Cloud Desktop Security Control Method, Device, Storage Medium and System

By assigning two cloud desktops to employees and dividing screens on terminal devices to operate separately, the contradiction between data security and efficient office in cloud office is solved, and the balance between data protection and flexible office is achieved.

CN116319764BActive Publication Date: 2025-07-18ALIBABA (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310265932.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-13
Publication Date
2025-07-18
Estimated Expiration
2043-03-13

AI Technical Summary

Technical Problem

In the cloud office scenario, how to take into account the dual needs of enterprise data security and employees' efficient office work, and avoid cyber attacks or data leakage caused by inadvertent operations.

Method used

Each employee is assigned two cloud desktops, and different security policies are configured: one is used to ensure data security, the other is used to meet efficient office needs, and the screen is divided on the terminal device to display and operate these cloud desktops separately, limiting user operation behavior through different security policies.

Benefits of technology

It achieves that without increasing costs, it not only protects enterprise data security, but also provides a flexible and efficient office experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116319764B_ABST
    Figure CN116319764B_ABST
Patent Text Reader

Abstract

The present application provides a cloud desktop security control method, device, storage medium and system. The system includes: a control server, which is used to centrally configure a first cloud desktop and a second cloud desktop for any target user, configure a first security policy for the first cloud desktop, and configure a second security policy for the second cloud desktop; a client that is communicatively connected to the first cloud desktop and the second cloud desktop corresponding to the target user respectively, and the display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop; a target cloud desktop among the first cloud desktop and the second cloud desktop corresponding to the target user, which is used to obtain the operation behavior triggered by the target user through the target screen and process the operation behavior according to the security policy corresponding to the target cloud desktop. Through this solution, the effect of protecting data security while taking into account the user's requirement for an efficient and flexible office experience is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet technologies, and in particular, to a cloud desktop security control method, device, storage medium, and system. Background Art

[0002] With the consideration of factors such as enterprise data qualification security and production cost reduction, more and more enterprises choose the transformation path of cloud-based office, and adopt the cloud desktop method to efficiently, securely, and flexibly deliver office resources required by enterprise employees, such as terminal devices like printers.

[0003] In the cloud-based office scenario, a simple usage mode is: an employee is assigned a cloud desktop, and the employee accesses the cloud desktop allocated to himself / herself in the cloud through the corresponding host (usually also called a thin client, which is a terminal device installed with client software corresponding to the cloud desktop).

[0004] In daily office work, in order to quickly solve problems and efficiently produce, employees inevitably need to query information through the Internet and inevitably transfer data between different office tools and websites. However, employees usually do not fully know the data risks brought by various network operations, which may lead to the enterprise's production data suffering from network attacks or data leakage due to inadvertent operations. Therefore, how to balance the dual needs of enterprise data security and employees' efficient office is an urgent problem to be solved. Summary of the Invention

[0005] Embodiments of the present invention provide a cloud desktop security control method, device, storage medium, and system, which balance the dual needs of data security and efficient office.

[0006] In a first aspect, an embodiment of the present invention provides a cloud desktop security control method, which is applied to a target cloud desktop corresponding to a target user. The target cloud desktop is one of a first cloud desktop and a second cloud desktop assigned to the target user. The first cloud desktop and the second cloud desktop corresponding to the target user are respectively communicatively connected to the same client of the target user. The display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop;

[0007] The method includes:

[0008] Receiving a security policy corresponding to the target cloud desktop sent by a management and control server; wherein, the first cloud desktop is configured with a first security policy, and the second cloud desktop is configured with a second security policy;

[0009] Obtaining an operation behavior triggered by the target user through a target screen, where the target screen is the screen corresponding to the target cloud desktop among the first screen and the second screen;

[0010] Process the operation behavior according to the security policy corresponding to the target cloud desktop.

[0011] In a second aspect, an embodiment of the present invention provides a cloud desktop security control device, which is applied to a target cloud desktop corresponding to a target user. The target cloud desktop is one of a first cloud desktop and a second cloud desktop assigned to the target user. The first cloud desktop and the second cloud desktop corresponding to the target user are respectively communicatively connected to the same client of the target user. The display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop;

[0012] The device includes:

[0013] A receiving module, configured to receive the security policy corresponding to the target cloud desktop sent by a management and control server; wherein, the first cloud desktop is configured with a first security policy, and the second cloud desktop is configured with a second security policy;

[0014] An obtaining module, configured to obtain the operation behavior triggered by the target user through a target screen, where the target screen is the screen corresponding to the target cloud desktop among the first screen and the second screen;

[0015] A processing module, configured to process the operation behavior according to the security policy corresponding to the target cloud desktop.

[0016] In a third aspect, an embodiment of the present invention provides an electronic device, including: a memory, a processor, and a communication interface; wherein, an executable code is stored on the memory, and when the executable code is executed by the processor, the processor is caused to execute the cloud desktop security control method as described in the first aspect.

[0017] In a fourth aspect, an embodiment of the present invention provides a non-transitory machine-readable storage medium, on which an executable code is stored. When the executable code is executed by a processor of an electronic device, the processor can at least implement the cloud desktop security control method as described in the first aspect.

[0018] In a fifth aspect, an embodiment of the present invention provides a cloud desktop security control method, which is applied to a client corresponding to a target user. The method includes:

[0019] Communicatively connect to a first cloud desktop and a second cloud desktop corresponding to the target user, wherein the first cloud desktop is configured with a first security policy, the second cloud desktop is configured with a second security policy, and the display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop;

[0020] Send the operation behavior triggered by the target user through the target screen to the target cloud desktop corresponding to the target screen, so that the target cloud desktop processes the operation behavior according to the corresponding security policy, where the target cloud desktop is one of the first cloud desktop and the second cloud desktop.

