A cloud desktop terminal management system
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN UNITED INFORMATION TECH CO LTD
- Filing Date
- 2023-05-16
- Publication Date
- 2026-05-26
AI Technical Summary
[0038] When obtaining cloud desktop terminal permissions, this invention determines whether the cloud desktop terminal status meets the requirements based on the standards corresponding to the requesting user. It can judge whether the request status is abnormal based on the conditions of the cloud desktop terminal, thereby adaptively improving the accuracy of network security judgment for the requesting user.
Smart Images

Figure CN116582536B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cloud desktop technology, specifically to a cloud desktop terminal management system. Background Technology
[0002] A cloud terminal typically refers to a terminal device using cloud desktop technology. It connects to the system desktop in the cloud via a specific communication protocol and displays the data on the cloud desktop terminal, redirecting the input and output data of the cloud terminal to the cloud server.
[0003] Cloud terminals need to connect to cloud servers via communication protocols to present the cloud system to the front end. During this process, data transmission is involved. To ensure data security during data transmission, most existing cloud desktop terminal management systems detect the network environment and ensure that information is stored and retrieved securely in a secure transmission environment.
[0004] Because cloud terminals operate in different environments, a unified cloud desktop terminal management system is needed to assess the security of the environment in which cloud terminal users operate. Summary of the Invention
[0005] The purpose of this invention is to provide a remote data security storage method to solve the following technical problems:
[0006] How to adaptively improve the accuracy of network security judgments for requesting users.
[0007] The objective of this invention can be achieved through the following technical solutions:
[0008] A cloud desktop terminal management system, the system comprising:
[0009] Cloud servers are used to store data in the cloud.
[0010] The cloud desktop terminal is used to send requests to the management terminal, obtain information from the management terminal, and determine the status of the cloud server based on the information from the management terminal.
[0011] When the cloud server status meets the requirements, a key is sent to the management terminal according to the key request instruction.
[0012] The management side is used to encrypt all remote desktop data using a key encryption algorithm, send the key to the cloud desktop terminal, and determine the cloud desktop terminal's permissions and status by comparing the cloud desktop terminal's request information with the standard corresponding to the requesting user.
[0013] When the cloud desktop terminal permissions and cloud desktop terminal status meet the requirements, the management terminal sends a key request instruction to the cloud desktop terminal.
[0014] As a further description of the present invention, the method of using the management system includes:
[0015] S100: All remote desktop data is encrypted using a key encryption algorithm, and the key is sent to the cloud desktop terminal.
[0016] S200: Send a request message to the management terminal via the cloud desktop terminal. The management terminal determines the cloud desktop terminal's permissions and status by comparing the request message with the criteria corresponding to the requesting user.
[0017] When the cloud desktop terminal permissions and cloud desktop terminal status meet the requirements, the management terminal sends a key request instruction to the cloud desktop terminal.
[0018] The S300 and cloud desktop terminal obtain information from the management terminal and determine the database status based on this information.
[0019] When the database status meets the requirements, a key is sent to the management terminal according to the key request instruction.
[0020] As a further description of the present invention, the request information includes authorization authentication information and cloud desktop terminal network information;
[0021] The cloud desktop terminal network information includes the cloud desktop terminal IP, cloud desktop terminal DNS, and whether a proxy server is used.
[0022] Determine the permissions of the cloud desktop terminal based on the permission authentication information. When the permissions of the cloud desktop terminal are qualified, obtain the historical request information corresponding to the cloud desktop terminal user.
[0023] The historical request information includes the cloud desktop terminal IP, cloud desktop terminal DNS, and whether the cloud desktop terminal uses a proxy server.
[0024] Determine the status of the cloud desktop terminal based on the network information and cloud desktop terminal information.
[0025] As a further description of the present invention, the process of determining the state of the cloud desktop terminal is as follows:
[0026] The stability value Q of the cloud desktop terminal is calculated using the formula Q = α1*P1 + α2*P2 + α3*P3.
