Desktop Cloud Server and Terminal Secure Communication Method
By using a built-in security chip and a secret tube platform in the terminal, the quantum key is used to generate a true random conversation key, which solves the problem of low security in data transmission between the desktop cloud server and the terminal, and realizes absolutely secure communication and file-specific access, meeting users' diverse office needs.
Patent Information
- Application Number
- CN202211480165.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-22
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-09-22
AI Technical Summary
In the prior art, the data transmission between the desktop cloud server and the terminal is low in security, and the terminal encryption method is complex, which cannot meet the user's needs for freedom and proprietary file editing.
Quantum key encryption technology is adopted to generate true random conversation keys by incorporating a security chip and a secret tube platform in the terminal, encrypted communication between the terminal and the server, ensuring absolute security of data transmission, and achieving exclusive access to files in confidential mode.
It realizes absolutely secure communication between desktop cloud server and terminal, meets users' free needs for file editing, and ensures file proprietary rights, improving data transmission security and user experience.
Smart Images

Figure CN115865907B_ABST
Abstract
Description
[0001] This application is a divisional application of the patent with the application date of September 22, 2022, application number CN202211156166.3, and invention title of "Desktop Cloud Server and Terminal Secure Communication Method". Technical Field
[0002] The present invention relates to the technical field of desktop cloud, and particularly relates to a desktop cloud server and terminal secure communication method. Background Art
[0003] Desktop cloud has become a new office mode to replace traditional computers with the characteristics of data not landing and providing users with mobile office. In this mode, user data is stored in the server. In the prior art, the server only verifies the user's login password to open relevant virtual desktop resources for it. After the verification passes, the data is not encrypted during the data transmission between the server and the terminal. Therefore, the security of the transmitted data is extremely low and is easily stolen by hackers; and in the prior art, the confidentiality method of files is achieved by installing encryption software on the terminal. This method encrypts all files on the terminal. For users, it complicates the editing and transmission of non-confidential files. In other words, the terminals in the prior art include a non-encrypted ordinary operating system and a fully encrypted confidential operating system, and there is no disclosed implementation method that can switch between the two to meet both the confidential office needs and the general needs of freely editing and sending out files; at the same time, in the prior art, before an encrypted file on a terminal is decrypted, as long as other terminals also install authorized encryption software or know the opening password of the encrypted file, the encrypted file can be normally opened on other terminals. There is no way to limit the opening of the encrypted file to a specific terminal before it is decrypted, which cannot meet the user's need for exclusive rights to the terminal they hold. Summary of the Invention
[0004] In order to overcome the disadvantages and deficiencies in the prior art, the present invention provides a method for secure communication between a desktop cloud server and a terminal. The server stores virtual desktop resources. After the authentication request initiated by the terminal in the confidentiality mode is passed, the server opens the virtual desktop resources matching the authentication information of the terminal and maps the virtual desktop image to the terminal. When the virtual desktop resources matching the authentication information of the terminal are located in the first server and the terminal is networked and connected to the second server, the secure communication method includes: S106: The second server establishes an application session with the first server and generates a third session ID; S107: The second encryption machine communicatively connected to the second server carries the third session ID and the cloud ID associated with the authentication information to apply for a session key key-C from the second key management platform, encrypts the access request initiated by the second server to the first server using the session key key-C, and sends it to the first server; S108: After the first server verifies that the cloud ID passes, it applies for a session key key-c from the first key management platform based on the third session ID to decrypt the access request and retrieves the virtual desktop matching the cloud ID; S109: Encrypts the virtual desktop image using the session key key-c and transmits it to the second server, and the second server decrypts it using the session key key-C and transmits it to the terminal; wherein, the first key management platform includes QKD1, the second key management platform includes QKD2, the session key key-C is generated by the QKD2 device, and the session key key-c is generated by the QKD1 device.
[0005] Further, the terminal is built-in with a security chip pre-filled with quantum keys. Before step 106 is implemented, the secure communication method further includes: The terminal establishes an application session with the second server and generates a second session ID; Encrypts the second session ID using the protection key formed by the quantum key, and sends the identity code of the security chip and the ciphertext of the second session ID to the second key management platform to obtain a session key key-B; The user inputs authentication information on the terminal, encrypts it using the session key key-B and transmits it to the second server; The second encryption machine carries the second session ID to the second key management platform to apply for a session key key-b to decrypt the authentication information; The second server queries that the virtual desktop resources matching the authentication information are located in the first server and initiates an access request to the first server.
