Method, device, and computer program product for peripheral authentication
By communicating directly with peripheral devices and edge devices, utilizing edge device resources for computing and storage, and employing an authentication mechanism based on identifiers and location information, the resource waste and security issues in virtual desktop technology are resolved, achieving an efficient and secure user experience.
Patent Information
- Application Number
- CN202111229480.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-21
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2041-10-21
AI Technical Summary
Existing virtual desktop technologies suffer from wasted hardware and software resources on client devices, high network resource consumption, and a lack of effective peripheral device authentication methods, which negatively impact user experience and security.
By communicating directly with edge devices through peripheral devices, utilizing edge device resources for computing and storage, and employing an authentication mechanism based on identifiers and location information, an efficient and secure authentication process is achieved.
It reduces network resource consumption, lowers latency, improves user experience, and enhances data security and privacy, adapting to the security needs of different users and application scenarios.
Smart Images

Figure CN116015698B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present disclosure relate to the field of computer, and in particular, to a method, device and computer program product for peripheral device authentication. BACKGROUND
[0002] A virtual desktop can be used to implement remote dynamic access of a desktop system. For example, a virtual desktop can be used to access files, install and run application programs, etc. Generally, a user uses a virtual desktop through a client device. For example, a user can access a virtual desktop by using an application or a browser running on a client device. However, the operation processing performed when using a virtual desktop is generally completed by using the resources of a remote server, and thus there is a waste of hardware and software resources of the client device.
[0003] To this end, it is proposed to use a peripheral device having the ability to be directly connected to an edge device to implement the use of a virtual desktop. Thus, it is possible to implement the use of a virtual desktop without using the hardware and software resources at the client, but directly connecting the peripheral device to the edge device to access the virtual desktop deployed on the edge device. Therefore, effective authentication of the edge device to the peripheral device is an important prerequisite for protecting the security of the business, and thus an effective and efficient authentication method is particularly important. SUMMARY
[0004] Generally, embodiments of the present disclosure propose a method, device and computer program product for peripheral device authentication.
[0005] In a first aspect of the present disclosure, a method implemented at a peripheral device is provided. The method includes sending, to an edge device, a first authentication request for at least the peripheral device to use resources of the edge device. The first authentication request includes at least a first identifier associated with the peripheral device and location information of the peripheral device. The method further includes receiving, from the edge device, an indication of authentication success or failure.
[0006] In a second aspect of the present disclosure, a method implemented at an edge device is provided. The method includes receiving, from a peripheral device, a first authentication request for at least the peripheral device to use resources of the edge device. The first authentication request includes at least a first identifier associated with the peripheral device and location information of the peripheral device. The method further includes authenticating, based at least on the first identifier and the location information of the peripheral device, at least the peripheral device to use the resources of the edge device. The method further includes sending, to the peripheral device, an indication of authentication success or failure.
[0007] In a third aspect of the disclosure, a peripheral device is provided. The device includes a processor and a memory storing computer-executable instructions. The computer-executable instructions, when executed by the processor, cause the device to perform acts including sending, to an edge device, a first authentication request for at least the peripheral device to use a resource of the edge device. The first authentication request includes at least a first identifier associated with the peripheral device and location information of the peripheral device. The acts further include receiving, from the edge device, an indication of a success or failure of the authentication.
[0008] In a fourth aspect of the disclosure, an edge device is provided. The device includes a processor and a memory storing computer-executable instructions. The computer-executable instructions, when executed by the processor, cause the device to perform acts including receiving, from a peripheral device, a first authentication request for at least the peripheral device to use a resource of the edge device. The first authentication request includes at least a first identifier associated with the peripheral device and location information of the peripheral device. The acts further include authenticating, based at least on the first identifier and the location information of the peripheral device, at least the peripheral device to use the resource of the edge device. The acts further include sending, to the peripheral device, an indication of a success or failure of the authentication.
[0009] In a fifth aspect of the disclosure, a computer program product is provided, tangibly stored on a computer readable medium and comprising machine executable instructions that, when executed, cause a machine to perform the method according to the first aspect.
[0010] In a sixth aspect of the disclosure, a computer program product is provided, tangibly stored on a computer readable medium and comprising machine executable instructions that, when executed, cause a machine to perform the method according to the second aspect.
[0011] It is to be understood that the description of the background of the disclosure in this summary section is not intended to limit or restrict the scope of the disclosure to the key or important features described, but merely to aid in understanding of the disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0012] The above and other features, aspects, and advantages of embodiments of the disclosure will become more apparent from the following detailed description when taken in conjunction with the accompanying drawings. In the drawings, like reference numerals refer to like elements, wherein:
[0013] Figure 1 A schematic diagram illustrating an environment in which embodiments of the disclosure can be implemented is shown;
[0014] Figure 2 A flowchart illustrating an example method implemented at a peripheral device, according to some embodiments of the disclosure is shown;
[0015] Figure 3 A flow diagram illustrating an example method implemented at an edge device, in accordance with some embodiments of the present disclosure, is shown;
[0016] Figure 4 A flow diagram illustrating an example authentication procedure between a peripheral device and an edge device, in accordance with some embodiments of the present disclosure, is shown;
[0017] Figure 5 A flow diagram illustrating another example authentication procedure between a peripheral device and an edge device, in accordance with some embodiments of the present disclosure, is shown; and
[0018] Figure 6 A block diagram illustrating an example computing device that can be used to implement embodiments of the present disclosure is shown. DETAILED DESCRIPTION
[0019] The principles of embodiments of the present disclosure will now be described, by way of example only, with reference to a number of example embodiments and the accompanying drawings. While preferred embodiments of the present disclosure are shown in the drawings, it is understood that these embodiments are merely for the purpose of better understanding the present disclosure and are not to be construed as limiting the scope of the present disclosure in any way.
