A relay control system, method and device for cross-network remote desktop access
By setting up a relay control system between high and low security levels networks, physical isolation and strict inspection of data are achieved, the problem of lack of control at the network level in the prior art is solved, ensuring the secure transmission of data and the high security of the system.
Patent Information
- Application Number
- CN202411755254.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-03
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-12-03
AI Technical Summary
The lack of control at the network level of existing VPN and remote desktop technologies makes it difficult to effectively control the transmission of sensitive data to low-security networks, increasing resource overhead and risk of vulnerability.
The relay control system adopts a cross-network remote desktop access, and by setting up cloud desktop client, proxy server, proxy client and one-way export/import module between high-security and low-security networks, physical isolation and strict inspection of data format/content are realized to ensure the secure transmission of data.
It realizes secure access to remote desktop services of high-security-level networks with low-security-level networks, prevents illegal data transmission, reduces the risk of network attacks, and ensures data integrity and security through hardware-level detection.
Smart Images

Figure CN119254532B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing, and more particularly to a relay control system, method and device for cross-network remote desktop access. Background Art
[0002] As the process of informatization accelerates, units have increasing requirements for network data security and convenience. When the work intranet needs to access the Internet, VPN technology is often used to build a bridge, build a secure and private channel, simulate the LAN environment, and protect data from eavesdropping and tampering. VPN uses tunnel encryption to protect the privacy and integrity of data and prevent man-in-the-middle attacks and eavesdropping.
[0003] By configuring a VPN connection, intranet users can easily access Internet resources and perform file transfers and remote operations. In addition to VPN, remote operations can also be achieved through remote desktop, HTTP, FTP / SFTP and other protocols, and users can freely upload and download files. In particular, RDP and VNC technologies, combined with VPN, can achieve remote desktop connection to computers on the Internet or work intranet, and copy files to this computer in the remote desktop session. These methods provide feasible solutions for cross-network remote desktop connections.
[0004] However, the potential problem with VPN-based and VPN-based remote desktop technology solutions is that the network layer and physical link layer are connected, and data can be transmitted bidirectionally without any control. If the work intranet sends data to the Internet, the data contains work secret data that should not be sent out, and additional technical means are needed to detect and block the data in order to achieve control of outbound data, which increases the resource overhead of the terminal computer and is prone to the risk of bypassing detection vulnerabilities. Summary of the invention
[0005] In view of the problems existing in the prior art, the purpose of the present invention is to provide a relay control system, method and device for cross-network remote desktop access, which realizes the remote desktop service of a high-security level network accessing a low-security level network in a physically isolated network, and can perform strict data format and content checks on data entering and leaving the network, thereby effectively preventing the transmission of illegal data.
[0006] In order to achieve the above object, the present invention is implemented through the following technical solutions:
[0007] A relay control system for cross-network remote desktop access, comprising: a cloud desktop client and a cloud desktop proxy server arranged in a high-security network, a cloud desktop proxy client and a cloud desktop server arranged in a low-security network, and a one-way export module and a one-way import module;
[0008] The cloud desktop proxy server is respectively connected with the cloud desktop client, the one-way export module and the one-way import module for data connection, and the cloud desktop proxy client is respectively connected with the cloud desktop server, the one-way export module and the one-way import module for data connection;
[0009] The cloud desktop client is used to authenticate and communicate with the cloud desktop proxy server, send cloud desktop control data and keyboard and mouse data to the cloud desktop proxy server, and receive cloud desktop control data and image data returned from the cloud desktop proxy server;
[0010] The cloud desktop proxy server is used to extract cloud desktop control data and keyboard and mouse data, filter and encapsulate them, and then send them to the one-way export module; it is also used to receive the encapsulated data sent by the one-way import module, unpack them, and then send them to the cloud desktop client;
[0011] The one-way export module is used to receive the encapsulated data sent by the cloud desktop proxy server, and after detection, send the cloud desktop control data and keyboard and mouse data therein to the cloud desktop proxy client;
[0012] The one-way import module is used to receive the encapsulated data sent by the cloud desktop agent client, and after detection, send the cloud desktop control data and image data therein to the cloud desktop agent server;
[0013] The cloud desktop proxy client is used to receive the cloud desktop control data and keyboard and mouse data sent by the one-way export module, encapsulate them into remote protocol data and send them to the cloud desktop server, and receive the image data of the cloud desktop control data sent by the cloud desktop server, filter and encapsulate them, and then send them to the one-way import module;
[0014] The cloud desktop server is used to receive the cloud desktop control data and keyboard and mouse data sent by the cloud desktop proxy client, generate the cloud desktop control data and image data and return them to the cloud desktop proxy client.
