Data encryption method and device, and remote desktop system
By detecting exceptions and encrypting keywords in the remote desktop system, the problem of insufficient security of the remote desktop system is solved, and information security is ensured.
Patent Information
- Application Number
- CN202110963713.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-20
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2041-08-20
AI Technical Summary
The existing remote desktop system is poor in security, which can easily lead to cloud information leakage.
When an abnormality is detected, the remote desktop system enters a secure working mode, ensuring data security by detecting whether the terminal device copies data and encrypting keywords.
Improve the security of the remote desktop system, prevent illegal users from copying important information, and avoid information leakage.
Smart Images

Figure CN113656820B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of desktop virtualization, and more specifically, to a data encryption method and device, and a remote desktop system. Background Art
[0002] Desktop virtualization (VDI) refers to the virtualization of a computer's terminal system (also known as a desktop) to achieve security and flexibility in desktop use. A personal desktop system can be accessed via the network from any device, anywhere, and at any time. By utilizing virtualization technology, various physical devices can be virtualized, effectively improving resource utilization, thereby saving costs and improving application quality. With the support of virtualization technology, the connection between network software and hardware devices will be more flexible, and scalability will be greatly improved. Cloud desktops utilize virtualization technology to essentially centrally store and manage various user information. Through simple network access devices, users can access the cloud desktop for centralized management and efficient resource sharing.
[0003] With the development and maturity of cloud computing, the use scenarios of cloud desktops are becoming more and more extensive. Many industries such as universities, medical care, and government are gradually popularizing cloud desktop office work, and cloud desktops will also be an overall trend in the future.
[0004] In this scenario, once the host is controlled by illegal personnel, content can be copied and pasted at will, resulting in information leakage. Therefore, how to ensure the security of cloud information has become an urgent problem to be solved.
[0005] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0006] The embodiments of the present application provide a data encryption method and device, and a remote desktop system to at least solve the technical problem that the current remote desktop system has poor security and is prone to cloud information leakage.
[0007] According to one aspect of an embodiment of the present application, a data encryption method is provided, which is applied to a remote desktop system, wherein the remote desktop system includes a server and multiple terminal devices, wherein multiple virtual machines are running on the server, and each virtual machine corresponds to a terminal device. The method includes the following steps: when an abnormality is detected in the current use environment of the remote desktop system, controlling the remote desktop system to enter a safe working mode; in the safe working mode, detecting whether any terminal device among the multiple terminal devices copies data from the virtual machine running on the server; when any terminal device among the multiple terminal devices is detected to have copied data from the virtual machine, encrypting the copied data.
[0008] Optionally, detecting whether there is an abnormality in the current usage environment of the remote desktop system includes at least one of the following: if target audio data is detected in the current usage environment of the remote desktop system, determining that there is an abnormality in the current usage environment of the remote desktop system; if it is identified that the facial image of the user of any terminal device does not match the pre-stored user facial image, determining that there is an abnormality in the current usage environment of the remote desktop system.
[0009] Optionally, the copied data is encrypted, including: selecting keywords from the copied data, wherein the keywords include first-type keywords and second-type keywords, the first-type keywords include: name, email address, telephone number, target noun and target business information, and the second-type keywords are different from the first-type keywords; encrypting the keywords.
[0010] Optionally, before selecting keywords from the copied data, the method further includes: collecting first-type keywords to obtain a first form; reducing redundant information of the first-type keywords in the first form to obtain a second form; and refining the first-type keywords in the first form to obtain a third form.
[0011] Optionally, selecting the first type of keywords from the copied data includes: matching the data with a third form to obtain a matching result, wherein the matching result includes the first type of keywords contained in the data and location information of the first type of keywords in the data; matching the matching result with the second form to obtain the first type of keywords contained in the data.
[0012] Optionally, selecting the second type of keywords from the copied data includes: selecting numbers from the data to obtain the second type of keywords contained in the data.
[0013] Optionally, encrypting the keywords includes one of the following methods: encrypting the keywords in the data using a preset encryption algorithm; replacing the keywords in the data with target symbols; and randomly generating garbled codes from the keywords in the data.
