Power operation and maintenance system based on image projection
By using an image projection-based power operation and maintenance system, and leveraging graphical protocol connections and national cryptographic encryption channels, efficient and secure operation and maintenance of clients on different operating systems has been achieved. This solves the problem of client adaptation difficulties in existing technologies and improves security and maintenance efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-22
- Publication Date
- 2026-03-27
AI Technical Summary
Existing power operation and maintenance systems cannot provide services in the B/S (Browser/Server) mode in secure areas, and client-side adaptation to different operating systems is difficult in the C/S mode, resulting in low program security, large scale, and low maintenance efficiency.
The power operation and maintenance system based on image projection connects the client and server via a graphical protocol to realize the presentation and synchronous updating of image information. The client only needs to display the image information, while the server completes the relevant processing of the operating system. Data interaction is carried out through a national cryptographic encryption channel.
It solves the difficulty of client compatibility with different operating systems, improves operational security and efficiency, reduces the size of client software packages, and simplifies the upgrade and deployment process.
Smart Images

Figure CN116346848B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power operation and maintenance, and particularly relates to a power operation and maintenance system based on image projection. BACKGROUND
[0002] There are two schemes for the existing operation and maintenance system. Scheme one: a BS mode, that is, a browser / server mode. A user accesses a web page of the operation and maintenance system through a local browser to complete operation and maintenance. Scheme two: a CS mode, that is, a client / server mode. The existing CS mode needs to develop a client, and a function page presented to a client is implemented in the client, and data presented to the client needs to be acquired and updated by interacting with a server.
[0003] In a security area under the power operation and maintenance system, the web protocol is not allowed to be used due to security reasons, and the operation and maintenance service cannot be provided by using the BS mode. Moreover, due to the existence of multiple versions and different types of operating systems of the server of the workstation under the power operation and maintenance system, it is difficult for the client in the existing CS mode scheme to adapt to different operating systems, which will cause the program security of the client to be not high, the program scale to be too large, the client to be dependent on a database, and the maintenance efficiency to be low, and further cause the problem that the client is difficult to adapt to different operating systems.
[0004] At present, there is no effective solution to the problem that the client is difficult to adapt to different operating systems in the related art. SUMMARY
[0005] The power operation and maintenance system based on image projection is provided in the embodiment to solve the problem that the client is difficult to adapt to different operating systems in the related art.
[0006] In a first aspect, the power operation and maintenance system based on image projection is provided in the embodiment, and includes a client and a server.
[0007] The client includes a first communication module and a graphic client module.
[0008] The first communication module is connected with the server, is configured to provide a data interaction channel of the client and the server, and is configured to acquire graphic protocol connection information and proxy information based on the data interaction channel.
[0009] The graphic client module is connected with the first communication module, is configured to establish a graphic protocol connection with the server according to the graphic protocol connection information and the proxy information, and is configured to present image information in the server based on the graphic protocol.
[0010] In response to the operation of the image information, the operation information corresponding to the image information is synchronized to the server, and the image information is synchronously updated based on the feedback of the server.
[0011] In some embodiments, the client further comprises an authentication module;
[0012] The authentication module is connected with the first communication module, and is configured to send an authentication request to the server through the data interaction channel.
[0013] After the authentication is passed in the server, the graphical protocol connection information and the proxy information are obtained from the server through the first communication module, and the graphical protocol connection information and the proxy information are transmitted to the graphical client module.
[0014] In some embodiments, the server comprises a second communication module, a background service module and a container module.
[0015] The second communication module is connected with the first communication module, the background service module and the container module respectively.
[0016] The background service module is connected with the container module, and is configured to obtain the graphical protocol connection information and the proxy information of the service connection from the container module, and transmit the graphical protocol connection information and the proxy information to the client through the second communication module.
[0017] The container module is configured to establish a graphical protocol connection with the graphical client module, and project the image information to the client based on the graphical protocol.
[0018] When the operation information corresponding to the image information is synchronized, the image information is updated based on the operation information, and the updated image information is fed back to the client.
[0019] In some embodiments, the first communication module is a first national secret channel module, and the second communication module is a second national secret channel module.
[0020] The first national secret channel module is connected with the second national secret channel module in the server, and is configured to establish a national secret encrypted data interaction channel.
