Data protection method, device and desktop cloud system
By establishing a two-way connection and continuous detection mechanism in the desktop cloud system, verifying login information and environmental information, the problem of low data security is solved, and secure and efficient user access and data protection is achieved.
Patent Information
- Application Number
- CN202011541360.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-23
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2040-12-23
AI Technical Summary
Desktop cloud systems have low data security, especially under complex typical IT infrastructure, making it difficult to prevent external and horizontal attacks.
By establishing a two-way connection between the cloud management platform and the cloud terminal, verifying login information and environment information, continuously detecting user sessions and terminal status, restricting access rights, and encrypting response data in data transmission to include watermarks.
It improves the security of data transmission, prevents data leakage and horizontal attacks, reduces enterprise operation and maintenance costs, and realizes a safe and efficient user and terminal equipment access mechanism.
Smart Images

Figure CN114662080B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of desktop cloud, and particularly to a data protection method, apparatus, and desktop cloud system. Background Art
[0002] In the construction of traditional enterprise networks, the PC is both the foundation and the core. However, during the network setup process of the PC, a series of problems are prone to occur, such as complex configuration and deployment, high software and hardware upgrade costs, scattered confidential data, and imperfect data security guarantee mechanisms, which are not conducive to the centralized management and maintenance of data. The traditional PC office mode can be replaced by diversified terminal devices, that is, as Figure 1 shown in the desktop cloud system to improve the office efficiency of enterprise employees and reduce the enterprise operation and maintenance costs.
[0003] From Figure 1 it can be seen that the desktop cloud system may include: a cloud terminal, a cloud management platform, and a cloud application server. Among them, the cloud terminal is respectively connected to the cloud management platform through a switch, and the cloud management platform is connected to the cloud application server. Among them, cloud applications are deployed in the cloud application server, and the cloud terminal is the client for users to access the cloud applications. The cloud management platform is used to manage the server side of the cloud terminal and the cloud applications.
[0004] At the same time, the typical IT infrastructure of enterprises has become increasingly complex. An enterprise may operate multiple internal networks, have branches with local infrastructure, individuals with remote office access or mobile office, and services on the cloud. This complexity has exceeded the traditional network security strategy based on perimeter defense because there is no single, clearly distinguishable enterprise boundary. For network security control based on perimeter defense, once an attacker breaks through the boundary, further lateral attacks will be unhindered.
[0005] Therefore, the current desktop cloud system based on the typical IT infrastructure has relatively low data security. Summary of the Invention
[0006] This application provides a data protection method, apparatus, and desktop cloud system, aiming to solve the problem of relatively low data security of the desktop cloud system.
[0007] To achieve the above objective, this application provides the following technical solutions:
[0008] This application provides a data protection method, which is applied to the cloud management platform in the desktop cloud system. The method includes:
[0009] After authenticating the authentication request of the cloud terminal, establish a two-way connection with the cloud terminal, and send the login page of the desktop cloud system to the cloud terminal;
[0010] In the case of receiving the login information sent by the cloud terminal, verify the target information; the target information includes: the login information and the environmental information of the cloud terminal; the environmental information includes: whether the cloud terminal is connected to an unfiled storage peripheral, whether there are high-risk vulnerabilities and viruses in the cloud desktop system;
[0011] In the case of passing the verification of the target information, return the desktop cloud system and the target cloud applications to the cloud terminal; the target cloud applications refer to: the cloud applications that the user is allowed to access according to the preset access control policy;
[0012] During the process of the user accessing the target cloud applications, continuously detect whether any of the target conditions is met; the target conditions include: whether the user's single-session access duration exceeds the preset duration, whether the user's access time exceeds the preset time range, and whether there is dangerous environmental information in the cloud terminal;
[0013] In the case of detecting that any of the target conditions is met, stop responding to the user's access request for the target cloud applications.