[0021] In a sixth aspect, an embodiment of the present invention provides a cloud desktop security control device, which is applied to a client corresponding to a target user. The device includes:

[0022] A connection module, configured to communicate with a first cloud desktop and a second cloud desktop corresponding to the target user. Among them, the first cloud desktop is configured with a first security policy, the second cloud desktop is configured with a second security policy, and the display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop;

[0023] A sending module, configured to send the operation behavior triggered by the target user through the target screen to the target cloud desktop corresponding to the target screen, so that the target cloud desktop processes the operation behavior according to the corresponding security policy, where the target cloud desktop is one of the first cloud desktop and the second cloud desktop.

[0024] In a seventh aspect, an embodiment of the present invention provides an electronic device, including: a memory, a processor, and a communication interface; wherein, an executable code is stored on the memory, and when the executable code is executed by the processor, the processor is caused to execute the cloud desktop security control method as described in the fifth aspect.

[0025] In an eighth aspect, an embodiment of the present invention provides a non-transitory machine-readable storage medium, on which an executable code is stored. When the executable code is executed by a processor of an electronic device, the processor can at least implement the cloud desktop security control method as described in the fifth aspect.

[0026] In a ninth aspect, an embodiment of the present invention provides a cloud desktop security control system, including:

[0027] A management and control server, configured to configure a first cloud desktop and a second cloud desktop for a target user, configure a first security policy for the first cloud desktop, and configure a second security policy for the second cloud desktop;

[0028] A client respectively communicatively connected to the first cloud desktop and the second cloud desktop corresponding to the target user, where the display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop;

[0029] The target cloud desktop corresponding to the target user is used to obtain the operation behavior triggered by the target user through the target screen, and process the operation behavior according to the security policy corresponding to the target cloud desktop. Wherein, the target cloud desktop includes the first cloud desktop and the second cloud desktop corresponding to the target user, and the target screen is the screen corresponding to the target cloud desktop among the first screen and the second screen.

[0030] In the solution provided in the embodiments of the present invention, for example, multiple employees in an enterprise form a target user set. When allocating cloud desktops to each user in the target user set, each target user can be allocated two different cloud desktops: the first cloud desktop and the second cloud desktop. Moreover, the first cloud desktop is configured with a first security policy, and the second cloud desktop is configured with a second security policy. In order to enable the target user to use the two allocated cloud desktops, the display screen corresponding to its client needs to be divided into a first screen corresponding to the above-mentioned first cloud desktop and a second screen corresponding to the second cloud desktop. Thus, the operation behaviors of the target user on the first screen and the second screen need to be restricted by the security policies of the corresponding cloud desktops. In practical applications, the first security policy can be a security policy set to ensure data security, and the second security policy is a security policy set to meet the user's high-efficiency office needs. Thus, through this solution, the effect of both protecting data security and taking into account the user's requirement for an efficient and flexible office experience is achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following-described drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0032] Figure 1 It is a schematic diagram of the composition of a cloud desktop security control system provided by an embodiment of the present invention;

[0033] Figure 2 It is a flowchart of a cloud desktop security control method provided by an embodiment of the present invention;

[0034] Figure 3 It is a schematic diagram of copying data between different cloud desktops provided by an embodiment of the present invention;

[0035] Figure 4 It is a schematic diagram of mutual access between different cloud desktops provided by an embodiment of the present invention;

[0036] Figure 5 It is a flowchart of a cloud desktop security control method provided by an embodiment of the present invention;

[0037] Figure 6 A structural schematic diagram of a cloud desktop security control device provided by an embodiment of the present invention;

[0038] Figure 7 A structural schematic diagram of an electronic device provided by this embodiment;

[0039] Figure 8 A structural schematic diagram of a cloud desktop security control device provided by an embodiment of the present invention;

[0040] Figure 9 A structural schematic diagram of an electronic device provided by this embodiment. Detailed implementation manners

[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. In addition, the sequence of steps in the following method embodiments is only an example and is not strictly limited.

[0042] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the embodiments of the present invention are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for the user to choose to authorize or refuse.

[0043] A cloud desktop is a cloud-based desktop service based on computing, which uses Desktop as a Service (DaaS for short) to provide users with an easy-to-use, secure, and efficient cloud-based desktop office system. The cloud desktop runs in the cloud. For example, several virtual machines are built in the cloud, and different cloud desktops are built in different virtual machines. Therefore, the cloud desktop can also be called a cloud computer and is allocated to different users for use. A user uses a thin client or a conventional user terminal (such as a notebook computer, etc.) installed with a client program corresponding to the cloud desktop to connect to the cloud desktop through the public network or a dedicated line, so as to realize remote access to the cloud desktop.

[0044] Data is transmitted between the cloud desktop and the client through a certain streaming transmission protocol.

[0045] The cloud desktop security control solution provided by the embodiments of the present invention can be applicable to providing cloud-based office services for users such as enterprises. By means of the software and hardware resources provided by the cloud service provider, cloud desktops allocated to different employees are constructed for the enterprise, and the use of the cloud desktops is controlled on demand.

[0046] Figure 1 It is a schematic diagram of the composition of a cloud desktop security control system provided by the embodiments of the present invention. As Figure 1 shown in the figure, the system includes:

[0047] A control server, which is used to configure a first cloud desktop and a second cloud desktop for a target user, configure a first security policy for the first cloud desktop, and configure a second security policy for the second cloud desktop;

[0048] A client that is communicatively connected to the first cloud desktop and the second cloud desktop corresponding to the target user respectively. Among them, the display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop;

[0049] The target cloud desktop corresponding to the target user is used to obtain the operation behavior triggered by the target user through the target screen, and process the operation behavior according to the security policy corresponding to the target cloud desktop. Among them, the target cloud desktop includes the first cloud desktop and the second cloud desktop corresponding to the target user, and the target screen is the screen corresponding to the target cloud desktop among the first screen and the second screen.