[0006] Further, the main control unit of the terminal writes the key parameters into the data header of the data to be encrypted, and sends the data to be encrypted to the security chip, and the security chip generates the protection key from the quantum keys stored in its own internal memory according to the key parameters.
[0007] Furthermore, there are multiple servers, including a primary server and at least one secondary server. A cipher tube platform is equipped on one side of each server. The server is communicably connected to the cipher tube platform, and the cipher tube platforms communicate with each other through optical fibers or quantum satellites to enable the QKD1 and the QKD2 to distribute session keys based on a preset protocol.
[0008] Furthermore, after the terminal is networked and connected to the server, if the virtual desktop to which the terminal has access rights cannot be obtained from the connected server, the connected server sends an inquiry request to the primary server. The primary server reports the location information of the virtual desktop to the connected server, and the connected server sends an access request to the server storing the virtual desktop information.
[0009] Furthermore, the primary server records the corresponding relationship between the authentication information and the cloud ID. The cloud ID records the server information where the virtual desktop matching the terminal is located. Both the primary server and the secondary servers record the authentication information of the terminal.
[0010] Furthermore, there are multiple servers, and each server records the corresponding relationship between the authentication information and the cloud ID. If the connected server is different from the server where the virtual desktop is located, the server information where the virtual desktop is located can be directly obtained from the connected server, and the connected server sends an access request to the server where the virtual desktop is located.
[0011] Furthermore, in the confidentiality mode, when the files of the virtual desktop are sent out, the protection module of the server intercepts the outgoing behavior and verifies the authentication information input by the terminal.
[0012] Furthermore, the server is also connected to a quantum computer suitable for providing computing power support for the server, and the quantum computer communicates with the server based on the TCP protocol.
[0013] Furthermore, after the authentication request initiated by the terminal to the server is passed, the authentication unit of the server issues a temporary identity token to the terminal. The temporary identity token at least includes the authentication information, the valid login time, and the session ID. Subsequently, before the application session is disconnected, all accesses of the terminal to the server carry the temporary identity token.
[0014] The desktop cloud server and terminal secure communication method provided by the present invention. The server stores virtual desktop resources. After the terminal initiates an authentication request in the confidentiality mode and is passed, the server opens the virtual desktop resources that match the terminal authentication information, and maps the virtual desktop image to the terminal. When the virtual desktop resources that match the terminal authentication information are located on the first server and the terminal is networked and connected to the second server, an application session is established between the second server and the first server. The secure management platform distributes session keys for encryption and decryption to the first server and the second server based on the session ID, and the session keys are generated by QKD devices and have the characteristic of true randomness. Therefore, the communication method between the desktop cloud server and the terminal of the present invention has the characteristic of absolute security. The data transmission between each desktop cloud server is encrypted by the session key, and the encrypted communication data is difficult to be cracked, ensuring the communication security between the servers. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 It is a schematic diagram of data transmission of the desktop cloud server and terminal secure communication method in the embodiment of the present invention;
[0017] Figure 2 It is a flowchart of the desktop cloud server and terminal secure communication method in the first embodiment of the present invention;
[0018] Figure 3 It is a flowchart of step S102 in the first embodiment of the present invention;
[0019] Figure 4 It is a flowchart of the preferred implementation manner of the desktop cloud server and terminal secure communication method in the first embodiment of the present invention;
[0020] Figure 5 It is a flowchart of the desktop cloud server and terminal secure communication method in the second embodiment of the present invention;
[0021] Figure 6 It is a flowchart of the desktop cloud server and terminal secure communication method in the third embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0023] In the description of the specification of the present invention, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, the meaning of "a plurality" is a plurality, such as two, three, four, etc., unless otherwise specifically defined.
[0024] In the description of the specification of the present invention, unless otherwise clearly specified and limited, terms such as "connection" shall be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or integrated; it may be a mechanical connection, an electrical connection, or communication with each other; it may be directly connected, or indirectly connected through an intermediate medium, and it may be the internal connection of two components or the interaction relationship between two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0025] The following will describe in detail the technical solutions provided by each embodiment of the present application with reference to the accompanying drawings.