[0014] Optionally, after returning the desktop cloud system and the target cloud applications to the cloud terminal in the case of passing the verification of the target information, it further includes:
[0015] In the case of receiving the encrypted access request sent by the cloud terminal, decrypt the encrypted access request and send the decrypted access request to the cloud application;
[0016] In the case of receiving the response data of the cloud application to the decrypted access request, convert the response result into an image; the image contains a watermark of the basic user information of the cloud terminal; the watermark is located under the image layer of the image;
[0017] Encrypt the image to obtain the encrypted image;
[0018] Send the encrypted image to the cloud terminal.
[0019] Optionally, the target information further includes: the login location information of the cloud terminal and the login time information of the cloud terminal.
[0020] Optionally, it further includes:
[0021] In the case of failing to pass the verification of the target information, send a prompt message indicating the user authorization error to the cloud terminal, and return the login page to the cloud terminal.
[0022] Optionally, it further includes:
[0023] When any of the target conditions is detected, send a prompt message indicating the user authorization error to the cloud terminal, and send the login page to the cloud terminal.
[0024] This application also provides a data protection method, which is applied to a cloud terminal in a desktop cloud system. The method includes:
[0025] When receiving a startup instruction from a user, send an authentication request to the cloud management platform;
[0026] After establishing a two-way connection with the cloud management platform, when receiving the login page of the desktop cloud system sent by the cloud management platform, display the login page;
[0027] When receiving the login information input by the user on the login page, send the login information to the cloud management platform;
[0028] After receiving the target cloud application and the desktop cloud system sent by the cloud management platform, if receiving an access instruction for the target cloud application triggered by the user, send the encrypted access request to the cloud management platform.
[0029] Optionally, it further includes:
[0030] When receiving the encrypted image sent by the cloud management platform, decrypt the encrypted image to obtain the decrypted image; the encrypted image refers to: the cloud management platform converts the response data of the cloud server in response to the access request into an image and encrypts the image;
[0031] Restore the decrypted image to obtain the response data.
[0032] This application also provides a data protection device, which is applied to a cloud management platform in a desktop cloud system and includes:
[0033] A first execution module, configured to establish a two-way connection with the cloud terminal after passing the authentication request of the cloud terminal, and send the login page of the desktop cloud system to the cloud terminal;
[0034] A verification module, configured to verify target information when receiving the login information sent by the cloud terminal; the target information includes: the login information and the environment information of the cloud terminal; the environment information includes: whether the cloud terminal is connected to an unrecorded storage peripheral, whether there are high-risk vulnerabilities and viruses in the cloud desktop system;
[0035] The first sending module is used to return the desktop cloud system and the target cloud application to the cloud terminal when the verification of the target information is passed; the target cloud application refers to the cloud application that the user is allowed to access according to the preset access control policy.
[0036] The detection module is used to continuously detect whether any of the target conditions are met during the user's access to the target cloud application; the target conditions include: whether the user's single-session access duration exceeds the preset duration, whether the user's access time exceeds the preset time range, and whether there is dangerous environmental information on the cloud terminal.
[0037] The second execution module is used to stop responding to the user's access request for the target cloud application when it is detected that any of the target conditions are met.
[0038] This application also provides a data protection device, which is applied to the cloud terminal in the desktop cloud system and includes:
[0039] The second sending module is used to send an authentication request to the cloud management platform when receiving the user's startup instruction.
[0040] The display module is used to display the login page of the desktop cloud system after establishing a two-way connection with the cloud management platform and receiving the login page sent by the cloud management platform.
[0041] The third sending module is used to send the login information to the cloud management platform when receiving the login information input by the user on the login page of the desktop cloud system.
[0042] The fourth sending module is used to send the encrypted access request to the cloud management platform when receiving the target cloud application and the desktop cloud system sent by the cloud management platform and then receiving the access instruction triggered by the user for the target cloud application.
[0043] This application also provides a desktop cloud system, including a cloud terminal, a cloud management platform, and a cloud server;
[0044] The cloud terminal sends an authentication request to the cloud management platform when receiving the user's startup instruction.
