Cloud Browser Access Method, Device, System and Storage Medium
By realizing unconscious transmission of login information in the cloud browser system, the problem of high complexity of cloud browser access operations is solved and access efficiency is improved.
Patent Information
- Application Number
- CN202310475022.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-27
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2043-04-27
AI Technical Summary
The access operation of existing cloud browsers is very complex, and users need to log in and authenticate multiple times between the local browser and the cloud browser.
The user's login information is obtained from the designated storage path through the terminal device and sent it to the cloud server. The cloud server schedules the cloud browser for access authentication, returns the video streaming results, and realizes the unconscious transmission of the login information between the local browser and the cloud browser.
Reduces the complexity of login authentication operations when accessing different applications/services across local browsers and cloud browsers, and improves access efficiency.
Smart Images

Figure CN116405572B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud intelligent technologies, and particularly to a method, device, system, and storage medium for accessing a cloud browser. Background Art
[0002] A cloud browser is a browser that executes computing tasks on a cloud server. Some functions of the cloud browser, such as page layout and script execution, which require relatively high computing capabilities, are deployed on the cloud server. After rendering a web page on the cloud server, the rendering result is transmitted to the local browser of the terminal in the form of a video stream and displayed on the local browser. The cloud browser can provide an isolated Web (World Wide Web) access environment to facilitate access security management. For end users, since the local browser and the cloud browser are isolated from each other, when the user logs in to an account on the local browser and accesses a Web site through the local browser, if the access is redirected to the cloud browser for execution, the user still needs to log in again on the cloud browser. This login method results in a relatively high complexity of access operations across the local browser and the cloud browser. Therefore, there is a need to propose a new solution. Summary of the Invention
[0003] Multiple aspects of this application provide a method, device, system, and storage medium for accessing a cloud browser to reduce the complexity of access operations across the local browser and the cloud browser.
[0004] An embodiment of this application provides a method for accessing a cloud browser, including: in response to a user's access request for a first service, obtaining the user's login information from a specified storage path; sending the access request and the user's login information to a cloud server, so that the cloud server schedules the cloud browser to access the first service and uses the first service to perform access authentication on the login information; receiving and displaying a video stream returned by the cloud server according to the access result of the first service.
[0005] Optionally, in response to a user's access request for a first service, obtaining the user's login information from a specified storage path includes: in response to a user's access request for a first service, determining a target storage path corresponding to the first service from at least one storage path; where the login information stored in different storage paths is different; obtaining the user's login information from the target storage path.
[0006] Optionally, the user's login information includes: identity information preset for logging in to the cloud browser; and / or, identity information provided by the user when initiating an access request for a second service; the second service and the first service use the same authentication server for access authentication; and / or; a login token obtained from the authentication server according to the access request.
[0007] Optionally, before obtaining the user's login information from a specified storage path in response to the user's access request for the first service, it further includes: in response to the user's access request for the second service, presenting a login page of the authentication server; obtaining the identity information provided by the user on the login page; sending an access request to the server of the second service and sending the identity information to the server of the second service, so that the server of the second service invokes the authentication server to perform login authentication on the identity information; if the identity information passes the login authentication, receiving the access result of the second service returned by the server of the second service and saving the identity information in a specified storage path locally.
[0008] An embodiment of the present application further provides a browser access method, including: receiving an access request for a first service and the user's login information sent by a terminal device; the user's login information is obtained by the local browser of the terminal device from a specified storage path; scheduling a cloud browser to access the first service and using the first service to perform access authentication on the login information; obtaining an access result returned by the first service after the login information passes the access authentication; sending a video stream of the access result to the terminal device for display.
[0009] Optionally, the user's login information includes: identity information provided by the user when initiating an access request for a second service, and the second service uses an authentication server for access authentication; and / or, a login token obtained by the terminal device from the authentication server according to the access request; scheduling a cloud browser to access the first service and using the first service to perform access authentication on the login information includes: determining a target cloud browser for accessing the first service; using the target cloud browser to access the first service and sending the login information to the first service, so that the first service invokes the authentication server to perform access authentication on the login information.
[0010] An embodiment of the present application further provides a terminal device, including a memory, a processor, a display component, and a communication component; the memory is used to store one or more computer instructions; the processor is used to execute the one or more computer instructions to: invoke the display component and the communication component to execute the steps in the browser access method provided by the embodiment of the present application.
[0011] An embodiment of the present application further provides a server, including: a memory and a processor; the memory is used to store one or more computer instructions; the processor is used to execute the one or more computer instructions for: executing the steps in the browser access method provided by the embodiment of the present application.
[0012] An embodiment of the present application further provides a cloud browser access system, including: a terminal device, a cloud server, and an authentication server; wherein, the terminal device is used to respond to a user's access request for a first service, obtain the user's login information from a specified storage path; send the access request and the user's login information to the cloud server; receive and display the video stream returned by the cloud server according to the access result of the first service; the cloud server is used to receive the access request for the first service and the user's login information sent by the terminal device; the user's login information is obtained by the local browser of the terminal device from a specified storage path; schedule the cloud browser to access the first service and use the first service to perform access authentication on the login information; obtain the access result returned by the first service after the login information passes the access authentication; send the video stream of the access result to the terminal device for display.
