A method, device, equipment and readable medium for end-cloud integration

Through application and network redirection technology, local systems and cloud desktop applications are integrated, which solves the problem of independence between cloud desktop and local system network, realizes unsensed network convergence and consistent user experience, simplifies network management and reduces costs.

CN115643080BActive Publication Date: 2025-07-18ALIBABA (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211281935.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-19
Publication Date
2025-07-18
Estimated Expiration
2042-10-19

AI Technical Summary

Technical Problem

In the prior art, cloud desktop is independent of the network environment of the local system, resulting in the need to use different networks when accessing the network, and lack of convergence, resulting in inconsistent complex network management and user experience.

Method used

Through application redirection and network redirection, the local system applications and cloud desktop applications are integrated, and network traffic is intercepted and matched through the network management module, and processed or forwarded according to preset rules to achieve the integration of the local network and the cloud network.

Benefits of technology

It realizes the unconscious convergence of local applications and cloud applications, provides a consistent user experience, simplifies network management, reduces costs, does not require physical dedicated lines or VPNs, and supports flexible traffic management and secure isolation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115643080B_ABST
    Figure CN115643080B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for end-cloud integration, including: integrating local applications running on a local system and cloud applications running on a cloud desktop through application redirection; establishing a connection between a local network and a network on the cloud; intercepting the network traffic of the integrated local application and cloud application based on the local network and the network on the cloud after the connection is established, and matching the intercepted network traffic based on a first preset rule; and locally processing, forwarding, or discarding the intercepted network traffic based on the matching result. The present invention also discloses an end-cloud integration device, a computer device, and a readable storage medium. The present invention integrates the local network and the network on the cloud, connects the network environment of the local desktop with the network environment of the cloud desktop, facilitates the management of network traffic, and improves the user experience of the cloud desktop and cloud applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of cloud applications, and particularly relates to a method, device, equipment and readable medium for end-cloud integration. Background Art

[0002] With the popularization of the network and the improvement of bandwidth, products such as cloud desktops and cloud games have grown rapidly, and various resources on the cloud can be used on local computers or mobile devices. In the prior art, there is a cloud desktop that completely isolates the local system and the cloud system. However, all applications are within the cloud desktop, and all networks are cloud networks. The local environment and the cloud desktop environment are basically independent, especially the network environment, which brings some troubles. For example, in the following scenarios: local applications can be integrated into the cloud desktop system through application redirection. When accessing network services enabled within the cloud desktop, local applications need to access the cloud network at this time; the local system accesses a specific internal network, and there are some services open on the internal network. At this time, the system services or cloud applications of the cloud desktop need to access the services provided in the local network; based on security network policies, different applications need to access different networks, including local applications accessing the local network, cloud applications accessing the cloud network, and cloud applications accessing the local network.

[0003] Some cloud computers already support opening cloud applications in the local desktop, opening the cloud desktop in the local desktop, and opening local applications in the cloud desktop and integrating them into the window system, status bar, and notification bar of the cloud desktop, that is, a solution based on application redirection. At the same time, it also involves accessing two networks. One is the local network used by the local terminal, and the other is the cloud network used by the cloud desktop and cloud applications. These two environments are often isolated. When integrating the applications of the cloud desktop and the local system, when accessing the network, the applications on the cloud desktop access the cloud network, and the applications of the local system access the local network. In this way, the integration of local applications and cloud applications can be achieved, but the networks are still independent, that is, local applications must use the local network, and cloud applications must use the cloud network.

[0004] The information disclosed in this background art section is only intended to enhance the overall understanding of the present invention and should not be regarded as an admission or any form of implication that this information constitutes prior art already known to those of ordinary skill in the art. Summary of the Invention

[0005] The purpose of the present invention is to provide a method, device, equipment and readable medium for end-cloud integration, which integrates the cloud network environment and the local network environment, connects the local network and the cloud network, and local desktops and cloud desktops, local applications and cloud applications, and local networks and cloud networks can all provide services for customers after being integrated through a streaming protocol, avoiding the use of complex physical dedicated lines or means such as VPN networks (Virtual Private Network), managing traffic through flexible control strategies, and on the basis of application redirection, realizing the same experience of cloud desktops and local desktops, making users unaware, thereby improving the user experience.