[0021] In some embodiments, the background service module comprises an authentication service sub-module.
[0022] The authentication service sub-module is connected with the authentication module in the client, and is configured to obtain an authentication request and perform authentication processing on the client and the server based on the authentication request.
[0023] In some embodiments, the authentication service submodule is further configured to obtain graphical protocol connection information and proxy information of a service connection from the container module after authentication is passed.
[0024] The authentication token information is sorted, and the token information, the graphical protocol connection information, and the proxy information are transmitted to the client.
[0025] In some embodiments, the authentication token information includes an authentication password and an authentication validity period.
[0026] In some embodiments, the background service module further includes an agent management submodule and a service service submodule.
[0027] The agent management submodule is connected to the agent submodule in the container module and is configured to manage the agent submodule.
[0028] The service service submodule is connected to the rich management terminal submodule in the container module and is configured to receive a service request initiated by the rich management terminal submodule and perform service processing according to the service request.
[0029] In some embodiments, the container module includes an agent submodule, an image service terminal submodule, and a rich management terminal submodule.
[0030] The image service terminal submodule establishes a graphical protocol connection with the graphical client module through the proxy submodule, projects image information provided by the rich management terminal submodule to the client based on the graphical protocol, and transmits operation information corresponding to the image information to the rich management terminal submodule when the operation information is synchronized.
[0031] The rich management terminal submodule is configured to provide image information processed by the background service module and generate a corresponding service request according to the operation information.
[0032] In some embodiments, the container module further includes an agent submodule.
[0033] The agent submodule is connected to the image service terminal submodule and is configured to start the rich management terminal submodule and the image service terminal submodule and collect the graphical protocol connection information and the proxy information of the current container module.
[0034] Compared with related technologies, the power operation and maintenance system based on image projection provided in this embodiment includes a client and a server. The client includes a first communication module and a graphics client module. The first communication module is connected to the server and is used to provide a data interaction channel between the client and the server, and to obtain graphics protocol connection information and proxy information based on the data interaction channel. The graphics client module is connected to the first communication module and is used to establish a graphics protocol connection with the server according to the graphics protocol connection information and proxy information. Based on the graphics protocol, the image information in the server is presented. When operation information is generated in response to the operation image information, the operation information corresponding to the image information is synchronized to the server, and the presented image information is updated synchronously based on the feedback from the server. This solves the problem of the client's difficulty in adapting to different operating systems. The processing related to the operating system is set on the server, and the client only needs to display the image information, thus realizing the client's adaptation to different operating systems. Moreover, the data transmitted by the graphics protocol connection does not contain business interface information and sensitive data information, which can improve operation and maintenance security.
[0035] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects and advantages of this application more readily apparent. Attached Figure Description
[0036] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0037] Figure 1 This is a structural block diagram of a power operation and maintenance system based on image projection provided in an embodiment of this application;
[0038] Figure 2 This is a structural block diagram of a background service module provided in an embodiment of this application;
[0039] Figure 3 This is a structural block diagram of a container module provided in an embodiment of this application;
[0040] Figure 4 This is a structural block diagram of a power operation and maintenance system based on image projection provided in a preferred embodiment of this application.
[0041] In the figure: 100, client; 110, first communication module; 120, graphical client module; 130, authentication module; 200, server; 210, second communication module; 220, background service module; 221, authentication service sub-module; 222, Agent management sub-module; 223, business service sub-module; 230, container module; 231, image server sub-module; 232, Agent sub-module; 233, rich management end sub-module; 234, Agent sub-module. DETAILED DESCRIPTION
[0042] In order to more clearly understand the purpose, technical solution and advantages of the present application, the present application is described and explained below in conjunction with the drawings and examples.
[0043] Unless otherwise defined, technical terms or scientific terms used in the present application shall have the general meaning understood by a person with ordinary skill in the art to which the present application belongs. In the present application, "one", "a", "an", "the", "these" and similar words do not represent a quantitative limitation, and they can be singular or plural. In the present application, the terms "include", "contain", "have" and any variants thereof are intended to cover non-exclusive inclusion; for example, a process, method and system, product or device containing a series of steps or modules (units) are not limited to the listed steps or modules (units), but can include steps or modules (units) not listed, or can include other steps or modules (units) inherent to the process, method, product or device. In the present application, the terms "connected", "connected", "coupled" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. In the present application, "multiple" means two or more. The association between the associated objects is described by "and / or", which means that there can be three relationships, for example, "A and / or B" can mean that A exists alone, A and B exist together, and B exists alone. In general, the character " / " represents an "or" relationship between the objects before and after it. In the present application, the terms "first", "second", "third" and the like are only used to distinguish similar objects, and do not represent a specific order of the objects.