[0045] After passing the authentication request of the cloud terminal, the cloud management platform establishes a two-way connection with the cloud terminal and sends the login page of the desktop cloud system to the cloud terminal.
[0046] After the cloud terminal establishes a two-way connection with the cloud management platform and receives the login page of the desktop cloud system sent by the cloud management platform, it displays the login page.
[0047] When the cloud terminal receives the login information entered by the user on the login page of the desktop cloud system, it sends the login information to the cloud management platform;
[0048] When the cloud management platform receives the login information sent by the cloud terminal, it verifies the target information; the target information includes: the login information and the environment information of the cloud terminal; the environment information includes: whether the cloud terminal is connected to an unrecorded storage peripheral, whether there are high-risk vulnerabilities and viruses in the cloud desktop system;
[0049] When the cloud management platform passes the verification of the target information, it returns the desktop cloud system and the target cloud application to the cloud terminal; the target cloud application refers to: among the cloud applications deployed by the cloud server, the cloud applications that the user is allowed to access according to the preset access control policy;
[0050] During the process of the user accessing the target cloud application, the cloud management platform continuously detects whether any of the target conditions are met; the target conditions include: whether the user's single-session access duration exceeds the preset duration, whether the user's access time exceeds the preset time range, and whether there is dangerous environment information in the cloud terminal;
[0051] When the cloud management platform detects that any of the target conditions are met, it stops responding to the user's access request for the target cloud application.
[0052] In the data protection method, device and desktop cloud system described in this application, after the cloud management platform passes the authentication request of the cloud terminal, it establishes a two-way connection with the cloud terminal and sends the login page of the desktop cloud system to the cloud terminal; when receiving the login information sent by the cloud terminal, it verifies the target information. In this application, since the target information includes: login information and the environment information of the cloud terminal, where the environment information includes: whether the cloud terminal is connected to an unrecorded storage peripheral, whether there are high-risk vulnerabilities and viruses in the cloud desktop system.
[0053] Therefore, in this application, first, verify multiple aspects of information of the cloud terminal, and if the verification passes, return the desktop cloud system and the target cloud application to the cloud terminal.
[0054] Second, in this application, the target cloud application refers to: according to the preset access control policy, the cloud applications that the user is allowed to access, that is, this application provides minimized authorization for visitors, thus providing a secure and efficient access mechanism for users and terminal devices.
[0055] Third, during the process of a user accessing a target cloud application, continuously detect whether any of the conditions in the target conditions is met. In the case where any of the met conditions is detected, stop responding to the user's access request for the target cloud application. That is, this application continuously detects the cloud terminal, thereby preventing enterprise data leakage and restricting internal lateral movement attacks (for example, when a certain cloud terminal is attacked during the process of accessing the target application and acts as a zombie to attack other cloud terminals), etc.
[0056] In summary, this application can solve the problem of low data security in the desktop cloud system. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0058] Figure 1 Schematic diagram of the application scenario of the data protection method disclosed in the embodiments of this application;
[0059] Figure 2 Flowchart of the data protection method implemented by the desktop cloud system disclosed in the embodiments of this application;
[0060] Figure 3 Schematic diagram of the data response process among the cloud terminal, cloud management platform, and cloud server disclosed in the embodiments of this application;
[0061] Figure 4 Schematic diagram of the structure of a data protection device disclosed in the embodiments of this application;
[0062] Figure 5 Schematic diagram of the structure of another data protection device provided in the embodiments of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0063] The following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the drawings in the embodiments of this application. Obviously, the described embodiments are only some embodiments of this application, rather than all embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application.
[0064] Figure 1A schematic diagram of an application scenario for a data protection method provided by an embodiment of this application, including: a cloud terminal, a cloud management platform, and a cloud application server. Among them, the cloud terminal and the cloud application server are respectively connected to the cloud management platform. Among them, cloud applications are deployed on the cloud server, and for the cloud terminal to access the cloud applications on the cloud server, it needs to pass the authentication of the cloud management platform, that is, after the cloud management platform authenticates the cloud terminal, the cloud terminal can access the cloud applications on the cloud server through the cloud management platform.