[0006] Based on the above purpose, on the one hand, an embodiment of the present invention provides a method for end-cloud integration, including the following steps: integrating local applications running on a local system and cloud applications running on a cloud desktop through application redirection; establishing a connection between the local network and the cloud network; intercepting the network traffic of the integrated local applications and cloud applications based on the established local network and cloud network, and matching the intercepted network traffic based on a first preset rule; and performing local processing, forwarding processing or discarding processing on the intercepted network traffic based on the matching result.

[0007] In some embodiments, establishing a connection between the local network and the cloud network includes: sending authentication information from the local system to the cloud desktop, and authenticating the authentication information by the cloud desktop; in response to successful authentication, establishing a protocol channel between the local system and the cloud desktop.

[0008] In some embodiments, matching the intercepted network traffic based on a first preset rule includes: matching the intercepted network traffic based on a domain name preset rule; or matching the intercepted network traffic based on an Internet protocol address preset rule; or matching the intercepted network traffic based on a process name preset rule.

[0009] In some embodiments, matching the intercepted network traffic based on a domain name preset rule includes: performing at least one of full matching, prefix matching, suffix matching and keyword matching on the intercepted network traffic based on the domain name preset rule.

[0010] In some embodiments, establishing a connection between the local network and the cloud network includes: establishing a connection between a local network management module and a cloud network management module through the protocol channel of the cloud desktop; intercepting the network traffic of the integrated local applications and cloud applications based on the established local network and cloud network includes: intercepting all network traffic of the local applications within the local system through the local network management module, and intercepting all network traffic of the cloud applications within the cloud desktop through the cloud network management module.

[0011] In some embodiments, performing local processing, forwarding processing, or discarding processing on the intercepted network traffic based on the matching result includes: in response to the matching result being accessing the cloud network, directly sending the intercepted network traffic to the cloud network by the cloud network management module, or forwarding the intercepted network traffic to the cloud network management module by the local network management module and then sending the intercepted network traffic to the cloud network by the cloud network management module; in response to the matching result being accessing the local network, directly sending the intercepted network traffic to the local network by the local network management module, or forwarding the intercepted network traffic to the local network management module by the cloud network management module and then sending the intercepted network traffic to the local network by the cloud network management module; in response to the matching result being prohibited access, discarding the intercepted network traffic by the local network management module / the cloud network management module.

[0012] In some embodiments, the method further includes: monitoring network traffic and performing speed limiting or packet dropping processing on the network traffic based on a second preset rule.

[0013] On the other hand, an embodiment of the present invention further provides an edge-cloud fusion device, including: an application redirection module configured to fuse local applications running on a local system and cloud applications running on a cloud desktop through application redirection; a network redirection module configured to establish a connection between a local network and a cloud network; a matching module configured to intercept network traffic of the fused local applications and cloud applications based on the local network and the cloud network after the connection is established, and match the intercepted network traffic based on a first preset rule; and a processing module configured to perform local processing, forwarding processing, or discarding processing on the intercepted network traffic based on the matching result.

[0014] On yet another aspect, an embodiment of the present invention further provides a computer device, including: at least one processor; and a memory storing computer instructions that can run on the processor, and when the instructions are executed by the processor, the steps of the above method are implemented.

[0015] On yet another aspect, an embodiment of the present invention further provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the above method.

[0016] The present invention has at least the following beneficial technical effects: cloud integration, consistent usage, the cloud environment and the end environment are almost completely integrated, achieving a consistent usage experience; simple to use, low cost, only need to install a network management module on the local desktop and the cloud desktop, without the need to transform the network architecture by using physical dedicated lines or VPNs, etc.; rules can be customized, convenient for expansion. It supports customizing various rules, facilitating traffic management and function expansion; communication is secure, easy to control, without the need to penetrate the intranet to the public network and expose it, and data is transmitted in an encrypted cloud desktop protocol channel. Through rules, it is convenient to...; applications are unaware, the network management module takes over all traffic within the desktop, without the need for separate configuration of applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other embodiments can be obtained based on these drawings.

