Method, apparatus and computer device for remote script execution without proxy in Windows system

By configuring the remote execution environment of the Windows system and choosing the appropriate script execution method, the problem of the existing technology that cannot provide stable, secure and flexible remote execution capabilities without additional installation and configuration is solved, and efficient and automated operation and maintenance management is achieved.

CN119356949BActive Publication Date: 2025-06-24杭州美创科技股份有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411940374.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-06-24
Estimated Expiration
2044-12-26

AI Technical Summary

Technical Problem

The existing Windows system remote execution scripting method has shortcomings in some scenarios, such as the inability to provide stable, secure and flexible remote execution capabilities without additional installation and configuration, especially when executing complex PowerShell scripts or programs with GUI interfaces.

Method used

By configuring the remote execution environment of the Windows system, setting up identity authentication and selecting the appropriate script execution method, including configuring WinRM services. Initialize the remote connection and perform connection tests. After ensuring that the connection is stable, select the execution method according to the script type and storage location. Finally, run the script according to the execution method and process its execution results.

Benefits of technology

It provides more stable, secure and flexible remote execution capabilities without additional installation and configuration, further improving the efficiency of automated operation and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119356949B_ABST
    Figure CN119356949B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device and computer equipment for remote script execution without a proxy in a Windows system. The method includes: configuring a remote execution environment for the Windows system, including setting identity authentication and selecting a script execution method, and configuring the WinRM service when selecting the script execution method; initializing a remote connection and performing a connection test; selecting an execution method for the script according to the storage location and type of the script; executing the script according to the execution method, and processing the result of the script execution. By implementing the method of the present invention, it is possible to provide a more stable, secure and flexible remote execution capability without additional installation and configuration, and further improve the efficiency of automated operation and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a script execution method, and more specifically to a method, device, and computer device for remotely executing scripts without a proxy in a Windows system. Background Art

[0002] Remotely executing scripts in a Windows system is commonly used in various scenarios such as batch configuration management, software deployment, system monitoring, and troubleshooting. It can help IT administrators efficiently manage and automate operations on multiple servers. Especially in a large-scale network environment or a distributed architecture, it can significantly improve work efficiency and response speed.

[0003] Currently, common methods for remotely executing scripts in a Windows system include SSH-based methods, third-party automation tools, and WinRM (Windows Remote Management). For SSH-based methods, although the SSH protocol is usually associated with Linux systems, in Windows 10 and above versions, Microsoft has integrated OpenSSH client and server components, enabling Windows users to also perform secure remote command execution and file transfer through the SSH protocol. However, in some older Windows systems, this method may require manual installation and configuration of the SSH service, increasing additional operation complexity. Moreover, this method is prone to improper configuration, which can easily lead to security vulnerabilities and increase security risks. Using third-party automation tools for remote execution, generally tools such as Puppet, Ansible Tower (part of Red Hat Ansible Engine), and SaltStack can be used. These tools provide advanced functions and can perform automated operations such as software deployment and configuration management on multiple Windows servers. Usually, a proxy program needs to be installed on the target machine. However, the proxy program in this way needs to run continuously, which may consume additional CPU and memory resources. Especially in a large-scale environment, this may become a performance bottleneck. Some tools are commercial software and require purchasing a license to use all their functions, increasing the operation and maintenance costs. The third method, WinRM, is a protocol launched by Microsoft for remotely managing Windows systems, allowing commands and scripts to be executed through the network and widely used in automated operation and maintenance tasks. However, in some scenarios, WinRM may have limitations on executing complex logic PowerShell scripts and cannot fully meet the requirements. If a program with a graphical interface is running, when the remote connection is interrupted, the program may stop and cannot continue to execute.

[0004] Although the existing Windows remote execution script methods can meet the needs of automated operation and maintenance to a certain extent, there are still deficiencies in some scenarios. For example, when the Windows host cannot install the proxy program or the OpenSSH component, the existing methods may fail; in addition, in some cases, WinRM also has limited support for executing complex PowerShell scripts or programs with a GUI interface.

[0005] Therefore, it is necessary to design a new method to provide more stable, secure, and flexible remote execution capabilities without additional installation and configuration, and further improve the efficiency of automated operation and maintenance. Summary of the Invention

[0006] The purpose of the present invention is to overcome the defects of the prior art and provide a proxy-free remote script execution method, device, and computer device for the Windows system.

