for the second indicator, such as multiple indicator values for multiple sampling periods within the statistical period corresponding to the second indicator; subsequently, the multiple indicator values of client 101A for the second indicator in the query result are aggregated, for example, added together, to obtain the second indicator value of the second indicator.
[0334] In some feasible implementations of this embodiment, the execution entity is the authentication node 130, which runs the authentication service 104 and the data analysis service 105. Correspondingly, based on the identifier of client 101A, obtaining the indicator value of the authentication index may include: obtaining global playback data based on the identifier of client 101A, which is used to instruct the service node cluster to process the data in the historical playback request process of client 101A for playback domain name A; and determining the indicator value of the authentication index based on the global playback data.
[0335] Optionally, in one example, each service node 120 in the service node cluster reports the playback data of client 101A to the authentication node 130. The authentication node 130 aggregates the data based on the address of client 101A and the playback domain name A to obtain the global playback data corresponding to client 101A. The global playback data may include the total playback duration (duration_sum), total number of playbacks (session_count), average playback duration (duration_avg), average concurrent playback duration (duration_concurrency), number of concurrent playbacks (session_cocurrency), and the number of global uses of token A by client 101A for playback domain name A.
[0336] If the authentication metrics include the global usage count of tokenA in the service node cluster, and the authentication rules include the statistical period corresponding to the global usage count of tokenA in the service node cluster, then the metric value for determining the authentication metrics based on the global playback data can include: calculating the global usage count of tokenA by different clients within the corresponding statistical period based on the global usage count of tokenA by client 101A in the global playback data, and obtaining the global usage count of tokenA by the service node cluster.
[0337] Optionally, in one example, the global playback data includes the values of the authentication index in different sampling periods, and the authentication rules include the statistical period corresponding to the authentication index. Based on the global playback data, determining the value of the authentication index may include: obtaining the values of the authentication index in different sampling periods from the global playback data, adding the values of the authentication index in different sampling periods to obtain the value of the authentication index for the corresponding statistical period.
[0338] Step 1104: Determine whether the value of the authentication index meets the corresponding authentication conditions to obtain the authentication result.
[0339] Optionally, if the authentication condition corresponding to the authentication indicator is less than or equal to a preset threshold, then if the indicator value is less than or equal to the corresponding preset threshold, the authentication result is determined to indicate that the authentication has passed; if the indicator value is greater than the corresponding preset threshold, the authentication result is determined to indicate that client 101A is an abnormal client, and hotlinking processing, such as blocking, is performed on the abnormal client. See step 906 for details, which will not be repeated here.
[0340] It should be noted that authentication indicators can include one or more indicators, and authentication conditions are used to describe the conditions that each indicator in the authentication indicators needs to meet.
[0341] In this solution, authentication metrics and conditions are set to measure the security of global playback on the service node cluster. The metric values for the client are obtained to measure the global playback status of the client for the playback domain A in the service node cluster. Subsequently, it is determined whether the metric values of the authentication metrics meet the set authentication conditions to analyze whether there are any anomalies in the global playback status of the client for the playback domain A in the service node cluster. This allows for the dynamic identification of users who engage in hotlinking and reduces the possibility of large-scale hotlinking.
[0342] It should be noted that the "A" in playback domain A, token A, and client 101A has no special meaning; it is merely for ease of description and distinction.
[0343] It should be noted that in some feasible implementations of this embodiment, the execution subject is the authentication node 130. Subsequently, the authentication node 130 sends the authentication result to the service node. After the authentication result indicates that the authentication is successful, the service node responds to the playback request, determines the playback content, and sends the playback content to the client 101. Subsequently, the service node collects the playback data of the client 101 and reports the playback data to the node where the data analysis service 105 is located, such as the authentication node 130 and the aggregation node 140.
[0344] The present invention also provides a playback request authentication device, which can be applied to the above-mentioned service node 120 and authentication node 130, as shown in FIG12, including:
[0345] The authentication module is used to obtain authentication data from the playback request. The authentication data includes the playback domain name and the client's identifier. The playback request is sent by the client to the service node, which is located in the service node cluster.
[0346] The rule acquisition module is used to acquire the authentication rules corresponding to the playback domain name. The authentication rules include authentication indicators and authentication conditions corresponding to the authentication indicators. The authentication indicators are used to measure the security of global playback for the playback domain name.
[0347] The indicator value acquisition module is used to obtain the indicator value of the authentication indicator based on the client's identifier. The indicator value is used to indicate the global playback status of the client for the playback domain name in the service node cluster.