[0027] Where, when i=1, α1 is the IP weight coefficient, P1 is the IP coefficient, when the cloud desktop terminal IP is the same as the previous cloud desktop terminal IP, P1=0; when the cloud desktop terminal IP is different from the previous cloud desktop terminal IP but appears in the historical cloud desktop terminal IP, P1=0.5; when the cloud desktop terminal IP appears for the first time, P1=1.
[0028] When i = 2, α2 is the DNS weight coefficient, and P2 is the DNS coefficient. When the DNS of the requesting party is the same as the DNS of the previous requesting party, P2 = 0; when the DNS of the requesting party is different from the DNS of the previous requesting party but appears in the historical DNS of the requesting party, P2 = 0.5; when the DNS of the requesting party appears for the first time, P2 = 1.
[0029] When i = 3, μ3 is the server weight coefficient and A3 is the proxy server coefficient. When no proxy server is used, P3 = 0, and when a proxy server is used, P3 = 1.
[0030] The stability value Q of the cloud desktop terminal is compared with the reference threshold Q1 corresponding to the cloud desktop terminal user:
[0031] If Q≥Q1, then the cloud desktop terminal is judged to be in an abnormal state;
[0032] Otherwise, determine that the cloud desktop terminal is in normal status;
[0033] The reference threshold Q1 is determined based on historical request information.
[0034] As a further description of the present invention, the method for determining the reference threshold Q1 is as follows:
[0035] Through formula Calculate the reference threshold P th ;
[0036] Where n is the number of times a user makes a request within a specific time period; j1 is the number of different types of IPs requested within a specific time period; j2 is the number of different IPs requested within a specific time period compared to the previous request; k1 is the number of different types of DNS requests requested within a specific time period; k2 is the number of different DNS requests requested within a specific time period compared to the previous request; l1 is the number of times a proxy server is used within a specific time period; β1, β2, and β3 are preset ratio coefficients.
[0037] The beneficial effects of this invention are:
[0038] When obtaining cloud desktop terminal permissions, this invention determines whether the cloud desktop terminal status meets the requirements based on the standards corresponding to the requesting user. It can judge whether the request status is abnormal based on the conditions of the cloud desktop terminal, thereby adaptively improving the accuracy of network security judgment for the requesting user. Attached Figure Description
[0039] The invention will now be further described with reference to the accompanying drawings.
[0040] Figure 1 This is a schematic diagram of the cloud desktop terminal management system of the present invention. Detailed Implementation
[0041] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0042] Please see Figure 1 As shown, a cloud desktop terminal management system is provided, the system comprising:
[0043] Cloud servers are used to store data in the cloud.
[0044] The cloud desktop terminal is used to send requests to the management terminal, obtain information from the management terminal, and determine the status of the cloud server based on the information from the management terminal.
[0045] When the cloud server status meets the requirements, a key is sent to the management terminal according to the key request instruction.
[0046] The management side is used to encrypt all remote desktop data using a key encryption algorithm, send the key to the cloud desktop terminal, and determine the cloud desktop terminal's permissions and status by comparing the cloud desktop terminal's request information with the standard corresponding to the requesting user.
[0047] When the cloud desktop terminal permissions and cloud desktop terminal status meet the requirements, the management terminal sends a key request instruction to the cloud desktop terminal.
[0048] Through the above technical solution, when obtaining cloud server terminal permissions, the system judges whether the cloud server terminal status meets the requirements according to the corresponding standards. It can judge whether the status of the cloud server terminal is abnormal based on the conditions it is in, thereby adaptively improving the accuracy of network security judgment of cloud server terminals.
[0049] As a further description of the present invention, the method of using the management system includes:
[0050] S100: All remote desktop data is encrypted using a key encryption algorithm, and the key is sent to the cloud desktop terminal.
[0051] S200: Send a request message to the management terminal via the cloud desktop terminal. The management terminal determines the cloud desktop terminal's permissions and status by comparing the request message with the criteria corresponding to the requesting user.
[0052] When the cloud desktop terminal permissions and cloud desktop terminal status meet the requirements, the management terminal sends a key request instruction to the cloud desktop terminal.
[0053] The S300 and cloud desktop terminal obtain information from the management terminal and determine the database status based on this information.