[0026] This application provides a secure communication method between a desktop cloud server and a terminal. The terminal is built-in with a security chip pre-filled with quantum keys. The terminal includes, but is not limited to, a computer. In addition to the hardware of a conventional terminal, the terminal of this application also includes a security chip. The security chip is electrically connected to the main control unit of the terminal. The security chip has the function of data storage and certain data processing capabilities. Before it is fixedly installed inside the terminal housing, a certain number of bytes of quantum keys are pre-filled in its internal storage area through a key filling machine. The total capacity of the quantum keys is determined according to the amount of data to be encrypted by the terminal, and can be 32M or 64M. The protection key in the present invention is formed by extracting part of the quantum random numbers from the quantum keys according to the key parameters. The length of the protection key can be 128 bits. The security chip also pre-stores an encryption algorithm, such as the national encryption algorithm SM4. The main control unit of the terminal writes the key parameters into the data header of the data to be encrypted and sends the data to be encrypted to the security chip. The security chip generates a protection key from the quantum keys stored in its own internal storage according to the key parameters, and substitutes the protection key and the data to be encrypted into the encryption algorithm to implement data encryption. The data decryption is the same, that is, substituting the decryption key and the data to be decrypted into the encryption algorithm to implement. It can be understood that the data packet to be encrypted generally includes a data header and a data part. The encryption and decryption operations in the embodiments of this application are performed on the data part. The security chip has a unique identity code, and the identity codes of the security chips of different terminals are different. The corresponding relationship between the quantum keys and the identity codes of the security chips is shared on the key management platform. The key management platform includes a quantum random number generator, a key switch, and a quantum security service mobile engine. In fact, after the quantum random number generator in the key management platform generates quantum random numbers, it sends them to the key switch for deviation correction processing to form quantum keys, and then fills them into the security chip through the key filling machine. When filling, the identity codes of each security chip and the key information filled on the security chip are registered in the quantum security service mobile engine. Therefore, the key management platform stores the corresponding relationship between the quantum keys and the security chips. The server stores a virtual desktop pool, which includes system resources such as windows, UOS, Kylin OS, deepin, etc., and software resources such as office, DingTalk, etc. The server provider can configure a number of software resources on its designated system according to the needs of terminal users to form a virtual desktop and present it to users. The terminal and the server are connected through a classical network. The server is communicably connected to an encryption machine, and the encryption machine is used to encrypt or decrypt the data transmitted from the terminal to the server. As Figures 1 to 3 shown, in the first embodiment of this application, the secure communication method includes:
[0027] S101: The terminal accepts the user's selection to configure it as a normal mode or a confidential mode;
[0028] Specifically, the terminal includes two operation modes. If the user selects the normal mode, the use of the terminal is the same as that in the prior art. The terminal comes with an operating system, and the user can freely send local files under the environment of this operating system without going through review. If the user selects the confidentiality mode, the terminal is equivalent to a display device at this time, and is used to display the virtual desktop resources adapted to it on the server.
[0029] S102: In the confidentiality mode, after the authentication request sent by the terminal to the server is passed, the server opens the virtual desktop pool resources matching the terminal authentication information, and maps the virtual desktop image on the terminal;
[0030] Specifically, an application program for starting the confidentiality mode is installed on the terminal. After the terminal is powered on, the user can enter the authentication interface for accessing the desktop cloud server by opening this application program. The user inputs authentication information. If the server verifies that the input is correct, the virtual desktop pool resources matching the authentication information are opened to this terminal. It can be understood that before step S102 is implemented, the system administrator configures the virtual desktop matching the authentication information, and generates a cloud ID uniquely associated with the authentication information. The cloud ID records at least the server information where the virtual desktop is located. After the terminal authentication is passed, only the virtual desktop matching the authentication information has the access right. In other words, the terminal user can purchase specific virtual desktop resources from the server provider according to actual needs. After the virtual desktop resources are configured by the system administrator on the server side, they are opened to the terminal when the terminal authentication is passed. Generally, the resources available for operation are different after different terminal users pass the authentication. After the terminal passes the authentication, the corresponding virtual desktop image is mapped on the terminal.
[0031] S103: The terminal collects the operation instructions input by the user on the virtual desktop, encrypts them with the session key key-A, and then transmits them to the server;
[0032] S104: The encryption machine applies to the cipher management platform for the session key key-a to decrypt the operation instructions and then sends them to the server, and the server executes corresponding actions with reference to the operation instructions.
[0033] Exemplarily, the user double-clicks on a certain office application program on the terminal virtual desktop to generate corresponding operation instructions. These operation instructions are wirelessly transmitted to the server after being encrypted with the session key key-A on the terminal. The server sends the ciphertext of the operation instructions to the encryption machine. The encryption machine applies to the cipher management platform for the session key key-a to decrypt the operation instructions. After decryption, the plaintext of the operation instructions is sent back to the server. If the server obtains the content of the operation instruction as "open a certain office application program", it will execute the open action.
