User browser-based protection system
By generating and rendering drawing instructions in the user's browser, the problems of high network bandwidth, large data transmission volume, and high latency in existing technologies are solved, achieving more efficient page rendering and user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ZHEJIANG QIZHI TECH CO LTD
- Filing Date
- 2023-02-13
- Publication Date
- 2026-06-02
AI Technical Summary
Existing browser-based protection systems have high network bandwidth requirements, large data transmission volumes, and significant latency, resulting in poor network performance.
A server-side connection is used between a remote browser and the user's browser to generate drawing instructions and transmit them to the user's browser. The page is then rendered in the user's browser using a drawing library, reducing data transmission volume and latency.
By combining drawing commands and drawing libraries, page rendering speed is improved, network bandwidth requirements are reduced, data transmission latency is decreased, and a more efficient user experience is provided.
Smart Images

Figure CN116257710B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of bastion host technology, and in particular to protection systems based on user browsers. Background Technology
[0002] Current browser-based protection systems consist of a user endpoint device, an isolation server, and a remote browser. They use a pixel-push method to mirror the remote browser's view onto the user's browser on the endpoint device. Specifically, the remote browser uses a specific protocol and data format to send the rendered webpage content to the user endpoint device. In response to user actions (e.g., keystrokes, mouse movements, and scrolling commands), the user's browser on the endpoint device sends instructions back to the isolation server via a secure, encrypted channel. The remote browser then processes the webpage according to these instructions and returns the processed content to the user's browser. The problems with this approach are: pixel-push requires high network bandwidth, involves large data transmission volumes, and has significant latency.
[0003] There is currently no effective solution to the problems of high network bandwidth requirements, large data transmission volume, and high latency in related technologies. Summary of the Invention
[0004] This embodiment provides a protection system based on a user's browser to address the problems of high network bandwidth requirements, large data transmission volume, and high latency in related technologies.
[0005] Firstly, this embodiment provides a protection system based on a user's browser, including: a remote browser, a server, and a user's browser;
[0006] The remote browser connects to the user's browser through the server and is used to generate drawing instructions corresponding to the page when the page is pushed, and transmit the drawing instructions to the user's browser through the server.
[0007] The user's browser is used to load the drawing library and render the target page based on the drawing instructions and the drawing library.
[0008] In some embodiments, the system further includes a remote browser instance module;
[0009] The remote browser instance module is connected to the remote browser and is used to load a custom plugin when the system starts up, and to manage user operations on the target page based on the custom plugin.
[0010] In some embodiments, the user operation control includes file upload, file download, clipboard synchronization, page request interception, multi-page management, application management, and lifecycle monitoring of the target page.
[0011] In some embodiments, the system further includes a controller;
[0012] The controller is connected to both the remote browser instance module and the user browser, and is used to provide a data transmission channel for interactive data between the remote browser instance module and the user browser.
[0013] In some embodiments, the controller is also used to maintain data transmission channels and corresponding mapping relationships, access control, and the recording of audit logs.
[0014] In some embodiments, the server includes a session service module, a session execution module, and a VNC service module;
[0015] The session service module is connected to the session execution module and is used to manage session operations;
[0016] The session execution module is connected to the VNC service module and is used to perform session tasks;
[0017] The VNC service module is used to provide VNC services.
[0018] In some embodiments, the session service module and the session execution module are distributed in a distributed architecture, with one session service module connecting to at least two session execution modules.
[0019] In some embodiments, the session service module manages session work based on a VNC session pooling mechanism.
[0020] In some embodiments, the user browser includes a session frontend and a web management terminal;
[0021] The session frontend is used to provide the user's browser client;
[0022] The web management interface is used to manage user browsers.
[0023] In some embodiments, the system further includes a management module;
[0024] The management module is connected to the web management terminal and is used for system configuration and information entry.