[0065] In the embodiment of this application, each cloud terminal cannot access all the cloud applications on the cloud server. Regarding which applications on the cloud server the cloud terminal can access, it is configured by the administrator according to certain policies.
[0066] Specifically, the system administrator uses the pre-set administrator account on the cloud terminal to log in to the management page of the cloud management platform, upload an authorization file for system authorization, and add the login account information of the configuration administrator and the audit administrator. The configuration administrator uses the account assigned by the system administrator on the cloud terminal to log in to the management page of the cloud management platform, add ordinary user information, configure cloud application access information, and configure user access control policies. The ordinary user uses the account information assigned by the configuration administrator to log in on the cloud terminal. After logging in to the cloud desktop system, the accessible cloud applications with corresponding permissions can be seen, and relevant operations can be performed on the cloud applications. The audit administrator uses the account assigned by the system administrator on the cloud terminal to log in to the management page of the cloud management platform, and can view and audit the operation logs of the system administrator and the configuration administrator and the access logs of ordinary users.
[0067] Among them, the above-mentioned system administrator refers to: the one who can log in to the service page of the cloud management platform and has the permissions to manage the configuration administrator and the audit administrator and manage system authorization. The configuration administrator refers to: the one who can log in to the service page of the cloud management platform and has the permissions to manage ordinary users, cloud terminals, cloud applications, and access control policies. The audit administrator refers to: the one who can log in to the service page of the cloud management platform and has the permissions to audit the operation logs of the system administrator and the configuration administrator and the access logs of ordinary users. The ordinary user refers to: the one who can access the cloud applications on the cloud desktop through the cloud terminal. For the convenience of description, it is hereinafter simply referred to as the user.
[0068] Figure 2 The data protection method in the desktop cloud system provided by the embodiment of this application may include the following steps:
[0069] S201. When the cloud terminal receives a start instruction from the user, it sends an authentication request to the cloud management platform.
[0070] S202. After the cloud management platform passes the authentication of the authentication request, it establishes a two-way connection with the cloud terminal.
[0071] In this embodiment, the two-way connection may specifically be a TCP connection.
[0072] S203. The cloud management platform sends the login page of the desktop cloud system to the cloud terminal.
[0073] S204. When the cloud terminal receives the login page of the desktop cloud system sent by the cloud management platform, it displays the login page.
[0074] S205. When the cloud terminal receives the login information entered by the user on the login page of the desktop cloud system, it sends the login information to the cloud management platform.
[0075] In this embodiment, the login information may include: username, password, and the mobile dynamic verification code obtained from the bound mobile phone.
[0076] S206. The cloud management platform verifies the target information.
[0077] In this embodiment, the target information includes: login information and the environmental information of the cloud terminal.
[0078] Optionally, in this embodiment, the target information may further include: the login location information of the cloud terminal and the login time information of the cloud terminal.
[0079] In this embodiment, the environmental information may include: whether the cloud terminal is connected to an unrecorded storage peripheral, and whether there are high-risk vulnerabilities and viruses in the cloud desktop system.
[0080] S207. The cloud management platform determines whether the target information passes the verification. If so, it executes S208. If not, it executes S211.
[0081] In this embodiment, if the login information in the target information is legal, and the environmental information is not connected to an unrecorded storage peripheral and there are no high-risk vulnerabilities and viruses in the cloud desktop system, it means that the target information passes the verification. Otherwise, it means that the target information fails the verification.
[0082] S208. The cloud management platform returns the desktop cloud system and the target cloud application to the cloud terminal.
[0083] In this embodiment, the target cloud application refers to the cloud application that the user is allowed to access according to the preset access control policy.
[0084] In this embodiment, the cloud management platform returns the desktop cloud system and the target cloud application to the cloud terminal, indicating that the user can access the target cloud application on the cloud terminal. Among them, the specific access interaction process is introduced in the Figure 3 corresponding embodiment and will not be elaborated here.