[0020] The term "comprising" and variations thereof as used herein are intended to mean "including but not limited to." The term "or" as used herein is intended to mean "and / or." The term "based on" means "based, at least in part, on." The term "one example embodiment" and "some embodiments" means "at least one example embodiment." The term "another embodiment" means "at least one additional embodiment." The terms "a first," "a second," etc. are meant to be aliases for distinct but like objects. Other aliases can be used, however, without departing from the scope of the present disclosure.
[0021] As used herein, the term "determining" encompasses a wide variety of actions. For example, "determining" can include calculating, computing, processing, deriving, investigating, looking up (such as, for example, looking up in a table, a database or another data structure), ascertaining and the like. Also, "determining" can include receiving (such as, for example, receiving information), accessing (such as, for example, accessing data in a memory) and the like. Also, "determining" can include resolving, selecting, choosing, establishing and the like.
[0022] The term "peripheral device" as used herein refers to a device or equipment used for information processing on the user side. Examples of peripheral devices can include, but are not limited to, the following types of devices: mouse, keyboard, display, camera, earphone, microphone, etc.
[0023] As used herein, the term "edge device" refers to a device for edge computing. The edge device can be an apparatus or device that provides storage resources, computing resources, network bandwidth, and the like resources for other clients (mobile stations, smart phones, smart watches, personal digital assistants (PDAs), cell phones, devices using wireless modems, laptop computers and / or touch screen computers, tablets, game consoles, notebooks and multimedia devices, and peripheral devices of the above, and the like terminals or devices).
[0024] In recent years, the related technology of virtual desktops has been continuously developed. As mentioned above, the operation processing performed when using a virtual desktop is usually completed by using the resources of a remote server, so there is a waste of hardware and software resources of the client device. Although the continuous development of virtual desktops and similar technologies promotes the development of personal computing devices, such as thin clients, zero clients, and the like. However, these client devices still need to have native computing resources, storage resources, and the like. In addition, it is very difficult to manage and maintain different client devices and the programs on the corresponding client devices for using virtual desktops. In addition, since data needs to be sent to a remote server (such as a cloud data center server) for operation processing, it can cause high network resource consumption. In this case, the conventional virtual desktop using scheme is difficult to achieve fast response of user interaction, thereby reducing the user experience.
[0025] To this end, a new way of efficient interaction between a user terminal and a virtual desktop infrastructure has been proposed. The peripheral device can be provided with the ability to directly and independently communicate with the edge device, so that it can directly implement the use of the virtual desktop without any intermediaries or other auxiliary connections. Thus, it is possible to achieve a true zero client without using the hardware and software resources at the client, but directly connecting the peripheral device to the edge device to completely move the computing and storage, and the like to the remote infrastructure. By directly processing user data at the edge device, it is possible to reduce the consumption of network resources caused by transmitting user data to the cloud for processing, thereby reducing the latency, and thus providing a better experience for users in some scenarios that require low latency (for example, using game applications, video, audio related applications, and the like). Directly processing user data at the edge device 120 can also improve data security and privacy. With the continuous development of the fifth generation (5G) technology, such a flexible and easy-to-operate interaction method can be more widely applied.
[0026] However, the effective authentication of the peripheral device by the edge device is an important prerequisite for protecting the security of the above-mentioned services, and therefore an effective and efficient authentication method is particularly important. In addition, it is expected that direct access to virtual desktops will be widely used in personal use computers, computers for personal work use, and even shared computers for company business in the future, so the direct access to virtual desktops is adapted to different users and profiles, and the authentication of the edge device can achieve different levels of security and convenience for different application scenarios, which puts forward new requirements. In addition, it is still a problem to be solved to provide a secure, intuitive, and easy-to-use authentication solution for the peripheral device.
[0027] Embodiments of the present disclosure propose a scheme for peripheral device authentication. In the scheme, the peripheral device sends an authentication request for at least the use of the resources of the edge device by the peripheral device to the edge device, the authentication request at least including an identifier associated with the peripheral device and location information of the peripheral device. Accordingly, the edge device receives the authentication request and authenticates the peripheral device based on the identifier and the location information of the peripheral device. Then, the edge device sends an indication of authentication success or failure to the peripheral device. In this way, effective authentication of the peripheral device can be achieved with a lower complexity authentication process, so that the security of the access of the peripheral device to the virtual desktop can be improved while ensuring a good user experience.
[0028] The basic principles and several example embodiments of the present disclosure are described below with reference to Figures 1 to 6 It should be understood that these example embodiments are given only to enable those skilled in the art to better understand and implement embodiments of the present disclosure, and do not limit the scope of the present disclosure in any way.