[0054] When the database status meets the requirements, a key is sent to the management terminal according to the key request instruction.
[0055] As a further description of the present invention, the request information includes authorization authentication information and cloud desktop terminal network information;
[0056] The cloud desktop terminal network information includes the cloud desktop terminal IP, cloud desktop terminal DNS, and whether a proxy server is used.
[0057] Determine the permissions of the cloud desktop terminal based on the permission authentication information. When the permissions of the cloud desktop terminal are qualified, obtain the historical request information corresponding to the cloud desktop terminal user.
[0058] The historical request information includes the cloud desktop terminal IP, cloud desktop terminal DNS, and whether the cloud desktop terminal uses a proxy server.
[0059] Determine the status of the cloud desktop terminal based on the network information and cloud desktop terminal information.
[0060] Through the above technical solution, this embodiment of the invention determines the security of a cloud desktop terminal based on its IP address, DNS, and whether a proxy server is used. Significant changes in the IP address and DNS indicate poor network stability. Using a proxy server also affects network security. The IP address, DNS, and proxy server usage information can be directly obtained from the cloud desktop terminal's network information. Furthermore, by obtaining the user's historical IP address, DNS, and proxy server usage information, corresponding standards can be determined based on the user's historical information. Through information acquisition and comparison, the system can determine whether the cloud desktop terminal's status meets the requirements.
[0061] As a further description of the present invention, the process of determining the state of the cloud desktop terminal is as follows:
[0062] The stability value Q of the cloud desktop terminal is calculated using the formula Q = α1*P1 + α2*P2 + α3*P3.
[0063] Where, when i=1, α1 is the IP weight coefficient, P1 is the IP coefficient, when the cloud desktop terminal IP is the same as the previous cloud desktop terminal IP, P1=0; when the cloud desktop terminal IP is different from the previous cloud desktop terminal IP but appears in the historical cloud desktop terminal IP, P1=0.5; when the cloud desktop terminal IP appears for the first time, P1=1.
[0064] When i = 2, α2 is the DNS weight coefficient, and P2 is the DNS coefficient. When the DNS of the requesting party is the same as the DNS of the previous requesting party, P2 = 0; when the DNS of the requesting party is different from the DNS of the previous requesting party but appears in the historical DNS of the requesting party, P2 = 0.5; when the DNS of the requesting party appears for the first time, P2 = 1.
[0065] When i = 3, μ3 is the server weight coefficient and A3 is the proxy server coefficient. When no proxy server is used, P3 = 0, and when a proxy server is used, P3 = 1.
[0066] The stability value Q of the cloud desktop terminal is compared with the reference threshold Q1 corresponding to the cloud desktop terminal user:
[0067] If Q≥Q1, then the cloud desktop terminal is judged to be in an abnormal state;
[0068] Otherwise, determine that the cloud desktop terminal is in normal status;
[0069] The reference threshold Q1 is determined based on historical request information.
[0070] As a further description of the present invention, the method for determining the reference threshold Q1 is as follows:
[0071] Through formula Calculate the reference threshold P th ;
[0072] Where n is the number of times a user makes a request within a specific time period; j1 is the number of different types of IPs requested within a specific time period; j2 is the number of different IPs requested within a specific time period compared to the previous request; k1 is the number of different types of DNS requests requested within a specific time period; k2 is the number of different DNS requests requested within a specific time period compared to the previous request; l1 is the number of times a proxy server is used within a specific time period; β1, β2, and β3 are preset ratio coefficients.
[0073] Through the above technical solution, this embodiment of the invention provides a method for determining the status of a cloud desktop terminal. Specifically, the method determines the status based on whether the cloud desktop terminal's IP address and DNS are the same as before, whether they appear for the first time, and whether a proxy server is used. Specifically, when a user requests a new cloud desktop terminal IP address and DNS for the first time, it indicates that the network status has changed, thus indicating poor security. Similarly, using a proxy server also indicates poor security for the cloud desktop terminal. Therefore, the stability value Q of the cloud desktop terminal is calculated using the formula Q = α1*P1 + α2*P2 + α3*P3, thereby determining the stability of the cloud desktop terminal's network status. Furthermore, by comparing the stability value Q with a reference threshold Q1, which is determined based on historical request information, the method can adaptively determine whether the status of the cloud desktop terminal is normal based on different cloud desktop terminal statuses.