[0050] In fact, the above target user can be any user in the target user set. It can be seen that the cloud desktop security control system includes a subsystem in the cloud and a subsystem at the user end. Among them, the subsystem in the cloud includes a control server and a cloud desktop set created for the target user set through the control server. The subsystem at the user end includes clients corresponding to each user in the target user set.

[0051] In practical applications, the target user set can be a set composed of multiple employees (assumed to be N employees, N>1) in an enterprise. The control server constructs a corresponding cloud desktop set for the enterprise according to the demand information of the enterprise.

[0052] In the embodiments of the present invention, an enterprise can provide the cloud service provider with the required resource specification information and the number of employees. Among them, the resource specification information includes, for example, the number of CPU cores, the memory capacity, and so on. Based on the resource specification information and the employee information, the control server can construct two cloud desktops for each employee.

[0053] For example, if the resource specifications corresponding to an employee declared by an enterprise are 4-core CPU and 8G memory, then the two cloud desktops corresponding to one employee can respectively occupy 2-core CPU and 4G memory. Specifically, in this example, the management server can build two virtual machines that respectively occupy 2-core CPU and 4G memory, deploy cloud desktops in these two virtual machines, and allocate these two cloud desktops to a certain employee, that is, establish the correspondence between the identifier of this employee and these two cloud desktops, indicating that this employee can use these two cloud desktops.

[0054] It can be seen from this that when the target user set corresponding to an enterprise includes N users, the management server can create 2N cloud desktops for this target user set. Among them, each user has two cloud desktops. Two cloud desktop sets can be formed, such as Figure 1 the secure desktop set and the non-secure desktop set shown in the figure. Among them, the secure desktop set includes one cloud desktop for each of the N users, and the non-secure desktop set includes the other cloud desktop for each of these N users.

[0055] In fact, the management server can create two isolated local area networks for this target user set: the first local area network and the second local area network. The N cloud desktops included in the secure desktop set are deployed in the first local area network, and the N cloud desktops included in the non-secure desktop set are deployed in the second local area network. That is to say, the N virtual machines corresponding to the N cloud desktops included in the secure desktop set (one cloud desktop is deployed in one virtual machine) are located in the first local area network, and the N virtual machines corresponding to the N cloud desktops included in the non-secure desktop set are located in the second local area network. In practical applications, optionally, this local area network can be a Virtual Private Cloud (VPC).

[0056] In addition to creating corresponding two cloud desktops for each user in the target user set, the management server also issues different security policies to each cloud desktop in the above two different cloud desktop sets through the communication connection with the virtual machines where each cloud desktop is located.

[0057] For an enterprise, in practical applications, employees in this enterprise will have the need to access the external network during daily work. However, some sensitive data in the enterprise also needs to be protected for data security to prevent random leakage. For this actual need, two security policies can be set: respectively called the first security policy and the second security policy. Among them, the first security policy is set for the purpose of realizing data security and aims to provide a secure office environment; the second security policy is set to meet the actual work needs of enterprise employees and aims to provide a loose and flexible office environment.

[0058] In practical applications, the above-mentioned first security policy and second security policy may include two types of policies: network security policy and copy security policy. Among them, the network security policy describes whether the cloud desktop can access the external network and whether it can communicate with other cloud desktops in the same desktop set. The copy security policy describes whether data can be copied between two cloud desktops of the same user.

[0059] For Figure 1 the secure desktop set and the non-secure desktop set in [specific reference], the above-mentioned first security policy can be distributed to N cloud desktops in the secure desktop set, and the second security policy can be distributed to N cloud desktops in the non-secure desktop set. In this way, the cloud desktops in the two desktop sets will have different security policies, that is, two cloud desktops corresponding to one user are configured with different security policies.

[0060] Since two cloud desktops corresponding to one user have different security policies, the operation behaviors of the user on these two cloud desktops will be restricted by the security policies configured for these two cloud desktops.

[0061] In an optional embodiment, the applications hosted on the cloud desktops in the secure desktop set and the non-secure desktop set may be different. Applications involving sensitive information in an enterprise can be deployed on the cloud desktops in the secure desktop set, and other ordinary applications can be deployed on the cloud desktops in the non-secure desktop set, or can also be deployed on the cloud desktops in the secure desktop set. That is to say, the two cloud desktops corresponding to one user can be the same or partially the same.

[0062] In view of this, the enterprise can notify the control server of the applications involving sensitive information. When the control server creates cloud desktops, it deploys the applications involving sensitive information on the cloud desktops added to the secure desktop set, and does not deploy the applications involving sensitive information on the cloud desktops added to the non-secure desktop set.

[0063] The above describes the process of creating two cloud desktop sets for the target user set in the cloud and configuring different security policies for the cloud desktops in the two cloud desktop sets.

[0064] Correspondingly, on the user side, it is also necessary to provide corresponding clients for each user in the target user set. As described in the above example, assuming that there are N users in the target user set, then one client can be deployed in the terminal device of each user.

[0065] For ease of description, take any target user in the target user group as an example. Assume that the target user is assigned a first cloud desktop and a second cloud desktop. The first cloud desktop is configured with a first security policy, and the second cloud desktop is configured with a second security policy. In the terminal device of the target user, a client corresponding to these two cloud desktops is installed. It should be noted that in the embodiments of the present invention, the client will establish communication connections with the two cloud desktops corresponding to the target user respectively, that is, it has two communication connections, such as Figure 1 the first communication connection and the second communication connection shown in

[0066] In order to display the screens of the first cloud desktop and the second cloud desktop on the terminal device of the target user, the first screen and the second screen can be divided by split-screen technology. Thus, the display screen corresponding to the client includes the first screen and the second screen, where the first screen corresponds to the first cloud desktop and is used to display the screen of the first cloud desktop, and the second screen corresponds to the second cloud desktop and is used to display the screen of the second cloud desktop.