[0034] In a further preferred embodiment, the secure communication method further includes:
[0035] S105: While the server performs the corresponding action, it generates a running image. The running image is encrypted by the session key key-a and then transmitted to the terminal. The terminal decrypts it using the session key key-A and displays it on the interface of the terminal.
[0036] Specifically, the server generates a running image on the virtual desktop in response to the operation instruction input by the terminal. The server sends the running image to the encryptor. The encryptor encrypts the running image data using the session key key-a and then sends it back to the server. The server transmits the ciphertext of the running image to the terminal main control unit. The main control unit sends the ciphertext of the running image to the security chip. The security chip decrypts it using the session key key-A and then sends it back to the main control unit. The main control unit performs digital-to-analog conversion on the plaintext of the running image and then displays it on the terminal interface. It can be understood that the running image is essentially composed of multiple image data streams. Encryption and decryption operations can be performed on the data packets formed by the image data streams at preset time intervals, and the transmission of data ciphertext can be realized. It can be understood that after S102 is implemented, S103 to S105 can be executed cyclically.
[0037] Among them, the session key key-A and the session key key-a are true random numbers generated by the quantum random number generator in the cipher management platform based on the principles of quantum physics. It can be understood that the true random numbers generated by the quantum random number generator in the cipher management platform can be filled in the security chip as protection keys or stored in the quantum security service mobile engine in the cipher management platform as session keys.
[0038] The desktop cloud server and terminal secure communication method provided by the present invention enables the terminal to be selectively configured as a normal mode or a confidentiality mode, so that the terminal not only retains the conventional information processing capabilities but also can access its own private virtual desktop function at any time to meet the diverse office needs of users. In particular, a security chip is placed inside the terminal. In the confidentiality mode, the operation instructions transmitted from the terminal to the server and / or the application images fed back from the server to the terminal can be encrypted by the session key formed by the quantum random number. Since the quantum random number has the characteristic of true randomness, the encrypted communication data is difficult to crack. Therefore, the communication method between the desktop cloud server and the terminal of the present invention has the characteristic of absolute security.
[0039] In the first embodiment of the present application, step S102 is specifically implemented as:
[0040] S1021: The terminal accesses the network, establishes a network connection with the server, and the two establish an application session to generate a first session ID;
[0041] S1022: The terminal encrypts the first session ID with the protection key formed by the quantum key built in the security chip, and sends the identity code of the security chip and the ciphertext of the first session ID to the key management platform to obtain the session key key-A;
[0042] Specifically, the correspondence between the identity code of the security chip and the quantum key has been pre-shared in the key management platform. The terminal main control unit includes a random number generation unit that can randomly generate key parameters. The key parameters include a key offset. For example, the offset 16 is randomly generated. The terminal main control unit writes the identity code of the security chip and the key parameters into the data header of the first session ID data packet. After the first session ID data packet is sent by the terminal main control unit to the security chip, the security chip obtains the key parameters, such as the offset, from the data header of the first session ID, that is, starts from the 17th bit from the starting position of the quantum key and intercepts 128 bits of true random number to form the protection key. The security chip encrypts the data part of the first session ID with the protection key, and combines the ciphertext of the data part and the data header into a data packet and sends it back to the terminal main control unit. The terminal sends the first session ID data packet to the key management platform. The key management platform locates the quantum key information filled by the security chip stored in itself through the identity code, and then extracts part of the quantum random number from the quantum key according to the key parameters to generate the protection key. The key management platform sends the protection key and the first session ID data packet to the encryption machine. The encryption machine decrypts the data part of the first session ID with the protection key and sends the plaintext of the first session ID back to the key management platform. The key management platform generates the session key key-A corresponding to the first session ID, registers the correspondence between the first session ID and the session key key-A, and then sends the session key key-A to the terminal so that the terminal can encrypt data such as operation instructions with the session key key-A. That is, in the present invention, the encryption and decryption operations of the data on the server side are implemented in the encryption machine, and the encryption and decryption operations of the data on the terminal side are implemented in the security chip.