[0044] In the present embodiment, an image projection-based power operation and maintenance system is provided. Figure 1 is a structure block diagram of the image projection-based power operation and maintenance system of the present embodiment. As shown in Figure 1 , the power operation and maintenance system comprises a client 100 and a server 200;
[0045] The client 100 comprises a first communication module 110 and a graphical client module 120;
[0046] The first communication module 110 is connected with the server 200, and is configured to provide a data interaction channel between the client 100 and the server 200, and to obtain the graphical protocol connection information and the proxy information based on the data interaction channel.
[0047] The graphical client module 120 is connected with the first communication module 110, and is configured to establish a graphical protocol connection with the server 200 according to the graphical protocol connection information and the proxy information, and to present the image information in the server 200 based on the graphical protocol.
[0048] When the operation information is generated in response to the operation image information, the operation information corresponding to the image information is synchronized to the server 200, and the presented image information is updated based on the feedback of the server 200.
[0049] It should be noted that the client 100 can be installed on a desktop system of a customer center, such as a desktop system of a data center. The client 100 can be a mobile terminal, a fixed terminal, or a portable terminal, such as a mobile phone, a station, a unit, a device, a multimedia computer, a multimedia tablet, an Internet node, a communicator, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio broadcast receiver, an electronic book device, a game device, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. The server 200 can be installed on a separate server 200. Generally, one client 100 corresponds to one server 200, that is, one data center corresponds to one server 200. In other embodiments, one client 100 can also correspond to multiple servers 200, but only one pair of client 100 and server 200 is selected for remote operation at a time.
[0050] For the first time to set up the power operation and maintenance system taking the data center as an example, the client 100 is installed into the operating system of the data center, and the server 200 is installed into the server 200, and the server 200 is mainly responsible for data processing of the power operation and maintenance system. The first communication module 110 of the client 100 and the second communication module 210 of the server 200 are used to build a data interaction channel between the client 100 and the server 200. The data interaction channel can not only transmit graphic protocol connection information and proxy information, but also transmit sensitive information such as authentication-related information. In order to improve the security of transmission, the information transmitted in the data interaction channel can be encrypted. The encryption method is not limited here. Next, according to the graphic protocol connection information and the proxy information, the graphic protocol connection with the server 200 is established; then the related data transmission of the image information can be realized through the graphic protocol to achieve efficient interaction between the client 100 and the server 200. For example, based on the graphic protocol, the image information in the server 200 is presented. Or, when responding to the operation of the image information to generate operation information, the operation information corresponding to the image information is synchronized to the server 200, and the presented image information is updated based on the feedback of the server 200. Since the graphic client module 120 in the client 100 can directly realize efficient interaction with the server 200 through the graphic protocol, the delay of presenting the image information in the client 100 can be reduced; and the data transmitted by the graphic protocol does not contain business interface information and sensitive data information, which can improve the operation and maintenance security.
[0051] Through the above power operation and maintenance system, the system includes a client 100 and a server 200; the client 100 includes a first communication module 110 and a graphic client module 120; the first communication module 110 is connected with the server 200, and is used to provide a data interaction channel between the client 100 and the server 200, and obtain graphic protocol connection information and proxy information based on the data interaction channel; the graphic client module 120 is connected with the first communication module 110, and is used to establish a graphic protocol connection with the server 200 according to the graphic protocol connection information and the proxy information; present the image information in the server 200 based on the graphic protocol; when responding to the operation of the image information to generate operation information, the operation information corresponding to the image information is synchronized to the server 200, and the presented image information is updated based on the feedback of the server 200, which solves the problem that the client 100 is difficult to adapt to different operating systems, sets the processing related to the operating system to the server 200, and the client 100 only needs to display the image information, thereby realizing that the client 100 adapts to different operating systems, and the data transmitted by the graphic protocol connection does not contain business interface information and sensitive data information, which can improve the operation and maintenance security.