[0013] An embodiment of the present application further provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, it can implement the steps in the method provided by the embodiment of the present application.
[0014] In the embodiment of the present application, when the local browser of the terminal device receives an access request for a certain service, if the service needs to be accessed through the cloud browser, the terminal device can obtain the user's login information from a specified storage path, and send the access request and the user's login information to the cloud server. The cloud server can schedule the cloud browser to execute the access request of the service and use the service to perform access authentication on the login information. The cloud server can obtain the access result returned by the service after the login information passes the authentication, and return the access result to the terminal device in the form of a video stream. Furthermore, the transfer of the login information between the local browser and the cloud browser is realized without the user's awareness, and then the login to the cloud browser is realized without the user manually inputting the login information. Thus, when accessing different applications / services across the local browser and the cloud browser, the operation complexity of login authentication is reduced, and the access efficiency is improved. Description of the Drawings
[0015] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application, and do not constitute an improper limitation to the present application. In the drawings:
[0016] Figure 1 Schematic structural diagram of a cloud browser access system provided by an exemplary embodiment of the present application;
[0017] Figure 2 Schematic structural diagram of a cloud browser access system provided by another exemplary embodiment of the present application;
[0018] Figure 3 Schematic structural diagram of a cloud browser access system provided by yet another exemplary embodiment of the present application;
[0019] Figure 4 Schematic signaling interaction diagram of a cloud browser access system provided by yet another exemplary embodiment of the present application;
[0020] Figure 5 Schematic flowchart of the cloud browser access method executed on the terminal device side provided by an exemplary embodiment of the present application;
[0021] Figure 6 Schematic flowchart of the cloud browser access method executed on the cloud server side provided by an exemplary embodiment of the present application;
[0022] Figure 7 Schematic structural diagram of a terminal device provided by an exemplary embodiment of the present application;
[0023] Figure 8 Schematic structural diagram of a server provided by an exemplary embodiment of the present application. Detailed implementation manners
[0024] To make the objectives, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with the specific embodiments of the present application and the corresponding drawings. Apparently, the described embodiments are only a part rather than all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the protection scope of the present application.
[0025] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "the" and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. "Plural" generally includes at least two, but does not exclude the case of including at least one.
[0026] It should be understood that the term "and / or" used herein is merely a description of the associated relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this text generally represents an "or" relationship between the associated objects before and after.
[0027] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a commodity or system comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such commodity or system. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the commodity or system comprising the said element.
[0028] Aiming at the technical problem that the access operation of the cloud browser in the prior art has a relatively high complexity, in some embodiments of the present application, a solution is provided. The technical solutions provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0029] Figure 1 It is a schematic structural diagram of a cloud browser access system provided for an exemplary embodiment of the present application, as Figure 1 shown, the cloud browser access system 100 includes: a terminal device 10 and a cloud server 20.
[0030] Among them, the terminal device 10 refers to the device on the user side, and may include but is not limited to mobile phones, computers, smart wearable devices, etc. A browser client capable of performing network access runs on the terminal device 10. The browser client can directly access the Web network according to a given URL (Uniform Resource Identifier), or indirectly access the Web network through the isolated Web access environment provided by the cloud browser.
[0031] Relative to the cloud browser, the browser client on the terminal device runs locally on the terminal device on the client side and can be called a local browser. The local browser can receive the user's access operation for an application / service and send an access request to the site (server) where the application / service is located.
[0032] Among them, the cloud server 20 can create and run one or more cloud browsers, and any cloud browser can run in a secure isolation environment to provide secure access services. The access operations of the local browser for some applications / services can be implemented based on the cloud browser. For example, when the local browser accesses a specific service, if the service needs to be accessed by the cloud browser, the local browser can send the access request for the service to the cloud server 20. The cloud server 20 can use the cloud browser to access the service, render the access result page, and return the access result page in the form of a video stream.
[0033] When the local browser accesses an application / service through the cloud browser, it needs to perform login authentication to ensure the security of the access operation. In this embodiment, a cloud browser plugin can be run in the local browser, and this cloud browser plugin is used to assist in performing "user-free operation" login authentication when the local browser accesses the cloud browser. The following will give an exemplary description.
[0034] In this embodiment, the local browser is mainly used for: receiving the user's access request for the first service; among them, the first service can be any application / service located on the remote server, for example, it can be a software as a service (SaaS) application, a microservice application or any other application on the cloud server. The cloud browser plugin on the local browser can determine whether the access request meets the cloud access conditions. Among them, the cloud access conditions can include, but are not limited to: the network address corresponding to the accessed service hits the preset address list, accessing a service deployed on the internal network server of an organization (or unit) through the public network, accessing a service deployed on the public network server through the internal network of an organization (or unit), or the network environment where the local browser is located is an unauthenticated secure environment. If the access request meets the above cloud access conditions, the local browser can access the first service through the cloud browser to improve the access security based on the isolation and anti-attack performance of the cloud server.