[0074] The foregoing has provided a detailed description of one embodiment of the present invention, but this description is merely a preferred embodiment and should not be construed as limiting the scope of the invention. All equivalent variations and modifications made within the scope of the claims of this invention should still fall within the patent coverage of this invention.
Claims
1. A cloud desktop terminal management system, characterized in that, The system includes: Cloud servers are used to store data in the cloud. The cloud desktop terminal is used to send requests to the management terminal, obtain information from the management terminal, and determine the status of the cloud server based on the information from the management terminal. When the cloud server status meets the requirements, a key is sent to the management terminal according to the key request instruction. The management side is used to encrypt all remote desktop data using a key encryption algorithm, send the key to the cloud desktop terminal, and determine the cloud desktop terminal's permissions and status by comparing the cloud desktop terminal's request information with the standard corresponding to the requesting user. When the cloud desktop terminal permissions and cloud desktop terminal status meet the requirements, the management terminal sends a key request instruction to the cloud desktop terminal. The method of using the management system includes: S100: All remote desktop data is encrypted using a key encryption algorithm, and the key is sent to the cloud desktop terminal. S200: Send a request message to the management terminal via the cloud desktop terminal. The management terminal determines the cloud desktop terminal's permissions and status by comparing the request message with the criteria corresponding to the requesting user. When the cloud desktop terminal permissions and cloud desktop terminal status meet the requirements, the management terminal sends a key request instruction to the cloud desktop terminal. The S300 and cloud desktop terminal obtain information from the management terminal and determine the database status based on this information. When the database status meets the requirements, a key is sent to the management terminal according to the key request instruction; The request information includes authorization authentication information and cloud desktop terminal network information; The cloud desktop terminal network information includes the cloud desktop terminal IP, cloud desktop terminal DNS, and whether a proxy server is used. Determine the permissions of the cloud desktop terminal based on the permission authentication information. When the permissions of the cloud desktop terminal are qualified, obtain the historical request information corresponding to the cloud desktop terminal user. The historical request information includes the cloud desktop terminal IP, cloud desktop terminal DNS, and whether the cloud desktop terminal uses a proxy server. Determine the status of the cloud desktop terminal based on the cloud desktop terminal network information and cloud desktop terminal information; The process for determining the status of the cloud desktop terminal is as follows: Through formula Calculate the stability value Q of the cloud desktop terminal; Where, when i=1, This is the IP weighting coefficient. This is the IP coefficient; when the cloud desktop terminal IP is the same as the previous cloud desktop terminal IP, =0; When the cloud desktop terminal IP is different from the previous cloud desktop terminal IP but appears in the historical cloud desktop terminal IP list. =0.5; When the cloud desktop terminal IP first appears, =1; When i=2 This is the DNS weighting coefficient. This is the DNS coefficient, which is used when the DNS of the requesting end is the same as the DNS of the previous requesting end. =0; when the requesting DNS is different from the previous requesting DNS but appears in the historical requesting DNS. =0.5; When the requesting DNS first appears, =1; When i=3 This is the server weight coefficient. This is the proxy server factor; when no proxy server is used, =0, when using a proxy server =1; By comparing the stable value Q of the cloud desktop terminal with the reference threshold corresponding to the cloud desktop terminal user. Compare: If Q≥ If so, the cloud desktop terminal is judged to be in an abnormal state; Otherwise, determine that the cloud desktop terminal is in normal status; The reference threshold Determined based on historical request information; The reference threshold The method for determining it is as follows: Through formula Calculate the reference threshold ; in, The number of requests made by a user within a specific time period; The number of different types of IP addresses requesting within a specific time period. The number of requesting IPs that are different from the previous request within a specific time period; The number of different types of DNS requests within a specific time period. The number of DNS requests that differ from the previous request within a specific time period; The number of times the proxy server was used within a specific time period; , and This is the preset scaling factor.