[0029] Figure 1 An environment 100 in which embodiments of the present disclosure can be implemented is shown. As Figure 1 shown, the environment 100 includes a peripheral device 110 and an edge device 120. The peripheral device 110 and the edge device 120 have a communication connection therebetween. The peripheral device 110 can communicate with the edge device 120 using a wireless communication method. For example, the peripheral device 110 can have a 5G, WiFi 6, or Ethernet communication interface to implement communication with the edge device 120. The peripheral device can have a communication connection with another peripheral device (not shown). The peripheral device 110 can be associated with different users. For example, multiple users can operate the peripheral device 110 at different times, respectively.
[0030] As Figure 1As shown, a virtual desktop 130 can be deployed on the edge device 120 for users to perform operations such as computing and storage. The virtual desktop 130 can be used by different users. In some other embodiments, multiple virtual desktops (not shown) can be deployed on the edge device 120. These virtual desktops can be used by the same user for different purposes, or they can be used by different users. The scope of this disclosure is not limited in this regard. In some embodiments, the edge device 120 can be associated with a base station of a network service provider. For example, the edge device 120 can be deployed on the base station side. In particular, the edge device 120 can be deployed on the side of a 5G distributed base station to achieve high-quality communication between the edge device 120 and the peripheral device 110.
[0031] It should be understood that Figure 1 The environment 100 shown is merely exemplary and should not constitute any limitation on the functionality and scope of the implementation described in this disclosure. Figure 1 The number of peripheral devices and edge devices shown is given for illustrative purposes. Environment 100 may include any suitable number of peripheral devices and edge devices. For example, environment 100 may also include a cloud that can communicate with at least one of peripheral devices 110 and edge devices 120. The cloud may host a scheduling service for managing and scheduling at least one of peripheral devices 110 and edge devices 120.
[0032] Figure 2 A flowchart illustrating an example method 200 implemented at a peripheral device according to some embodiments of the present disclosure is shown. For example, method 200 may be implemented by, for example... Figure 1 The method is executed by the peripheral device 110 shown. It should be understood that the method 200 can also be executed by other devices, and the scope of this disclosure is not limited in this respect. It should also be understood that the method 200 may also include additional actions not shown and / or the actions shown may be omitted, and the scope of this disclosure is not limited in this respect.
[0033] like Figure 2 As shown, at block 210, peripheral device 110 sends an authentication request (also called a first authentication request) to edge device 120 for at least peripheral device 110's use of resources of edge device 120. This first authentication request includes at least an identifier associated with peripheral device 110 (also called a first identifier) and location information of peripheral device 110. For example, the location information of peripheral device 110 can be obtained via the Internet using a chip built into peripheral device 110. In some embodiments, the first authentication request may also include other relevant auxiliary authentication information, such as historical authentication information of peripheral device 110.
[0034] In some embodiments, the peripheral device 110 can be configured to send a first authentication request to the edge device 120 if an indication for authentication from the user is received. For example, in the case that the peripheral device 110 has keys, the peripheral device 110 can be configured to send the first authentication request to the edge device 120 if it detects that the user presses certain keys in a certain order, or that the user continuously presses a certain key at a certain time. In some embodiments, the peripheral device 110 can utilize its indicator light to indicate that an indication for authentication from the user has been received, for example, by blinking the indicator light to indicate that it has received an indication from the user.
[0035] In some embodiments, the peripheral device 110 can receive an identifier (also referred to as a second identifier) associated with the peripheral device 110 that is input by the user. In turn, the peripheral device 110 can send the received second identifier to the edge device 120 for subsequent authentication. In some other embodiments, if the peripheral device 110 does not obtain the identifier information input by the user, the authentication process can proceed without the need for the user to input the identifier information.
[0036] In some embodiments, if the above information is not successfully authenticated, the peripheral device 110 can receive an indication from the edge device 120 for further authentication of at least the peripheral device 110 using the resources of the edge device 120. In some embodiments, the peripheral device 110 can receive authentication information (also referred to as first authentication information) input by the user for further authentication of the peripheral device 110 using the resources of the edge device 120. Accordingly, the peripheral device 110 can send an authentication request (also referred to as a second authentication request) including at least the first authentication information to the edge device 120 to request further authentication of the peripheral device 110. In some embodiments, the second authentication request can also include location information of the peripheral device 110 or any other information obtained by the peripheral device 110 for authentication, etc.
[0037] Alternatively, the peripheral device 110 can communicate with another peripheral device in the surrounding, and based on the indication of the user, or the indication of the other peripheral device, or be set to automatically pair with the other peripheral device. The paired group of peripheral devices can request the authentication for the group of peripheral devices to the edge device 120 as a whole, so that the authentication of the group of peripheral devices by the edge device 120 can be achieved with only a single authentication, further simplifying the authentication process. For example, a certain peripheral device can be selected from the group of peripheral devices to carry the authentication information associated with the group of peripheral devices to jointly request the authentication to the edge device 120. For ease of discussion, the peripheral device 110 is selected to request the authentication for the group of peripheral devices to the edge device 120 as an example. In some embodiments, the peripheral device 110 can receive the authentication information (also referred to as second authentication information) input by the user for the authentication of the group of peripheral devices to use the resources of the edge device 120. Accordingly, the peripheral device 110 can send an authentication request (also referred to as third authentication request) including at least the second authentication information to the edge device 120 to request the authentication of the group of peripheral devices jointly to the edge device 120. In some embodiments, the third authentication request can further include the location information of the peripheral device or any other information obtained by the peripheral device for the authentication, etc.