[0014] Optionally, when it is detected that there is no abnormality in the current usage environment of the remote desktop system, the remote desktop system is controlled to exit the safe working mode; detecting that there is no abnormality in the current usage environment of the remote desktop system includes at least one of the following: if it is detected that any terminal device inputs a preset instruction, it is determined that there is no abnormality in the current usage environment of the remote desktop system; if it is identified that the facial image of the user of any terminal device matches the pre-stored user facial image, it is determined that there is no abnormality in the current usage environment of the remote desktop system.
[0015] According to another aspect of an embodiment of the present application, a remote desktop system is also provided, including: a server and multiple terminal devices, multiple virtual machines running on the server, each virtual machine corresponding to a terminal device, wherein the multiple terminal devices are used to control the multiple virtual machines running on the server; the server is used to execute the above data encryption method.
[0016] According to another aspect of an embodiment of the present application, a data encryption device is also provided, including: a control module, used to control the remote desktop system to enter a safe working mode when an abnormality is detected in the current use environment of the remote desktop system, wherein the remote desktop system includes a server and multiple terminal devices, and multiple virtual machines are running on the server, and each virtual machine corresponds to a terminal device; a detection module, used to detect whether any terminal device among the multiple terminal devices copies data from the virtual machine running on the server in the safe working mode; an encryption module, used to encrypt the copied data when it is detected that any terminal device among the multiple terminal devices copies data from the virtual machine.
[0017] According to another aspect of the embodiments of the present application, a non-volatile storage medium is provided. The non-volatile storage medium includes a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the above data encryption method.
[0018] According to another aspect of the embodiments of the present application, a processor is further provided, which is used to run a program stored in a memory, wherein the above data encryption method is executed when the program is running.
[0019] In an embodiment of the present application, a data encryption method is provided, which is applied to a remote desktop system, wherein the remote desktop system includes a server and multiple terminal devices, wherein multiple virtual machines are run on the server, and each virtual machine corresponds to a terminal device, and comprises the following steps: when an abnormality is detected in the current use environment of the remote desktop system, controlling the remote desktop system to enter a safe working mode; in the safe working mode, detecting whether any terminal device among the multiple terminal devices copies data from the virtual machine running on the server; when any terminal device among the multiple terminal devices is detected to have copied data from the virtual machine, encrypting the copied data, and performing special encryption processing on the content initiated by the user to copy in an unsafe scenario, thereby ensuring that illegal users cannot copy the correct content, thereby ensuring the security of the information, thereby achieving the technical effect of improving the security of the remote desktop system and avoiding information leakage in the remote desktop system, and thus solving the technical problem that the current remote desktop system has poor security and is prone to cloud information leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0021] Figure 1 It is a schematic diagram of desktop virtualization technology;
[0022] Figure 2 is a flow chart of a data encryption method according to an embodiment of the present application;
[0023] Figure 3 is a structural block diagram of a remote desktop system according to an embodiment of the present application;
[0024] Figure 4 This is a structural block diagram of a data encryption device according to an embodiment of the present application. DETAILED DESCRIPTION
[0025] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0026] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0027] Figure 1 It is a schematic diagram of desktop virtualization technology, such as Figure 1As shown, VDI, in simple terms, is to virtualize the user's desktop by running Windows or other types of operating systems on clustered servers in the data center. Users connect to the virtual desktop (usually a virtual machine) through the client computing protocol from the client device (zero terminal). Users access the virtual desktop through the zero terminal just like accessing a traditional locally installed desktop. As long as there is a network, users can connect to the desktop they want to connect to at any time and any place. IT personnel can more easily manage desktop users and data because all data is with the service provider, and customer data is more secure. Users can access the virtual machine assigned to them on the cluster server through the zero terminal to obtain the desktop image and control the obtained virtual desktop through reverse control.