[0007] To achieve the above purpose, the present invention adopts the following technical solutions: The proxy-free remote script execution method for the Windows system includes:

[0008] Configure the Windows system remote execution environment, including setting identity authentication, selecting a script execution method, and configuring the WinRM service when selecting the script execution method;

[0009] Initialize the remote connection and perform a connection test;

[0010] Select the execution method of the script according to the storage location and type of the script;

[0011] Execute the script according to the execution method and process the result of the script execution.

[0012] Its further technical solution is: The configuration of the Windows system remote execution environment, including setting identity authentication, selecting a script execution method, and configuring the WinRM service, includes:

[0013] Set the identity authentication of the execution user, where the identity authentication of the execution user includes a regular user or a domain user;

[0014] Select a script execution method, where the script execution method includes a non-encrypted service or an SSL encrypted service, and configure the WinRM service when selecting the script execution method.

[0015] Its further technical solution is: The configuration of the WinRM service when selecting the script execution method includes:

[0016] Log in to the Windows server with administrative privileges and start PowerShell;

[0017] Execute the winrm quickconfig -quiet command to quickly configure the WinRM service;

[0018] Enable basic authentication;

[0019] When non-encrypted communication needs to be allowed, run the PowerShell command to configure the Windows Remote Management service;

[0020] Set the maximum number of Shells that can be opened simultaneously by each user;

[0021] Set the maximum memory usage of each Shell;

[0022] Configure the WinRM listening port;

[0023] When SSL encryption service is required, write and execute a.ps1 script, and this script should contain all configuration steps and run this script with administrator privileges.

[0024] Its further technical solution is: the initializing the remote connection and performing a connection test includes:

[0025] Determine whether a lock needs to be created according to the identity authentication, and create a lock when needed, where the lock is used to limit concurrent execution;

[0026] Confirm whether there is an established remote connection session in the system currently;

[0027] Start a Shell on the remote host and run a connection test script to obtain the test execution result;

[0028] Reuse the connection or close the remote connection session according to the test execution result.

[0029] Its further technical solution is: the selecting the execution method of the script according to the storage location and type of the script includes:

[0030] Obtain the storage location of the script and the type of the script, the storage location of the script includes the target host or the remote execution system, and the type of the script includes PowerShell or non-PowerShell;

[0031] If the PowerShell script is stored in the remote system, use the base64 encoding execution method; if the PowerShell script is stored in the target system, call the PowerShell command execution method, and use the Invoke-Expression method for non-PowerShell scripts.

[0032] Its further technical solution is as follows: If the PowerShell script is stored in the remote system, use the base64 encoding execution method; if the PowerShell script is stored in the target system, call the PowerShell command execution method. After using the Invoke-Expression method for non-PowerShell scripts, it further includes:

[0033] For programs with a GUI interface, solve the problem of the program exiting after the remote connection is disconnected by creating a scheduled task, and use the scheduled task to trigger the script execution.

[0034] Its further technical solution is as follows: Execute the script according to the execution method and process the result of the script execution, including:

[0035] Execute the script according to the execution method, and process the result of the script execution in a synchronous or asynchronous manner; the synchronous method is to return the result after waiting for the execution to complete, and the asynchronous method is to dynamically obtain the output result in real time.

[0036] The present invention also provides a device for remotely executing scripts without a proxy in the Windows system, including:

[0037] A configuration unit for configuring the remote execution environment of the Windows system, including setting identity authentication, selecting a script execution method, and configuring the WinRM service when selecting the script execution method;

[0038] An initialization unit for initializing the remote connection and performing a connection test;

[0039] A selection unit for selecting the execution method of the script according to the storage location and type of the script;

[0040] An execution processing unit for executing the script according to the execution method and processing the result of the script execution.

[0041] The present invention also provides a computer device, which includes a memory and a processor. A computer program is stored on the memory, and when the processor executes the computer program, the above-mentioned method is implemented.

[0042] The present invention also provides a storage medium, which stores a computer program, and when the computer program is executed by a processor, the above-mentioned method is implemented.