[0038] To protect the privacy of different users, the virtual desktop 130 deployed on the edge device 120 can create an account associated with the different users, and all the operations of the user will be associated to the account. Thus, the authentication of the peripheral device 110 to the edge device 120 is also linked to the account associated with the user. Therefore, in some embodiments, the above authentication information input by the user can further include account information, which can indicate the account situation associated with the user. For example, the account information can indicate that there is no account associated with the user, to request the edge device 120 to establish a new account for the user to link the peripheral device 110 to the new account. Alternatively, the account information can indicate the information such as the name of the existing account associated with the user, to request the edge device 120 to link the peripheral device 110 to the associated existing account. Alternatively, the indication of the account information can be informed to the edge device 120 by the user through another device (such as a mobile phone, a laptop).
[0039] In some embodiments, depending on the type of the peripheral device 110, the peripheral device 110 can acquire the information input by the user in various ways. For example, if the peripheral device 110 is a keyboard, it can acquire the above-mentioned authentication information by detecting the input sequence of the user to the keyboard. For example, if the peripheral device 110 has buttons, it can acquire the above-mentioned authentication information by detecting the pressing sequence and time of the user to the buttons. For example, if the peripheral device 110 is a device that can track the motion trajectory, it can detect the above-mentioned authentication information by its motion trajectory. For example, if the peripheral device 110 is a device that can acquire audio, it can acquire the above-mentioned authentication information by detecting the sound characteristics of the user. For example, if the peripheral device 110 is a device that can acquire images, it can acquire the above-mentioned authentication information by the acquired video or photo of the user. In some embodiments, depending on the number of keys involved in the keyboard input, the number of buttons available for the button input, the complexity of the trajectory formed in the motion input, the content of the audio and video input, etc., the security level of the authentication can be set according to actual needs, and the above-mentioned authentication methods can be arbitrarily combined, and the scope of the present disclosure is not limited in this regard.
[0040] As shown in FIG. 2, at block 220, the peripheral device 110 receives an indication of authentication success or failure from the edge device 120. If the peripheral device 110 is successfully authenticated to the edge device 120, the peripheral device 110 will be connected to the edge device 120 by default in subsequent operations. If the peripheral device 110 is instructed to reconnect to another edge device, the above-mentioned authentication process can be repeated. Figure 2
[0041] In some embodiments, to further improve security, an overage logout policy can be adopted. That is, after the peripheral device 110 is connected to the edge device 120 for more than a certain time, the peripheral device 110 will be disconnected. The peripheral device 110 can repeat the above-mentioned authentication process to continue to connect to the edge device 120.
[0042] In some embodiments, the peripheral device 110 can use its indicator light to embody the received indication of authentication success or failure. For example, if the peripheral device 110 receives an indication of authentication success, a green indicator light can be turned on; if the peripheral device 110 receives an indication of authentication failure, a red indicator light can be turned on.
[0043] In some embodiments, peripheral device 110 may be factory-configured to automatically connect to a 5G network upon first power-on and connect to edge device 120 via the 5G network to send a registration verification request to verify whether peripheral device 110 has been registered. This registration verification request may include at least an identifier associated with peripheral device 110 and location information of peripheral device 110. In some embodiments, if peripheral device 110 has been pre-registered with edge device 120 by a user, peripheral device 110 can successfully connect to edge device 120 to use virtual desktop 130 without performing the aforementioned authentication process. In some other embodiments, if peripheral device 110 has not been previously registered, peripheral device 110 receives information from edge device 120 indicating that peripheral device 110 is not registered and instructing it to wait for subsequent operations. Peripheral device 110 then waits for subsequent operations to perform the aforementioned authentication process.
[0044] Alternatively or additionally, instead of using peripheral device 110, users may access virtual desktop 130 using conventional devices (e.g., desktop computers, laptops, smartphones) that can independently perform the user's desired operations.
[0045] The above text combined Figures 1 to 2 This paper describes an authentication scheme implemented at peripheral device 110. Based on this scheme, efficient authentication can be achieved through simple operations at peripheral device 110, improving the user experience. The following section combines... Figure 3 Describe the authentication process implemented at edge device 120.
[0046] Figure 3 A flowchart illustrating an example method 300 implemented at an edge device according to some embodiments of the present disclosure is shown. For example, method 300 may be implemented by, for example... Figure 1 The method is performed by the edge device 120 shown. It should be understood that the method 300 can also be performed by other devices, and the scope of this disclosure is not limited in this respect. It should also be understood that the method 300 may also include additional actions not shown and / or the actions shown may be omitted, and the scope of this disclosure is not limited in this respect.
[0047] like Figure 3 As shown, at block 310, edge device 120 receives from peripheral device 110 an authentication request for at least peripheral device 110 to use resources of edge device 120. The authentication request includes at least a first identifier associated with peripheral device 110 and location information of peripheral device 110.
[0048] In some embodiments, the edge device 120 may receive a second identifier associated with the peripheral device 110, input by a user, from the peripheral device 110. In some embodiments, the peripheral device 110 may not need to obtain the second identifier information; that is, the authentication process may be performed without requiring user input of identifier information.
[0049] In some embodiments, the edge device 120 may obtain the user's location information. For example, the edge device 120 may obtain the location information from another device (such as a laptop browser or a mobile browser) used by the user to log in to the virtual desktop 130 for assisted registration.