[0067] It is equivalent to dividing the display screen of the terminal device into two operation domains: a secure operation domain (i.e., the first screen) and a non-secure operation domain (i.e., the second screen). Operations can be performed on the first cloud desktop on the first screen, and operations can be performed on the second cloud desktop on the second screen.

[0068] The sizes of the above two display areas on the terminal device can be adjusted. For example, if the user is currently operating on the first screen, the size of the first screen can be enlarged, and the size of the corresponding second screen will be reduced. Adapted to the scaling of the screen size, the corresponding cloud desktop screens displayed thereon will also scale. Eventually, the operations on the two operation domains achieve an experience integration, and the user feels like performing daily office work on a single computer.

[0069] For the first cloud desktop and the second cloud desktop of the target user, the operation behaviors triggered by the target user through the corresponding first screen or second screen can be obtained to process the operation behaviors according to the configured security policies. Simply put, if the operation behavior triggered by the user does not violate the configured security policy, it is determined that the operation behavior is valid and the operation behavior is executed. On the contrary, if the operation behavior triggered by the user violates the configured security policy, it is determined that the operation behavior is invalid, and an error prompt message is displayed on the corresponding screen.

[0070] In summary, in the cloud-based office scenario for enterprise employees based on cloud desktops, a secure operation domain and a non-secure operation domain are set on the client side, and different levels of security policies are configured for the cloud desktops connected to these two operation domains respectively. This enables users to perform cloud desktop-related operations on the same terminal based on the security policies configured for the two connected cloud desktops respectively, achieving the effect of both protecting the enterprise's data security and meeting the enterprise employees' requirement for an efficient and flexible office experience.

[0071] In practical applications, perhaps the cloud-based office solution previously adopted by a certain enterprise is to allocate one cloud desktop to each employee. The resources occupied by this cloud desktop are called the first resources. When this enterprise wants to adopt the cloud-based office solution provided by the embodiments of the present invention based on its own needs, in order not to increase the cost of this enterprise, the first resources occupied by the original one cloud desktop can be divided into two parts: the second resources and the third resources. Thus, the two cloud desktops corresponding to one employee respectively occupy the second resources and the third resources. The proportions of the second resources and the third resources in the first resources can be determined according to the number of application programs to be run on the two cloud desktops and / or the differences in the required resources.

[0072] It should be noted that in the embodiments of the present invention, only the case of allocating two cloud desktops to each user in the target user group and configuring different security policies for each cloud desktop is illustrated. In fact, if there are more configuration requirements for security policies according to the actual needs of the enterprise, more cloud desktops can also be created for each user, and different security policies are configured for different cloud desktops. Moreover, the user group is not limited to the case of enterprise users.

[0073] Figure 2 It is a flowchart of a cloud desktop security control method provided by the embodiments of the present invention. This method can be executed by the target cloud desktops corresponding to the target users in the above-mentioned target user group. The target cloud desktops are the first cloud desktop and the second cloud desktop corresponding to the target users. As Figure 2 shown, this method includes the following steps:

[0074] 201. Receive the security policy corresponding to the target cloud desktop sent by the management and control server.

[0075] 202. Obtain the operation behavior triggered by the target user through the target screen, where the target screen is the screen corresponding to the target cloud desktop among the first screen and the second screen of the target user.

[0076] 203. Process the operation behavior according to the security policy corresponding to the target cloud desktop.

[0077] As described above, each cloud desktop in the secure desktop set is deployed within the first local area network. The secure desktop set is mainly for providing a secure office environment. The cloud desktops in this office environment all belong to secure cloud desktops and are all configured with a first security policy. Generally speaking, the first security policy has the following characteristics:

[0078] It has no ability to access the external network, that is, it cannot access the external network;

[0079] It cannot access the secure cloud desktops of other users in the same desktop set;

[0080] Data can only go in but not out: Non-secure cloud desktops under the same user (cloud desktops outside the secure desktop set are called non-secure cloud desktops) can copy data to the secure cloud desktop, but cannot copy data from the secure cloud desktop to non-secure cloud desktops.

[0081] Among them, the first two belong to network security policies, and the third belongs to data copy security policies.

[0082] To implement the above first security policy, corresponding network settings will be made in terms of physical deployment. For example, in the case of setting the secure desktop set within the first local area network, the network access interface of the first local area network to the outside is configured to be closed; a firewall is set up between different secure cloud desktops to prevent mutual access between different secure cloud desktops; there is no physical connection between the local area networks where the secure desktop set and the non-secure desktop set are located respectively.

[0083] Based on this, assuming that the target cloud desktop of the target user in the above steps is the first cloud desktop in the secure desktop set, that is, the first cloud desktop is a secure cloud desktop, the configured first security policy includes at least one of the following:

[0084] The first cloud desktop corresponding to the target user cannot access the external network; the first cloud desktop corresponding to the target user cannot access the cloud desktops of other users within the first local area network (i.e., within the secure desktop set); the data generated by the first cloud desktop corresponding to the target user cannot be copied to the second cloud desktop corresponding to the target user. Among them, the second cloud desktop is located in the non-secure desktop set.