[0025] Compared with related technologies, the protection system based on a user browser provided in this embodiment includes a remote browser, a server, and a user browser. The remote browser connects to the user browser through the server and is used to generate drawing instructions corresponding to the page when the page is pushed, and transmits the drawing instructions to the user browser through the server. The user browser is used to load a drawing library and render the target page based on the drawing instructions and the drawing library. This solves the problems of high network bandwidth requirements, large data transmission volume, and large latency in related technologies. By using drawing instructions and the drawing library to render the target page in the user browser, the rendering speed is improved, and the bandwidth requirements and data transmission latency are reduced.
[0026] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects and advantages of this application more readily apparent. Attached Figure Description
[0027] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0028] Figure 1 This is a structural block diagram of a user browser-based protection system provided in an embodiment of this application;
[0029] Figure 2 This is a structural block diagram of a user browser-based protection system provided in a preferred embodiment of this application;
[0030] Figure 3 This is a timing diagram of the interactions between various modules in the startup process and VNC session allocation process provided in an embodiment of this application;
[0031] Figure 4 This is a timing diagram of the interaction between modules based on page request interception provided in one embodiment of this application;
[0032] Figure 5 This is a timing diagram of the interactions between modules based on file upload, provided in one embodiment of this application.
[0033] Figure 6 This is a timing diagram of the interactions between modules in a file download module according to an embodiment of this application;
[0034] Figure 7 This is a timing diagram of the interaction between modules based on clipboard synchronization provided in one embodiment of this application;
[0035] Figure 8This is a timing diagram of the interaction between modules in a multi-page management system provided in one embodiment of this application;
[0036] Figure 9 This is a timing diagram of the interaction between modules based on application management, provided in one embodiment of this application.
[0037] Figure 10 This is a schematic diagram of relationships provided in an embodiment of this application;
[0038] Figure 11 This is a timing diagram of the interactions between modules based on the local proxy mode provided in an embodiment of this application;
[0039] Figure 12 This is a flowchart illustrating a redirection mode provided in an embodiment of this application;
[0040] Figure 13 This is a flowchart illustrating the proxy mode provided in one embodiment of this application.
[0041] In the diagram: 10. User browser; 11. Session frontend; 12. Web management terminal; 20. Server; 21. Session service module; 22. Session execution module; 23. VNC service module; 30. Remote browser; 40. Controller; 50. Remote browser instance module; 60. Management module. Detailed Implementation
[0042] To better understand the purpose, technical solution, and advantages of this application, the application is described and illustrated below in conjunction with the accompanying drawings and embodiments.
[0043] Unless otherwise defined, the technical or scientific terms used in this application shall have the general meaning as understood by one of ordinary skill in the art to which this application pertains. Words such as “a,” “an,” “an,” “the,” “the,” and “these,” used in this application, do not indicate quantitative limitation and may be singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that comprises a series of steps or modules (units) is not limited to the listed steps or modules (units) but may include steps or modules (units) not listed, or may include other steps or modules (units) inherent to such processes, methods, products, or devices. The terms “connected,” “linked,” and “coupled,” used in this application, are not limited to physical or mechanical connections but may include electrical connections, whether direct or indirect. The term “multiple” used in this application refers to two or more. The "and / or" operator describes the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: A alone, A and B simultaneously, and B alone. Typically, the character " / " indicates that the objects before and after it are in an "or" relationship. The terms "first," "second," and "third," etc., used in this application are merely for distinguishing similar objects and do not represent a specific ordering of the objects.
[0044] This embodiment provides a protection system based on the user's browser. Figure 1 This is a structural block diagram of the user browser-based protection system in this embodiment, as shown below. Figure 1 As shown, the system includes: a remote browser 30, a server 20, and a user browser 10;
[0045] The remote browser 30 connects to the user browser 10 through the server 20 and is used to generate drawing instructions corresponding to the page when the page is pushed, and transmit the drawing instructions to the user browser 10 through the server 20.
[0046] User browser 10 is used to load the drawing library and render the target page based on the drawing instructions and the drawing library.