[0018] Figure 1 It is a schematic diagram of an embodiment of the method for end-cloud integration provided by the present invention;

[0019] Figure 2 It is a system block diagram of an embodiment of the method for end-cloud integration provided by the present invention;

[0020] Figure 3 It is a schematic diagram of an embodiment of the method for end-cloud integration provided by the present invention;

[0021] Figure 4 It is a schematic diagram of an embodiment of the device for end-cloud integration provided by the present invention;

[0022] Figure 5 It is a schematic diagram of an embodiment of the computer device provided by the present invention;

[0023] Figure 6 It is a schematic diagram of an embodiment of the computer-readable storage medium provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the following will describe the specific embodiments of the present invention in detail. However, it should be understood that the protection scope of the present invention is not limited by the specific embodiments.

[0025] It should be noted that in the embodiments of the present invention, all expressions using "first" and "second" are for distinguishing two entities or parameters with the same name but different identities. It can be seen that "first" and "second" are only for the convenience of expression and should not be construed as a limitation on the embodiments of the present invention. This will not be elaborated one by one in the subsequent embodiments.

[0026] Unless otherwise clearly stated, throughout the specification and claims, the term "comprise" or its variations such as "comprises" or "including" etc. will be understood to include the stated elements or components, without excluding other elements or other components.

[0027] To facilitate the understanding of the technical solutions provided by the embodiments of the present application by those skilled in the art, the related technologies are briefly described below: Some cloud computers already support opening cloud applications in the local desktop, opening cloud desktops in the local desktop, and opening local applications in the cloud desktop and integrating them into the window system, status bar, and notification bar of the cloud desktop, that is, a solution based on application redirection. At the same time, it also involves accessing two networks. One is the local network used by the local terminal, and the other is the cloud network used by the cloud desktop and cloud applications. These two environments are often isolated. When integrating the applications of the cloud desktop and the local system, when accessing the network, the applications on the cloud desktop access the cloud network, and the applications of the local system access the local network. In this way, the integration of local applications and cloud applications can be achieved, but the networks are still independent, that is, local applications must use the local network, and cloud applications must use the cloud network.

[0028] Based on the above purposes, in the first aspect of the embodiments of the present invention, an embodiment of the method for end-cloud integration is proposed. Figure 1 Shown is a schematic diagram of an embodiment of the method for end-cloud integration provided by the present invention. As Figure 1 shown, the method for end-cloud integration in the embodiments of the present invention includes the following steps:

[0029] 001. Integrate the local applications running on the local system and the cloud applications running on the cloud desktop through application redirection;

[0030] In this embodiment, a cloud desktop, which can also be called a cloud computer, is an overall service solution that includes cloud resources, a transmission protocol, and a cloud terminal. An open cloud terminal uses the transmission protocol to provide resources such as desktops, applications, and hardware to users in a service mode of on-demand service and elastic allocation. Users can achieve single-machine multi-user without having to consider building a complex IT infrastructure. A cloud application is a remote application technology that deploys an application in a virtualized cloud environment and streams the cloud screen to a client machine, allowing the client to operate it just like a local application. Redirection means redirecting various network requests to other locations through various methods. In a cloud desktop, a cloud application runs, and a local application runs in the local system. The local application and the cloud desktop are integrated through application redirection.

[0031] 002. Establish a connection between the local network and the cloud network;

[0032] In this embodiment, the local network environment and the cloud network environment are integrated through network redirection. The local network environment is connected through the local network management module in the local system, and the cloud network environment is connected through the cloud management module in the cloud desktop. The local network management module and the cloud network management module establish a connection using the cloud desktop protocol data channel. Avoid using complex physical dedicated lines or VPN networks and other means. It is simple and low-cost to connect the local network and the cloud network, realizing a consistent usage experience for users of the cloud desktop and the local system.