[0085] Each cloud desktop in the non-secure desktop set is deployed within the second local area network. The non-secure desktop set is mainly for providing a relaxed and flexible office environment. The cloud desktops in this office environment all belong to non-secure cloud desktops and are all configured with a second security policy. Generally speaking, the second security policy has the following characteristics:

[0086] It has the ability to access the external network, that is, it can access the external network;

[0087] It can access the non-secure cloud desktops of other users in the same desktop set;

[0088] Data can be input and output: Non-secure cloud desktops under the same user can copy data to secure cloud desktops, and non-secure cloud desktops of one user can also transfer data to non-secure cloud desktops of another user.

[0089] Based on this, assuming that the target cloud desktop of the target user in the above steps is the second cloud desktop located in the non-secure desktop set, that is, the second cloud desktop is a non-secure cloud desktop, the configured second security policy includes at least one of the following:

[0090] The second cloud desktop corresponding to the target user can access the external network; the second cloud desktop corresponding to the target user can access each other with cloud desktops corresponding to other users within the second local area network (that is, within the non-secure desktop set); the data generated by the second cloud desktop corresponding to the target user can be copied to the first cloud desktop corresponding to the target user.

[0091] The content of the above first security policy and second security policy is only for example and not limited thereto.

[0092] The following respectively describes the processing procedures for the operation behaviors triggered for the target user when the target cloud desktop is the first cloud desktop and the second cloud desktop.

[0093] When the target cloud desktop is the first cloud desktop corresponding to the target user, the first screen corresponding to the first cloud desktop is the area where the target user operates on the first cloud desktop.

[0094] When the operation behavior triggered by the user received by the first cloud desktop is a data access operation triggered by the target user on the first screen, it is determined whether the data access operation is valid according to the communication address to be accessed included in the data access operation and the first security policy. If it is invalid, an error prompt message is output through the first screen. If it is valid, the data access operation is executed.

[0095] Among them, the data access operation can be an operation for the target user to access the external network or an operation to access the cloud desktops of other users.

[0096] After receiving the data access operation, the first cloud desktop determines whether the data access operation is valid according to the first security policy configured by itself, that is, whether it can access the corresponding communication address to be accessed. Optionally, the first cloud desktop can perform a ping process on the communication address to be accessed. If the communication address to be accessed can be pinged, it is determined that the data access operation is valid. If it cannot be pinged, it is determined that the data access operation is invalid.

[0097] The above data access operations are, for example: the target user triggers an operation to open a certain browser to access a certain web page in the screen of the first cloud desktop presented on the first screen, or triggers another type of access address input box, enters the communication address corresponding to a certain cloud desktop in the access address input box, or triggers an operation to transfer certain data to a certain network disk. These operations will trigger the client to send the data access operations input by the target user on the first screen to the corresponding first cloud desktop. Among them, the data access operations will include the communication address to be accessed. For example, in the above examples, the communication address to be accessed includes: the URL address of a certain web page, the IP address and user identifier corresponding to a certain cloud desktop, and the URL address corresponding to the network disk.

[0098] Specifically, for example, after the target user opens a certain browser on the first screen and triggers an operation to access a certain web page, after the first cloud desktop obtains this data access operation, based on the configuration content of "not being able to access the external network" in the first security policy, the first cloud desktop determines that it is not possible to access this web page, and displays an error prompt message through the first screen, such as "This web page cannot be accessed". In fact, because the network access interface of the first local area network where the first cloud desktop is located is closed to the outside, it is not possible to ping the web page address.

[0099] Another example is that the target user enters the IP address corresponding to the cloud desktop of user A on the first screen. After the first cloud desktop obtains this data access operation, based on the configuration content of "not being able to access the secure cloud desktops of other users in the same desktop set and data only going in but not out" in the first security policy, the first cloud desktop determines that this data access operation is invalid, and displays an error prompt message through the first screen, such as "Unable to access this cloud desktop". Among them, user A may be the same as or different from the target user.

[0100] In fact, if the cloud desktop of user A is a secure cloud desktop, that is, a cloud desktop located in the same desktop set (i.e., in the same local area network) as the first cloud desktop, due to the firewall configuration results between different secure cloud desktops, different secure cloud desktops cannot access each other, so it will be determined that this data access operation is invalid. If the cloud desktop of user A is a non-secure cloud desktop, that is, a cloud desktop located in a different desktop set (i.e., in another local area network) from the first cloud desktop, since the two local area networks are physically unconnected, that is, unable to access the external network, it will be determined that this data access operation is invalid.

[0101] In addition to the above data access operations, there may also be data access operations triggered by the target user on the first screen: a data copy operation triggered by the target user on the first screen and the second screen in sequence. This data access operation means that the target user wants to copy the data in the first cloud desktop to his own second cloud desktop. At this time, due to the configuration content of "data only goes in but not out - the secure cloud desktops under the same user are not allowed to copy data to non-secure cloud desktops" in the first security policy, it is determined that this data copy operation is invalid, and an error prompt message is output through the first screen, such as "Copying data is not allowed".

[0102] Based on this data copy security policy of "the secure cloud desktops under the same user are not allowed to copy data to non-secure cloud desktops", it is possible to prevent the data in the secure cloud desktop from being transmitted out of the secure office environment and then to the non-secure office environment.

[0103] In the embodiment of the present invention, a triggering method of a data copy operation is defined, including: performing a drag operation on the data to be copied between the first screen and the second screen of the target user, so as to realize a more convenient and fast data copy operation.

[0104] As Figure 3 shown, on the terminal device of the target user, the first screen corresponding to the first cloud desktop is on the left, and the second screen corresponding to the second cloud desktop is on the right. The file X displayed on the first screen is the data to be copied. The target user can select the file X and drag the file X from the first screen to the second screen, thereby triggering a data copy operation to copy the file X from the first cloud desktop to the second cloud desktop.