[0047] It should be noted that the user browser 10 can be set in the client, and the user can operate the user browser 10 in the client to use it. The client can be a mobile terminal, fixed terminal, or portable terminal, such as a mobile phone, site, unit, device, multimedia computer, multimedia tablet, internet node, communicator, desktop computer, laptop computer, notebook computer, netbook computer, tablet computer, personal communication system (PCS) device, personal navigation device, personal digital assistant (PDA), audio / video player, digital camera / camcorder, positioning device, television receiver, radio broadcast receiver, e-book device, gaming device, or any combination thereof, including accessories and peripherals of these devices, or any combination thereof.
[0048] The remote browser 30 can be set in a remote terminal. The server 20 serves as a data transmission channel between the remote browser 30 and the user browser 10, and can be used to transmit page-related data to isolate the remote browser 30 and the user browser 10.
[0049] In this embodiment, the push page can be generated by Chromium's Compositor using Chromium's Compositor when the user browser 10 starts up and the remote browser 30 needs to push each page to the user browser 10 for display (push page). The SKIA drawing instructions corresponding to the page are then transmitted to the user browser 10 via the server 20. The user browser 10 loads the SKIA drawing library and executes the drawing instructions locally, thereby rendering the page from the remote browser 30 in the user browser 10. Of course, the push page can also be generated at any time when the remote browser 30 needs to push each page to the user browser 10 for display, thus satisfying various usage requirements.
[0050] In other embodiments, other drawing instructions and corresponding drawing libraries may also be used, which will not be described in detail.
[0051] Through the aforementioned system, the remote browser 30 transmits primarily SKIA drawing commands to the user's browser 10. This is significantly less image transmission than existing pixel-push solutions, resulting in lower bandwidth requirements and lower latency. Simultaneously, the target page's native HTML and DOM-related code do not reach the client, yet a localized user experience is achieved. This resolves the issues of high network bandwidth requirements, large data transmission volumes, and significant latency inherent in related technologies.
[0052] Figure 2 This is a structural block diagram of a protection system for a user browser 10 according to a preferred embodiment, based on Figure 2 The protection system is described in detail.
[0053] In some embodiments, server 20 includes session service module 21, session execution module 22, and VNC service module 23;
[0054] Session service module 21, connected to session execution module 22, is used to manage session operations;
[0055] The session execution module 22 and the VNC service module 23 are connected to perform session tasks.
[0056] VNC service module 23 is used to provide VNC services.
[0057] Specifically, the session service module 21 (session-server) manages session tasks. For example, it manages the session worker (session execution module 22), manages the VNC session connection pool, and provides a WebSocket for the VNC access screen in the user's browser 10, through which page data from the remote browser 30 based on the RFB protocol is transmitted. The session execution module 22 (session-worker) can be a session worker thread used to perform session tasks, such as creating and destroying sessions.
[0058] The session service module 21 and session execution module 22 are configured in a distributed (master-server) architecture. One session service module 21 connects to at least two session execution modules 22, and multiple modules can be deployed for horizontal scaling. For example, the session execution module 22 and the VNC service module 23 can be considered as an expansion unit; each expansion unit is connected to the session service module 21. Each expansion unit is also connected to a remote browser 30.
[0059] In this embodiment, horizontal scaling of the session execution module 22 and the VNC service module 23 can be supported without changing the overall architecture, making it convenient to use and highly applicable.
[0060] In some embodiments, the session service module 21 manages session work based on a VNC session pooling mechanism.