[0050] like Figure 3 As shown, at block 320, edge device 120 authenticates at least one peripheral device's use of edge device 120's resources based at least on a first identifier and the location information of the peripheral device. In some embodiments, edge device 120 may authenticate at least one peripheral device based on the first identifier, the location information of the peripheral device, a second identifier, and the user's location information. Alternatively, edge device 120 may authenticate at least one peripheral device based solely on the location information of the peripheral device and the user's location information.
[0051] like Figure 3 As shown, at box 330, edge device 120 sends an indication of successful or failed authentication to peripheral device.
[0052] In some embodiments, if the first identifier matches the second identifier, and the distance between the location information of the peripheral device 110 and the location information of the user is less than a certain threshold distance (referred to as the threshold distance), then the edge device 120 may send an authentication success indication to the peripheral device 110. Alternatively, the edge device 120 may send an authentication success indication to the peripheral device 110 solely based on the fact that the distance between the location information of the peripheral device 110 and the location information of the user is less than the threshold distance.
[0053] In some embodiments, if the first identifier and the second identifier do not match, but the distance between the location information of the peripheral device 110 and the location information of the user is less than a threshold distance, the edge device 120 may send an instruction to the peripheral device 110 to further authenticate at least the peripheral device 110's use of the resources of the edge device 120. It should be understood that the aforementioned threshold distance can be pre-configured by the user, and the threshold distance can be set to any value as needed, without limitation by this disclosure.
[0054] In some embodiments, the edge device 120 can receive a second authentication request from the peripheral device 110, the second authentication request comprising first authentication information entered by the user on the peripheral device 110, the first authentication information being used to further authenticate the peripheral device 110 for using the resource of the edge device 120. And accordingly, if the received first authentication information matches a reference authentication information (also referred to as first reference authentication information), the edge device 120 sends an indication of authentication success to the peripheral device 110 to indicate to the peripheral device 110 that the use of the virtual desktop 130 on the edge device 120 is permitted.
[0055] Alternatively, the edge device 120 can receive a third authentication request from the peripheral device 110. The third authentication request comprises at least second authentication information entered by the user on the peripheral device 110, the second authentication information being used to further authenticate a group of peripheral devices including the peripheral device 110 for using the resource of the edge device 120. And accordingly, if the received second authentication information matches a reference authentication information (also referred to as second reference authentication information), the edge device 120 sends an indication of authentication success to the group of peripheral devices respectively to indicate that the use of the virtual desktop 130 on the edge device 120 is permitted. In some embodiments, the above-mentioned reference authentication information can be pre-configured to the edge device 120 by the user. Alternatively, the above-mentioned reference authentication information can be pre-configured to assist the first authentication without the user manually setting.
[0056] In some embodiments, the above-mentioned authentication information received by the edge device 120 can further comprise account information indicating a status of an account associated with the user. If the account information indicates that there is no account associated with the user, the edge device 120 generates a new account for the user and links the peripheral device 110 to the new account. Accordingly, if the edge device 120 receives a request for authentication for a group of peripheral devices, the edge device 120 links the group of peripheral devices to the new account. Alternatively, if the account information indicates specific information of an existing account associated with the user, such as the name of the existing account, the edge device 120 links the peripheral device 110 to the existing account. Accordingly, if the edge device 120 receives a request for authentication for a group of peripheral devices, the edge device 120 links the group of peripheral devices to the existing account associated.
[0057] In some embodiments, as mentioned above, an overdue logout policy can be employed. That is, after the peripheral device 110 is connected to the edge device 120 for more than a certain time, the edge device 120 can cancel the authentication with the peripheral device 110, so that the peripheral device 110 is disconnected from the edge device 120. In this way, the security of the service can be further improved.
[0058] In some embodiments, prior to the above authentication process, the edge device 120 can receive a registration verification request from the peripheral device 110 to verify whether the edge device 120 has registered the peripheral device 110. The registration verification request can include at least a first identifier associated with the peripheral device 110 and location information of the peripheral device 110. If the edge device 120 learns that the peripheral device 110 has been registered, the peripheral device 110 can directly connect with the edge device 120 to access the virtual desktop 130 without the subsequent authentication process. If the edge device 120 learns that there is no information matching the first identifier of the peripheral device 110, the edge device 120 sends information to the peripheral device 110 indicating that the peripheral device 110 is not registered and instructing it to wait for the subsequent operation.
[0059] The flowchart of an example authentication process between the peripheral device 110 and the edge device 120 is discussed below in connection with Figure 4 and Figure 5 . Figure 4 The flowchart of an example authentication process between the peripheral device 110 and the edge device 120 is shown according to some embodiments of the present disclosure. It should be understood that Figure 4 the examples are merely illustrative and do not limit the scope of the present disclosure.
[0060] After the peripheral device 110 is powered on, the peripheral device 110 sends a registration verification request including a first identifier associated with the peripheral device 110 and location information of the peripheral device 110 to the edge device 120 at 402. Accordingly, the edge device 120 determines whether the peripheral device 110 has been registered based on the information in the received registration verification request at 404. If the peripheral device 110 has not been registered, the edge device 120 sends information to the peripheral device 110 indicating that the peripheral device 110 has not been registered and instructing it to wait for the subsequent operation at 406. Then, the peripheral device 110 waits for the subsequent operation.