[0348] The authentication module is used to determine whether the indicator value meets the authentication conditions in order to obtain the authentication result.
[0349] The authentication module, rule acquisition module, indicator value acquisition module, and authentication module can all be implemented in software or hardware. For example, the implementation of the authentication module will be described below. Similarly, the implementation methods of the rule acquisition module, indicator value acquisition module, and authentication module can refer to the implementation method of the authentication module.
[0350] As an example of a software functional unit, the authentication module may include code running on a compute instance or a cluster of multiple compute instances. A compute instance may include at least one of a physical host (computing device), a virtual machine, or a container. Furthermore, the compute instance may be one or more. For example, the authentication module may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers running the code may be distributed within the same region or in different regions. Further, the multiple hosts / virtual machines / containers running the code may be distributed within the same availability zone (AZ) or in different AZs, each AZ comprising one or more geographically proximate data centers. Typically, a region may include multiple AZs.
[0351] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.
[0352] As an example of a hardware functional unit, the authentication module may include at least one computing device, such as a server. Alternatively, the authentication module may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD can be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.
[0353] The authentication module comprises multiple computing devices that can be distributed within the same region or in different regions. Similarly, the authentication module can be distributed within the same Availability Zone (AZ) or in different AZs. Likewise, the authentication module can be distributed within the same Virtual Private Cloud (VPC) or multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0354] It should be noted that, in other embodiments, the authentication module can be used to execute any step in the above-described playback request authentication method, such as any step in any of the methods shown in Figures 5 to 7 and 9 to 11; the rule acquisition module can be used to execute any step in the above-described playback request authentication method, such as any step in any of the methods shown in Figures 5 to 7 and 9 to 11; the index value acquisition module can be used to execute any step in the above-described playback request authentication method, such as any step in any of the methods shown in Figures 5 to 7 and 9 to 11; and the authentication module can be used to execute any step in the above-described playback request authentication method, such as any step in any of the methods shown in Figures 5 to 7 and 9 to 11. The steps implemented by the authentication module, rule acquisition module, index value acquisition module, and authentication module can be specified as needed. By implementing different steps in the above-described playback request authentication method, the authentication module, rule acquisition module, index value acquisition module, and authentication module can all the functions of the above-described playback request authentication device be realized.
[0355] The present invention also provides a computing device 1300. As shown in FIG13, the computing device 1300 includes: a bus 1302, a processor 1304, a memory 1306, and a communication interface 1308. The processor 1304, the memory 1306, and the communication interface 1308 communicate with each other via the bus 1302. The computing device 1300 may be a server or a terminal device. It should be understood that the present invention does not limit the number of processors and memories in the computing device 1300.
[0356] Bus 1302 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, only one line is used in Figure 13, but this does not imply that there is only one bus or one type of bus. Bus 1302 can include pathways for transmitting information between various components of computing device 1300 (e.g., memory 1306, processor 1304, communication interface 1308).
[0357] The processor 1304 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0358] The memory 1306 may include volatile memory, such as random access memory (RAM). The processor 1304 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0359] The memory 1306 stores executable program code, and the processor 1304 executes this executable program code to implement the functions of the aforementioned authentication module, rule acquisition module, index value acquisition module, and authentication module, thereby implementing the playback request authentication method, such as the method shown in any of Figures 5 to 7 and Figures 9 to 11. That is, the memory 1306 stores instructions for executing the playback request authentication method, such as the instructions shown in any of Figures 5 to 7 and Figures 9 to 11.
[0360] The communication interface 1308 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the computing device 1300 and other devices or communication networks.
[0361] This invention also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0362] As shown in Figure 14, the computing device cluster includes at least one computing device 1300. The memory 1306 of one or more computing devices 1300 in the computing device cluster may store the same instructions for executing the above-described playback request authentication method, such as the instructions for any of the methods shown in Figures 5 to 7 and Figures 9 to 11.
[0363] In some possible implementations, the memory 1306 of one or more computing devices 1300 in the computing device cluster may also store partial instructions for executing the aforementioned playback request authentication method, such as partial instructions for the methods shown in any of Figures 5 to 7 and 9 to 11. In other words, a combination of one or more computing devices 1300 can jointly execute the instructions for executing the aforementioned playback request authentication method, such as the instructions for the methods shown in any of Figures 5 to 7 and 9 to 11.