[0035] If the access request for the first service meets the cloud access conditions, the local browser can obtain the user's login information from the specified storage path, and send the access request and the user's login information to the cloud server 20.
[0036] Among them, the specified storage path can be the cache path of the local browser on the local terminal device 10, can be other storage paths specified by the user on the terminal device 10, can be the storage paths specified by the user in other trusted devices, or can be the storage paths specified by the user on the cloud server 20. This embodiment does not make any restrictions on this.
[0037] Optionally, the user's login information may include: the identity information provided by the user when initiating a historical access request, and / or, the identity information pre-configured for logging in to the cloud browser, and / or, the login token obtained from the authentication server according to the access request. Specific details will be introduced in subsequent embodiments and will not be elaborated here. Among them, the identity information may include: the user's account / password or other identity identification information.
[0038] Among them, the cloud server 20 is mainly used for: receiving the access request for the first service and the user's login information sent by the terminal device 10; scheduling the cloud browser to access the first service and using the first service to perform access authentication on the login information. The first service may return an access result after the login information passes the access authentication. The cloud browser may render the page corresponding to the access result, and then the cloud server 20 may send the access result to the terminal device 10 in the form of a video stream for display.
[0039] Optionally, when scheduling the cloud browser to execute the access request for the first service, the cloud server 20 may determine the target cloud browser for accessing the first service from multiple cloud browsers on the cloud server 20. Among them, the target cloud browser may be determined according to the service type of the first service. The service type of the first service may be associated with the security level of the first service or the number of required resources. For example, when the first service is a financial type of service or a service deployed on an enterprise intranet service server, a cloud browser with a higher security level may be selected as the target browser. For another example, when the first service is an online shopping mall or a game platform with a large number of pictures, a cloud browser with a higher specification (such as dual-core or quad-core) may be selected as the target cloud browser. The cloud server 20 may use the target cloud browser to access the first service and send the login information to the first service, and then the first service may perform access authentication on the user according to the login information.
[0040] After the login information passes the authentication, the first service may return an access result to the cloud browser. After obtaining the access result, the cloud browser may render the content page corresponding to the access result and send the content page to the terminal device 10 in the form of a video stream for display.
[0041] The terminal device 10 may receive and display the video stream returned by the cloud server 20 through the local browser. The user may view the access result of the first service through the local browser on the terminal device 10. Optionally, if the terminal device 10 detects an interaction operation of the user on the access result, the interaction operation may be sent to the cloud server 20. The cloud server 20 may use the cloud browser to respond to the interaction operation and return the response result in the form of a video stream, which will not be elaborated here.
[0042] In this embodiment, when the local browser of the terminal device receives a service access request, if the service needs to be accessed through the cloud browser, the terminal device can obtain the user's login information from the specified storage path and send the access request and the user's login information to the cloud server. The cloud server can schedule the cloud browser to execute the access request of the service and use the service to perform access authentication on the login information. The cloud server can obtain the access result returned by the service after the login information is authenticated and return the access result to the terminal device in the form of a video stream. Furthermore, the transfer of the login information between the local browser and the cloud browser is realized without the user's awareness, and then the login to the cloud browser is realized without the user manually inputting the login information. Thus, when accessing different applications / services across the local browser and the cloud browser, the operation complexity of login authentication is reduced and the access efficiency is improved.
[0043] In some alternative embodiments, as Figure 2 shown, the cloud browser access system 100 further includes: an authentication server 30. The authentication server 30 is used to manage the login information of different users and provide a login authentication service. Optionally, the authentication server 30 can be implemented as an IDP (Identity Providers) server. The IDP server can provide services for storing and managing digital identities, services for adding or deleting permissions, and services for identity authentication, etc. In an actual application scenario, an enterprise can utilize various services provided by the IDP to enable different employees or users to connect to the respective resource providers (Service Provider, SP) they need.
[0044] In the above and following embodiments of the present application, the terminal device 10 and the cloud server 20 can use the authentication server 30 to manage and authenticate the login information. When the cloud browser is scheduled to access the first service, after the cloud browser opens the first service, it can provide the obtained login information to the first service. The first service can call the authentication service interface provided by the authentication server 30 to authenticate the login information. If the login information passes the authentication, the first service can return the specific access content to the cloud browser.
[0045] Based on this implementation manner, the accessed application / service (such as the first service) can implement login authentication by calling the authentication service interface provided by the authentication server 30. Thus, there is no need to specifically modify the cloud browser and the accessed service, which reduces the development cost on the one hand and ensures the security and reliability of the login authentication process on the other hand.
[0046] In the foregoing embodiments, the login information of the user is exemplarily described. The login information of the user may include: identity information provided when the user initiates a historical access request, and / or identity information pre-configured for logging in to the cloud browser, and / or a login token obtained from the authentication server according to the access request. The following will exemplarily describe the above different implementation forms of the login information respectively.