[0028] The VDI virtual desktop solution works by installing server virtualization software on a server, creating a dedicated virtual machine for each user. The virtual desktop software, along with the user's required operating system and various applications, is then deployed within the virtual machine. The complete virtual desktop is then delivered to the remote user via the desktop remote display protocol. Essentially, desktop virtualization delivers only a single screen to the end user; application installation, deployment, operation, and management are all handled on the data center's servers. The user's mouse clicks, movements, and keyboard strokes are processed by the server, and the results are then returned to the user.
[0029] Desktop virtualization delivers only a screen to the end user. The installation, deployment, operation and management of applications are actually performed on the server in the data center. By isolating data and users, security is achieved; however, it cannot prevent data from being transmitted in text form over the network or other means.
[0030] Without solving the above technical problems, the present application proposes a data encryption method, which will be described in detail below in conjunction with specific embodiments.
[0031] According to an embodiment of the present application, an embodiment of a data encryption method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0032] Figure 2 This is a flow chart of a data encryption method according to an embodiment of the present application, which is applied to a remote desktop system. The remote desktop system includes a server and multiple terminal devices, wherein multiple virtual machines are running on the server, and each virtual machine corresponds to a terminal device, such as Figure 2 As shown, the method includes the following steps:
[0033] Step S202: When an abnormality is detected in the current use environment of the remote desktop system, the remote desktop system is controlled to enter a safe working mode;
[0034] According to an optional embodiment of the present application, detecting whether there is an abnormality in the current usage environment of the remote desktop system includes at least one of the following: if target audio data is detected in the current usage environment of the remote desktop system, determining that there is an abnormality in the current usage environment of the remote desktop system; if it is identified that the facial image of the user of any terminal device does not match the pre-stored user facial image, determining that there is an abnormality in the current usage environment of the remote desktop system.
[0035] It should be noted that after the remote desktop system establishes a connection, users can copy and paste graphic and text content normally.
[0036] Copying text and image content refers to the process of copying the contents of a text file (such as Word, WPS, or Excel) to another text file or to the sending interface of other application software (such as WeChat, DingTalk, or Email). When the remote desktop system is not in safe mode, users can copy and paste text content normally.
[0037] When the remote desktop system detects that the current usage environment is unsafe, it enters safe mode and starts monitoring all clipboard operations.
[0038] Specifically, the detection of the current usage environment being unsafe can be achieved in a variety of ways: when abnormal sounds are detected, such as gunshots, explosions, cries for help, screams, etc.; or, facial recognition technology can be used to detect that the person currently using the user device is not a legitimate user, etc.
[0039] When it is detected that the current usage environment is unsafe, it enters safe mode. In safe mode, the clipboard operations are monitored to monitor the content copying operations of possible illegal users, and the copied content is processed in the clipboard to prevent illegal users from copying the real and complete content, thereby preventing information leakage.
[0040] Step S204: In the secure working mode, detecting whether any of the multiple terminal devices copies data from the virtual machine running on the server;
[0041] Step S206: When it is detected that any one of the plurality of terminal devices copies data from the virtual machine, the copied data is encrypted.
[0042] If it is detected that data (drawing or text content) is written to the current clipboard buffer area, the data will be encrypted before being pasted.
[0043] The focus of this step is how to encrypt data. Specifically, when data is detected to be written to the clipboard cache area, the data in the clipboard is specially encrypted before being read, and then the processed data is used for pasting.
[0044] Through the above steps, by performing special encryption processing on the content initiated by the user in an unsafe scenario, it is ensured that illegal users cannot copy the correct content, thereby ensuring the security of the information, thereby achieving the technical effect of improving the security of the remote desktop system and avoiding information leakage in the remote desktop system.
[0045] According to another optional embodiment of the present application, when executing step S206, the copied data is encrypted, which is achieved by the following method: selecting keywords from the copied data, wherein the keywords include first-type keywords and second-type keywords, the first-type keywords include: name, email address, telephone number, target noun and target business information, and the second-type keywords are different from the first-type keywords; encrypting the keywords.