[0052] In some embodiments, the client 100 further includes an authentication module 130.
[0053] The authentication module 130 is connected with the first communication module 110, and is configured to send an authentication request to the server 200 through a data interaction channel.
[0054] After the authentication of the server 200 is passed, the graphical protocol connection information and the proxy information are obtained from the server 200 through the first communication module 110, and the graphical protocol connection information and the proxy information are transmitted to the graphical client module 120.
[0055] Specifically, in the process of establishing a stable data interaction channel between the client 100 and the server 200, the client 100 and the server 200 need to verify the identity of each other, which can be completed by cooperation of the authentication module 130 and the authentication service submodule 221 of the server 200. For example, two-way authentication or one-way authentication can be used to complete the authentication, which will not be described in detail. After the authentication of the server 200 is passed, the graphical protocol connection information and the proxy information are obtained from the server 200 through the first communication module 110, and the graphical protocol connection information and the proxy information are transmitted to the graphical client module 120. In other embodiments, the establishment of the data interaction channel can also be completed by other ways, which is not limited.
[0056] In some embodiments, the server 200 includes a second communication module 210, a background service module 220, and a container module 230.
[0057] The second communication module 210 is connected with the first communication module 110, the background service module 220, and the container module 230, respectively.
[0058] The background service module 220 is connected with the container module 230, and is configured to obtain the graphical protocol connection information and the proxy information of the service connection from the container module 230, and transmit the graphical protocol connection information and the proxy information to the client 100 through the second communication module 210.
[0059] The container module 230 is configured to establish a graphical protocol connection with the graphical client module 120, and project image information to the client 100 based on the graphical protocol.
[0060] When the operation information corresponding to the image information is synchronized, the image information is updated based on the operation information, and the updated image information is fed back to the client 100.
[0061] Specifically, the second communication module 210 and the first communication module 110 can be wired or wireless communication modules. The background service module 220 is mainly responsible for transmitting graphical protocol connection information and proxy information, so that the container module 230 and the graphical client module 120 establish a graphical protocol connection; so that image information can be projected into the graphical client module 120 in the client 100 based on the graphical protocol, so that the data exchanged between the client 100 and the server 200 is not business interface data, but graphical protocol data, and the data itself does not contain business interface information and sensitive data information, thereby improving data transmission security. In this way, the interface and sensitive data of the server 200 can also be protected, and the interface of the server 200 and the leakage of sensitive data are avoided.
[0062] In some embodiments, the first communication module 110 is a first national secret channel module; and the second communication module 210 is a second national secret channel module.
[0063] The first national secret channel module is connected with the second national secret channel module in the server 200, and is used to establish a national secret encrypted data interaction channel.
[0064] Specifically, in order to avoid the leakage of sensitive data information (connection information and proxy information), the first national secret channel module is connected with the second national secret channel module in the server 200, and is used to establish a national secret encrypted data interaction channel.
[0065] In this embodiment, the client 100 includes the first national secret channel module, the graphical client module 120, and the authentication module 130, and is a thin client, which is less dependent, only retains the national secret channel, authentication function and graphical client module 120 function, the software package size is small, and it is easier to adapt to different workstation server 200 operating systems, and is convenient for upgrading and deployment.
[0066] In some embodiments, as shown in Figure 2 The authentication service submodule 221 is connected with the authentication module 130 in the client 100, and is used to obtain an authentication request and perform authentication processing on the client 100 and the server 200 based on the authentication request.
[0067] The authentication service submodule 221 is connected with the authentication module 130 in the client 100, and is used to obtain an authentication request and perform authentication processing on the client 100 and the server 200 based on the authentication request.
[0068] In this embodiment, the specific form of the authentication module 130 and the authentication service submodule 221 is not limited, and the authentication connection between the client 100 and the server 200 is quickly and stably completed through the authentication interaction of the authentication module 130 and the authentication service submodule 221.
[0069] In some embodiments, the authentication service submodule 221 is further configured to obtain graphical protocol connection information and agent information of the service connection from the container module 230 after the authentication is passed.
[0070] The authentication Token information is sorted, and the Token information, graphical protocol connection information, and agent information are transmitted to the client 100.