[0061] Specifically, the configuration parameters maintained in the VNC session configuration file are as follows: 1. Maximum number of sessions (maxActive): The maximum number of VNC sessions that can be created. The maximum number of sessions may be limited by machine memory; generally, a VNC session requires 1GB of memory to support it. For example, a protection system with 32GB of memory would configure this parameter to 32. 2. Maximum number of idle sessions (maxIdle): The maximum number of idle VNC sessions to maintain. This is configured based on the instantaneous number of newly logged-in users in the protection system. For example, if the estimated number of newly logged-in users in the protection system is 5, then this parameter would be configured to 5. 3. Minimum number of idle sessions (minIdle): The minimum number of idle VNC sessions to maintain. When this minimum number of idle sessions is reached, the LRU (Least Recently Used) eviction mechanism is triggered to evict those allocated but unused VNC sessions and create new VNC sessions to replenish the session pool. The minimum number of idle sessions can be less than half of the maximum number of sessions to reduce the impact of allocated but unused VNC sessions on the protection system. 4. Maximum Wait Time for VNC Session (maxWait): The maximum waiting time when retrieving a new session from the VNC session pool. The maximum wait time can be set by the user, such as 5s, 10s, or 17s, etc.
[0062] In this embodiment, Figure 3 This is a sequence diagram illustrating the interactions between various modules during the startup and VNC session allocation process. During system startup, a certain number of VNC sessions are preloaded based on the maximum number of idle sessions (maxIdle). These VNC sessions form a VNC session pool. When a user logs into the system and opens a new application, it is directly allocated from this preloaded pool. After allocation, the backend maintains the mapping relationship between ngSessionId (the system login user's session ID) and vncSessionId (the ID used by the vnc-server to create a remote desktop session), ensuring that the same ngSessionId is always assigned the same vncSessionId. The lifecycle of this VNC session is synchronized with the lifecycle of the system session. When the system session expires or the user logs out, the corresponding VNC session is destroyed, and a new VNC session is created in the backend to replenish it (depending on configuration parameters). The size of the VNC session window is created based on the maximum screen size.
[0063] After logging into the system, opening the application (the web address that needs to be isolated), and then closing the application while maintaining the system login state, the vncSessionId corresponding to ngSessionId will remain in the allocation state, resulting in resource waste. An LRU eviction mechanism is needed to evict VNC sessions and improve system throughput. The LRU eviction mechanism should be triggered when the number of idle sessions falls below minIdle. Evicting allocated but unused VNC sessions based on the maximum idle time will improve the overall system throughput.
[0064] For example, if `maxActive = 100`, `maxIdle = 5`, and `minIdle = 2`, then 5 VNC sessions will be created at startup. After VNC sessions are allocated, the background needs to create new sessions to maintain the number of 5 idle sessions until 96 sessions have been allocated and there are 4 idle sessions remaining. At this point, the total number of sessions created reaches 100, and the background will no longer create new sessions to replenish the number. When the number of idle sessions falls below 2, the LRU eviction mechanism is triggered, evicting the allocated VNC session with the longest idle time and recreating new sessions to replenish the number.
[0065] This embodiment enables users to quickly open web applications, achieves pooling of remote browser instances, and maximizes the consistency between the lifecycle of the system login user and the lifecycle of the remote browser instance, thereby improving the user experience.
[0066] In some of these embodiments, such as Figure 2 As shown, the protection system based on the user's browser also includes a remote browser instance module 50;
[0067] The remote browser instance module 50 is connected to the remote browser 30 and is used to load custom plugins when the system starts up, and to control user operations on the target page based on the custom plugins.
[0068] Specifically, when the protection system starts, a custom plugin (browser-plugin) is loaded, and user operation control is performed on the target page based on the custom plugin. This user operation control includes file upload, file download, clipboard synchronization, page request interception, multi-page management, application management, and lifecycle monitoring of the target page.
[0069] In this embodiment, browser control technology is used to extend the functionality of the remote browser (allowing users to perform functions such as file upload, file download, clipboard synchronization, page request interception, multi-page management, application management, and target page lifecycle monitoring on the browser, achieving the goal of seamless use, just like using a local browser), thereby improving the user experience and achieving the goal of allowing users to operate the remote browser without being aware of its existence.