[0043] In other embodiments, only the key parameters for generating the protection key can be written into the data header of the first session ID. The identity code of the security chip can be used as a separate data packet, and when the terminal sends the first session ID data packet to the key management platform, the security chip identity code data packet is sent together. In the present invention, the protection key can be randomly generated from the quantum key, so that the quantum key filled in the security chip can be recycled. Of course, the protection key can also be sequentially formed from the quantum key. For example, starting from the starting position of the quantum key, 128 bits are sequentially intercepted each time encryption is required to form the protection key. Since the quantum key itself has the characteristic of true randomness, the protection key randomly generated or sequentially generated also has the characteristic of true randomness, so that the data encrypted by the protection key has the characteristic of absolute security and is difficult to be cracked.
[0044] S1023: The user inputs authentication information on the terminal, encrypts it using the session key key-A, and transmits it to the server.
[0045] Specifically, the user inputs authentication information in the application program that starts the confidentiality mode on the terminal. The main control unit of the terminal sends the authentication information to the security chip through the data bus connecting it to the security chip. The security chip encrypts it using the session key key-A and then sends it back to the main control unit, and the main control unit transmits the ciphertext of the authentication information to the server.
[0046] S1024: The server sends the ciphertext of the authentication information and the first session ID to the encryption machine. The encryption machine applies for a decryption key from the cipher management platform with the first session ID. Specifically, after the terminal and the server establish an application session, both of them hold the first session ID. The encryption machine transmits the first session ID to the cipher management platform by wire. The cipher management platform generates a session key key-a that is the same as or associated with the session key key-A with reference to the first session ID and sends it to the encryption machine. It can be understood that if the session IDs carried by the terminal and the server when applying for the session key from the cipher management platform are the same, the session keys sent by the cipher management platform to both of them are the same or associated. One of the same or associated session keys can encrypt the data, and the other can decrypt the data ciphertext. Preferably, the session key key-A and the session key key-a are the same.
[0047] S1025: The encryption machine decrypts the authentication information using the session key key-a and sends it to the authentication unit of the server to confirm the access permission of the terminal. The terminal user can only access the virtual desktop resources associated with his authentication information pre-configured by the system administrator.
[0048] In the technical solution provided by the present invention, the session key is obtained by the security chip encrypting the session ID with its own protection key and exchanging it in the cipher management platform. Since different terminals are filled with different quantum keys, the protection keys formed based on the quantum keys are also different. Therefore, the data encrypted on the server side with the session key obtained by using the protection key of Terminal A can only be decrypted on Terminal A. If the data encrypted with the session key obtained by using the protection key of Terminal A is intercepted by Terminal B, since Terminal B cannot form the same protection key as Terminal A, the intercepted data cannot be decrypted. Therefore, in the confidentiality mode, the virtual desktop matching the authentication information is only accessible to a unique specific terminal, and other terminals cannot access it. Thus, the security of the user's confidential files is fully guaranteed, meeting the user's need for exclusive ownership of the terminal they hold.
[0049] In a further preferred embodiment, on the server side, after encrypting the session key key-A using the protection key in the secure pipe platform, the session key key-A is sent to the terminal to ensure the security during the transmission of the session key key-A; on the terminal side, the session key key-A is decrypted using the protection key in the security chip, and after decryption, the operation instructions input to the virtual desktop of the terminal can be encrypted using the session key key-A.
[0050] In a further preferred embodiment, after the terminal is authenticated, the authentication unit issues a temporary identity token to the terminal, and the server sends the temporary identity token to the encryption machine. The encryption machine encrypts the temporary identity token using the session key key-a and then sends it back to the server. The server transmits the encrypted temporary identity token to the terminal main control unit;
[0051] The terminal main control unit sends the encrypted temporary identity token to the security chip, and the security chip decrypts it using the session key key-A. Subsequently, before the application session is disconnected, all accesses of the terminal to the server carry the temporary identity token. The temporary identity token data packet encapsulates authentication information, valid login time, session ID, etc. When the terminal encrypts and transmits data to the server, the temporary identity token is written into the data header of the data to be encrypted.
[0052] In a further preferred embodiment, in the confidentiality mode, when a file of the virtual desktop is to be sent out, the protection module of the server intercepts the sending-out behavior and verifies the authentication information input by the terminal.
[0053] Exemplarily, when the terminal logs in to an application program in the confidentiality mode and enters the confidentiality mode, and selects a file in the virtual desktop to be copied to a USB flash drive, a prompt box for inputting authentication information pops up on the terminal interface. If the authentication information input by the user is consistent with the information corresponding to the virtual desktop resource filed in the server, the selected file is allowed to be copied to the USB flash drive. If the authentication information input by the user is inconsistent with the information filed in the server, the copy operation is invalid and the external sending cannot be achieved.