[0015] Furthermore, the cloud desktop client has a built-in tool for remotely accessing the cloud desktop, and the tool for remotely accessing the cloud desktop supports RDP, VNC or SPICE protocol.
[0016] Furthermore, the cloud desktop proxy client is specifically used for:
[0017] Receive the cloud desktop control data and image data sent by the cloud desktop server, extract the application layer data, perform remote protocol capability tailoring on the control data, clean or transcode the image data, encapsulate it and send it to the one-way import module.
[0018] Correspondingly, the present invention also discloses a relay control method for cross-network remote desktop access, comprising:
[0019] By executing the cloud desktop access authentication process, multiple authentication, protocol conversion and security checks are performed between the cloud desktop client and the cloud desktop server to establish two-way communication;
[0020] By executing the cloud desktop interactive operation process, the cloud desktop keyboard and mouse data of the cloud desktop client is transmitted to the cloud desktop server, and the cloud desktop image data generated by the cloud desktop server is returned to the cloud desktop client.
[0021] Furthermore, the cloud desktop access authentication process includes the following steps:
[0022] S101: Initiate a local access authentication request to the cloud desktop proxy server through the cloud desktop client;
[0023] S102: Performing local access authentication through the cloud desktop proxy server, and receiving a cloud desktop access authentication protocol sent by the cloud desktop client after the authentication is passed;
[0024] S103: Processing the cloud desktop access authentication protocol through the cloud desktop proxy server, extracting its application layer data, filtering the entrained data, transcoding and encapsulating it into an exportable format, generating encapsulation protocol data and sending it to the one-way export module;
[0025] S104: The one-way export module performs format and content legitimacy check of the encapsulated protocol data through the built-in FPGA, and sends the data to the cloud desktop proxy client after passing the check;
[0026] S105: The cloud desktop proxy client decapsulates the encapsulated protocol data into the cloud desktop access authentication protocol, encapsulates the data into the cloud desktop remote protocol, and sends the data to the cloud desktop server;
[0027] S106: The cloud desktop server performs access authentication according to the cloud desktop remote protocol and returns access authentication response data;
[0028] S107: The cloud desktop proxy client encapsulates the access authentication response data into an importable format, generates encapsulated response data and sends it to the one-way import module;
[0029] S108: The one-way import module performs format and content legitimacy check of the encapsulated return data through the built-in FPGA, and sends the data to the cloud desktop proxy server after passing the check;
[0030] S109: The cloud desktop proxy server restores the encapsulated return data to access authentication response data and sends it to the cloud desktop client;
[0031] S110: The cloud desktop client receives and processes the returned access authentication response data.
[0032] Further, step S104 is specifically as follows:
[0033] The sending end of the one-way export module sends the received encapsulation protocol data to the FPGA with built-in isolation transmission card to check the legality of the data format and content;
[0034] If the check fails, the data is discarded directly;
[0035] If the detection is successful, the encapsulation protocol data is sent to the receiving end of the unidirectional export module through the isolation transmission card;
[0036] The receiving end of the one-way export module forwards the encapsulated data to the cloud desktop proxy client.