[0061] The edge device 120 can receive, from the peripheral device 110, the second identifier associated with the peripheral device 110, and obtain the location information of the user and the account information associated with the user. After the peripheral device 110 receives the indication from the user for authentication, at 408, the peripheral device 110 sends, to the edge device 120, a first authentication request for the peripheral device 110 to use the resource of the edge device 120. The first authentication request includes at least the first identifier associated with the peripheral device 110 and the location information of the peripheral device 110. At 410, the edge device 120 determines that the first identifier matches the second identifier, and the distance between the location information of the peripheral device 110 and the location information of the user is less than a threshold distance. In turn, at 412, the edge device 120 sends, to the peripheral device 110, an indication that the authentication is successful. In turn, the peripheral device 110 can be successfully linked to the account associated with the user on the virtual desktop 130.
[0062] In this way, the peripheral device 110 can be securely and efficiently accessed by the edge device 120 to enable the use of the virtual desktop 130 while making the overall authentication process easy for the user to operate.
[0063] Figure 5 A flowchart illustrating another example authentication process between the peripheral device 110 and the edge device 120 according to some embodiments of the present disclosure is shown. It should be understood that, Figure 5 The examples are merely illustrative and do not limit the scope of the present disclosure.
[0064] After the peripheral device 110 is powered on, at 502, the peripheral device 110 sends, to the edge device 120, a registration verification request including a first identifier associated with the peripheral device 110 and location information of the peripheral device 110. Accordingly, at 504, the edge device 120 determines whether the peripheral device 110 has been registered based on the information in the received registration verification request. If the peripheral device 110 has not been registered, at 506, the edge device 120 sends, to the peripheral device 110, information indicating that the peripheral device 110 has not been registered and instructing it to wait for a subsequent operation. In turn, the peripheral device 110 waits for the subsequent operation.
[0065] Edge device 120 can receive a second identifier associated with peripheral device 110, obtain user location information and account information associated with the user, and obtain first reference authentication information for authenticating peripheral device 110. After peripheral device 110 receives an authentication instruction from the user, at 508, peripheral device 110 sends a first authentication request to edge device 120 for peripheral device 110 to use resources of edge device 120. This first authentication request includes at least the first identifier associated with peripheral device 110 and the location information of peripheral device 110. At 510, edge device 120 determines that the first identifier and the second identifier do not match, but the distance between the location information of peripheral device 110 and the location information of the user is less than a threshold distance. Subsequently, at 512, edge device 120 sends an instruction to peripheral device 110 for further authentication of peripheral device 110's use of edge device 120's resources.
[0066] After peripheral device 110 receives the first authentication information input by the user, at step 514, peripheral device 110 sends a second authentication request, including the first authentication information, to edge device 120 to request further authentication of peripheral device 110. At step 516, peripheral device 110 determines that the first authentication information matches the first reference authentication information. Subsequently, at step 518, edge device 120 sends an authentication success indication to peripheral device 110. Then, peripheral device 110 can be successfully linked to the user-associated account on virtual desktop 130.
[0067] In this way, the edge device 120 can further authenticate the peripheral device 110 based on the specific authentication method of the peripheral device 110, thereby improving the security of the authentication process.
[0068] Figure 6 A schematic block diagram of an example device 600 that can be used to implement embodiments of the present disclosure is shown. For example, device 600 can be used in, for example... Figure 1 The environment shown is implemented in 100 locations. For example... Figure 6 As shown, device 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to computer program instructions stored in read-only memory (ROM) 602 or loaded from storage unit 608 into random access memory (RAM) 603. RAM 603 may also store various programs and data required for the operation of device 600. CPU 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.
[0069] A number of the components in device 600 are connected to the I / O interface 605, including an input unit 606, such as a keyboard, mouse, etc.; an output unit 607, such as various types of displays, speakers, etc.; a storage unit 608, such as a disk, a CD, etc.; and a communication unit 609, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 609 allows device 600 to exchange information / data with other devices over a computer network, such as the Internet, and / or various telecommunication networks.
[0070] The various processes and processes described above, such as method 200 and method 300, can be performed by processing unit 601. For example, in some embodiments, method 200 and method 300 can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed on device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by CPU 601, one or more acts of method 200 and method 300 described above can be performed.
[0071] The present disclosure can be a method, apparatus, system, and / or computer program product. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for performing various aspects of the present disclosure.
[0072] The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a SRAM, a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or punched tape, a magnetically encoded device such as magnetic strip cards, an optically encoded device such as a compact disc (CD) or DVD, and / or any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.
[0073] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.
[0074] Computer readable program instructions for carrying out operations of the present disclosure can be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state-setting data, or either source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The computer readable program instructions can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.
[0075] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process, such that the instructions which execute on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0076] These computer readable program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can include a non-transitory computer readable storage medium that can be a computer- readable storage medium having no data storage cycles that change state. The instructions can be executed by one or more processors of a computer, other programmable data processing apparatus, or other devices to produce a computer-implemented process such that the instructions which execute via the one or more processors of the computer or other programmable data processing apparatus create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. A computer readable storage medium can be, but is not limited to, a floppy disk, a hard disk, a solid state drive, a DVD, a CD, a tape, a magnetic
[0077] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable data processing apparatus implement the functions / acts specified in the flowchart and / or block diagram block or blocks.