[0085] S209. During the process of the cloud management platform being accessed by the user to the target cloud application, continuously detect whether any of the conditions in the target conditions is met. If so, execute S210; if not, execute S209.
[0086] In this embodiment, the target conditions may include: whether the single - session access duration of the user exceeds the preset duration, whether the access time of the user exceeds the preset time range, and whether there is dangerous environmental information on the cloud terminal.
[0087] In this step, if any of the conditions in the target conditions is met, execute S210; if all of the conditions in the target conditions are not met, continue to execute this step, that is, continue to detect whether any of the conditions in the target conditions is met.
[0088] S210. The cloud management platform stops responding to the user's access request for the target cloud application.
[0089] In this embodiment, after executing this step, execute S211.
[0090] S211. The cloud management platform sends a prompt message indicating user authorization error to the cloud terminal, and sends a login page to the cloud terminal.
[0091] In the embodiment of this application, after the cloud management platform passes the verification of the target information, it sends the desktop cloud system and the target cloud application to the cloud terminal, and the user of the cloud terminal can access the target cloud application. In order to improve the protection of data security during the process of the user accessing the target cloud application, in addition to continuously detecting whether any of the conditions in the target conditions in S209 is met, in the embodiment of this application, the cloud management platform also processes the response data, where the response data is the response data of the cloud server to the access request of the cloud terminal. The specific processing process is as Figure 3 shown Figure 3 For the data response process among the cloud terminal, the cloud management platform, and the cloud server, it may include the following steps:
[0092] S301. When the cloud management platform receives the encrypted access request sent by the cloud terminal, decrypt the encrypted access request and send the decrypted access request to the cloud server.
[0093] In this embodiment, the specific implementation manner of the encryption and decryption process of the access request is the prior art and will not be elaborated here.
[0094] S302. When the cloud management platform receives the response data of the cloud application to the decrypted access request sent by the cloud server, convert the response result into an image.
[0095] In this embodiment, virtualization technology can be adopted to convert response data into images, that is, display the response data in the form of images.
[0096] Among them, the image contains a watermark of the basic user information of the cloud terminal, and the watermark is located under the image layer of the image. Therefore, it will not affect the display of the response data.
[0097] S303. The cloud management platform encrypts the image to obtain the encrypted image.
[0098] In this step, an encryption algorithm can be used to encrypt the image. Among them, the encryption algorithm is an existing encryption algorithm, and the specific content of the encryption algorithm is not limited in this embodiment.
[0099] S304. The cloud management platform sends the encrypted image to the cloud terminal.
[0100] S305. When the cloud terminal receives the encrypted image, it decrypts the encrypted image to obtain the decrypted image.
[0101] In this embodiment, the decryption algorithm used by the cloud terminal to decrypt the encrypted image is the decryption algorithm corresponding to the encryption algorithm used by the cloud management platform. The specific content of the decryption algorithm is not limited in this embodiment.
[0102] S306. The cloud terminal restores the decrypted image to obtain the response data.
[0103] In this embodiment, the user can operate the response data normally.
[0104] The embodiments of the present application have the following beneficial effects:
[0105] Beneficial effect one:
[0106] Use the zero-trust architecture system to continuously verify access permissions in the way of software-defined perimeter, and block external and lateral attacks.
[0107] Beneficial effect two:
[0108] In this embodiment, the response data is converted into an image, the image contains a watermark of the basic user information of the cloud terminal, and the image is encrypted and transmitted, so as to prevent data leakage during the transmission process. Even if it is leaked, it can be effectively traced through the watermark information.
[0109] Beneficial effect three:
[0110] The desktop cloud and the zero-trust architecture system can make full use of the original resources such as terminals and servers to upgrade and migrate the architecture system. At the same time, using the characteristics of the desktop cloud disk network dual standby, it can ensure the continuity of business and reduce the enterprise operation and maintenance costs.