[0037] Furthermore, the cloud desktop interactive operation process includes the following steps:
[0038] S201: Initiate local access authentication and cloud desktop access authentication to the cloud desktop proxy server through the cloud desktop client, and send cloud desktop keyboard and mouse operation data to the cloud desktop proxy server after the authentication is passed;
[0039] S202: Processing the cloud desktop keyboard and mouse operation data through the cloud desktop proxy server, extracting its application layer data, filtering the entrained data, transcoding and packaging it into an exportable format, and generating first packaged data to send to the one-way export module;
[0040] S203: The one-way export module performs a format and content legality check of the first packaged data through the built-in FPGA, and sends the first packaged data to the cloud desktop proxy client after the check passes;
[0041] S204: The cloud desktop proxy client decapsulates the first encapsulated data into cloud desktop keyboard and mouse operation data, encapsulates the data into corresponding cloud desktop remote protocol data, and sends the data to the cloud desktop server;
[0042] S205: The cloud desktop server receives the cloud desktop remote protocol data, processes it, and returns the cloud desktop image data;
[0043] S206: The cloud desktop proxy client encapsulates the cloud desktop image data into an importable format, generates second encapsulated data and sends it to the one-way import module;
[0044] S207: The one-way import module performs a format and content legality check of the second packaged data through the built-in FPGA, and sends the data to the cloud desktop proxy server after passing the check;
[0045] S208: The cloud desktop proxy server restores the second packaged data into cloud desktop image data, and sends the data to the cloud desktop client;
[0046] S209: The cloud desktop client receives the cloud desktop image data and renders the cloud desktop image data into a recognizable image.
[0047] Correspondingly, the present invention also discloses a relay control device for cross-network remote desktop access, comprising:
[0048] Memory for storing computer programs;
[0049] A processor is used to implement the relay control method steps for cross-network remote desktop access as described in any one of the above items when executing the computer program.
[0050] Compared with the prior art, the beneficial effects of the present invention are as follows: the present invention provides a relay control system, method and device for cross-network remote desktop access, adopts two single-guide systems to realize one-in and one-out, and uses hardware to control different data types entering and leaving the network respectively, thereby realizing the remote desktop service of a high-security level network accessing a low-security level network in a physically isolated network, performing strict data format and content checks on data entering and leaving the network, and adopting a whitelist mechanism to filter data, which can effectively prevent the transmission of illegal data.
[0051] The present invention utilizes the hardware-level FPGA programmable capability of the non-bypassable isolation transmission card to control the format and content of the transmitted data, thereby preventing the invalidation of data inspection caused by illegal tampering of the software.
[0052] The present invention connects two networks by adopting a single-conductor system, thereby achieving physical isolation of the two networks and reducing the risk of attacks or penetration at the network level.
[0053] The present invention extracts application layer data and strips off network protocols at layer 4 and below, thereby preventing the risk of network attacks at layer 4 and below.
[0054] The present invention effectively reduces the risk of harmful data entering the intranet through image data by video cleaning or transcoding.
[0055] It can be seen that compared with the prior art, the present invention has outstanding substantive features and significant progress, and the beneficial effects of its implementation are also obvious. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0057] Figure 1 It is a system structure diagram of a specific implementation mode of the present invention.
[0058] Figure 2 It is a method flow chart of a specific implementation mode of the present invention.
[0059] Figure 3 It is a schematic diagram of the cloud desktop access authentication process of a specific implementation mode of the present invention.
[0060] Figure 4 It is a schematic diagram of the cloud desktop interactive operation process of a specific implementation mode of the present invention.
[0061] In the figure, 1. Cloud desktop client; 2. Cloud desktop proxy server; 3. Cloud desktop proxy client; 4. Cloud desktop server; 5. One-way export module; 6. One-way import module. DETAILED DESCRIPTION
[0062] The specific implementation of the present invention is described below with reference to the accompanying drawings.
[0063] like Figure 1 As shown, the present invention discloses a relay control system for cross-network remote desktop access, including: a cloud desktop client 1 and a cloud desktop proxy server 2 set in a high-security network, a cloud desktop proxy client 3 and a cloud desktop server 4 set in a low-security network, and a one-way export module 5 and a one-way import module 6; the cloud desktop proxy server 2 is respectively connected to the cloud desktop client 1, the one-way export module 5 and the one-way import module 6, and the cloud desktop proxy client 3 is respectively connected to the cloud desktop server 4, the one-way export module 5 and the one-way import module 6. Among them, the one-way export module 5 and the one-way import module 6 are both network security isolation and information one-way import systems, using a "2+1" architecture (i.e., a sending end, a receiving end, and a one-way isolation transmission card), deployed between physically isolated networks of different security levels, to achieve one-way data flow without feedback.
[0064] The cloud desktop client 1 is used to authenticate and communicate with the cloud desktop proxy server 2, send cloud desktop control data and keyboard and mouse data to the cloud desktop proxy server 2, and receive cloud desktop control data and image data returned from the cloud desktop proxy server 2.