[0054] In a further preferred embodiment, the server is also connected to a quantum computer suitable for providing computing power support for it, and the quantum computer communicates with the server based on the TCP protocol.
[0055] To meet the usage requirements of end-users in multiple regions, it is necessary to deploy multiple desktop cloud servers in different cities across the country. To improve the communication efficiency between the end and the server, the end generally connects to the server closest to it. In other embodiments of the present invention, when the virtual desktop resources matching the authentication information of the end are located in the first server, and the end is networked with the second server. In other words, if the server where the end is initially authenticated is in region A, and the end is moved by the user to region B, since the end is close to the server in region B, the end automatically or manually selects to network with the server in region B by the user to avoid excessive time delay in data transmission. In this case, as Figure 4 shown, the secure communication method further includes:
[0056] S106: The second server establishes an application session with the first server and generates a third session ID;
[0057] Specifically, before implementing step S106, the end is networked with the second server to establish an application session and generate a second session ID. The end and the second server each hold this second session ID;
[0058] The end main control unit sends the second session ID data packet to the security chip. The security chip extracts part of the quantum random numbers from the quantum key filled in itself to form a protection key, encrypts the second session ID with the protection key, and sends the second session ID ciphertext back to the end main control unit. The end main control unit wirelessly sends the identity code of the security chip and the second session ID ciphertext to the second secret management platform. The second secret management platform generates a protection key suitable for decrypting the second session ID data packet according to the identity code, and sends the protection key and the second session ID ciphertext to the second encryption machine communicatively connected to the second secret management platform. The second encryption machine decrypts the second session ID ciphertext with the protection key and sends it back to the second secret management platform. The second secret management platform generates a session key key-B and transmits it to the end, and registers the corresponding relationship between the session key key-B and the second session ID;
[0059] The user inputs authentication information on the end. The end main control unit sends the authentication information to the security chip. After the security chip encrypts the authentication information with the session key key-B, it is transmitted by the end main control unit to the second server;
[0060] The second server sends the authentication information to the second encryption machine. The second encryption machine applies for the session key key-b from the second key management platform with the second session ID, and decrypts the authentication information by using the session key key-b. Since the session IDs carried by the second encryption machine and the terminal when applying for the session key from the second key management platform are the same, the session key key-B distributed by the second key management platform to the two is the same as or associated with the session key key-b, and the data encrypted by one of the session keys can be decrypted by the other session key;
[0061] The second encryption machine sends the plaintext of the authentication information to the second server. The second server queries that the virtual desktop resource matching the authentication information is located in the first server, initiates an access request to the first server, and establishes an application session with the first server.
[0062] Preferably, in the present invention, there are multiple desktop cloud servers, including a main server and several slave servers. A key management platform is equipped on one side of each server. The servers are wired-connected to each device of the key management platform. The key management platforms communicate with each other through optical fibers or quantum satellites. After the terminal is network-connected to the server, if the virtual desktop to which the terminal has access rights cannot be obtained from the connected server, the connected server initiates an inquiry request to the main server. The main server reports the location information of the virtual desktop to the connected server, and the connected server initiates an access request to the server storing the virtual desktop information. In fact, the main server records the corresponding relationship between the authentication information and the cloud ID. The cloud ID records the server information where the virtual desktop matching the terminal is located. Both the main server and the slave servers record the terminal authentication information. That is, as long as the input of the authentication information is correct when the terminal is connected to any desktop cloud server deployed by the supplier, it can enter the confidentiality mode. However, if the connected server is different from the server where the virtual desktop is located, the connected desktop obtains the server where the virtual desktop is located from the main server, and then the server where the virtual desktop is located transmits the virtual desktop to the connected server, or directly sends the virtual desktop data in a package to the connected server. In this embodiment, the first server is the main server and the second server is the slave server.
[0063] Certainly, in other embodiments, there are multiple desktop cloud servers, and each server records the corresponding relationship between the authentication information and the cloud ID. If the connected server is different from the server where the virtual desktop is located, the information of the server where the virtual desktop is located can be directly obtained from the connected server, and then the connected server can initiate an access to the server where the virtual desktop is located.