[0033] 003. Intercept all network traffic of local applications in the local system and cloud applications in the cloud desktop through the network management module, and match the intercepted network traffic based on a first preset rule; and

[0034] In this embodiment, the network management module intercepts all network traffic of local applications in the local system and cloud applications in the cloud desktop, and matches the intercepted traffic according to the domain name or IP address. It supports customizing various rules to facilitate traffic management and function expansion. The network management module takes over all traffic within the desktop without the need for individual configuration of the application, achieving application unawareness.

[0035] 004. Perform local processing, forwarding processing, or discarding processing on the intercepted network traffic based on the matching result.

[0036] In this embodiment, after matching the corresponding traffic, actions such as local processing, forwarding, and discarding can be performed. The intercepted traffic is forwarded to its own network environment for processing according to the specified rules, or forwarded to the network management module at the opposite end through the cloud desktop protocol data channel, and then forwarded to the network environment at the opposite end to use the network at the opposite end, or the traffic is throttled, packet dropped, etc. according to the rules. Through flexible control strategies and secure isolation mechanisms, a safe and flexible usage experience is provided for users.

[0037] Figure 2 The following shows the system block diagram of the embodiment of the method for end-cloud integration provided by the present invention. In this embodiment, as Figure 2 shown, cloud applications are run in the cloud desktop, and local applications are run in the local system. The local applications and the cloud desktop are integrated through application redirection, and the local network and the cloud network are integrated through network redirection by the network management module. The network management module intercepts all network traffic and processes it. The local network management module and the cloud network management module are connected through the protocol channel of the cloud desktop.

[0038] Figure 3 The following shows the schematic diagram of the embodiment of the method for end-cloud integration provided by the present invention. In this embodiment, as Figure 3 shown, taking the video conferencing scenario as an example, the video conferencing server is built in the cloud network environment and cannot be accessed by the local network. The local desktop A wants to share its desktop screen with the cloud desktop B through this video conferencing software.

[0039] The local desktop A and the cloud desktop B are connected through the cloud desktop protocol data channel, and cloud network integration is performed through the solution described in this case. After the network request of the video conferencing software on the local desktop A is intercepted and analyzed by the network management module, it is forwarded to the cloud desktop A, and the video conferencing server is accessed through the network of the cloud desktop A, so as to connect with the cloud desktop B.

[0040] In some embodiments of the present invention, establishing a connection between the local network and the cloud network includes: sending authentication information from the local system to the cloud desktop, and authenticating the authentication information by the cloud desktop; in response to successful authentication, a protocol channel is established between the local system and the cloud desktop.

[0041] In this embodiment, the SDK client of the local system sends the address and authentication information to the server corresponding to the cloud desktop, and the server corresponding to the cloud desktop performs authentication. If the authentication is successful, a protocol channel is established between the local system and the cloud desktop, which is communication secure, convenient to manage and control, and does not require penetrating the internal network to the public network and exposing it. The data is transmitted in the encrypted surface protocol channel.

[0042] In some embodiments of the present invention, matching the intercepted network traffic based on a first preset rule includes: matching the intercepted network traffic based on a domain name preset rule; or matching the intercepted network traffic based on an Internet protocol address preset rule; or matching the intercepted network traffic based on a process name preset rule.

[0043] In this embodiment, different preset rules are set according to user requirements, and the corresponding preset rule is selected according to the usage environment, specifically including a domain name preset rule for matching according to the domain name, an Internet protocol address preset rule for matching according to the IP address, a process name preset rule for matching according to the process name, etc. Custom rules are supported, which is convenient for traffic management and function extension.

[0044] In some embodiments of the present invention, matching the intercepted network traffic based on a domain name preset rule includes: performing at least one of full match, prefix match, suffix match, and keyword match on the intercepted network traffic based on the domain name preset rule.

[0045] In this embodiment, the domain name preset rule includes full match, prefix match, suffix match, keyword match, etc. of the domain name. Custom rules are supported, which is convenient for traffic management and function extension.

[0046] In some embodiments of the present invention, establishing a connection between the local network and the cloud network includes: establishing a connection between the local network management module and the cloud network management module through the protocol channel of the cloud desktop; intercepting all network traffic of local applications in the local system and cloud applications in the cloud desktop by the network management module includes: intercepting all network traffic of local applications in the local system by the local network management module, and intercepting all network traffic of cloud applications in the cloud desktop by the cloud network management module.