[0065] In a specific implementation, the cloud desktop client 1 is deployed on the terminal user, and provides software for remote access to the cloud desktop, which can be a cloud desktop remote client that supports various remote protocols such as RDP, VNC or SPICE. It is used to authenticate and communicate with the cloud desktop proxy server 2, send cloud desktop control data and keyboard and mouse data to the cloud desktop proxy server 2, and receive cloud desktop control data and image data returned from the cloud desktop proxy server 2.
[0066] The cloud desktop proxy server 2 is used to extract cloud desktop control data and keyboard and mouse data, filter and encapsulate them, and then send them to the one-way export module 5; it is also used to receive the encapsulated data sent by the one-way import module 6, unpack them, and then send them to the cloud desktop client 1.
[0067] In a specific implementation, the cloud desktop proxy server 2 provides the proxy function of the cloud desktop server, can extract cloud desktop control data and keyboard and mouse data, filter out various entrained data, and encapsulate them into data and content in the format required by the one-way export module 5, and can also perform local authentication on the connected cloud desktop client 1. At the same time, it receives the encapsulated data sent by the one-way import module 6, unpacks it into the remote protocol data required by the cloud desktop client 1, and sends it to the cloud desktop client 1.
[0068] The one-way export module 5 is used to receive the encapsulated data sent by the cloud desktop agent server 2, and after detection, send the cloud desktop control data and keyboard and mouse data therein to the cloud desktop agent client 3.
[0069] In a specific implementation, the one-way export module 5 provides a one-way data transmission service without feedback, as well as hardware-level data format and content detection capabilities to ensure that only cloud desktop control data and keyboard and mouse data can be released. Specifically, it is used to receive legal data encapsulated by the cloud desktop proxy server 2, and send the checked legal data to the cloud desktop proxy client 3.
[0070] The one-way import module 6 is used to receive the encapsulated data sent by the cloud desktop agent client 3, and after detection, send the cloud desktop control data and image data therein to the cloud desktop agent server 2.
[0071] In a specific implementation, the one-way import module 6 provides a one-way data transmission service without feedback, as well as hardware-level data format and content detection capabilities to ensure that only cloud desktop control data and image data can be released. Specifically, it is used to receive legal data encapsulated by the cloud desktop proxy client 3, and send the checked legal data to the cloud desktop proxy server 2.
[0072] The cloud desktop agent client 3 is used to receive the cloud desktop control data and keyboard and mouse data sent by the one-way export module 5, encapsulate them into remote protocol data and send them to the cloud desktop server 4, and receive the image data of the cloud desktop control data sent by the cloud desktop server 4, filter and encapsulate them, and then send them to the one-way import module 6.
[0073] In a specific implementation, the cloud desktop proxy client 3 provides the proxy function of the cloud desktop client, receives the cloud desktop control data and keyboard and mouse data that are encapsulated and legally sent by the one-way export module 5, and unpacks them into the remote protocol data required by the cloud desktop server 4, and sends them to the cloud desktop server 4. At the same time, it receives the control data and image data sent by the cloud desktop server 4, extracts the application layer data, performs remote protocol capability tailoring on the control data to remove high-risk transmission channels, cleans or transcodes the image data, and encapsulates them into data and content in the format required by the one-way import module 6.
[0074] The cloud desktop server 4 is used to receive the cloud desktop control data and keyboard and mouse data sent by the cloud desktop proxy client 3, generate cloud desktop control data and image data and return them to the cloud desktop proxy client 3.
[0075] In a specific implementation, the cloud desktop server 4 provides a cloud desktop virtualization service for remote users of a high security level network to access resources of a low security level network. It is specifically used to receive cloud desktop control data and keyboard and mouse data from the cloud desktop proxy client 3, and return the cloud desktop control data and image data to the cloud desktop proxy client 3.
[0076] The present invention discloses a relay control system for cross-network remote desktop access, which uses two single-guide systems to achieve one-in and one-out, and uses hardware to control different data types (control data, keyboard and mouse data, image data) in and out of the network, and has anti-tampering capabilities. Among them, the cloud desktop client and the cloud desktop proxy server perform secondary authentication, including local access authentication and cloud desktop access authentication, to ensure legal client access. In addition, the data exchange between the cloud desktop client and the cloud desktop proxy server, and the cloud desktop proxy client and the cloud desktop server, all extracts application layer data for relay forwarding, and at the same time controls the negotiation information transmitted by the application layer, can perform negotiation protocol conversion, and shields the high-risk transmission channel between the cloud desktop client and the cloud desktop server.