[0046] Data encryption is implemented in two modules: a keyword information repository and encryption processing. The keyword information repository integrates all keyword information and stores it in a configuration file for information matching during encryption. The encryption processing method reads data from the clipboard, filters the data for keywords, and encrypts the keywords.
[0047] Keywords can be divided into special keywords (i.e., the first type of keywords mentioned above) and general keywords (i.e., the second type of keywords mentioned above). Special keywords include names, email addresses, phone numbers, professional terms, and user-customized professional information. General keywords can be numbers, for example, meaning that all numbers appearing in the text are encrypted. In actual implementation, you can specify both special keywords and general keywords based on actual needs, or you can specify only special keywords and omit general keywords.
[0048] In some optional embodiments of the present application, before selecting keywords from the copied data, first-type keywords are collected to obtain a first form; redundant information of the first-type keywords in the first form is reduced to obtain a second form; and the first-type keywords in the first form are refined to obtain a third form.
[0049] It should be noted that this step is the process of building a keyword information resource library. Specifically, the first form can be obtained by arranging the special keywords. The special keywords can be arranged from a preset database, or the first type of keywords can be crawled from the Internet.
[0050] The first type of keywords in the first form are processed with dimensionality reduction to reduce redundant information and make them easier to match. For example, the name format is organized into 2-4 characters; the phone number is 11 digits and 12 digits with area code or other; the email format is organized into a specific string + "@" + a specific string, etc., to obtain the second form.
[0051] The first type of keywords in the first form are refined, for example: common or as many surnames as possible are collected to match names; phone number prefixes such as 139 / 187 / area codes of various regions / inter-regional numbers of a country are collected to match phone numbers; precise address keywords are collected to match address information; various email suffixes are collected to match email addresses; and so on, various refinement methods are used to obtain the third form.
[0052] In other optional embodiments of the present application, selecting first-type keywords from copied data includes the following steps: matching the data with a third form to obtain a matching result, wherein the matching result includes the first-type keywords contained in the data and location information of the first-type keywords in the data; matching the matching result with the second form to obtain the first-type keywords contained in the data.
[0053] In this step, special keywords and / or general keywords are identified. The identification of special keywords includes the following process:
[0054] 1) Extract the information in the third form, match it with the copied data, and record the matching results and the location of the matching text;
[0055] 2) Perform a secondary match on the matching results in step 1) in the second table to obtain the first type of keywords present in the copied data.
[0056] According to an optional embodiment of the present application, selecting the second type of keywords from the copied data includes: selecting numbers from the data to obtain the second type of keywords contained in the data.
[0057] For common keywords, it is possible to identify whether they are common keywords in the full text of the data. For example, if the common keyword is a number, all numbers in the full text are identified.
[0058] According to another optional embodiment of the present application, the keyword is encrypted, including one of the following methods: encrypting the keyword in the data using a preset encryption algorithm; replacing the keyword in the data with a target symbol; randomly generating garbled code for the keyword in the data.
[0059] In this step, the matched keywords are encrypted (using a message digest algorithm such as MD5); or, special processing similar to the encryption function is also performed; specifically, the special processing refers to replacing all found keywords with special symbols or a combination of special symbols, including but not limited to: *, ~, !, @, #, ¥, %, ..., &, +, -, etc.; or, they can be directly replaced with randomly generated garbled characters.
[0060] The specially processed ciphertext is used to replace the original text in the clipboard before encryption, and then when the user initiates a paste operation, the data in the clipboard (the specially processed ciphertext) is pasted to the corresponding position.
[0061] In some optional embodiments of the present application, when it is detected that there is no abnormality in the current usage environment of the remote desktop system, the remote desktop system is controlled to exit the safe working mode; detecting that there is no abnormality in the current usage environment of the remote desktop system includes at least one of the following: if it is detected that any terminal device inputs a preset instruction, it is determined that there is no abnormality in the current usage environment of the remote desktop system; if it is identified that the facial image of the user of any terminal device matches the pre-stored user facial image, it is determined that there is no abnormality in the current usage environment of the remote desktop system.