[0043] The beneficial effects of the present invention compared with the prior art are as follows: By configuring the remote execution environment of the Windows system, setting identity authentication, and selecting an appropriate script execution method, including configuring the WinRM service. Initialize the remote connection and conduct a connection test. After ensuring a stable connection, select the execution method according to the script type and storage location. Finally, run the script according to the execution method and process its execution results to ensure efficient and stable automated operation and maintenance. Without the need for additional installation and configuration, it provides a more stable, secure, and flexible remote execution ability, further improving the efficiency of automated operation and maintenance.

[0044] The following further describes the present invention in conjunction with the accompanying drawings and specific embodiments. Description of the Drawings

[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0046] Figure 1 It is a schematic flowchart of the method for agentless remote script execution in the Windows system provided by the embodiment of the present invention;

[0047] Figure 2 It is a schematic sub - flowchart of the method for agentless remote script execution in the Windows system provided by the embodiment of the present invention;

[0048] Figure 3 It is a schematic sub - flowchart of the method for agentless remote script execution in the Windows system provided by the embodiment of the present invention;

[0049] Figure 4 It is a schematic sub - flowchart of the method for agentless remote script execution in the Windows system provided by the embodiment of the present invention;

[0050] Figure 5 It is a schematic block diagram of the device for agentless remote script execution in the Windows system provided by the embodiment of the present invention;

[0051] Figure 6 It is a schematic block diagram of the computer device provided by the embodiment of the present invention. Detailed Embodiments

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0053] It should be understood that when used in this specification and the appended claims, the terms "comprising" and "including" indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0054] It should also be understood that the terms used in this specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in this specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms.

[0055] It should be further understood that the term "and / or" used in this specification of the present invention and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0056] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of the method for executing remote scripts without a proxy in the Windows system provided by the embodiments of the present invention. By configuring the remote execution environment of the Windows system, including identity authentication and the WinRM service, it is ensured that remote scripts can be executed without a proxy. Utilize the WinRM quick configuration to select an appropriate script execution method, support non-encrypted and SSL-encrypted communications, and ensure security. The remote connection passes authentication and connection tests to ensure stable and reliable connections. According to the script type and storage location, select an appropriate execution method, support the base64 encoding execution of PowerShell scripts or call PowerShell commands. Finally, adopt a synchronous or asynchronous execution method to ensure real-time acquisition of the script execution results and improve the efficiency of automated operation and maintenance.

[0057] Figure 1 is a schematic flowchart of the method for executing remote scripts without a proxy in the Windows system provided by the embodiments of the present invention. As Figure 1 shown, the method includes the following steps S110 to S140.

[0058] S110. Configure the Windows system remote execution environment, including setting up identity authentication and selecting a script execution method. When selecting a script execution method, configure the WinRM service.

[0059] In this embodiment, the configuration of the execution environment mainly determines the identity authentication method and script execution method for remote execution of the Windows system, and enables and configures the corresponding WinRM service on the target Windows host.

[0060] In one embodiment, please refer to Figure 2 , the above step S110 may include steps S111 to S112.

[0061] S111. Set the identity authentication of the execution user. Among them, the identity authentication of the execution user includes a regular user or a domain user.

[0062] In this embodiment, a regular user or a domain user can be selected and configured as the identity for script execution according to requirements. Among them, a regular user is suitable for a single-machine environment or a small local area network, and the user account is stored in the local computer's security account database.

[0063] A domain user is suitable for an enterprise network environment. The user account is managed by Active Directory and can achieve cross-computer authentication. The username of a domain user usually contains the @ or \ character, such as domain\username or username@domain.com.

[0064] S112. Select a script execution method. Among them, the script execution method includes a non-encrypted service or an SSL encrypted service, and configure the WinRM service when selecting a script execution method.

[0065] In this embodiment, configuring the WinRM service when selecting a script execution method includes:

[0066] Log in to the Windows server with administrative privileges and start PowerShell; execute the winrm quickconfig -quiet command to quickly configure the WinRM service; enable basic authentication; when non-encrypted communication needs to be allowed, run the PowerShell command to configure the Windows Remote Management service; set the maximum number of Shells that can be opened simultaneously by each user; set the maximum memory usage of each Shell; configure the WinRM listening port; when an SSL encrypted service is required, write and execute a.ps1 script, and this script should contain all the configuration steps and run this script with administrative privileges.