[0077] Correspondingly, such as Figure 2 As shown, the present invention also discloses a relay control method for cross-network remote desktop access, comprising the following steps:
[0078] S1: Perform multiple authentication, protocol conversion and security check between the cloud desktop client and the cloud desktop server by executing the cloud desktop access authentication process to establish two-way communication.
[0079] S2: The cloud desktop keyboard and mouse data of the cloud desktop client are transmitted to the cloud desktop server by executing the cloud desktop interactive operation process, and the cloud desktop image data generated by the cloud desktop server is returned to the cloud desktop client.
[0080] In a specific embodiment, Figure 3 As shown, the cloud desktop access authentication process performed in step S1 specifically includes the following steps:
[0081] S101: Initiate a local access authentication request to the cloud desktop proxy server through the cloud desktop client.
[0082] Specifically, after the cloud desktop client configures the cloud desktop proxy server, it initiates a local access authentication request. The cloud desktop proxy server performs local access authentication. If the authentication is successful, the cloud desktop protocol is received.
[0083] S102: Perform local access authentication through the cloud desktop proxy server, and receive a cloud desktop access authentication protocol sent by the cloud desktop client after the authentication is passed.
[0084] As an example, after the local access authentication of the cloud desktop client is passed, the cloud desktop access authentication protocol and other types of application control protocols are sent.
[0085] S103: Process the cloud desktop access authentication protocol through the cloud desktop proxy server, extract its application layer data, filter the entrained data, transcode and encapsulate it into an exportable format, and then generate encapsulation protocol data and send it to the one-way export module.
[0086] As an example, the cloud desktop proxy server receives the cloud desktop access authentication protocol, extracts its application layer data, filters the entrained data according to the protocol format, transcodes and encapsulates it into data with legal exportable format and content, and sends it to the one-way export module.
[0087] S104: The one-way export module performs format and content legitimacy check of the encapsulated protocol data through the built-in FPGA, and sends the data to the cloud desktop proxy client after passing the check.
[0088] As an example, first, the sending end of the one-way export module sends the received encapsulated data to the hardware FPGA capability of the isolation transmission card to perform a legality check and transmission on the data format and content. Data that fails the check will be discarded, and data that passes the check will be released and sent to the receiving end of the one-way export module through the isolation transmission card. At this time, the receiving end of the one-way export module forwards the received legal encapsulated data to the cloud desktop proxy client.
[0089] S105: The cloud desktop proxy client decapsulates the encapsulated protocol data into the cloud desktop access authentication protocol, encapsulates the data into the cloud desktop remote protocol, and sends the data to the cloud desktop server.
[0090] As an example, after receiving the encapsulated data, the cloud desktop proxy client unpacks it into cloud desktop access authentication or other application control protocols, encapsulates it into a cloud desktop remote protocol of the type required by the cloud desktop server, and sends it to the cloud desktop server.
[0091] S106: The cloud desktop server performs access authentication according to the cloud desktop remote protocol and returns access authentication response data.
[0092] As an example, the cloud desktop server receives a cloud desktop access authentication request or other application control protocol sent by the cloud desktop proxy client, performs access authentication or other application control processing, and returns access authentication response data or other application control data.
[0093] S107: The cloud desktop proxy client encapsulates the access authentication response data into an importable format, generates encapsulated response data and sends it to the one-way import module.
[0094] As an example, the cloud desktop proxy client receives access authentication response data or other application control data, extracts its application layer data, identifies and blocks redundant high-risk transmission channels, tailors its remote protocol capabilities, and then filters the entrained data according to the protocol format, transcodes and encapsulates it into data with legal importable format and content, and sends it to the one-way import module.
[0095] S108: The one-way import module performs a format and content legitimacy check of the encapsulated return data through the built-in FPGA, and sends the data to the cloud desktop proxy server after passing the check.