[0047] In some alternative embodiments, the login information for logging in to the cloud browser is pre-configured by the user. In this implementation manner, the user may store the account and password (i.e., identity information) for logging in to the cloud browser at a specified storage path. The storage path may be located in a secure and trusted storage space locally or in a secure and trusted storage space on the cloud server. When the local browser accesses a specified service through the cloud browser, it may obtain the identity information specified by the user from the above-specified storage path, and send an access request and the identity information to the cloud server. Among them, the identity information may be managed by the authentication server 30. Furthermore, after the cloud browser obtains the identity information, it may use the authentication server 30 to authenticate the identity information.
[0048] In some other alternative embodiments, the login information for logging in to the cloud browser is provided when the user initiates a historical access request. The following will take the historical access request being implemented as an access request for a second service as an example for exemplary description. The second service is a service accessible by the local browser, and the second service and the first service use the same authentication server 30 for logging in to manage accounts and access authentication.
[0049] Optionally, the local browser may respond to the user's access request for the second service, display the login page of the authentication server 30 for the user to input, and obtain the account and password provided by the user on the login page, that is, the identity information. The local browser may send an access request to the server of the second service and send the identity information to the server of the second service, so that the server of the second service may call the authentication server 30 to perform login authentication on the identity information. If the identity information passes the login authentication, the local browser may receive the access result of the second service returned by the server of the second service and save the identity information in a specified storage path locally. The saved identity information is the login information authenticated by the authentication server 30 and has high security. Furthermore, when accessing an application / service through the cloud browser subsequently, the identity information may be automatically transmitted to the cloud browser without the need to perform login authentication manually again.
[0050] In some other alternative embodiments, the login information for logging in to the cloud browser may include: the login token requested by the terminal device 10 from the authentication server 30. When the user initiates an access request for the first service, the terminal device 10 may log in to the authentication server 30 and request the authentication server 30 to issue a login token. Among them, the terminal device 10 may log in to the authentication server 30 according to the user account currently logged in to the local browser, or the terminal device 10 may log in to the authentication server 30 according to the identity information provided in the historical access request for the second service, or the terminal device 10 may log in to the authentication server 30 according to its own physical address. This embodiment does not make any restrictions.
[0051] The authentication server 30 may dynamically generate a login token according to the login information and the login timestamp provided by the local browser, and return the login token to the terminal device 10. The terminal device 10 may store the login token as login information in a specified path locally. The local browser may obtain the login token as login information from the specified path and send the login information to the cloud server. The cloud server may schedule the cloud browser to access the first service. Among them, the first service is a service that supports token login. Furthermore, the first service may use the authentication server 30 to perform access authentication on the login token. If the authentication server 30 confirms that the login token is valid, the first service may determine that the user has passed the access authentication.
[0052] In this implementation manner, using the dynamically generated login token as the login information and passing the login token between the local browser and the cloud browser can enable the user to avoid manually performing cloud browser login authentication again, and at the same time, based on the dynamic characteristics and security features of the login token, improve the access security of the cloud browser.
[0053] In some alternative embodiments, different applications / services use different authentication servers. When the local browser on the terminal device 10 reuses the login information, it can reuse the login information of the applications / services that use the same authentication server. For example, for service A1 that the local browser can directly access and service A2 that needs to be accessed through the cloud browser, the same authentication server C1 is used for login information management and authentication. Then, when the local browser requests the cloud browser to access server A2, it can send the login information provided by the user when requesting to access service A1 to the cloud browser for login authentication. Another example, for service B1 that the local browser can directly access and service B2 that needs to be accessed through the cloud browser, the same authentication server C2 is used for login information management and authentication. Then, when the local browser requests the cloud browser to access server B2, it can send the login information provided by the user when requesting to access service B1 to the cloud browser for login authentication.
[0054] Among them, the login information managed by different authentication servers can be stored under different storage paths. Continuing with the first service as an example, when the terminal device 10 receives an access request from a user for the first service, it can determine the target storage path corresponding to the first service from at least one storage path, and obtain the user's login information from the target storage path.
[0055] Among them, the at least one storage path can correspond to different types of authentication servers. When the terminal device 10 determines the target storage path corresponding to the first service, it can identify the target identifier of the authentication server used by the first service, and determine the storage path corresponding to the target identifier from the at least one storage path as the target storage path. Continuing with the above example, in the cache space of the local browser, the authentication server C1 and the authentication server C2 can respectively correspond to the cache paths L1 and L2, which are used to store the login information managed and authenticated by the authentication server C1 and the authentication server C2 respectively. When the local browser receives an access request for service A2, it can obtain the user's login information from path L1, and send an access request to the cloud server according to the login information. When the local browser receives an access request for service B2, it can obtain the user's login information from path L2, and send an access request to the cloud server according to the login information.
[0056] In some embodiments, the login information is stored in the scope of the cookie (data stored on the user's local terminal) in the form of a cookie, and the scope can be the domain of the authentication server. The login information for login authentication using different authentication servers can be stored under the domains of different authentication servers.