[0047] In this embodiment, continue to refer to Figure 2 , the local network and the cloud network are integrated through network redirection of the network management module. The local network management module intercepts and processes all network traffic in the local system, and the cloud network management module intercepts and processes all network traffic in the cloud desktop. The local network management module and the cloud network management module are connected through the protocol channel of the cloud desktop. The cloud environment and the end environment are integrated to achieve a consistent usage experience. It only needs to install the network management module in the local system and the cloud desktop, and there is no need to transform the network architecture by using physical dedicated lines or VPNs, etc. It is simple to use and has low cost.

[0048] In some embodiments of the present invention, local processing, forwarding processing, or discarding processing of intercepted network traffic based on the matching result includes: in response to the matching result being accessing the cloud network, the intercepted network traffic is directly sent to the cloud network by the cloud network management module, or the intercepted network traffic is forwarded to the cloud network management module by the local network management module and the intercepted network traffic is sent to the cloud network by the cloud network management module; in response to the matching result being accessing the local network, the intercepted network traffic is directly sent to the local network by the local network management module, or the intercepted network traffic is forwarded to the local network management module by the cloud network management module and the intercepted network traffic is sent to the local network by the cloud network management module; in response to the matching result being prohibited access, the intercepted network traffic is discarded by the local network management module / cloud network management module.

[0049] In this embodiment, continuing to refer to Figure 2 , when the cloud application accesses the cloud network environment, the cloud network management module intercepts the network traffic of cloud application A in the cloud desktop, matches it based on the preset rules, and directly sends it to the cloud network environment according to the matching result.

[0050] In this embodiment, continuing to refer to Figure 2 , when the cloud application accesses the local network environment, the cloud network management module intercepts the network traffic of cloud application A in the cloud desktop, matches it based on the preset rules, and forwards it to the local network management module through the protocol channel according to the matching result, and the local network management module sends it to the local network environment.

[0051] In this embodiment, continuing to refer to Figure 2 , when the local application accesses the cloud network environment, the local network management module intercepts the network traffic of local application B in the local system, matches it based on the preset rules, and forwards it to the cloud network management module through the protocol channel according to the matching result, and the cloud network management module sends it to the cloud network environment.

[0052] In this embodiment, continuing to refer to Figure 2 , when the local application accesses the local network environment, the local network management module intercepts the network traffic of local application B in the local system, matches it based on the preset rules, and directly sends it to the local network environment according to the matching result.

[0053] In some embodiments of the present invention, the method further includes: monitoring the network traffic and performing speed limiting or packet dropping processing on the network traffic based on the second preset rules.

[0054] In this embodiment, network isolation is achieved by monitoring network traffic. Taking process A and process B as examples, both process A and process B want to access a certain domain name on the other side. However, if process B accesses it, there will be security risks. By formulating preset rules, process A can be allowed to access, and process B can be refused access, thus isolating B from the network on the other side. This provides users with a safe and flexible usage experience.

[0055] It should be particularly noted that each step in the various embodiments of the above-mentioned method for end-cloud integration can be mutually crossed, replaced, added, or deleted. Therefore, these reasonable permutation and combination transformations for the method of end-cloud integration should also fall within the protection scope of the present invention, and the protection scope of the present invention should not be limited to the embodiments.

[0056] Based on the above objectives, in the second aspect of the embodiments of the present invention, a device for end-cloud integration is proposed. Figure 4 The following shows a schematic diagram of an embodiment of the device for end-cloud integration provided by the present invention. As Figure 4 shown, the device for end-cloud integration in the embodiments of the present invention includes the following modules: an application redirection module 011, configured to integrate the local applications running on the local system and the cloud applications running on the cloud desktop through application redirection; a network redirection module 012, configured to establish a connection between the local network and the cloud network; a matching module 013, configured to intercept all network traffic of the local applications in the local system and the cloud applications in the cloud desktop through the network management module, and match the intercepted network traffic based on the first preset rule; and a processing module 014, configured to perform local processing, forwarding processing, or discarding processing on the intercepted network traffic based on the matching result.