[0111] Figure 4 A data protection device provided by an embodiment of the present application, which is applied to a cloud management platform, includes: a first execution module 401, a verification module 402, a first sending module 403, a detection module 404, and a second execution module 405, wherein,
[0112] The first execution module 401 is configured to establish a two-way connection with the cloud terminal after authenticating the authentication request of the cloud terminal, and send the login page of the desktop cloud system to the cloud terminal;
[0113] The verification module 402 is configured to verify the target information when receiving the login information sent by the cloud terminal; the target information includes: the login information and the environment information of the cloud terminal; the environment information includes: whether the cloud terminal is connected to an unfiled storage peripheral, whether there are high-risk vulnerabilities and viruses in the cloud desktop system;
[0114] The first sending module 403 is configured to return the desktop cloud system and the target cloud application to the cloud terminal when the verification of the target information is passed; the target cloud application refers to: the cloud application that the user is allowed to access according to the preset access control policy;
[0115] The detection module 404 is configured to continuously detect whether any of the target conditions are met during the process of the user accessing the target cloud application; the target conditions include: whether the single-session access duration of the user exceeds the preset duration, whether the access time of the user exceeds the preset time range, and whether there is dangerous environment information in the cloud terminal;
[0116] The second execution module 405 is configured to stop responding to the user's access request to the target cloud application when it is detected that any of the target conditions are met.
[0117] Optionally, the device may further include a third execution module, configured to, after the first sending module 403 returns the desktop cloud system and the target cloud application to the cloud terminal when the verification of the target information is passed, decrypt the encrypted access request when receiving the encrypted access request sent by the cloud terminal, and send the decrypted access request to the cloud application; when receiving the response data of the cloud application to the decrypted access request, convert the response result into an image; the image contains a watermark of the basic user information of the cloud terminal; the watermark is located under the image layer of the image; encrypt the image to obtain an encrypted image; and send the encrypted image to the cloud terminal.
[0118] Optionally, the device may further include: a fifth sending module, configured to send a prompt message indicating an error in user authorization to the cloud terminal and return the login page to the cloud terminal when the verification of the target information fails.
[0119] Optionally, the device may further include: a fifth sending module, further configured to send a prompt message indicating an error in user authorization to the cloud terminal and send the login page to the cloud terminal when any condition in the target conditions is detected to be met.
[0120] Figure 5 Another data protection device provided by this application, which is applied to a cloud terminal, may include:
[0121] A second sending module 501, configured to send an authentication request to the cloud management platform when receiving a start instruction from a user;
[0122] A display module 502, configured to display the login page when receiving the login page of the desktop cloud system sent by the cloud management platform after establishing a two-way connection with the cloud management platform;
[0123] A third sending module 503, configured to send the login information to the cloud management platform when receiving the login information input by the user on the login page of the desktop cloud system;
[0124] A fourth sending module 504, configured to, after receiving the target cloud application and the desktop cloud system sent by the cloud management platform, if receiving an access instruction triggered by the user for the target cloud application, send the encrypted access request to the cloud management platform.
[0125] Optionally, the device may further include a fourth execution module, configured to decrypt the encrypted image to obtain a decrypted image when receiving the encrypted image sent by the cloud management platform; the encrypted image refers to: the cloud management platform converts the response data of the cloud server in response to the access request into an image and encrypts the image; restoring the decrypted image to obtain the response data.
[0126] If the functions described in the method embodiments of this application are implemented in the form of software function units and sold or used as independent products, they can be stored in a storage medium readable by a computing device. Based on this understanding, the part that contributes to the prior art or a part of the technical solution in the embodiments of this application can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a computing device (which may be a personal computer, a server, a mobile computing device, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.
[0127] The various embodiments in this specification are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.
[0128] For the above description of the disclosed embodiments, the features recorded in the various embodiments in this specification can be replaced or combined with each other, enabling those skilled in the art to implement or use this application.