[0062] When it is detected that the current customer environment has been restored to safety, the security mode is exited. Specifically, there are multiple ways to detect whether the current customer environment has been restored to safety. For example, if the method for detecting environmental anomalies is through the recognition of abnormal sounds, the method for determining whether the customer environment has been restored to safety may be to determine that the current customer environment has been restored to safety when a specific password entered by a legitimate user is detected. For another example, if the method for detecting environmental anomalies is through facial recognition, the method for determining whether the customer environment has been restored to safety may be to determine that the current customer environment has been restored to safety when the user of the current device is detected to be a legitimate authorized user.
[0063] The above method provided in the embodiment of the present application encrypts the keywords in the data in the clipboard when the system detects that the current scenario is unsafe, so that illegal users cannot fully decipher the data after obtaining it through the network or other means, and the key information is hidden to achieve data security.
[0064] Figure 3 This is a structural block diagram of a remote desktop system according to an embodiment of the present application. Figure 3As shown, the system includes: a server 30 and multiple terminal devices 32. Multiple virtual machines are running on the server 30, and each virtual machine corresponds to a terminal device 32. The multiple terminal devices 32 are used to control the multiple virtual machines running on the server 30; the server 30 is used to execute the above data encryption method.
[0065] Figure 4 is a structural block diagram of a data encryption device according to an embodiment of the present application, such as Figure 4 As shown, the device includes:
[0066] A control module 40 is configured to control the remote desktop system to enter a safe working mode when an abnormality is detected in the current use environment of the remote desktop system, wherein the remote desktop system includes a server and multiple terminal devices, and the server runs multiple virtual machines, each virtual machine corresponding to a terminal device;
[0067] A detection module 42 is configured to detect, in a secure working mode, whether any of the multiple terminal devices copies data from a virtual machine running on the server;
[0068] The encryption module 44 is configured to encrypt the copied data when it is detected that any one of the plurality of terminal devices copies data from the virtual machine.
[0069] It should be noted that Figure 4 The preferred implementation of the embodiment shown can be found in Figure 2 The relevant description of the illustrated embodiment will not be repeated here.
[0070] An embodiment of the present application further provides a non-volatile storage medium, which includes a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the above data encryption method.
[0071] The above-mentioned non-volatile storage medium is used to store programs that perform the following functions: when an abnormality is detected in the current usage environment of the remote desktop system, controlling the remote desktop system to enter a safe working mode; in the safe working mode, detecting whether any terminal device among multiple terminal devices copies data from a virtual machine running on a server; when any terminal device among multiple terminal devices is detected to have copied data from a virtual machine, encrypting the copied data.
[0072] An embodiment of the present application further provides a processor, which is used to run a program stored in a memory, wherein the above data encryption method is executed when the program is running.
[0073] The above-mentioned processor is used to run a program that performs the following functions: when an abnormality is detected in the current usage environment of the remote desktop system, controlling the remote desktop system to enter a safe working mode; in the safe working mode, detecting whether any terminal device among multiple terminal devices copies data from a virtual machine running on a server; when any terminal device among multiple terminal devices is detected to have copied data from a virtual machine, encrypting the copied data.