[0105] Actually, because the first cloud desktop and the second cloud desktop are in different local area networks, based on the configuration content of "not being able to access the external network" in the first security policy, it can also be determined that this data copy operation is invalid. However, for this type of operation of the data copy operation, optionally, it can also be based on this data copy security policy of "the secure cloud desktops under the same user are not allowed to copy data to non-secure cloud desktops", and determine that this data copy operation is invalid according to the following judgment idea: after the first cloud desktop receives the data copy operation information sent by the client, based on the drag behavior indicated in the data copy operation information from the first screen to the second screen direction that triggers the data copy operation, it is determined that this data copy operation is invalid.

[0106] The above introduces the process of processing the operation behavior triggered by the user from the first screen when the target cloud desktop is the first cloud desktop configured with the first security policy by the target user.

[0107] Next, the process of processing the operation behavior triggered by the user from the second screen when the target cloud desktop is the second cloud desktop configured with the second security policy by the target user is introduced.

[0108] When the target cloud desktop is the second cloud desktop corresponding to the target user, the second screen corresponding to the second cloud desktop is the area where the target user operates on the second cloud desktop.

[0109] When the operation behavior triggered by the user received by the second cloud desktop is a data access operation triggered by the target user on the second screen, if it is determined that the data access operation is valid according to the communication address to be accessed included in the data access operation and the second security policy, the corresponding data access processing is performed on the communication address to be accessed. If it is invalid, an error prompt message is output through the second screen.

[0110] The way the target user triggers this data access operation on the second screen is similar to the way of triggering the data access operation on the first screen above, which will not be elaborated here.

[0111] However, due to the configuration content in the second security policy that "can access the external network; can mutually access the non-secure cloud desktops of other users in the same desktop collection", the data access operation triggered by the target user can be normally executed, thus facilitating the daily office needs of the target user.

[0112] Different from the fact that different secure cloud desktops in the same secure desktop collection cannot mutually access under the first security policy, under the second security policy, different non-secure cloud desktops in the non-secure desktop collection can mutually access, so as to meet the needs of different users to share some data during work. For example Figure 4 As shown in, the non-secure cloud desktop a of user 1 and the non-secure cloud desktop b of user 2 can mutually transfer and access data. Because these two non-secure cloud desktops are in the same local area network and there is no firewall isolation between them, their communication addresses can be pinged.

[0113] When the operation behavior received by the second cloud desktop is a data copy operation triggered by the target user on the second screen and then on the first screen, if it is determined that the data copy operation is valid according to the second security policy, the data to be copied corresponding to the data copy operation is sent to the first cloud desktop corresponding to the target user.

[0114] That is to say, the target user can access the external network through the second cloud desktop to obtain the required data Y. After that, the target user can trigger a data copy operation by dragging the data Y from the second screen to the first screen. Since the second cloud desktop determines that the dragging behavior from the second screen to the first screen is valid when receiving this data copy operation, the data Y is copied into the first cloud desktop. It should be noted that in actual applications, the second cloud desktop and the first cloud desktop do not directly transmit the data to be copied because the local area networks to which they belong are physically isolated. For example, it can be forwarded through a management and control server.

[0115] In summary, in the cloud-based office scenario of enterprise employees based on cloud desktops, two screen operation areas, namely a secure operation area and a non-secure operation area, are defined on the terminal side, and different levels of security policy features are defined between the cloud desktops connected to the two operation areas. In addition, the two operation areas are integrated in the terminal experience, achieving the effect of protecting the enterprise's data security while taking into account the enterprise employees' requirement for an efficient and flexible office experience.

[0116] Figure 5 The flowchart of a cloud desktop security control method provided by an embodiment of the present invention. This method can be executed by the same client that is communicatively connected to the first cloud desktop and the second cloud desktop of the target user in the above text. As Figure 5 shown, this method may include the following steps:

[0117] 501. Communicatively connect to the first cloud desktop and the second cloud desktop corresponding to the target user. Among them, the first cloud desktop is configured with a first security policy, the second cloud desktop is configured with a second security policy, and the display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop.

[0118] 502. Send the operation behavior triggered by the target user through the target screen to the target cloud desktop corresponding to the target screen, so that the target cloud desktop processes the operation behavior according to the corresponding security policy. The target cloud desktop is one of the first cloud desktop and the second cloud desktop.

[0119] The operation behaviors that the target user can trigger on the target screen can refer to the relevant descriptions in the foregoing other embodiments and will not be elaborated here.

[0120] The cloud desktop security control device of one or more embodiments of the present invention will be described in detail below. Those skilled in the art can understand that these devices can all be configured by using commercially available hardware components through the steps taught by this solution.

[0121] Figure 6 The structural schematic diagram of a cloud desktop security control device provided by an embodiment of the present invention. This device is located in the target cloud desktop corresponding to the target user. The target cloud desktop is one of the first cloud desktop and the second cloud desktop assigned to the target user. The first cloud desktop and the second cloud desktop corresponding to the target user are respectively communicatively connected to the same client of the target user. The display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop. As Figure 6 shown, this device includes: a receiving module 11, an obtaining module 12, and a processing module 13.

[0122] A receiving module 11, configured to receive the security policy corresponding to the target cloud desktop sent by the management and control server, where the first cloud desktop is configured with a first security policy, and the second cloud desktop is configured with a second security policy.

[0123] An obtaining module 12, configured to obtain the operation behavior triggered by the target user through the target screen, where the target screen is the screen corresponding to the target cloud desktop among the first screen and the second screen.

[0124] A processing module 13, configured to process the operation behavior according to the security policy corresponding to the target cloud desktop.