[0129] The above description of the disclosed embodiments enables those skilled in the art to implement or use this application. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
Claims
1. A data protection method, characterized in that, A cloud management platform applied to a desktop cloud system, the method includes: After authenticating the authentication request of the cloud terminal, establish a two-way connection with the cloud terminal and send the login page of the desktop cloud system to the cloud terminal; When receiving the login information sent by the cloud terminal, verify the target information; the target information includes: the login information and the environment information of the cloud terminal; the environment information includes: whether the cloud terminal is connected to an unrecorded storage peripheral, whether there are high-risk vulnerabilities and viruses in the desktop cloud system; When the verification of the target information passes, return the desktop cloud system and the target cloud application to the cloud terminal; the target cloud application refers to: the cloud application that the user is allowed to access according to the preset access control policy; When receiving the encrypted access request sent by the cloud terminal, decrypt the encrypted access request and send the decrypted access request to the cloud application; When receiving the response data of the cloud application to the decrypted access request, convert the response data into an image; the image contains a watermark of the basic user information of the cloud terminal; the watermark is located under the image layer of the image; Encrypt the image to obtain an encrypted image; Send the encrypted image to the cloud terminal; During the process of the user accessing the target cloud application, continuously detect whether any of the target conditions is met; the target conditions include: whether the single-session access duration of the user exceeds the preset duration, whether the access time of the user exceeds the preset time range, and whether there is dangerous environment information in the cloud terminal; When it is detected that any of the target conditions is met, stop responding to the user's access request to the target cloud application.
2. The method according to claim 1, wherein The target information further includes: the login location information of the cloud terminal and the login time information of the cloud terminal.
3. The method according to claim 1, characterized in that It further includes: When the verification of the target information fails, send a prompt message indicating that the user authorization is incorrect to the cloud terminal, and return the login page to the cloud terminal.
4. The method according to claim 3, wherein It further includes: When it is detected that any of the target conditions is met, send a prompt message indicating that the user authorization is incorrect to the cloud terminal, and send the login page to the cloud terminal.
5. A data protection method, characterized in that, A cloud terminal applied to a desktop cloud system, the method includes: When receiving the start instruction of the user, send an authentication request to the cloud management platform; After establishing a two-way connection with the cloud management platform, when receiving the login page of the desktop cloud system sent by the cloud management platform, display the login page; When receiving the login information input by the user on the login page, send the login information to the cloud management platform; After receiving the target cloud application and the desktop cloud system sent by the cloud management platform, if receiving the access instruction of the user triggered to the target cloud application, send the encrypted access request to the cloud management platform; Upon receiving the encrypted image sent by the cloud management platform, decrypt the encrypted image to obtain the decrypted image; the encrypted image refers to: the cloud management platform converts the response data of the cloud server in response to the access request into an image and encrypts the image; Restore the decrypted image to obtain the response data; Wherein, the cloud terminal and the cloud server are respectively connected to the cloud management platform, a cloud application is deployed on the cloud server, and after the cloud management platform authenticates the cloud terminal, the cloud terminal accesses the cloud application on the cloud server through the cloud management platform.
6. A data protection device, characterized in that, A cloud management platform applied to a desktop cloud system, including: A first execution module, configured to establish a two-way connection with the cloud terminal after passing the authentication request for the cloud terminal, and send the login page of the desktop cloud system to the cloud terminal; A verification module, configured to verify the target information when receiving the login information sent by the cloud terminal; the target information includes: the login information and the environment information of the cloud terminal; the environment information includes: whether the cloud terminal is connected to an unrecorded storage peripheral, whether there are high-risk vulnerabilities and viruses in the desktop cloud system; A first sending module, configured to return the desktop cloud system and the target cloud application to the cloud terminal when the verification of the target information passes; the target cloud application refers to: the cloud application that the user is allowed to access according to the preset access control policy; A third execution module, configured to decrypt the encrypted access request when receiving the encrypted access request sent by the cloud terminal, and send the decrypted access request to the cloud application; when receiving the response data of the cloud application to the decrypted access request, convert the response data into an image; the image contains a watermark of the basic user information of the cloud terminal; the watermark is located under the image layer of the image; encrypt the image to obtain the encrypted image; send the encrypted image to the cloud terminal; A detection module, configured to continuously detect whether any of the target conditions are met during the user's access to the target cloud application; the target conditions include: whether the user's single-session access duration exceeds the preset duration, whether the user's access time exceeds the preset time range, and whether there is dangerous environment information in the cloud terminal; A second execution module, configured to stop responding to the user's access request to the target cloud application when it is detected that any of the target conditions are met.