[0057] Continuing with the first service and the second service as examples, when the local browser accesses the second service, if the second service uses an IDP server for login authentication, the login information provided by the user when accessing the second service can be stored in the form of a cookie under the domain of the IDP. Furthermore, when the user accesses the first service, the local browser can obtain the login information from the domain of the IDP, and send the login information to the cloud browser when sending an access request for the first service to the cloud browser.
[0058] Based on this implementation method, secure identity transfer across local and cloud browsers is achieved, reducing the sense of fragmentation in the browsing process in the cloud browser scenario.
[0059] Hereinafter, in conjunction with the accompanying drawings, the access system of the cloud browser provided by the embodiments of the present application will be further exemplarily described.
[0060] Such as Figure 3As shown in the figure, the cloud browser access system includes: a local browser, a cloud browser, a cloud browser management and control service, a locally accessible SP service provider, a cloud browser accessible SP service provider, and an IDP server. Among them, a cloud browser plugin is installed in the local browser. The locally accessible SP service provider provides SaaS service A and SaaS service B. The cloud browser accessible SP service provider provides SaaS service C and SaaS service D. The IDP server provides an identity authentication function and a session management function.
[0061] As Figure 3 shown in the figure, in step 1, the user accesses SaaS service A accessible by the local browser and provides identity information.
[0062] As Figure 3 shown in the figure, in step 2, the local browser accesses SaaS service A and logs in to the IDP server. Refer to Figure 4 for further description of this step. When the user accesses SaaS service A through the local browser, the local browser can send an access request to SaaS service A. The SP service provider of SaaS service A can use the IDP server to verify the login information. If the IDP server returns a verification result that the user is not logged in, the local browser can redirect the access target to the IDP login page for the user to log in. As Figure 4 shown in the figure, the local browser can obtain the identity information input by the user and use the IDP server for login authentication. If the IDP server returns an authentication passed result, the local browser can use the IDP cookie as the identity information and store the IDP cookie under the domain of the IDP for subsequent use. The local browser can redirect the access target to SaaS service A and pass the IDP cookie identity information to the SP service provider of SaaS service A.
[0063] As Figure 3 shown in the figure, in step 3, the SP service provider corresponding to SaaS service A can access the IDP identity authentication service to complete the identity authentication. After that, the SP service provider corresponding to SaaS service A can return the content of SaaS service A to the local browser, and then the local browser can display the Tab (tabulator key) page of SaaS service A.
[0064] As Figure 3 shown in the figure, in step 4, when the user accesses SaaS service C that requires a cloud browser environment, the browser plugin in the local browser can obtain the user's IDP identity from the cookie.
[0065] As Figure 3As shown, in step 5, the browser plugin can evoke the cloud browser and transfer the user's IDP login identity. Refer to Figure 4 To further illustrate this step, the local browser plugin can transfer the IDP cookie identity information to the cloud browser control service. The cloud browser control service can schedule cloud resources to create a cloud browser and transfer the IDP cookie identity information to the cloud browser. The cloud browser can open SaaS service C, access SaaS service C, and transfer the IDP cookie identity information to the SP service provider of SaaS service C.
[0066] As Figure 3 shown, in step 6, the cloud browser can access SaaS service C based on the transferred IDP identity. As Figure 4 shown, the cloud browser can use the IDP server to verify the identity of the DP cookie identity information. If the verification is successful, step 7 is executed.
[0067] As Figure 3 shown, in step 7, the SP service provider corresponding to SaaS service C can access the IDP identity authentication service to complete the identity authentication. After that, the SP service provider corresponding to SaaS service C can return the content of SaaS service C to the cloud browser. The cloud browser can render the Tab page of SaaS service C and transmit the rendering result to the local browser in the form of a video stream. Furthermore, the local browser can display the Tab (tabulator key) page of SaaS service C. Refer to Figure 4 To further illustrate this step, the cloud browser can return a cloud browser streaming credential (ticket) to the cloud browser plugin. Furthermore, the local browser can stream and display the result page rendered by the cloud browser so that the user can use SaaS service C through the local browser.
[0068] Based on this implementation, the identity transfer between the local browser and the cloud browser can be achieved without intrusion. When the user accesses multiple SaaS services that are docked with the same IDP across the local browser and the cloud browser, there is no need to log in again for identity authentication, improving the access efficiency of the cloud browser.
[0069] Figure 5 is a flowchart of a cloud browser access method provided by an exemplary embodiment of the present application. When this method is executed on the terminal device side, it may include steps as Figure 5 shown:
[0070] Step 501: In response to a user's access request for the first service, obtain the user's login information from a specified storage path.
[0071] Step 502: Send the access request and the user's login information to the cloud server, so that the cloud server schedules the cloud browser to access the first service and uses the first service to perform access authentication on the login information.
[0072] Step 503: Receive and display the video stream returned by the cloud server according to the access result of the first service.
[0073] Optionally, the user's login information includes: preset login information for logging in to the cloud browser; and / or, login information provided by the user when initiating an access request for the second service; the second service and the first service use the same authentication server for access authentication.
[0074] Optionally, in response to the user's access request for the first service, obtaining the user's login information from a specified storage path includes: in response to the user's access request for the first service, determining the target storage path corresponding to the first service from at least one storage path; where the login information stored in different storage paths is different; obtaining the user's login information from the target storage path.