[0078] The flow diagrams and the block diagrams in the drawings are presented to illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flow diagrams and the block diagrams can represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing the specified logical functions ("instructions"). In some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may
[0079] Embodiments of the present disclosure have been described above, and the description is intended to be illustrative of the embodiments and not restrictive of the disclosure. Many modifications and variations of the described embodiments are possible and are within the scope of the disclosure. The use of the terms "embodiment" or "implementation" or "aspect" does not limit the subject innovation to a version of the disclosure described but instead encompasses one or more implementations of the disclosure. The description used herein is intended to be illustrative, and not restrictive. Those skilled in the art will realize that many modifications and changes are possible and the present disclosure has been specifically devised to cover all such modifications and changes that fall within the scope of the present disclosure. The terms used herein have been chosen to best describe the principles and practical application of the embodiments of the present disclosure and to best enable others of ordinary skill in the art to understand the disclosure.
Claims
1. A method implemented at a peripheral device, comprising: sending, to an edge device, a first authentication request for at least the peripheral device to use resources of the edge device, the first authentication request including at least a first identifier associated with the peripheral device and location information of the peripheral device; and receiving, from the edge device, an indication of a success or failure of the authentication; wherein the first authentication request is configured by the peripheral device to initiate an authentication process in the edge device in which the edge device attempts to authenticate the peripheral device based on a comparison of the location information of the peripheral device to additional location information of a user associated with the peripheral device, wherein the additional location information is obtained by the edge device from a device other than the peripheral device; and wherein the first authentication request includes a request to jointly authenticate the peripheral device as a first peripheral device and one or more additional peripheral devices that are paired with each other based at least in part on their respective locations to form a paired group of peripheral devices including the first peripheral device and the additional peripheral devices, the first authentication request being sent by the first peripheral device to the edge device as a single joint authentication request for the group of peripheral devices.
2. The method of claim 1, wherein sending the first authentication request for at least the peripheral device to use resources of the edge device comprises: sending the first authentication request to the edge device in response to receiving an indication from the user for the authentication.
3. The method of claim 1 or 2, further comprising: receiving a second identifier associated with the peripheral device input by the user; and sending the second identifier to the edge device for use in the authentication.
4. The method of claim 1 or 2, further comprising: receiving an indication from the edge device to further authenticate at least the peripheral device to use the resources of the edge device.
5. The method of claim 4, further comprising: receiving authentication information input by the user for further authenticating the peripheral device to use the resources of the edge device; and sending an additional authentication request to the edge device including at least the authentication information for further authenticating the peripheral device to use the resources of the edge device.
6. The method of claim 4, further comprising: receiving authentication information input by the user for authenticating a group of peripheral devices including the peripheral device to use the resources of the edge device; and sending an additional authentication request to the edge device including at least the authentication information for authenticating the group of peripheral devices to use the resources of the edge device.
7. A method implemented at an edge device, comprising: receiving, from a peripheral device, a first authentication request for the peripheral device to use resources of the edge device, the first authentication request including at least a first identifier associated with the peripheral device and location information of the peripheral device; authenticating, based at least on the first identifier and the location information of the peripheral device, the peripheral device to use the resources of the edge device; and sending, to the peripheral device, an indication of success or failure of the authentication; wherein the authentication further comprises the edge device comparing the location information of the peripheral device with additional location information of a user, the user being associated with the peripheral device, the additional location information being obtained by the edge device from a device other than the peripheral device; and wherein the first authentication request comprises a request to jointly authenticate the peripheral device as a first peripheral device and one or more additional peripheral devices, the first peripheral device and the one or more additional peripheral devices being paired with each other to form a paired group of peripheral devices including the first peripheral device and the additional peripheral devices based at least in part on their respective locations, the first authentication request being sent by the first peripheral device to the edge device as a single joint authentication request for the group of peripheral devices.
8. The method of claim 7, further comprising: receiving, from the peripheral device, a second identifier associated with the peripheral device input by the user; and obtaining location information of the user.
9. The method of claim 8, wherein sending, to the peripheral device, the indication of success or failure of the authentication comprises: sending, to the peripheral device, an indication of success of the authentication in response to the first identifier matching the second identifier and a distance between the location information of the peripheral device and the location information of the user being less than a threshold distance.
10. The method of claim 8, further comprising: sending, to the peripheral device, an indication to further authenticate the peripheral device to use the resources of the edge device in response to the first identifier not matching the second identifier and the distance between the location information of the peripheral device and the location information of the user being less than a threshold distance.
11. The method of claim 10, wherein sending, to the peripheral device, the indication of success or failure of the authentication comprises: receiving, from the peripheral device, an additional authentication request for the peripheral device to use the resources of the edge device to further authenticate, the additional authentication request including at least authentication information input by the user to further authenticate the peripheral device; and sending, to the peripheral device, an indication of success of the authentication in response to the received authentication information matching reference authentication information.
12. The method of claim 10, wherein sending, to the peripheral device, the indication of success or failure of the authentication comprises: receiving, from the peripheral device, an additional authentication request for a group of peripheral devices including the peripheral device to use the resource of the edge device for authentication, the additional authentication request including at least authentication information input by the user for authenticating the group of peripheral devices; and in response to the received authentication information matching reference authentication information, sending, to the peripheral device, an indication that the authentication is successful, and the method further comprising: sending, to another peripheral device in the group of peripheral devices, the indication that the authentication is successful.