[0096] As an example, the sending end of the one-way import module sends the received encapsulated data to the hardware FPGA capability of the isolation transmission card to perform a legality check and transmission on the data format and content. Data that fails the check will be discarded, and data that passes the check will be released and sent to the receiving end of the one-way import module through the isolation transmission card. At this time, the receiving end of the one-way import module forwards the received legal encapsulated data to the cloud desktop proxy server.
[0097] S109: The cloud desktop proxy server restores the encapsulated return data to access authentication response data and sends it to the cloud desktop client.
[0098] As an example, the cloud desktop proxy server receives the imported encapsulated data, restores it to cloud desktop access authentication response data or other application control data, encapsulates it into the cloud desktop remote protocol required by the cloud desktop client, and sends it to the cloud desktop client.
[0099] S110: The cloud desktop client receives and processes the returned access authentication response data.
[0100] As an example, after receiving the cloud desktop access authentication response data or other application control data, the cloud desktop client makes a further authentication request or other application control negotiation request.
[0101] In a specific embodiment, Figure 4 As shown, the cloud desktop interactive operation process executed in step S2 specifically includes the following steps:
[0102] S201: Initiate local access authentication and cloud desktop access authentication to the cloud desktop proxy server through the cloud desktop client, and send cloud desktop keyboard and mouse operation data to the cloud desktop proxy server after the authentication is passed.
[0103] As an example, after the cloud desktop client configures the cloud desktop proxy server, it initiates an access authentication request, and the cloud desktop proxy server performs access authentication. If the authentication is passed, the cloud desktop access authentication can be processed. When the cloud desktop client completes the local access authentication and cloud desktop access authentication, it sends the cloud desktop keyboard and mouse operation data.
[0104] S202: Processing the cloud desktop keyboard and mouse operation data through the cloud desktop proxy server, extracting its application layer data, filtering the entrained data, transcoding and packaging it into an exportable format, and generating first packaged data to send to the one-way export module.
[0105] As an example, the cloud desktop proxy server receives the cloud desktop keyboard and mouse operation data, extracts its application layer data, filters the entrained data according to the protocol format, transcodes and encapsulates it into data with legal exportable format and content, and sends it to the one-way export module.
[0106] S203: The one-way export module performs a format and content legality check of the first packaged data through the built-in FPGA, and sends the first packaged data to the cloud desktop proxy client after the check passes.
[0107] As an example, the sending end of the one-way export module sends the received encapsulated data to the hardware FPGA capability of the isolation transmission card to perform a legality check and transmission on the data format and content. Data that fails the check will be discarded, and data that passes the check will be released and sent to the receiving end of the one-way export module through the isolation transmission card. At this time, the receiving end of the one-way export module forwards the received legal encapsulated data to the cloud desktop proxy client.
[0108] S204: The cloud desktop proxy client unpacks the first encapsulated data into cloud desktop keyboard and mouse operation data, and encapsulates the data into corresponding cloud desktop remote protocol data and sends the data to the cloud desktop server.
[0109] As an example, after receiving the encapsulated data, the cloud desktop proxy client unpacks it into cloud desktop keyboard and mouse operation data, encapsulates it into a cloud desktop remote protocol of the type required by the cloud desktop server, and sends it to the cloud desktop server.
[0110] S205: The cloud desktop server receives the cloud desktop remote protocol data, processes it, and returns the cloud desktop image data.
[0111] S206: The cloud desktop proxy client encapsulates the cloud desktop image data into an importable format, generates second encapsulated data and sends it to the one-way import module.
[0112] As an example, the cloud desktop proxy client receives cloud desktop image data, extracts its application layer data, performs video cleaning or transcoding according to the image data format, encapsulates it into data with legal importable format and content, and sends it to the one-way import module.
[0113] S207: The one-way import module performs a format and content legitimacy check of the second packaged data through the built-in FPGA, and sends the second packaged data to the cloud desktop proxy server after passing the check.
[0114] As an example, the sending end of the one-way import module sends the received encapsulated data to the hardware FPGA capability of the isolation transmission card to perform a legality check and transmission on the data format and content. Data that fails the check will be discarded, and data that passes the check will be released and sent to the receiving end of the one-way import module through the isolation transmission card. At this time, the receiving end of the one-way import module forwards the received legal encapsulated data to the cloud desktop proxy server.
[0115] S208: The cloud desktop proxy server restores the second packaged data into cloud desktop image data, and sends the data to the cloud desktop client.