[0075] Optionally, before obtaining the user's login information from a specified storage path in response to the user's access request for the first service, it further includes: in response to the user's access request for the second service, displaying the login page of the authentication server; obtaining the login information provided by the user on the login page; sending an access request to the server of the second service and sending the login information to the server of the second service, so that the server of the second service calls the authentication server to perform login authentication on the login information; if the login information passes the login authentication, receiving the access result of the second service returned by the server of the second service and saving the login information in the specified storage path locally.
[0076] In this embodiment, when the local browser of the terminal device receives a service access request, if the service needs to be accessed through a cloud browser, the terminal device can obtain the user's login information from a specified storage path and send the access request and the user's login information to the cloud server. The cloud server can schedule the cloud browser to execute the access request of the service and use the service to perform access authentication on the login information. The cloud server can obtain the access result returned by the service after the login information passes the authentication and return the access result to the terminal device in the form of a video stream. Furthermore, the transfer of the login information between the local browser and the cloud browser is realized without the user's awareness, and then the login to the cloud browser is realized without the user manually entering the login information. Thus, when accessing different applications / services across the local browser and the cloud browser, the operation complexity of login authentication is reduced and the access efficiency is improved.
[0077] Figure 6 FIG. 4 is a schematic flowchart of a cloud browser access method provided by an exemplary embodiment of the present application. When the method is executed on the cloud server side, it may include the steps as Figure 6 shown:
[0078] Step 601, receive an access request for a first service and the user's login information sent by the terminal device; the user's login information is obtained by the local browser of the terminal device from a specified storage path.
[0079] Step 602, schedule the cloud browser to access the first service and use the first service to perform access authentication on the login information.
[0080] Step 603, obtain the access result returned by the first service after the login information passes the access authentication.
[0081] Step 604, send the video stream of the access result to the terminal device for display.
[0082] Optionally, the user's login information includes: identity information provided by the user when initiating an access request for a second service, and the second service uses an authentication server for access authentication; and / or, a login token obtained by the terminal device from the authentication server according to the access request; correspondingly, scheduling the cloud browser to access the first service and using the first service to perform access authentication on the login information includes: determining a target cloud browser for accessing the first service; using the target cloud browser to access the first service and sending the login information to the first service, so that the first service calls the authentication server to perform access authentication on the login information.
[0083] In this embodiment, when the local browser of the terminal device receives a service access request, if the service needs to be accessed through the cloud browser, the terminal device can obtain the user's login information from the specified storage path and send the access request and the user's login information to the cloud server. The cloud server can schedule the cloud browser to execute the access request of the service and use the service to perform access authentication on the login information. The cloud server can obtain the access result returned by the service after the login information is authenticated and return the access result to the terminal device in the form of a video stream. Furthermore, the transfer of the login information between the local browser and the cloud browser is realized without the user's awareness, and then the login to the cloud browser is realized without the user manually inputting the login information. Thus, when accessing different applications / services across the local browser and the cloud browser, the operation complexity of login authentication is reduced and the access efficiency is improved.
[0084] It should be noted that the execution entity of each step of the method provided in the above embodiment can be the same device, or the method can also be executed by different devices as the execution entity. For example, the execution entity of steps 601 to 604 can be device A; for another example, the execution entity of steps 601 and 602 can be device A, and the execution entity of step 603 can be device B; and so on.
[0085] In addition, in some of the processes described in the above embodiments and the accompanying drawings, there are multiple operations that appear in a specific order. However, it should be clearly understood that these operations can be executed not in the order in which they appear in this article or in parallel. The operation numbers such as 601 and 602 are only used to distinguish different operations, and the numbers themselves do not represent any execution order. In addition, these processes can include more or fewer operations, and these operations can be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this article are used to distinguish different messages, devices, modules, etc., and do not represent a sequence, nor do they limit that "first" and "second" are of different types.
[0086] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties. And the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or refuse.
[0087] Figure 7 Schematically shows the structural diagram of the terminal device provided by an exemplary embodiment of the present application, as Figure 7As shown, the terminal device includes: a memory 701, a processor 702, a communication component 703, and a display component 704.
[0088] The memory 701 is used to store computer programs and can be configured to store various other data to support operations on the terminal device. Examples of such data include instructions for any application or method for operating on the terminal device.
[0089] The processor 702 is coupled to the memory 701 and is used to execute the computer program in the memory 701 for: in response to a user's access request for a first service, obtaining the user's login information from a specified storage path; sending the access request and the user's login information to a cloud server through the communication component 703, so that the cloud server schedules a cloud browser to access the first service and uses the first service to perform access authentication on the login information; receiving, through the communication component 703, a video stream returned by the cloud server according to the access result of the first service, and displaying the video stream through the display component 704.
[0090] Optionally, when the processor 702 obtains the user's login information from a specified storage path in response to the user's access request for the first service, it is specifically used for: in response to the user's access request for the first service, determining a target storage path corresponding to the first service from at least one storage path; where the login information stored in different storage paths is different; obtaining the user's login information from the target storage path.