[0071] Specifically, the client 100 requests login using a username and a password; the server 200 receives the request and verifies the username and the password; after the verification is passed, the server 200 issues a Token information and sends the Token information to the client 100; the client 100 stores the Token information, for example, in a local memory or a local program cache of the client 100; the client 100 needs to carry the Token information issued by the server 200 each time the client 100 requests resources from the server 200; the server 200 receives the request and verifies the Token information carried in the request by the client 100, and returns the requested data to the client 100 if the verification is passed. For example, the graphical protocol connection information and the agent information transmission can be requested, and the request carries the Token information.
[0072] The authentication Token information includes an authentication password and an authentication validity period. For example, a one-time authentication password OTP can be used, and the validity period of the OTP is set to 60 seconds to improve the security of the authentication.
[0073] In some embodiments, the background service module 220 further includes an agent management submodule 222 and a service service submodule 223.
[0074] The agent management submodule 222 is connected with the agent submodule 234 in the container module 230 and is configured to manage the agent submodule 234.
[0075] The service service submodule 223 is connected with the rich management terminal submodule 233 in the container module 230 and is configured to receive a service request initiated by the rich management terminal submodule 233 and perform service processing according to the service request.
[0076] Specifically, the agent management submodule 222 is mainly responsible for managing the agent submodule 234, and the service service submodule 223 is mainly responsible for providing various service services. In this embodiment, various service services are mainly provided by the service service submodule 223, and the database service of the remote end is not relied on, so that the security problem caused by the database connection leakage is avoided.
[0077] In some embodiments, as shown in FIG. 2, the background service module 220 further includes an agent management submodule 222 and a service service submodule 223. Figure 3As shown, the container module 230 includes an agent submodule 232, an image service terminal module 231, and a rich management terminal module 233;
[0078] The image service terminal module 231 establishes a graphics protocol connection with the graphics client module 120 through the agent submodule 232, projects image information provided by the rich management terminal module 233 to the client 100 based on the graphics protocol, and transmits operation information to the rich management terminal module 233 when synchronized to the operation information corresponding to the image information.
[0079] The rich management terminal module 233 is configured to provide image information processed by the background service module 220, and generate a corresponding service request according to the operation information.
[0080] Specifically, the agent submodule 232 provides proxy services to enable the image service terminal module 231 to establish a graphics protocol connection with the graphics client module 120, and the graphics protocol connection also needs to pass through a data interaction channel. The image service terminal module 231 is responsible for communication with the graphics client module 120 through the graphics protocol connection, receives operation information of the client 100 (including mouse clicks, keyboard inputs, screen swipes, etc.), and projects the interface of the rich management terminal module 233 to the client 100 through the image protocol, thereby enabling the client to operate on the client 100. The actual operation is the interface of the rich management terminal module 233 of the service end 200, which significantly reduces the delay feeling of the user and provides excellent use feeling.
[0081] The rich management terminal module 233 and the service service submodule 223 can perform data interaction through an internal private protocol and communicate using the internal network of the service end 200, thereby greatly saving network traffic and improving operation and management efficiency.
[0082] In some embodiments, the container module 230 further includes an Agent submodule 234;
[0083] The Agent submodule 234 is connected with the image service terminal module 231, and is configured to start the rich management terminal module 233 and the image service terminal module 231, and collect graphics protocol connection information and proxy information of the current container module 230.
[0084] Specifically, the Agent submodule 234 receives the management instructions of the Agent management submodule 222 under the management of the Agent management submodule 222, starts the rich management terminal module 233 and the image service terminal module 231, collects the current graphical protocol connection information and agent information of the container module 230, and transmits the graphical protocol connection information and agent information to the Agent management submodule 222 as a communication bridge. Of course, the Agent submodule 234 can also be responsible for receiving the management instructions of the Agent management submodule 222 to stop the rich management terminal module 233 and the image service terminal module 231. In this embodiment, the management can be optimized to ensure the stability of the operation.
[0085] The embodiment will be described and explained below through preferred embodiments.
[0086] Figure 4 The power operation and maintenance system based on image projection is the preferred embodiment, which comprises a client 100 and a server 200; wherein the client 100 comprises a first national secret channel module, a graphical client module 120 and an authentication module 130; the server 200 comprises a second national secret channel module, a background service module 220 and a container module 230. The background service module 220 is responsible for providing external services of the server 200, including an authentication service submodule 221, an Agent management submodule 222 and a business service submodule 223; the container module 230 comprises an Agent submodule 234, an agent submodule 232, an image service terminal module 231 and a rich management terminal module 233.