13. A peripheral device comprising: a processor, and a memory storing computer-executable instructions that, when executed by the processor, cause the device to perform acts comprising: sending, to an edge device, a first authentication request for at least the peripheral device to use a resource of the edge device, the first authentication request including at least a first identifier associated with the peripheral device and location information of the peripheral device; and receiving, from the edge device, an indication that the authentication is successful or failed; wherein the first authentication request is configured by the peripheral device to initiate an authentication process in the edge device in which the edge device attempts to authenticate the peripheral device based on a comparison of the location information of the peripheral device with additional location information of a user associated with the peripheral device, wherein the additional location information is obtained by the edge device from a device other than the peripheral device; and wherein the first authentication request includes a request to jointly authenticate the peripheral device as a first peripheral device and one or more additional peripheral devices that are paired with each other based at least in part on their respective locations to form a paired group of peripheral devices including the first peripheral device and the additional peripheral devices, the first authentication request being sent by the first peripheral device to the edge device as a single joint authentication request for the group of peripheral devices.
14. The device of claim 13, wherein sending the first authentication request for at least the peripheral device to use a resource of the edge device comprises: in response to receiving an indication from the user for the authentication, sending the first authentication request to the edge device.
15. The device of claim 13 or 14, the acts further comprising: receiving a second identifier associated with the peripheral device input by the user; and sending the second identifier to the edge device for use in the authentication.
16. The device of claim 13 or 14, the acts further comprising: receiving, from the edge device, an indication for further authentication of at least the peripheral device to use the resource of the edge device.
17. The device of claim 16, the acts further comprising: receiving authentication information input by the user for further authentication of the peripheral device to use the resource of the edge device; and sending, to the edge device, an additional authentication request including at least the authentication information for further authentication of the peripheral device for use of the resources of the edge device.
18. The device of claim 16, the actions further comprising: receiving authentication information input by the user for authentication of a group of peripheral devices including the peripheral device for use of the resources of the edge device; and sending, to the edge device, an additional authentication request including at least the authentication information for authentication of the group of peripheral devices for use of the resources of the edge device.
19. An edge device comprising: a processor, and memory storing computer executable instructions that, when executed by the processor, cause the device to perform actions comprising: receiving, from a peripheral device, a first authentication request for use of resources of the edge device by at least the peripheral device, the first authentication request including at least a first identifier associated with the peripheral device and location information of the peripheral device; authenticating, based at least on the first identifier and the location information of the peripheral device, use of the resources of the edge device by at least the peripheral device; and sending, to the peripheral device, an indication of success or failure of the authentication; wherein the authentication further comprises the edge device comparing the location information of the peripheral device to additional location information of a user, the user being associated with the peripheral device, the additional location information being obtained by the edge device from a device other than the peripheral device; and wherein the first authentication request comprises a request to jointly authenticate the peripheral device as a first peripheral device and one or more additional peripheral devices, the first peripheral device and the one or more additional peripheral devices being paired with each other to form a paired group of peripheral devices including the first peripheral device and the additional peripheral devices based at least in part on their respective locations, the first authentication request being sent by the first peripheral device to the edge device as a single joint authentication request for the group of peripheral devices.
20. The device of claim 19, the actions further comprising: receiving, from the peripheral device, a second identifier associated with the peripheral device input by the user; and obtaining location information of the user.
21. The device of claim 20, wherein sending, to the peripheral device, the indication of success or failure of the authentication comprises: sending, to the peripheral device, the indication of success of the authentication in response to the first identifier matching the second identifier and a distance between the location information of the peripheral device and the location information of the user being less than a threshold distance.
22. The device of claim 20, the actions further comprising: in response to the first identifier not matching the second identifier and a distance between the location information of the peripheral device and the location information of the user being less than a threshold distance, sending, to the peripheral device, an indication that the peripheral device is further authenticated to use the resource of the edge device.
23. The device of claim 22, wherein sending the indication of the success or failure of the authentication to the peripheral device comprises: receiving, from the peripheral device, an additional authentication request for the peripheral device to be further authenticated to use the resource of the edge device, the additional authentication request comprising at least authentication information entered by the user to further authenticate the peripheral device; and in response to the received authentication information matching reference authentication information, sending the indication of the success of the authentication to the peripheral device.
24. The device of claim 22, wherein sending the indication of the success or failure of the authentication to the peripheral device comprises: receiving, from the peripheral device, an additional authentication request for a group of peripheral devices including the peripheral device to be authenticated to use the resource of the edge device, the additional authentication request comprising at least authentication information entered by the user to authenticate the group of peripheral devices; and in response to the received authentication information matching reference authentication information, sending the indication of the success of the authentication to the peripheral device, and the acts further comprising: sending the indication of the success of the authentication to another peripheral device in the group of peripheral devices.
25. A computer program product tangibly stored on a computer readable medium and comprising machine executable instructions that, when executed, cause a machine to perform the method of any one of claims 1 to 6.
26. A computer program product tangibly stored on a computer readable medium and comprising machine executable instructions that, when executed, cause a machine to perform the method of any one of claims 7 to 12.
Citation Information
Patent Citations
Decoupled peripheral devices
US10360172B1
Zero-touch provisioning of IOT devices with multi-factor authentication
US10447683B1
Controlling access to protected functionality of a host device using a wireless device
US20160037345A1
Method and apparatus for geographic location based electronic security management
US20170195339A1