[0057] Based on the above objectives, in the third aspect of the embodiments of the present invention, a computer device is proposed. Figure 5 The following shows a schematic diagram of an embodiment of the computer device provided by the present invention. As Figure 5 shown, the computer device in the embodiments of the present invention includes the following devices: at least one processor 021; and a memory 022, where the memory 022 stores computer instructions 023 that can be run on the processor, and when the instructions are executed by the processor, the steps of the above method are implemented.

[0058] The present invention also provides a computer-readable storage medium. Figure 6 The following shows a schematic diagram of an embodiment of the computer-readable storage medium provided by the present invention. As Figure 6 shown, the computer-readable storage medium 031 stores a computer program 032 that, when executed by the processor, executes the above method.

[0059] Finally, it should be noted that those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program of the method for end-cloud integration can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium of the program can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc. The embodiments of the above computer program can achieve the same or similar effects as those of any of the foregoing method embodiments corresponding thereto.

[0060] In addition, the method disclosed according to the embodiments of the present invention can also be implemented as a computer program executed by a processor, and the computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the above functions defined in the method disclosed in the embodiments of the present invention are executed.

[0061] In addition, the above method steps and system units can also be implemented by using a controller and a computer-readable storage medium for storing a computer program that enables the controller to implement the above step or unit functions.

[0062] Those skilled in the art will also understand that the various exemplary logical blocks, modules, circuits, and algorithm steps described in connection with the disclosure herein can be implemented as electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability of hardware and software, a general description of the functions of various illustrative components, blocks, modules, circuits, and steps has been given. Whether this function is implemented as software or as hardware depends on the specific application and the design constraints imposed on the overall system. The functions that those skilled in the art can implement in various ways for each specific application, but such implementation decisions should not be construed as causing a departure from the scope of the disclosure of the embodiments of the present invention.

[0063] In one or more exemplary designs, the functionality can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functionality can be stored on or transmitted via a computer-readable medium as one or more instructions or code. Computer-readable media includes both computer storage media and communication media including any medium that facilitates transfer of a computer program from one location to another. The storage media can be any available media that can be accessed by a general purpose or special purpose computer. By way of example, and not limitation, the computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a general purpose or special purpose computer or a general purpose or special purpose processor. Additionally, any connection is properly termed a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. As used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc where disks usually reproduce data magnetically, while discs reproduce data optically with lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0064] The above are exemplary embodiments disclosed by the present invention. However, it should be noted that various changes and modifications can be made without departing from the scope of the embodiments disclosed by the present invention as defined by the claims. The functions, steps, and / or actions of the method claims according to the disclosed embodiments herein need not be performed in any particular order. In addition, although the elements disclosed by the embodiments of the present invention may be described or claimed in individual form, they can also be understood as plural unless explicitly limited to the singular.

[0065] It should be understood that as used herein, unless the context clearly supports the exception, the singular form "a" is also intended to include the plural form. It should also be understood that the "and / or" used herein refers to any and all possible combinations of one or more of the associated listed items.

[0066] The serial numbers of the disclosed embodiments of the present invention above are only for description and do not represent the superiority or inferiority of the embodiments.

[0067] Those of ordinary skill in the art can understand that all or part of the steps to implement the above embodiments can be completed by hardware, or can be completed by instructing relevant hardware through a program. The program can be stored in a computer-readable storage medium, and the above-mentioned storage medium can be a read-only memory, a magnetic disk, an optical disc, or the like.

[0068] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the disclosure of the embodiments of the present invention (including the claims) is limited to these examples; under the concept of the embodiments of the present invention, the technical features in the above embodiments or different embodiments can also be combined, and there are many other variations in different aspects of the embodiments of the present invention as described above, which are not provided in detail for the sake of brevity. Therefore, any omission, modification, equivalent replacement, improvement, etc. made within the spirit and principle of the embodiments of the present invention shall be included in the protection scope of the embodiments of the present invention.