[0087] The first national secret channel module is connected with the second national secret channel module, providing a national secret encrypted data interaction channel between the client 100 and the server 200, ensuring the security of data interaction between the client 100 and the server 200. The data interaction channel can transmit authentication related information, graphical protocol connection information and agent information. The authentication module 130 is responsible for sending an authentication request to the server 200 through the data interaction channel to verify the user identity information of the client 100; and according to the authentication response of the server 200, the graphical protocol connection information and agent information provided by the server 200 are transmitted to the graphical client module 120. The graphical client module 120 initiates a graphical protocol connection request to the server 200 according to the graphical protocol connection information and agent information provided by the server 200; after establishing the graphical protocol connection, the image information of the server 200 is presented to the user on the client 100, and the operation information corresponding to the user is synchronized with the server 200 through the graphical protocol; the user can perform keyboard and mouse operations in the image presented on the client 100, operate the rich management terminal module 233 of the server 200, and complete the remote operation and maintenance operation.
[0088] The authentication service submodule 221 is connected with the authentication module 130 of the client 100 through a data interaction channel, is responsible for processing an authentication request, and returns the authentication Token information, the graphical protocol connection information required for service connection, and the agent information to the client 100 after authentication. The Agent management submodule 222 is responsible for starting the container module 230, communicating with the Agent submodule 234 in the container module 230, collecting the agent information and the graphical protocol connection information of the current container module 230, and returning the information to the client 100 through the authentication service submodule 221. The business service submodule 223 is responsible for processing a business request initiated by the rich management terminal submodule 233 in the container module 230, and performing business processing, such as connecting a database to read and update configuration data. The authentication module 130 and the authentication service submodule 221 can support local password, AD / LDAP, Radius, UKey, fingerprint, and other identity authentication modes and combinations of these identity authentication modes into two-factor authentication. The authentication request is transmitted through a data interaction channel encrypted by a national secret, and the 11234 port (the port can be customized) can be used to improve the security of transmission.
[0089] The container module 230 uses a container technology to encapsulate the image service terminal submodule 231, is responsible for projecting the image information (operation interface) of the rich management terminal submodule 233 to the client 100 through a graphical protocol while synchronizing the operation information of the client 100 and the user, so that the user can operate the operation interface of the service end 200 on the client 100 to complete remote operation and maintenance. The agent submodule 232 is responsible for proxying the graphical protocol data transmitted to the service end 200 through a national secret channel to a specified port of the graphical service end 200 in the container; the image transmission channel is established, and the image data transmission between the client 100 and the service end 200 is all proxy-transmitted by the agent module. The Agent submodule 234 is responsible for receiving the management instructions of the Agent management submodule 222 of the service end 200, including starting and stopping the image service terminal submodule 231 and the rich management terminal submodule 233, collecting the agent information and the graphical protocol connection information, and returning the information to the Agent management submodule 222 of the service end 200. The image service terminal submodule 231 is responsible for communicating with the graphical client module 120, receiving the keyboard and mouse events of the client 100, and projecting the interface of the rich management terminal submodule 233 to the client 100 through the image protocol, so as to realize the keyboard and mouse operation of the client on the client 100, and the actual operation is the interface of the rich management terminal submodule 233 of the service end 200. The rich management terminal submodule 233 is responsible for providing a business management interface and interacting with the business service submodule 223 of the service end 200 through an internal private protocol of the service end 200.
[0090] Wherein, the Agent management submodule 222 and the Agent submodule 234 communicate with each other by using an internal private protocol to improve security; the container module 230 can use Docker technology or other container technology.
[0091] Wherein, the graphic protocol can be VNC, RDP or other graphic protocol, and needs to support keyboard and mouse operations to be synchronized between the client 100 and the server 200; the graphic protocol data is transmitted through a data interaction channel encrypted by a national secret, and can use port 15900 (the port can be customized) to improve the security of transmission. After the server 200 receives the graphic protocol data through the port 15900, the data is forwarded to the port 5900 (the port can be customized) in the container, and then is directly forwarded to the image server submodule 231 for processing by the proxy submodule 232 in the container. After the business service submodule 223 receives the operation and maintenance request of the user in the rich management terminal submodule 233, various operation and maintenance operations can be performed, including searching and updating database data, and initiating access and password change operations on the target asset.