7. A data protection device, characterized in that, A cloud terminal applied to a desktop cloud system, including: A second sending module, configured to send an authentication request to the cloud management platform when receiving the user's startup instruction; A display module, configured to display the login page when receiving the login page of the desktop cloud system sent by the cloud management platform after establishing a two-way connection with the cloud management platform; A third sending module, configured to send the login information to the cloud management platform when receiving the login information input by the user on the login page of the desktop cloud system; A fourth sending module, configured to, after receiving the target cloud application and the desktop cloud system sent by the cloud management platform, if receiving an access instruction triggered by the user for the target cloud application, send the encrypted access request to the cloud management platform; A fourth execution module, configured to decrypt the encrypted image to obtain a decrypted image when receiving the encrypted image sent by the cloud management platform; the encrypted image refers to: the cloud management platform converts the response data of the cloud server to the access request into an image and encrypts the image, restore the decrypted image to obtain the response data, wherein the cloud terminal and the cloud server are respectively connected to the cloud management platform, a cloud application is deployed on the cloud server, and after the cloud management platform authenticates the cloud terminal, the cloud terminal accesses the cloud application on the cloud server through the cloud management platform.
8. A desktop cloud system, characterized in that, It includes a cloud terminal, a cloud management platform and a cloud server; The cloud terminal sends an authentication request to the cloud management platform when receiving a startup instruction from the user; After passing the authentication request of the cloud terminal, the cloud management platform establishes a two-way connection with the cloud terminal and sends the login page of the desktop cloud system to the cloud terminal; After the cloud terminal establishes a two-way connection with the cloud management platform, when receiving the login page of the desktop cloud system sent by the cloud management platform, it displays the login page; The cloud terminal sends the login information to the cloud management platform when receiving the login information input by the user on the login page of the desktop cloud system; When receiving the login information sent by the cloud terminal, the cloud management platform verifies the target information; The target information includes: the login information and the environment information of the cloud terminal; the environment information includes: whether the cloud terminal is connected to an unrecorded storage peripheral, whether there are high-risk vulnerabilities and viruses in the desktop cloud system; When the verification of the target information by the cloud management platform passes, it returns the desktop cloud system and the target cloud application to the cloud terminal; the target cloud application refers to: among the cloud applications deployed on the cloud server according to the preset access control policy, the cloud applications that the user is allowed to access; When receiving the encrypted access request sent by the cloud terminal, the cloud management platform decrypts the encrypted access request and sends the decrypted access request to the cloud application; When receiving the response data of the cloud application to the decrypted access request, the cloud management platform converts the response data into an image; the image contains a watermark of the basic user information of the cloud terminal; the watermark is located under the image layer of the image; The cloud management platform encrypts the image to obtain an encrypted image; The cloud management platform sends the encrypted image to the cloud terminal; During the process of the user accessing the target cloud application, the cloud management platform continuously detects whether any of the target conditions are met; the target conditions include: whether the single-session access duration of the user exceeds a preset duration, whether the access time of the user exceeds a preset time range, and whether there is dangerous environmental information on the cloud terminal; When the cloud management platform detects that any of the target conditions are met, it stops responding to the user's access request for the target cloud application.
Citation Information
Patent Citations
Application software issuing method in virtual desktop environment
CN105592114A
Desktop cloud system
CN108021426A