[0125] Optionally, the target user is any user in a target user set, the target user set is configured with a first local area network and a second local area network that are isolated from each other, the first cloud desktop corresponding to the target user is located in the first local area network, and the second cloud desktop corresponding to the target user is located in the second local area network.

[0126] Optionally, the first security policy includes at least one of the following: the first cloud desktop corresponding to the target user cannot access the external network; the first cloud desktop corresponding to the target user cannot access the cloud desktops corresponding to other users in the first local area network; the data generated by the first cloud desktop corresponding to the target user cannot be copied to the second cloud desktop corresponding to the target user. The second security policy includes at least one of the following: the second cloud desktop corresponding to the target user can access the external network; the second cloud desktop corresponding to the target user can access the cloud desktops corresponding to other users in the second local area network; the data generated by the second cloud desktop corresponding to the target user can be copied to the first cloud desktop corresponding to the target user.

[0127] Optionally, when the target cloud desktop is the first cloud desktop corresponding to the target user and the target screen is the first screen, the processing module 13 is specifically configured to: if the operation behavior is a data access operation triggered by the target user on the first screen, when it is determined that the data access operation is invalid according to the to-be-accessed communication address included in the data access operation and the first security policy, an error prompt message is output through the first screen; if the operation behavior is a data copy operation triggered by the target user on the first screen and then on the second screen, when it is determined that the data copy operation is invalid according to the first security policy, an error prompt message is output through the first screen.

[0128] Optionally, the target cloud desktop is the second cloud desktop corresponding to the target user, and the target screen is the second screen. At this time, the processing module 13 is specifically configured to: if the operation behavior is a data access operation triggered by the target user on the second screen, when it is determined that the data access operation is valid according to the communication address to be accessed included in the data access operation and the second security policy, perform corresponding data access processing on the communication address to be accessed; if the operation behavior is a data copy operation triggered by the target user on the second screen and the first screen in sequence, when it is determined that the data copy operation is valid according to the second security policy, send the data to be copied corresponding to the data copy operation to the first cloud desktop corresponding to the target user.

[0129] Optionally, the triggering method of the data copy operation includes: performing a drag operation on the data to be copied between the first screen and the second screen of the target user.

[0130] Optionally, the first screen and the second screen of the target user are screens divided by a split screen method in the same terminal device of the target user, and the client is running in the terminal device.

[0131] Figure 6 The device shown can execute the steps executed by the target cloud desktop in the foregoing embodiments. For the detailed execution process and technical effects, refer to the descriptions in the foregoing embodiments and will not be elaborated here.

[0132] In a possible design, the above Figure 6 The structure of the cloud desktop security control device shown can be implemented as an electronic device. As Figure 7 shown, the electronic device may include: a processor 21, a memory 22, and a communication interface 23. Among them, executable code is stored on the memory 22. When the executable code is executed by the processor 21, the processor 21 can at least implement the cloud desktop security control method executed by the target cloud desktop provided in the foregoing embodiments. The electronic device may be a virtual machine in the cloud.

[0133] Figure 8 This is a schematic structural diagram of a cloud desktop security control device provided by an embodiment of the present invention. The device is located in the client corresponding to the target user. As Figure 8 shown, the device includes: a connection module 31 and a sending module 32.

[0134] The connection module 31 is used to communicate with the first cloud desktop and the second cloud desktop corresponding to the target user. Among them, the first cloud desktop is configured with a first security policy, the second cloud desktop is configured with a second security policy, and the display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop.

[0135] A sending module 32, configured to send the operation behavior triggered by the target user through the target screen to the target cloud desktop corresponding to the target screen, so that the target cloud desktop processes the operation behavior according to the corresponding security policy, where the target cloud desktop is one of the first cloud desktop and the second cloud desktop.

[0136] Figure 8 The device shown can execute the steps performed by the client in the foregoing embodiments. For the detailed execution process and technical effects, refer to the descriptions in the foregoing embodiments, which will not be elaborated herein.

[0137] In a possible design, the above Figure 8 The structure of the cloud desktop security control device shown can be implemented as an electronic device. As Figure 9 shown, the electronic device may include: a processor 41, a memory 42, and a communication interface 43. Among them, executable code is stored on the memory 42. When the executable code is executed by the processor 41, the processor 41 can at least implement the cloud desktop security control method performed by the client provided in the foregoing embodiments. The electronic device may be a user terminal.

[0138] In addition, an embodiment of the present invention provides a non-transitory machine-readable storage medium, on which executable code is stored. When the executable code is executed by a processor of an electronic device, the processor can at least implement the cloud desktop security control method provided in the foregoing embodiments.

[0139] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.

[0140] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of adding a necessary general hardware platform, and of course, can also be implemented by a combination of hardware and software. Based on such an understanding, the essence of the above technical solution or the part that contributes to the prior art can be embodied in the form of a computer product. The present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0141] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A cloud desktop security control method, characterized in that, Applied to the target cloud desktop corresponding to the target user, where the target cloud desktop is one of the first cloud desktop and the second cloud desktop assigned to the target user. The first cloud desktop and the second cloud desktop corresponding to the target user are respectively communicatively connected to the same client of the target user. The display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop; The target user is any user in the target user set. The target user set is configured with a first local area network and a second local area network that are isolated from each other. The first cloud desktop corresponding to the target user is located within the first local area network, and the second cloud desktop corresponding to the target user is located within the second local area network; The method includes: Receiving the security policy corresponding to the target cloud desktop sent by the management and control server; wherein, the first cloud desktop is configured with a first security policy, and the second cloud desktop is configured with a second security policy; The first security policy includes: The first cloud desktop corresponding to the target user cannot access the cloud desktops corresponding to other users within the first local area network; The data generated by the first cloud desktop corresponding to the target user cannot be copied to the second cloud desktop corresponding to the target user; The second security policy includes: The second cloud desktop corresponding to the target user can access the cloud desktops corresponding to other users within the second local area network; The data generated by the second cloud desktop corresponding to the target user can be copied to the first cloud desktop corresponding to the target user; Obtaining the operation behavior triggered by the target user through the target screen, where the target screen is the screen corresponding to the target cloud desktop among the first screen and the second screen; Processing the operation behavior according to the security policy corresponding to the target cloud desktop.