[0116] S209: The cloud desktop client receives the cloud desktop image data and renders the cloud desktop image data into a recognizable image.
[0117] Correspondingly, the present invention also discloses a relay control device for cross-network remote desktop access, comprising:
[0118] Memory for storing computer programs;
[0119] A processor is used to implement the relay control method steps for cross-network remote desktop access as described in any one of the above items when executing the computer program.
[0120] Those skilled in the art can clearly understand that the technology in the embodiments of the present invention can be implemented by means of software plus a necessary general hardware platform. Based on this understanding, the technical solution in the embodiments of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product is stored in a storage medium such as a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a disk or an optical disk, etc., which can store program codes, including several instructions to enable a computer terminal (which can be a personal computer, a server, or a second terminal, a network terminal, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The same and similar parts between the various embodiments in this specification can be referred to each other. In particular, for the terminal embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description in the method embodiment.
[0121] In the several embodiments provided by the present invention, it should be understood that the disclosed systems, systems and methods can be implemented in other ways. For example, the system embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of systems or units, which can be electrical, mechanical or other forms.
[0122] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0123] In addition, each functional module in each embodiment of the present invention may be integrated into one processing unit, or each module may exist physically separately, or two or more modules may be integrated into one unit.
[0124] Similarly, each processing unit in each embodiment of the present invention may be integrated into one functional module, or each processing unit may exist physically, or two or more processing units may be integrated into one functional module.
[0125] The present invention will be further described with reference to the accompanying drawings and specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and are not intended to limit the scope of the present invention. In addition, it should be understood that after reading the content taught by the present invention, those skilled in the art may make various changes or modifications to the present invention, and these equivalent forms also fall within the scope limited by the application.
Claims
1. A relay control system for cross-network remote desktop access, characterized in that: include: A cloud desktop client and a cloud desktop proxy server provided in a high-security network, a cloud desktop proxy client and a cloud desktop server provided in a low-security network, and a one-way export module and a one-way import module; The cloud desktop proxy server is respectively connected with the cloud desktop client, the one-way export module and the one-way import module for data connection, and the cloud desktop proxy client is respectively connected with the cloud desktop server, the one-way export module and the one-way import module for data connection; The cloud desktop client is used to authenticate and communicate with the cloud desktop proxy server, send cloud desktop control data and keyboard and mouse data to the cloud desktop proxy server, and receive cloud desktop control data and image data returned from the cloud desktop proxy server; The cloud desktop proxy server is used to extract cloud desktop control data and keyboard and mouse data, filter and encapsulate them, and then send them to the one-way export module; it is also used to receive the encapsulated data sent by the one-way import module, unpack them, and then send them to the cloud desktop client; The one-way export module is used to receive the encapsulated data sent by the cloud desktop proxy server, and after detection, send the cloud desktop control data and keyboard and mouse data therein to the cloud desktop proxy client; The one-way import module is used to receive the encapsulated data sent by the cloud desktop agent client, and after detection, send the cloud desktop control data and image data therein to the cloud desktop agent server; The cloud desktop proxy client is used to receive the cloud desktop control data and keyboard and mouse data sent by the one-way export module, encapsulate them into remote protocol data and send them to the cloud desktop server, and receive the cloud desktop control data and image data sent by the cloud desktop server, filter and encapsulate them, and then send them to the one-way import module; The cloud desktop server is used to receive the cloud desktop control data and keyboard and mouse data sent by the cloud desktop proxy client, generate the cloud desktop control data and image data and return them to the cloud desktop proxy client; The cloud desktop client has a built-in tool for remote access to the cloud desktop, and the tool for remote access to the cloud desktop supports RDP, VNC or SPICE protocol; The cloud desktop proxy client is specifically used for: Receive the cloud desktop control data and image data sent by the cloud desktop server, extract the application layer data, perform remote protocol capability tailoring on the control data, clean or transcode the image data, encapsulate it and send it to the one-way import module.
2. A relay control method for cross-network remote desktop access, characterized in that: The method adopts the relay control system for cross-network remote desktop access as claimed in claim 1, and the method comprises: By executing the cloud desktop access authentication process, multiple authentication, protocol conversion and security checks are performed between the cloud desktop client and the cloud desktop server to establish two-way communication; By executing the cloud desktop interactive operation process, the cloud desktop keyboard and mouse data of the cloud desktop client is transmitted to the cloud desktop server, and the cloud desktop image data generated by the cloud desktop server is returned to the cloud desktop client.