[0092] The power operation and maintenance system based on the above preferred embodiment has the following remote operation and maintenance management process:
[0093] Step S10, the client 100 installed on the desktop system of the power operation and maintenance system provides authentication information to the authentication module 130, and the authentication module 130 connects the authentication service submodule 221 of the server 200 to perform identity authentication.
[0094] Step S20, the authentication service submodule 221 of the server 200 verifies the authentication information. If the authentication fails, the authentication connection is rejected; if the authentication is passed, the graphic protocol connection information and the proxy information required for business connection are obtained from the Agent management submodule 222. After the authentication service submodule 221 receives the authentication pass request, the Agent management submodule 222 allocates or starts a container for the user who has successfully logged in. After the container is started, the proxy submodule 232 and the Agent submodule 234 are automatically started, the image server submodule 231 and the rich management terminal submodule 233 are started by the Agent submodule 234, the proxy information and the graphic protocol connection information are collected, and then are returned to the Agent management submodule 222 of the server 200.
[0095] Step S30, the Agent management submodule 222 returns the proxy information and the graphic protocol connection information to the authentication service submodule 221, and after the authentication service submodule 221 sorts the information, the Token information, the graphic protocol connection information and the proxy information required for business connection are returned to the client 100.
[0096] Step S40, the authentication module 130, the graphical protocol connection information and agent information provided by the service end 200 to the graphical client module 120. The graphical client module 120 initiates a graphical protocol connection request to the service end 200, and the request is forwarded to the graphical service end 200 submodule in the container by the agent module of the service end 200. After the client 100 connection information authentication is passed, the graphical protocol connection channel between the two parties is established. After the channel is successfully established, the graphical service end 200 submodule transmits the image of the rich management terminal module 233 to the client 100 through the graphical protocol connection, and the client 100 can see the image projection of the rich management terminal module 233.
[0097] Step S50, the user performs key mouse operation on the client 100, and transmits it to the graphical service end 200 submodule through the transmission channel of the graphical protocol connection by the graphical client module 120. Then the actual operation is the rich management terminal module 233, which interacts with the service service submodule 223 of the service end 200 through the internal private protocol of the service end 200 to complete the business processing.
[0098] Step S60, the graphical service end 200 submodule transmits the image information of the rich management terminal module 233 after business processing to the graphical client module 120 of the client 100 through the agent module, presents the result image to the customer, and completes the process of remote operation and maintenance.
[0099] In the preferred embodiment, the effects achieved include but are not limited to the following points:
[0100] 1. The service end 200 does not need to expose the business interface to the client 100, and the data exchanged between the client 100 and the service end 200 is not business interface data, but graphical protocol data, which does not contain business interface information and sensitive data information. Therefore, the interface and sensitive data of the service end 200 are protected, and the interface of the service end 200 is attacked and the sensitive data is leaked.
[0101] 2. The client 100 does not depend on the remote database service, avoiding the security problem caused by database connection leakage;
[0102] 3. The service end 200, the rich management terminal module 233 and the background service submodule interact through the internal private protocol and communicate in the internal network, greatly saving the network traffic and improving the operation and management efficiency;
[0103] 4. The client 100 is a thin client, which depends on less, only retains the national secret channel, authentication function and graphical protocol client 100 function, the software package size is small, and it is easier to adapt to different workstation service end 200 operating systems, and the upgrade and deployment are convenient.
[0104] It should be noted that the above-mentioned various modules can be functional modules or program modules, which can be implemented by software or hardware. For the modules implemented by hardware, the above-mentioned various modules can be located in the same processor; or the above-mentioned various modules can also be located in different processors in any combination.
[0105] It should be understood that the specific embodiments described herein are merely exemplary and not intended to limit the application. Based on the embodiments provided in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of protection of the present application.
[0106] Obviously, the drawings are only some examples or embodiments of the present application, and those skilled in the art can also apply the present application to other similar situations without creative labor. In addition, it can be understood that although the work done in the development process can be complex and long, some design, manufacture or production changes made by those skilled in the art according to the technical content disclosed in the present application are only routine technical means and should not be regarded as insufficient disclosure of the present application.