[0091] Optionally, the user's login information includes: preset identity information for logging in to the cloud browser; and / or identity information provided by the user when initiating an access request for a second service; the second service and the first service use the same authentication server for access authentication; and / or a login token obtained from the authentication server according to the access request.
[0092] Optionally, before the processor 702 obtains the user's login information from a specified storage path in response to the user's access request for the first service, it is further used for: in response to the user's access request for the second service, displaying a login page of the authentication server; obtaining the identity information provided by the user on the login page; sending an access request to the server of the second service and sending the identity information to the server of the second service, so that the server of the second service calls the authentication server to perform login authentication on the identity information; if the identity information passes the login authentication, receiving the access result of the second service returned by the server of the second service and saving the identity information in a specified storage path locally.
[0093] Furthermore, asFigure 7 As shown, the server further includes other components such as a power supply component 705 and an audio component 706. Figure 7 Only some components are schematically shown, which does not mean that the terminal device only includes Figure 7 the components shown.
[0094] Among them, the display component 704 includes a screen, and the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from users. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can not only sense the boundaries of touch or swipe actions, but also detect the duration and pressure associated with the touch or swipe operations.
[0095] The audio component 705 can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC). When the device where the audio component is located is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode, the microphone is configured to receive external audio signals. The received audio signals can be further stored in the memory or sent via the communication component. In some embodiments, the audio component further includes a speaker for outputting audio signals.
[0096] Figure 8 Schematically shows a schematic structural diagram of a server provided by an exemplary embodiment of the present application. As Figure 8 shown, the server includes: a memory 801, a processor 802, and a communication component 803.
[0097] The memory 801 is used to store computer programs and can be configured to store various other data to support operations on the server. Examples of these data include instructions for any application or method operating on the server.
[0098] The processor 802 is coupled to the memory 801 and is used to execute the computer programs in the memory 801 for: receiving, through the communication component 803, an access request for a first service sent by the terminal device and the user's login information; the user's login information is obtained by the local browser of the terminal device from a specified storage path; scheduling the cloud browser to access the first service and using the first service to perform access authentication on the login information; obtaining the access result returned by the first service after the login information passes the access authentication; and sending, through the communication component 803, the video stream of the access result to the terminal device for display.
[0099] Optionally, the user's login information includes: the login information provided by the user when initiating an access request for a second service, and the second service uses an authentication server for access authentication; and / or, the login token obtained by the terminal device from the authentication server according to the access request; correspondingly, scheduling the cloud browser to access the first service and using the first service to perform access authentication on the login information includes: determining the target cloud browser for accessing the first service; using the target cloud browser to access the first service, and sending the login information to the first service, so that the first service invokes the authentication server to perform access authentication on the login information.
[0100] Further, as Figure 8 shown, the server further includes other components such as a power supply component 804. Figure 8 Only some components are schematically shown, which does not mean that the server only includes Figure 8 the components shown.
[0101] In this embodiment, when the local browser of the terminal device receives an access request for a certain service, if the service needs to be accessed through a cloud browser, the terminal device can obtain the user's login information from a specified storage path, and send the access request and the user's login information to the cloud server. The cloud server can schedule the cloud browser to execute the access request for the service and use the service to perform access authentication on the login information. The cloud server can obtain the access result returned by the service after the login information passes the authentication, and return the access result to the terminal device in the form of a video stream. Furthermore, the transfer of the login information between the local browser and the cloud browser is realized without the user's awareness, and then the login of the cloud browser is realized without the user manually inputting the login information. Thus, when accessing different applications / services across the local browser and the cloud browser, the operation complexity of login authentication is reduced, and the access efficiency is improved.
[0102] In Figure 7 and Figure 8In this case, the memory may be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc.
[0103] In Figure 7 and Figure 8 In this case, the communication component is configured to facilitate communication, either wired or wirelessly, between the device in which the communication component is located and other devices. The device in which the communication component is located may access a wireless network based on a communication standard, such as Wi-Fi (Wireless Fidelity), 2G (such as Global System for Mobile Communications (GSM), etc.), 3G (such as Wideband Code Division Multiple Access (WCDMA)), 4G (such as Long Term Evolution (LTE), etc.), 4G+ (such as LTE-Advanced (LTE-A), etc.) or 5G (5th Generation Mobile Communication Technology), or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component may be implemented based on Near Field Communication (NFC) technology, Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wide Band (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0104] In Figure 7 and Figure 8Among them, a power supply component is used to provide power for various components of the device where the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the device where the power supply component is located.
[0105] Correspondingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, and when the computer program is executed, it can implement each step executable by the terminal device in the above method embodiment.
[0106] Correspondingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, and when the computer program is executed, it can implement each step executable by the server in the above method embodiment.
[0107] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM (Compact Disc Read-Only Memory), optical storage, etc.) containing computer-usable program code.
[0108] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified function in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0109] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the specified function in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0110] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide for implementing the process Figure 1 one process or multiple processes and / or blocks Figure 1 steps for the functions specified in one block or multiple blocks.