3. The relay control method for cross-network remote desktop access according to claim 2, characterized in that: The cloud desktop access authentication process includes the following steps: S101: Initiate a local access authentication request to the cloud desktop proxy server through the cloud desktop client; S102: Performing local access authentication through the cloud desktop proxy server, and receiving a cloud desktop access authentication protocol sent by the cloud desktop client after the authentication is passed; S103: Processing the cloud desktop access authentication protocol through the cloud desktop proxy server, extracting its application layer data, filtering the entrained data, transcoding and encapsulating it into an exportable format, generating encapsulation protocol data and sending it to the one-way export module; S104: The one-way export module performs format and content legitimacy check of the encapsulated protocol data through the built-in FPGA, and sends the data to the cloud desktop proxy client after passing the check; S105: The cloud desktop proxy client decapsulates the encapsulated protocol data into a cloud desktop access authentication protocol, encapsulates the data into a cloud desktop remote protocol, and sends the data to the cloud desktop server; S106: The cloud desktop server performs access authentication according to the cloud desktop remote protocol and returns access authentication response data; S107: The cloud desktop proxy client encapsulates the access authentication response data into an importable format, generates encapsulated response data and sends it to the one-way import module; S108: The one-way import module performs format and content legitimacy check of the encapsulated return data through the built-in FPGA, and sends the data to the cloud desktop proxy server after passing the check; S109: The cloud desktop proxy server restores the encapsulated return data to access authentication response data and sends it to the cloud desktop client; S110: The cloud desktop client receives and processes the returned access authentication response data.
4. The relay control method for cross-network remote desktop access according to claim 3, characterized in that: The step S104 is specifically as follows: The sending end of the one-way export module sends the received encapsulation protocol data to the FPGA with built-in isolation transmission card to check the legality of the data format and content; If the check fails, the data is discarded directly; If the detection is successful, the encapsulation protocol data is sent to the receiving end of the unidirectional export module through the isolation transmission card; The receiving end of the one-way export module forwards the encapsulated data to the cloud desktop proxy client.
5. The relay control method for cross-network remote desktop access according to claim 2, characterized in that: The cloud desktop interactive operation process includes the following steps: S201: Initiate local access authentication and cloud desktop access authentication to the cloud desktop proxy server through the cloud desktop client, and send cloud desktop keyboard and mouse operation data to the cloud desktop proxy server after the authentication is passed; S202: Processing the cloud desktop keyboard and mouse operation data through the cloud desktop proxy server, extracting its application layer data, filtering the entrained data, transcoding and packaging it into an exportable format, and generating first packaged data to send to the one-way export module; S203: The one-way export module performs a format and content legality check of the first packaged data through the built-in FPGA, and sends the first packaged data to the cloud desktop proxy client after the check passes; S204: The cloud desktop proxy client decapsulates the first encapsulated data into cloud desktop keyboard and mouse operation data, encapsulates the data into corresponding cloud desktop remote protocol data, and sends the data to the cloud desktop server; S205: The cloud desktop server receives the cloud desktop remote protocol data, processes it, and returns the cloud desktop image data; S206: The cloud desktop proxy client encapsulates the cloud desktop image data into an importable format, generates second encapsulated data and sends it to the one-way import module; S207: The one-way import module performs a format and content legality check of the second packaged data through the built-in FPGA, and sends the data to the cloud desktop proxy server after passing the check; S208: The cloud desktop proxy server restores the second packaged data into cloud desktop image data, and sends the data to the cloud desktop client; S209: The cloud desktop client receives the cloud desktop image data and renders the cloud desktop image data into a recognizable image.
6. A relay control device for cross-network remote desktop access, characterized in that: include: Memory for storing computer programs; A processor is used to implement the relay control method steps for cross-network remote desktop access as described in any one of claims 2 to 5 when executing the computer program.
Citation Information
Patent Citations
Method and system for isolating network transparent service access based on double one-way switching equipment
CN110912940A
Cloud desktop access method, zero-trust gateway, cloud desktop client and server
CN115499177A