2. The method according to claim 1, characterized in that, The first security policy further includes: The first cloud desktop corresponding to the target user cannot access the external network; The second security policy further includes: The second cloud desktop corresponding to the target user can access the external network.

3. The method according to claim 2, wherein The target cloud desktop is the first cloud desktop corresponding to the target user, and the target screen is the first screen; The processing the operation behavior according to the security policy corresponding to the target cloud desktop includes: If the operation behavior is a data access operation triggered by the target user on the first screen, when it is determined that the data access operation is invalid according to the to-be-accessed communication address included in the data access operation and the first security policy, an error prompt message is output through the first screen; If the operation behavior is a data copy operation triggered by the target user on the first screen and then on the second screen in sequence, when it is determined that the data copy operation is invalid according to the first security policy, an error prompt message is output through the first screen.

4. The method according to claim 2, wherein The target cloud desktop is the second cloud desktop corresponding to the target user, and the target screen is the second screen; The processing the operation behavior according to the security policy corresponding to the target cloud desktop includes: If the operation behavior is a data access operation triggered by the target user on the second screen, when it is determined that the data access operation is valid according to the communication address to be accessed included in the data access operation and the second security policy, perform corresponding data access processing on the communication address to be accessed; If the operation behavior is a data copy operation triggered by the target user on the second screen and then on the first screen in sequence, when it is determined that the data copy operation is valid according to the second security policy, send the data to be copied corresponding to the data copy operation to the first cloud desktop corresponding to the target user.

5. The method according to claim 3 or 4, characterized in that, The triggering manner of the data copy operation includes: performing a drag operation on the data to be copied between the first screen and the second screen of the target user.

6. The method according to any one of claims 1 to 5, characterized in that, The first screen and the second screen of the target user are screens divided by a split-screen method in the same terminal device of the target user, and the client is running in the terminal device.

7. A cloud desktop security control method, characterized in that, Applied to the client corresponding to the target user, the method includes: Communicating with the first cloud desktop and the second cloud desktop corresponding to the target user. Among them, the first cloud desktop is configured with a first security policy, the second cloud desktop is configured with a second security policy, and the display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop; the target user is any user in the target user set, and the target user set is configured with a first local area network and a second local area network that are isolated from each other. The first cloud desktop corresponding to the target user is located in the first local area network, and the second cloud desktop corresponding to the target user is located in the second local area network; The first security policy includes: the first cloud desktop corresponding to the target user cannot access the cloud desktops corresponding to other users in the first local area network; the data generated by the first cloud desktop corresponding to the target user cannot be copied to the second cloud desktop corresponding to the target user; The second security policy includes: the second cloud desktop corresponding to the target user can access the cloud desktops corresponding to other users in the second local area network; the data generated by the second cloud desktop corresponding to the target user can be copied to the first cloud desktop corresponding to the target user; Send the operation behavior triggered by the target user through the target screen to the target cloud desktop corresponding to the target screen, so that the target cloud desktop processes the operation behavior according to the corresponding security policy. The target cloud desktop is one of the first cloud desktop and the second cloud desktop.

8. An electronic device, characterized in that, Includes: A memory, a processor, and a communication interface; wherein, executable code is stored on the memory, and when the executable code is executed by the processor, the processor executes the cloud desktop security control method according to any one of claims 1 to 6, or executes the cloud desktop security control method according to claim 7.

9. A non-transitory machine-readable storage medium, characterized in that The non-transitory machine-readable storage medium stores executable code that, when executed by a processor of an electronic device, causes the processor to execute the cloud desktop security control method according to any one of claims 1 to 6, or execute the cloud desktop security control method according to claim 7.

10. A cloud desktop security control system, characterized in that It includes: A management server for configuring a first cloud desktop and a second cloud desktop for a target user, configuring a first security policy for the first cloud desktop, and configuring a second security policy for the second cloud desktop; The target user is any user in a set of target users. The set of target users is configured with a first local area network and a second local area network that are isolated from each other. The first cloud desktop corresponding to the target user is located within the first local area network, and the second cloud desktop corresponding to the target user is located within the second local area network; The first security policy includes: the first cloud desktop corresponding to the target user cannot access the cloud desktops corresponding to other users within the first local area network; the data generated by the first cloud desktop corresponding to the target user cannot be copied to the second cloud desktop corresponding to the target user; The second security policy includes: the second cloud desktop corresponding to the target user can access the cloud desktops corresponding to other users within the second local area network; the data generated by the second cloud desktop corresponding to the target user can be copied to the first cloud desktop corresponding to the target user; A client respectively communicatively connected to the first cloud desktop and the second cloud desktop corresponding to the target user, wherein the display screen corresponding to the client includes a first screen corresponding to the first cloud desktop and a second screen corresponding to the second cloud desktop; The target cloud desktop corresponding to the target user is used to obtain the operation behavior triggered by the target user through the target screen and process the operation behavior according to the security policy corresponding to the target cloud desktop. The target cloud desktop includes the first cloud desktop and the second cloud desktop corresponding to the target user, and the target screen is the screen corresponding to the target cloud desktop among the first screen and the second screen.

Citation Information

Patent Citations

  • Multi-network environment isolation method and terminal

    CN102685136A

  • Method for displaying multiple virtual desktop windows

    CN106227519A