[0070] The specific implementation of each extended function is described below:
[0071] For page request interception:
[0072] The sequence diagram of interactions between modules based on page requests is as follows: Figure 4 As shown, the main process is as follows: Within the same VNC session, one browser window corresponds to one application, i.e., a one-to-one mapping between windowId and application appId. The browser window is used to isolate applications (the plugin can set specific HTTP interception policies for specific windows, achieving the effect of setting different HTTP interception policies for different applications). vncSessionId and nghttpsessionId are mapped one-to-one, and the plugin and ngHttpsessionId are bound during VNC session allocation. The HTTP interception function is implemented in the plugin's chrome.webRequest module, setting the corresponding application's HTTP interception policy for each browser window.
[0073] This embodiment enables the interception of specific requests within a target application, allowing for better control over user behavior. It can be applied to specific applications and specific users, providing fine-grained control from both application and logged-in user perspectives.
[0074] For file upload and file download:
[0075] The interaction sequence diagram between the various modules based on file upload is as follows: Figure 5 As shown, the main process is as follows: A plugin injects JavaScript into the target page, listens for the file upload pop-up action on the target page, and blocks the file upload pop-up message. Simultaneously, the file upload pop-up message is synchronously sent to the user's browser. After receiving the message, the user's browser displays a local file upload pop-up, allowing the user to select a local file to upload. After the file is uploaded, the backend notifies the plugin to retrieve the file and set it in the corresponding input element on the remote page, thus achieving seamless file upload.
[0076] Based on the interaction sequence diagram between the various modules of file download, as shown below Figure 6 As shown, the main process is as follows: the plugin listens for file download events in the remote browser and synchronizes messages to the user's browser. After receiving the file download completion message, the user's browser retrieves the file from the background, achieving seamless file download.
[0077] This embodiment enables users to upload and download files seamlessly within their browser pages.
[0078] For clipboard synchronization:
[0079] The timing diagram of the interaction between modules based on clipboard synchronization is as follows: Figure 7 As shown, the main process is as follows: When the user's mouse hovers over a tab in the user's browser, a JavaScript program retrieves the content of the user's browser clipboard and synchronizes it to the backend. The backend then uses a toolkit to set the content from the user's browser clipboard to the clipboard of the remote browser. A remote plugin monitors the user's browser for copying or pressing Ctrl+C, captures the action, and sends a message to the backend. The backend then uses a toolkit to retrieve the content from the remote browser's clipboard and synchronizes the message to the user's browser. The user's browser uses JavaScript to set the content from the remote clipboard to its own clipboard, thus achieving real-time synchronization between the user's and remote browser clipboards, which is imperceptible to the user.
[0080] This embodiment enables bidirectional content synchronization between the user's browser clipboard and the remote browser clipboard, allowing users to operate the clipboard seamlessly.
[0081] For multi-page management:
[0082] The interaction sequence diagram between modules in a multi-page management system is as follows: Figure 8 As shown, the main process is as follows: The plugin listens for tab creation messages in the remote browser and synchronizes these messages to the user's browser in real time. Upon receiving the message, the user's browser creates a new tab and displays the corresponding content. Simultaneously, the plugin monitors changes to all target page URLs, titles, icons, etc., and synchronizes these changes to the user's browser in real time. This allows the user to operate the remote browser as if it were a local browser.
[0083] For application management:
[0084] Based on the interaction sequence diagram between various modules of application management, as shown below Figure 9 As shown, the main process is as follows: the page creation event is intercepted by a plugin in the remote browser and sent to the user's browser. The user's browser interacts with the backend to determine whether isolation is required, and then decides whether to use the isolation or non-isolation channel.
[0085] This embodiment provides functions related to isolated application management. Application configuration offers multiple configuration methods, including regular expressions, wildcards, and setting attributes such as whether to isolate and access modes for configured applications. This module's configuration can flexibly meet different page isolation scenarios for users. For example, if page-a is opened in isolation mode, and page-b is opened during the operation of page-a, and page-b is not within the scope of isolated applications, then page-b will not be opened in isolation mode when opened in the user's browser. Conversely, if page-b is within the isolated application scope, then page-b will be opened in isolation mode.