[0107] The term "embodiment" in the present application means that the specific features, structures or characteristics described in conjunction with the embodiment can be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily mean the same embodiment, nor does it mean independence or alternatives to other embodiments. It can be clearly or implicitly understood by those skilled in the art that the embodiments described in the present application can be combined with other embodiments without conflict.
[0108] The above-described embodiments only express several implementation manners of the present application, which are described in detail and specifically, but should not be understood as a limitation on the scope of patent protection. It should be noted that for those skilled in the art, without departing from the concept of the present application, several modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.
Claims
1. A power operation and maintenance system based on image projection, characterized in that, include: Client and server; The client includes a first communication module and a graphical client module; The first communication module is connected to the server and is used to provide a data interaction channel between the client and the server, and to obtain graphical protocol connection information and proxy information based on the data interaction channel; The graphics client module is connected to the first communication module and is used to establish a graphics protocol connection with the server according to the graphics protocol connection information and the proxy information; and to present the image information in the server based on the graphics protocol. When generating operation information in response to the operation of the image information, the operation information corresponding to the image information is synchronized to the server, and the presented image information is updated synchronously based on the feedback from the server. The server includes a second communication module, a backend service module, and a container module; The second communication module is connected to the first communication module, the backend service module, and the container module, respectively. The background service module is connected to the container module and is used to obtain the graphical protocol connection information and proxy information of the business connection from the container module, and transmit the graphical protocol connection information and the proxy information to the client through the second communication module; The container module is used to establish a graphics protocol connection with the graphics client module; and to project the image information onto the client based on the graphics protocol. When synchronizing the operation information corresponding to the image information, the image information is updated based on the operation information, and the updated image information is fed back to the client.
2. The power operation and maintenance system based on image projection according to claim 1, characterized in that, The client also includes an authentication module; The authentication module is connected to the first communication module and is used to send the authentication request to the server through the data interaction channel. After successful authentication on the server, the system obtains the graphics protocol connection information and proxy information from the server through the first communication module, and then transmits the graphics protocol connection information and proxy information to the graphics client module.
3. The power operation and maintenance system based on image projection according to claim 1, characterized in that, The first communication module is a first national cryptographic channel module; the second communication module is a second national cryptographic channel module; The first national cryptographic channel module is connected to the second national cryptographic channel module in the server to establish a national cryptographic encrypted data interaction channel.
4. The power operation and maintenance system based on image projection according to claim 1, characterized in that, The backend service module includes an authentication service sub-module; The authentication service submodule is connected to the authentication module in the client and is used to obtain authentication requests and perform authentication processing on the client and the server based on the authentication requests.
5. The power operation and maintenance system based on image projection according to claim 4, characterized in that, The authentication service submodule is also used to obtain the graphical protocol connection information and proxy information of the business connection from the container module after the authentication is successful; Organize the authentication token information and transmit the token information, the graphical protocol connection information, and the proxy information to the client.
6. The power operation and maintenance system based on image projection according to claim 5, characterized in that, The authentication token information includes the authentication password and the authentication validity period.
7. The power operation and maintenance system based on image projection according to claim 1, characterized in that, The backend service module also includes an Agent management submodule and a business service submodule; The Agent management submodule is connected to the Agent submodule in the container module and is used to manage the Agent submodule; The business service submodule is connected to the rich management terminal module in the container module, and is used to receive business requests initiated by the rich management terminal module and perform business processing according to the business requests.
8. The power operation and maintenance system based on image projection according to claim 1, characterized in that, The container module includes an agent submodule, an image service terminal module, and a rich management terminal module; The image service terminal module establishes a graphics protocol connection with the graphics client module through the proxy submodule; based on the graphics protocol, it projects the image information provided by the rich management terminal module to the client. When synchronizing the operation information corresponding to the image information, the operation information is transmitted to the rich management terminal module; The rich management terminal module is used to provide the image information processed by the background service module; and to generate corresponding business requests based on the operation information.
9. The power operation and maintenance system based on image projection according to claim 8, characterized in that, The container module also includes an Agent submodule; The Agent submodule is connected to the image service terminal module and is used to start the rich management terminal module and the image service terminal module, and to collect the current graphics protocol connection information and agent information of the container module.
Citation Information
Patent Citations
Bastion host, operation and maintenance auditing method, electronic equipment and storage medium
CN112887287A