[0064] S107: The second encryption machine communicatively connected to the second server applies to the second cipher management platform for a session key key-C, carrying the third session ID and the cloud ID associated with the authentication information. The second cipher management platform registers the correspondence between the third session ID and the session key key-C, and sends the session key key-C to the second encryption machine. The second encryption machine encrypts the access request initiated by the second server to the first server using the session key key-C and sends it to the first server;
[0065] S108: The first server verifies whether the cloud ID matches its own ID. If it matches, it confirms that the virtual desktop matching the terminal is located on the first server. The first server sends the access request data packet to the first encryption machine. The first encryption machine applies to the first cipher management platform for a session key key-c, carrying the third session ID. Since the session IDs carried by the first encryption machine and the second encryption machine are the same, the obtained session key key-C and the session key key-c are the same. Therefore, the access request can be decrypted using the session key key-c. The first encryption machine sends the access request plaintext to the first server, and the first server retrieves the virtual desktop matching the cloud ID;
[0066] S109: The data packet formed by the virtual desktop data stream is sent to the first encryption machine. The first encryption machine encrypts the image of the virtual desktop using the session key key-c and transmits it to the second server. The second server sends the image ciphertext to the second encryption machine to decrypt it using the session key key-C and then transmits the image of the virtual desktop to the terminal;
[0067] Among them, the first cipher management platform includes QKD1, the second cipher management platform includes QKD2, the session key key-C is generated by the QKD2 device, and the session key key-c is generated by the QKD1 device. It should be noted that the QKD device is a quantum key distribution device. QKD1 and QKD2 transmit quantum states based on the BB84 protocol or the B92 protocol to achieve key distribution. It can be understood that the quantum key data in QKD1 and QKD2 is the same. When the first server and the second server apply for keys based on the same session ID, the obtained session key key-C and the session key key-c are the same, and the two can perform mutually inverse encryption and decryption operations.
[0068] In the second embodiment of the present application, as Figure 5 shown, the secure communication method includes:
[0069] S201: The terminal accepts the user's selection to be configured in the normal mode or the confidentiality mode;
[0070] S202: After the authentication request initiated by the terminal to the server is passed in the confidentiality mode, the server opens the virtual desktop pool resources matching the terminal authentication information, and maps the virtual desktop image to the terminal;
[0071] S203: The terminal collects the operation instructions input by the user on the virtual desktop and transmits them to the server;
[0072] S204: The server executes corresponding actions according to the operation instructions and generates a running image. The server sends the running image to the encryption machine, and the encryption machine applies for a session key key-A from the secret management platform, encrypts the running image with the session key key-A, and then transmits it to the terminal;
[0073] S205: After receiving the encrypted running image, the terminal main control unit sends the encrypted running image to the security chip. The security chip applies for a session key key-a from the secret management platform to decrypt the running image, and the security chip sends the decrypted plaintext of the running image back to the terminal main control unit, so that the running image is displayed on the interface of the terminal;
[0074] Wherein, the session key key-A and the session key key-a are formed by quantum random numbers.
[0075] The difference between this embodiment and the first embodiment of the present application is that in this second embodiment, the operation instructions input by the terminal on the virtual desktop are not encrypted, and only the running image mapped by the virtual desktop to the terminal is encrypted, which improves the communication efficiency between the desktop cloud server and the terminal while ensuring the security of the running image transmission.
[0076] In the third embodiment of the present application, as Figure 6 shown, the secure communication method includes:
[0077] S301: The terminal accepts the user's selection to be configured as the normal mode or the confidentiality mode;
[0078] S302: After the authentication request initiated by the terminal to the server is passed in the confidentiality mode, the server opens the virtual desktop pool resources matching the terminal authentication information, and maps the virtual desktop image to the terminal;
[0079] S303: The terminal collects the operation instructions input by the user on the opened virtual desktop, encrypts them with the session key key-A, and then transmits them to the encryption machine;
[0080] S304: The encryption machine applies for a session key key-a from the secret management platform to decrypt the operation instructions and then sends them to the server, and the server executes corresponding actions according to the operation instructions;
[0081] Among them, the session key key-A and the session key key-a are formed by quantum random numbers.
[0082] The difference between this embodiment and the first embodiment of the present application is that in this third embodiment, the operation instruction encrypted by the terminal is not transmitted to the server and then sent by the server to the encryption machine, but the ciphertext of the operation instruction is directly transmitted to the encryption machine. The encryption machine in this embodiment includes a communication module that can receive data and perform encryption and decryption processing. This implementation method not only ensures the security of data transmission between the desktop cloud server and the terminal, but also improves the communication efficiency and the user operation experience.
[0083] It should be noted that encrypting or decrypting data using a key as described in the present invention means substituting the key and the data to be encrypted or decrypted into a preset algorithm to implement the encryption or decryption operation. At the same time, steps S101 to S105, S106 to S109, S201 to S205, S301 to S304, and S1021 to S1025 in the present invention are only used to indicate a part of the operation of this secure communication method, and do not limit that their execution order must be in the order described.