[0086] In some of these embodiments, such as Figure 2 As shown, the protection system based on the user's browser also includes a controller 40;
[0087] The controller 40 is connected to both the remote browser instance module 50 and the user browser, and is used to provide a data transmission channel for interactive data between the remote browser instance module 50 and the user browser.
[0088] Specifically, controller 40 can be considered as providing a data transmission channel between the session-frontend in the user's browser and the remote browser plugin in the remote browser instance module 50, maintaining the session-frontend port and the WebSocket connection from the remote browser plugin to the controller and the corresponding mapping relationship, access control during user operation, and recording of audit logs, etc.
[0089] The protection system in this application can provide fine-grained control over permissions from two dimensions: users and applications. A diagram illustrating the relationship between users, templates, and applications is shown below. Figure 10 As shown, permissions and policies are abstracted into corresponding templates, and these templates are dynamically assigned to one or more corresponding users and applications to achieve fine-grained control.
[0090] The permission template allows control over permissions for functions such as file upload, file download, clipboard text up and down, and clipboard image up and down.
[0091] The strategy template provides fine-grained control over file uploads and page requests.
[0092] The audit logs primarily record key user actions, mainly in the following six areas: 1. Host Access Logs: Records user access to the target host. 2. URL Access Logs: Records all URLs accessed by the user. 3. Application Access Logs: Records applications accessed by the user. 4. File Transfer Logs: Records all file uploads and downloads during user operations on the target application. 5. Clipboard Content Transfer Logs: Records bidirectional content synchronization between the internal and external clipboards during user operations on the target application. 6. Interception Logs: Records all intercepted file and page requests during user operations on the target application.
[0093] In some of these embodiments, such as Figure 2 As shown, the user's browser includes a session frontend 11 and a web management terminal 12;
[0094] Session frontend 11 is used to provide the user's browser client;
[0095] Web management terminal 12 is used to manage user browsers.
[0096] Specifically, the session frontend 11 can be a web client containing Novnc. The web management terminal 12 can work with the management module 60 to manage user browsers.
[0097] In some embodiments, the protection system based on the user's browser also includes a management module 60;
[0098] The management module 60 is connected to the web management terminal 12 and is used for system configuration and information entry.
[0099] Specifically, by utilizing the system configuration of management module 60, multiple access modes can be implemented.
[0100] The first type is IP forwarding mode: the corresponding application is configured in the system so that the target site can be opened in isolation by directly entering the corresponding page address in the browser navigation bar.
[0101] The second method is the local proxy mode: The client configures a proxy to point to the application's system proxy server. The proxy service can filter based on the page addresses opened by the user's browser, determining which page addresses need to pass through the system, allowing users to seamlessly access isolated applications. The local proxy implementation process is as follows: Figure 11 As shown, the main process is as follows: The proxy service filters the user's browser network traffic, determining which pages need to be accessed through the isolation system. Applications that need to go through the isolation system are returned as static pages directly from the gateway. Within these static pages, the `src` attribute of an `iframe` is used to open the actual target application through the isolation system.
[0102] The third type is the Nginx traffic splitting mode: In some scenarios, certain pages within a web service need to be accessed via RBI, while other pages do not. In this scenario, traffic splitting can be achieved by configuring rules on the Nginx server of the web service, redirecting or proxying the addresses of pages that need to be accessed via RBI to the system of this application. Therefore, there are redirection mode and proxy mode.
[0103] The redirection mode involves displaying relevant information about the isolation system in the user's browser navigation bar, with the URL format matching the IP forwarding pattern. During page redirection, the user's browser cookie is transparently passed to the remote browser, preventing secondary login. The implementation flowchart is as follows: Figure 12 .
[0104] The proxy mode works as follows: The browser navigation bar will not display any information about the isolation system; only the target URL will be shown. This is seamless for the user, making the isolation system transparent. During page redirection, the user's browser's cookie is transparently passed to the remote browser, avoiding secondary login. The implementation flowchart is as follows: Figure 13 .