[0364] It should be noted that the memory 1306 in different computing devices 1300 within the computing device cluster can store different instructions, which are used to execute certain functions of the playback request authentication device. That is, the instructions stored in the memory 1306 of different computing devices 1300 can implement the functions of one or more of the aforementioned authentication module, rule acquisition module, indicator value acquisition module, and authentication module.
[0365] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. Figure 15 illustrates one possible implementation. As shown in Figure 15, two computing devices 1300A and 1300B are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device. In this type of possible implementation, the memory 1306 in computing device 1300A stores instructions for executing the functions of the authentication module. Simultaneously, the memory 1306 in computing device 1300B stores instructions for executing the functions of the rule acquisition module, the indicator value acquisition module, and the authentication module.
[0366] The connection method between the computing device clusters shown in Figure 15 can be considered as follows: taking into account that the playback request authentication method provided by the present invention needs to receive a large amount of information in the playback request and determine authentication, the functions implemented by the rule acquisition module, the indicator value acquisition module and the authentication module are considered to be executed by the computing device 1300B.
[0367] It should be understood that the functions of computing device 1300A shown in Figure 15 can also be performed by multiple computing devices 1300. Similarly, the functions of computing device 1300B can also be performed by multiple computing devices 1300.
[0368] This invention also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computing device or stored on any usable medium. When the computer program product runs on at least one computing device, it causes the at least one computing device to execute the aforementioned playback request authentication method, such as the method shown in any of Figures 5 to 7 and Figures 9 to 11.
[0369] This invention also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute a playback request authentication method, such as the method shown in any of Figures 5 to 7 and Figures 9 to 11.
[0370] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0371] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0372] The basic principles of the present invention have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in the present invention are merely examples and not limitations, and should not be considered as essential features of the various embodiments of the present disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of the present disclosure to the necessity of employing the specific details described above.
[0373] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.
[0374] It should also be noted that in the apparatus, devices, and methods of this disclosure, the components or steps can be disassembled and / or recombined. These disassemblies and / or recombinations should be considered as equivalent solutions to this disclosure.
[0375] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
[0376] It is understood that the various numerical designations used in the embodiments of the present invention are merely for descriptive convenience and are not intended to limit the scope of the embodiments of the present invention.
Claims
1. A method for authenticating playback requests, characterized in that, The method includes: Obtain authentication data from the playback request, the authentication data including the playback domain name and the client identifier, the playback request being sent by the client to the service node, the service node being located in a service node cluster; Obtain the authentication rules corresponding to the playback domain name. The authentication rules include authentication indicators and authentication conditions corresponding to the authentication indicators. The authentication indicators are used to measure the security of global playback for the playback domain name. Based on the client's identifier and the playback domain name, the value of the authentication indicator is obtained. The indicator value is used to indicate the global playback status of the client for the playback domain name in the service node cluster. Determine whether the index value meets the authentication conditions to obtain the authentication result.
2. The method according to claim 1, characterized in that, The authentication condition is less than or equal to a preset threshold; The step of determining whether the indicator value meets the authentication condition to obtain the authentication result includes: If the value of the indicator is less than or equal to a preset threshold, the authentication result is determined to indicate that the authentication has passed. If the indicator value is greater than a preset threshold, the authentication result is used to indicate that the client is an abnormal client.
3. The method according to claim 1 or 2, characterized in that, The authentication rules also include the statistical period for the authentication metrics; obtaining the metric value of the authentication metrics based on the client's identifier includes: Based on the aforementioned statistical period, the data time period is determined; Based on the client's identifier and the playback domain name, obtain the authentication index value for the data period.
4. The method according to any one of claims 1 to 3, characterized in that, The client's identifier includes the token used by the client and the client's address; The authentication indicators include a first indicator and a second indicator; The step of obtaining the indicator value corresponding to the authentication indicator based on the client's identifier includes: Based on the token and the playback domain name, a first indicator value of the first indicator is determined, wherein the first indicator value is used to indicate the global number of times the token is used for the playback domain name in the service node cluster; Based on the client's address and the playback domain name, a second indicator value for the second indicator is determined. The second indicator value is used to indicate the global playback count or global playback duration of the client for the playback domain name in the service node cluster.
5. The method according to any one of claims 1 to 3, characterized in that, The step of obtaining the authentication index value based on the client's identifier and the playback domain name includes: Based on the client's identifier, global playback data is obtained. This global playback data is used to instruct the service node cluster to process the data during the client's historical playback request process for the playback domain name. Based on the global playback data, the value of the authentication metric is determined.