Claims

1. A method for end-cloud integration, characterized in that, It includes the following steps: Fuse the local applications running on the local system and the cloud applications running on the cloud desktop through application redirection; the application redirection refers to redirecting the respective locations corresponding to the local applications and the cloud applications; Establish a connection between the local network and the cloud network; Based on the established local network and cloud network, intercept the network traffic of the fused local applications and cloud applications, and match the intercepted network traffic based on the first preset rule; And Based on the matching result, perform local processing, forwarding processing, or discarding processing on the intercepted network traffic; The establishment of the connection between the local network and the cloud network includes: Establish a connection between the local network management module and the cloud network management module through the protocol channel of the cloud desktop; Based on the established local network and cloud network, intercepting the network traffic of the fused local applications and cloud applications includes: intercepting all network traffic of the local applications within the local system through the local network management module, and intercepting all network traffic of the cloud applications within the cloud desktop through the cloud network management module.

2. The method of edge-cloud integration according to claim 1, wherein Establishing a connection between the local network and the cloud network includes: Send authentication information from the local system to the cloud desktop, and the cloud desktop authenticates the authentication information; In response to successful authentication, establish a protocol channel between the local system and the cloud desktop.

3. The method of edge-cloud integration according to claim 1, characterized in that Matching the intercepted network traffic based on the first preset rule includes: Matching the intercepted network traffic based on the domain name preset rule; or Matching the intercepted network traffic based on the Internet protocol address preset rule; or Matching the intercepted network traffic based on the process name preset rule.

4. The method for edge-cloud integration according to claim 3, characterized in that Matching the intercepted network traffic based on the domain name preset rule includes: Performing at least one of full match, prefix match, suffix match, and keyword match on the intercepted network traffic based on the domain name preset rule.

5. The method of edge-cloud integration according to claim 1, wherein Based on the matching result, performing local processing, forwarding processing, or discarding processing on the intercepted network traffic includes: In response to the matching result being to access the cloud network, directly send the intercepted network traffic to the cloud network by the cloud network management module, or forward the intercepted network traffic to the cloud network management module by the local network management module and the cloud network management module send the intercepted network traffic to the cloud network; In response to the matching result being to access the local network, directly send the intercepted network traffic to the local network by the local network management module, or forward the intercepted network traffic to the local network management module by the cloud network management module and the local network management module send the intercepted network traffic to the local network; In response to the matching result being prohibited access, discard the intercepted network traffic by the local network management module / the cloud network management module.

6. The method of edge-cloud integration according to claim 1, characterized in that It also includes: Monitor the network traffic, and perform speed limit or packet loss processing on the network traffic based on the second preset rule; The second preset rule means that if it is monitored that the network traffic has a security risk, perform speed limit or packet loss processing on the network traffic.

7. A device for end-cloud integration, characterized in that, It includes: An application redirection module is configured to integrate a local application running on a local system and a cloud application running on a cloud desktop through application redirection; The application redirection refers to redirecting the respective positions corresponding to the local application and the cloud application; A network redirection module is configured to establish a connection between a local network and a cloud network; A matching module is configured to intercept the network traffic of the integrated local application and cloud application based on the local network and the cloud network after the connection is established, and match the intercepted network traffic based on a first preset rule; And A processing module is configured to perform local processing, forwarding processing, or discarding processing on the intercepted network traffic based on the matching result; The network redirection module is further configured to: Establish a connection between a local network management module and a cloud network management module through a protocol channel of the cloud desktop; Intercepting the network traffic of the integrated local application and cloud application based on the local network and the cloud network after the connection is established includes: intercepting all network traffic of the local application within the local system through the local network management module, and intercepting all network traffic of the cloud application within the cloud desktop through the cloud network management module.

8. A computer device, characterized in that, It includes: At least one processor; And A memory, where the memory stores computer instructions that can run on the processor, and when the computer instructions are executed by the processor, the steps of the method according to any one of claims 1-6 are implemented.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1-6 are implemented.

Citation Information

Patent Citations

  • System and method for achieving combination display of terminal local desktop and far-end virtual desktop

    CN103677970A

  • Method and device for publishing local application of cloud desktop, equipment and medium

    CN113778583A