[0105] Based on the protection system of the above preferred embodiments, this application has the following beneficial effects:
[0106] 1. Using this application enables users to achieve seamless operation in areas such as file uploading, file downloading, multi-page management, clipboard synchronization, and application management, thereby improving user experience.
[0107] 2. Intercepting page requests to control the behavior of the target application page.
[0108] 3. By configuring functional permissions and policy permissions for designated users, the purpose of controlling user behavior can be achieved; and by recording user behavior logs during the process of accessing the target application, the purpose of auditing user behavior can be achieved.
[0109] 4. Multiple access methods facilitate integration with various application systems.
[0110] 5. Improve the rendering speed of browser web pages by using Remote Comand Draw technology, reduce bandwidth requirements, and reduce data transmission latency.
[0111] 6. Flexible page isolation strategy: Isolated pages can be seamlessly opened on demand, while non-isolated pages can be opened seamlessly on demand. When a page is opened, cookies and local storage data from both the user's client and the remote browser are passed to the remote browser.
[0112] It should be understood that the specific embodiments described herein are merely illustrative of the application and not intended to limit it. All other embodiments derived by those skilled in the art based on the embodiments provided in this application without inventive effort are within the scope of protection of this application.
[0113] Obviously, the accompanying drawings are merely some examples or embodiments of this application. Those skilled in the art can apply this application to other similar situations based on these drawings without any creative effort. Furthermore, it is understood that although the work done in this development process may be complex and lengthy, for those skilled in the art, certain design, manufacturing, or production modifications made based on the technical content disclosed in this application are merely conventional technical means and should not be considered as insufficient disclosure of this application.
[0114] The term "embodiment" in this application refers to a specific feature, structure, or characteristic described in connection with an embodiment that may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily imply the same embodiment, nor does it imply that it is mutually exclusive with or independent of other embodiments. It will be clearly or implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments without conflict.
[0115] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of patent protection. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the appended claims.
Claims
1. A protection system based on a user's browser, characterized in that, include: Remote browser, server, and user browser; The remote browser connects to the user's browser through the server and is used to generate drawing instructions corresponding to the page when the page is pushed, and transmit the drawing instructions to the user's browser through the server. The drawing commands include SKIA drawing commands; The user's browser is used to load the drawing library and render the target page based on the drawing instructions and the drawing library. The system also includes a remote browser instance module; The remote browser instance module is connected to the remote browser and is used to load a custom plugin when the system starts up, and to control user operations on the target page based on the custom plugin. The user operation control includes file upload, file download, clipboard synchronization, page request interception, multi-page management, application management, and lifecycle monitoring of the target page; The system also includes a controller; The controller is connected to the remote browser instance module and the user browser respectively, and is used to provide a data transmission channel for interactive data between the remote browser instance module and the user browser; The controller is also used to maintain data transmission channels and corresponding mapping relationships, access control, and the recording of audit logs.
2. The protection system based on the user's browser according to claim 1, characterized in that, The server includes a session service module, a session execution module, and a VNC service module; The session service module is connected to the session execution module and is used to manage session operations; The session execution module is connected to the VNC service module and is used to perform session tasks; The VNC service module is used to provide VNC services.
3. The protection system based on the user's browser according to claim 2, characterized in that, The session service module and the session execution module are configured in a distributed architecture, with one session service module connected to at least two session execution modules.
4. The protection system based on the user's browser according to claim 2, characterized in that, The session service module manages session operations using a pooling mechanism based on VNC sessions.
5. The protection system based on the user's browser according to claim 1, characterized in that, The user browser includes a session frontend and a web management terminal; The session frontend is used to provide the user's browser client; The web management interface is used to manage user browsers.
6. The protection system based on the user's browser according to claim 5, characterized in that, The system also includes a management module; The management module is connected to the web management terminal and is used for system configuration and information entry.