[0074] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0075] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0076] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0077] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0078] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0079] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the relevant technology or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0080] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A data encryption method, characterized in that: The method is applied to a remote desktop system, which includes a server and multiple terminal devices, wherein multiple virtual machines are running on the server, each virtual machine corresponding to one of the terminal devices, and includes the following steps: When detecting that an abnormality exists in the current use environment of the remote desktop system, controlling the remote desktop system to enter a safe working mode; In the secure working mode, detecting whether any terminal device among the plurality of terminal devices copies data from the virtual machine running on the server; When detecting that any one of the plurality of terminal devices copies data from the virtual machine, encrypting the copied data; Detecting an abnormality in the current use environment of the remote desktop system includes at least one of the following: If it is detected that the target audio data exists in the current use environment of the remote desktop system, determining that an abnormality exists in the current use environment of the remote desktop system; If it is recognized that the facial image of the user of any one of the terminal devices does not match the pre-stored user facial image, it is determined that an abnormality exists in the current use environment of the remote desktop system; The step of encrypting the copied data includes: Selecting keywords from the copied data, wherein the keywords include first-type keywords and second-type keywords; encrypting the keyword; Before selecting keywords from the copied data, the method further includes: Collect the first type of keywords to obtain a first form; reducing redundant information of the first type of keywords in the first form to obtain a second form; performing refinement processing on the first type of keywords in the first form to obtain a third form; Matching the data with the third form to obtain a matching result, wherein the matching result includes the first type of keywords contained in the data and location information of the first type of keywords in the data; Matching the matching result with the second form to obtain the first type of keywords contained in the data; The method further comprises: When it is detected that there is no abnormality in the current use environment of the remote desktop system, controlling the remote desktop system to exit the safe working mode; Detecting that there is no abnormality in the current use environment of the remote desktop system includes at least one of the following: If it is detected that any of the terminal devices inputs a preset instruction, it is determined that there is no abnormality in the current use environment of the remote desktop system; If it is recognized that the facial image of the user of any one of the terminal devices matches the pre-stored user facial image, it is determined that there is no abnormality in the current use environment of the remote desktop system.
2. The method according to claim 1, characterized in that Encrypting the copied data includes: The first type of keywords includes: name, email address, phone number, target noun and target business information. The second type of keywords is different from the first type of keywords.
3. The method according to claim 2, characterized in that Selecting the second type of keywords from the copied data includes: selecting numbers from the data to obtain the second type of keywords contained in the data.
4. The method according to claim 2, characterized in that The keyword is encrypted, including one of the following methods: Encrypting the keywords in the data using a preset encryption algorithm; replacing keywords in the data with target symbols; Randomly generate garbled characters from the keywords in the data.
5. A remote desktop system, characterized in that: include: A server and multiple terminal devices, wherein multiple virtual machines are running on the server, and each virtual machine corresponds to one terminal device, wherein: The multiple terminal devices are used to control the multiple virtual machines running on the server; The server is used to execute the data encryption method described in any one of claims 1 to 4.
6. A data encryption device, characterized in that: include: a control module configured to control the remote desktop system to enter a safe working mode when an abnormality is detected in the current use environment of the remote desktop system, wherein the remote desktop system includes a server and a plurality of terminal devices, the server running a plurality of virtual machines, each virtual machine corresponding to one of the terminal devices; A detection module, configured to detect, in the secure working mode, whether any of the plurality of terminal devices copies data from the virtual machine running on the server; an encryption module, configured to encrypt the copied data when detecting that any one of the plurality of terminal devices copies data from the virtual machine; The control module is further configured to: determine that an abnormality exists in the current use environment of the remote desktop system if target audio data is detected in the current use environment of the remote desktop system; and determine that an abnormality exists in the current use environment of the remote desktop system if a facial image of a user of any of the terminal devices is not matched with a pre-stored user facial image; The device is further configured to select keywords from the copied data, wherein the keywords include first-type keywords and second-type keywords; and encrypt the keywords; The device is further configured to collect the first type of keywords to obtain a first form; reduce redundant information of the first type of keywords in the first form to obtain a second form; and perform precision processing on the first type of keywords in the first form to obtain a third form. Wherein, the device is also used to match the data with the third form to obtain a matching result, wherein the matching result includes the first type of keywords contained in the data, and the position information of the first type of keywords in the data; match the matching result with the second form to obtain the first type of keywords contained in the data; wherein, the device is also used to control the remote desktop system to exit the safe working mode when it is detected that there is no abnormality in the current use environment of the remote desktop system; detecting that there is no abnormality in the current use environment of the remote desktop system includes at least one of the following: if it is detected that any one of the terminal devices inputs a preset instruction, it is determined that there is no abnormality in the current use environment of the remote desktop system; if it is identified that the facial image of the user of any one of the terminal devices matches the pre-stored user facial image, it is determined that there is no abnormality in the current use environment of the remote desktop system.
7. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the data encryption method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Data encryption method, device and equipment and storage medium
CN111158857A