[0111] In a typical configuration, a computing device includes one or more processors (Central Processing Unit, CPU), an input / output interface, a network interface, and memory.
[0112] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0113] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (Parallel Random Access Machine, PRAM), static random access memory (SRAM), dynamic random access memory (Dynamic Random Access Memory, DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (Digital Video Disc, DVD) or other optical storage, magnetic cassette tapes, disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0114] It should also be noted that the term "comprise", "include" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising said element.
[0115] The above are only examples of the present application and are not intended to limit the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A method for accessing a cloud browser, characterized in that Including: In response to a user's access request for a second service, display the login page of the authentication server; Obtain the identity information provided by the user on the login page; Send an access request to the server of the second service and send the identity information to the server of the second service, so that the server of the second service calls the authentication server to perform login authentication on the identity information; If the identity information passes the login authentication, receive the access result of the second service returned by the server of the second service, and save the identity information as the user's login information in a specified storage path locally; In response to a user's access request for a first service, obtain the user's login information from the specified storage path; Send the access request and the user's login information to the cloud server, so that the cloud server schedules the cloud browser to access the first service and uses the first service to perform access authentication on the login information; the user's login information includes the identity information provided when the user initiates an access request for the second service; The second service and the first service use the same authentication server for access authentication; Receive and display the video stream returned by the cloud server according to the access result of the first service.
2. The method according to claim 1, characterized in that, In response to a user's access request for a first service, obtaining the user's login information from the specified storage path includes: In response to a user's access request for a first service, determine the target storage path corresponding to the first service from at least one storage path; wherein, the login information stored in different storage paths is different; Obtain the user's login information from the target storage path.
3. A method for accessing a cloud browser, characterized in that Receive the access request of the second service and the user's identity information sent by the terminal device, and use the authentication server to perform login authentication on the identity information; If the identity information passes the login authentication, return the access result of the second service to the terminal device; Receive the access request for the first service and the user's login information sent by the terminal device; The user's login information is obtained by the local browser of the terminal device from the specified storage path; the user's login information includes the identity information provided when the user initiates an access request for the second service; The second service and the first service use the same authentication server for access authentication; Schedule the cloud browser to access the first service and use the first service to perform access authentication on the login information; Obtain the access result returned by the first service after the login information passes the access authentication; Send the video stream of the access result to the terminal device for display.
4. The method according to claim 3, characterized in that, The scheduling the cloud browser to access the first service and using the first service to perform access authentication on the login information includes: Determine the target cloud browser for accessing the first service; Use the target cloud browser to access the first service and send the login information to the first service, so that the first service calls the authentication server to perform access authentication on the login information.
5. A terminal device, characterized in that, A memory, a processor, a display component, and a communication component; The memory is configured to store one or more computer instructions; The processor is configured to execute the one or more computer instructions for: invoking the display component and the communication component, and executing the steps in the method according to claim 1 or 2.
6. A server, characterized in that, Comprising: A memory and a processor; The memory is configured to store one or more computer instructions; The processor is configured to execute the one or more computer instructions for: executing the steps in the method according to claim 3 or 4.
7. A cloud browser access system, characterized in that, Comprising: A terminal device, a cloud server, and an authentication server; Wherein, the terminal device is configured to respond to a user's access request for a second service, and display a login page of the authentication server; Obtain the identity information provided by the user on the login page; Send an access request to the server of the second service, and send the identity information to the server of the second service, so that the server of the second service invokes the authentication server to perform a login authentication on the identity information; If the identity information passes the login authentication, receive the access result of the second service returned by the server of the second service, and save the identity information as the user's login information in a specified storage path locally; Respond to the user's access request for a first service, and obtain the user's login information from the specified storage path; Send the access request and the user's login information to the cloud server, so that the cloud server schedules a cloud browser to access the first service and uses the first service to perform an access authentication on the login information; the user's login information includes the identity information provided by the user when initiating an access request for the second service; the second service and the first service use the same authentication server for access authentication; receive and display the video stream returned by the cloud server according to the access result of the first service; The cloud server is configured to receive the access request for the second service and the user's identity information sent by the terminal device, and use the authentication server to perform a login authentication on the identity information; If the identity information passes the login authentication, return the access result of the second service to the terminal device; Receive the access request for the first service and the user's login information sent by the terminal device; the user's login information is obtained by the local browser of the terminal device from the specified storage path; the user's login information includes the identity information provided by the user when initiating an access request for the second service; the second service and the first service use the same authentication server for access authentication; Schedule a cloud browser to access the first service and use the first service to perform an access authentication on the login information; Obtain the access result returned by the first service after the login information passes the access authentication; Send the video stream of the access result to the terminal device for display.
8. A computer-readable storage medium storing a computer program, characterized in that, When executed by a processor, the computer program can implement the cloud browser access method according to any one of claims 1-4.
Citation Information
Patent Citations
Information processing method and device
CN108289101A
Multi-cloud deployment authentication method and system
CN114386009A
Access method and system, computing device and computer storage medium
CN115834700A