6. The method according to any one of claims 1 to 5, characterized in that, The global playback status includes at least one or more of the following: The client's total playback duration, the client's total number of playbacks, the client's average playback duration, the client's concurrent playback count, and the client's average concurrent playback duration.
7. The method according to any one of claims 1 to 6, characterized in that, The step of obtaining the authentication rules corresponding to the playback domain name includes: Obtain the authentication rules corresponding to the playback domain name input by the user.
8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: The authentication result is sent to the service node so that the service node, after the authentication result indicates that the authentication is successful, responds to the playback request by sending playback content to the client.
9. A playback request authentication device, characterized in that, The device includes: The authentication module is used to obtain authentication data from the playback request. The authentication data includes the playback domain name and the client's identifier. The playback request is sent by the client to the service node, and the service node is located in the service node cluster. The rule acquisition module is used to acquire the authentication rules corresponding to the playback domain name. The authentication rules include authentication indicators and authentication conditions corresponding to the authentication indicators. The authentication indicators are used to measure the security of global playback for the playback domain name. The indicator value acquisition module is used to acquire the indicator value of the authentication indicator based on the identifier of the client. The indicator value is used to indicate the global playback status of the client for the playback domain name in the service node cluster. The authentication module is used to determine whether the indicator value meets the authentication conditions in order to obtain the authentication result.
10. The apparatus according to claim 9, characterized in that, The authentication condition is less than or equal to a preset threshold; The authentication module is used to determine the authentication result to indicate that the authentication is successful when the indicator value is less than or equal to a preset threshold; and to determine the authentication result to indicate that the client is an abnormal client when the indicator value is greater than the preset threshold.
11. The apparatus according to claim 9 or 10, characterized in that, The authentication rules also include the statistical period for the authentication indicators; The indicator value acquisition module is used to determine the data period based on the statistical period; and to obtain the indicator value of the authentication indicator for the data period based on the client's identifier and the playback domain name.
12. The apparatus according to any one of claims 9 to 11, characterized in that, The client's identifier includes the token used by the client and the client's address; The authentication indicators include a first indicator and a second indicator; The indicator value acquisition module is used to determine a first indicator value of the first indicator based on the token and the playback domain name. The first indicator value is used to indicate the global number of times the token is used for the playback domain name in the service node cluster. Based on the client's address and the playback domain name, a second indicator value for the second indicator is determined. The second indicator value is used to indicate the global playback count or global playback duration of the client for the playback domain name in the service node cluster.
13. The apparatus according to any one of claims 9 to 11, characterized in that, The indicator value acquisition module is used to acquire global playback data based on the client's identifier. The global playback data is used to instruct the service node cluster on the data during the processing of the client's historical playback requests. Based on the global playback data, the value of the authentication metric is determined.
14. The apparatus according to any one of claims 9 to 13, characterized in that, The global playback status includes at least one or more of the following: The client's total playback duration, the client's total number of playbacks, the client's average playback duration, the client's concurrent playback count, and the client's average concurrent playback duration.
15. The apparatus according to any one of claims 9 to 14, characterized in that, The rule acquisition module is used to acquire the authentication rules corresponding to the playback domain name input by the user.
16. The apparatus according to any one of claims 9 to 15, characterized in that, The device further includes: The sending module is used to send the authentication result to the service node, so that the service node, after the authentication result indicates that the authentication is successful, responds to the playback request and sends playback content to the client.
17. A service node, characterized in that, Includes processor and memory; among which, The memory is used to store a program; the processor is used to execute the program stored in the memory, and when the program stored in the memory is executed, performs the method as described in any one of claims 1 to 8.
18. An authentication node, characterized in that, Includes processor and memory; among which, The memory is used to store a program; the processor is used to execute the program stored in the memory, and when the program stored in the memory is executed, performs the method as described in any one of claims 1 to 8.
19. A computing device cluster, characterized in that, It includes at least one computing device, each computing device including a processor and memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method as described in any one of claims 1 to 8.
20. A computer program product containing instructions, characterized in that, When the instruction is executed by the computing device cluster, the computing device cluster causes the computing device cluster to perform the method as described in any one of claims 1 to 8.
21. A computer-readable storage medium, characterized in that, Includes computer program instructions, which, when executed by a cluster of computing devices, perform the method as described in any one of claims 1 to 8.