[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for secure communication between a desktop cloud server and a terminal, characterized in that The server stores virtual desktop resources. After the authentication request initiated by the terminal in the confidentiality mode is passed, the server opens the virtual desktop resources that match the terminal authentication information and maps the virtual desktop image to the terminal. When the virtual desktop resources that match the terminal authentication information are located in the first server and the terminal is networked and connected to the second server, the secure communication method includes: S106: The second server establishes an application session with the first server and generates a third session ID; S107: The second encryption machine communicatively connected to the second server carries the third session ID and the cloud ID associated with the authentication information to apply for a session key key-C from the second key management platform, encrypts the access request initiated by the second server to the first server by using the session key key-C, and sends it to the first server; S108: After the first server verifies that the cloud ID passes, it applies for a session key key-c from the first key management platform based on the third session ID to decrypt the access request, and retrieves the virtual desktop that matches the cloud ID; S109: Encrypts the virtual desktop image by using the session key key-c and transmits it to the second server, and the second server decrypts it by using the session key key-C and then transmits it to the terminal; Wherein, the first key management platform includes QKD1, the second key management platform includes QKD2, the session key key-C is generated by the QKD2 device, and the session key key-c is generated by the QKD1 device.
2. The secure communication method according to claim 1, wherein, The terminal is built-in with a security chip pre-filled with quantum keys. Before step 106 is implemented, the secure communication method further includes: The terminal establishes an application session with the second server and generates a second session ID; Encrypts the second session ID by using the protection key formed by the quantum keys, and sends the identity code of the security chip and the ciphertext of the second session ID to the second key management platform to obtain a session key key-B; The user inputs authentication information on the terminal, encrypts it by using the session key key-B and transmits it to the second server; The second encryption machine carries the second session ID to apply for a session key key-b from the second key management platform to decrypt the authentication information; The second server queries that the virtual desktop resources that match the authentication information are located in the first server, and initiates an access request to the first server.
3. The secure communication method according to claim 2, wherein The terminal main control unit writes the key parameters into the data header of the data to be encrypted, and sends the data to be encrypted to the security chip, and the security chip generates the protection key from the quantum keys stored in its own internal memory according to the key parameters.
4. The secure communication method according to claim 1, characterized in that, There are multiple servers, including a primary server and at least one secondary server. A cipher tube platform is equipped on one side of each server. The server is communicably connected to the cipher tube platform. The cipher tube platforms perform data communication through optical fibers or quantum satellites, so that the QKD1 and the QKD2 distribute session keys based on a preset protocol.
5. The secure communication method according to claim 4, wherein After the terminal is networked with the server, if the virtual desktop to which the terminal has access rights cannot be obtained from the connected server, the connected server sends an inquiry request to the primary server. The primary server reports the location information of the virtual desktop to the connected server, and the connected server sends an access request to the server storing the virtual desktop information.
6. The secure communication method according to claim 4, wherein The primary server records the corresponding relationship between the authentication information and the cloud ID. The cloud ID records the server information where the virtual desktop matching the terminal is located. Both the primary server and the secondary server record the authentication information of the terminal.
7. The secure communication method according to claim 1, wherein There are multiple servers, and each server records the corresponding relationship between the authentication information and the cloud ID. If the connected server is different from the server where the virtual desktop is located, the server information where the virtual desktop is located can be directly obtained from the connected server, and the connected server sends an access to the server where the virtual desktop is located.
8. The secure communication method according to any one of claims 1 to 7, characterized in that In the confidentiality mode, when the files of the virtual desktop are sent out, the protection module of the server intercepts the sending-out behavior and verifies the authentication information input by the terminal.
9. The secure communication method according to claim 8, wherein The server is also connected to a quantum computer suitable for providing computing power support for the server. The quantum computer communicates with the server based on the TCP protocol.
10. The secure communication method according to claim 8, wherein After the authentication request sent by the terminal to the server is passed, the authentication unit of the server issues a temporary identity token to the terminal. The temporary identity token at least includes the authentication information, the valid login time, and the session ID. Subsequently, before the application session is disconnected, the access of the terminal to the server carries the temporary identity token.
Citation Information
Patent Citations
Method and device for connection authentication between desktop cloud client and server-side
CN105187362A
Encrypted password transport across untrusted cloud network
CN108781227A