[0067] In this embodiment, in the script remote execution system, it is necessary to configure the IP address, username, and password of the target Windows host, and these information should be encrypted and saved to ensure security. This usually involves back-end development work to ensure the secure storage and transmission of these sensitive information.

[0068] In this embodiment, two different configuration methods are provided for the WinRM service:

[0069] If you choose to use the non-encrypted method (only applicable to test environments or internal secure networks), you can follow the steps below:

[0070] Log in to the target Windows server and run PowerShell as an administrator. Run the following commands to configure the WinRM service:

[0071] winrm quickconfig –quiet;

[0072] winrm set winrm / config / service / auth '@{Basic="true"}';

[0073] winrm set winrm / config / service '@{AllowUnencrypted="true"}';

[0074] Set-Item WSMan:\localhost\Shell\MaxShellsPerUser 100;

[0075] Set-Item WSMan:\localhost\Shell\MaxMemoryPerShellMB 300;

[0076] Set-Item WSMan:\localhost\Listener\Listener*\Port 5985;

[0077] These commands will complete the basic configuration of WinRM, allow non-encrypted connections, and set limits on the number of sessions and memory usage.

[0078] For production environments, it is strongly recommended to use SSL encrypted services to increase security. You can create a.ps1 script to simplify this process.

[0079] Replace your.hostname with the actual hostname or IP address. Run PowerShell as an administrator and execute the following command to run the above script:

[0080] Type c:\enable_winrm_ssl.ps1 | PowerShell.exe -noprofile -;

[0081] This script will create a self-signed certificate and configure WinRM to use this certificate for communication over HTTPS port 5986. At the same time, it will also set up basic authentication and other related parameters.

[0082] In this embodiment, appropriate authentication methods and script execution methods can be selected according to the actual situation, and the WinRM service on the target Windows host can be correctly configured. Please ensure that best practices are followed during the configuration process, especially when dealing with sensitive information, and appropriate security measures must be taken.

[0083] S120. Initialize the remote connection and perform a connection test.

[0084] In this embodiment, in scenarios such as automated deployment, operation and maintenance management, or remote monitoring, initializing the remote connection and performing a connection test are key steps to ensure the smooth progress of subsequent operations.

[0085] In one embodiment, please refer to Figure 3 above, step S120 may include steps S121 to S124.

[0086] S121. Determine whether a lock needs to be created according to the authentication, and create a lock when needed, where the lock is used to limit concurrent execution.

[0087] In this embodiment, before starting a remote operation, it is first necessary to decide whether a lock needs to be created according to the authentication type. For the case of using domain users for authentication, considering the situation where multiple machines in the domain environment may send requests to the same target machine simultaneously, creating a lock can effectively prevent problems caused by multiple scripts executing simultaneously, such as resource competition or data conflicts. The specific method of creating a lock can be to create a temporary file or record on the target machine. When a task starts to execute, first check whether this file or record exists. If it exists, wait until the previous task is completed and the lock is released.

[0088] For the case of ordinary user authentication, since it is usually used in a single or a few controlled environments, there is no need to create a lock to limit concurrent execution.

[0089] S122. Confirm whether there is an established remote connection session in the system currently.

[0090] In this embodiment, before attempting to establish a new remote connection, it should be checked whether there is already an available connection session. If there is, the existing session can be directly reused, which can not only save the time for re - establishing the connection, but also reduce resource consumption. By checking the status of the session, it can be quickly determined whether the script can be immediately executed, thus improving the overall efficiency.

[0091] S123. Start a Shell on the remote host and run a connection test script to obtain the test execution result.

[0092] In this embodiment, once the status of the connection session is determined, the next step is to start a Shell on the remote host and execute a simple connection test script. The main purpose of this script is to verify whether the environment on the remote host is suitable for executing subsequent operations. For example, a command that outputs a specific string can be executed to test whether the connection is normal. If the output result is consistent with the expectation, it indicates that the environment configuration on the remote host is correct and subsequent tasks can be continued; if not, the problem needs to be further investigated. It may be a network problem, a permission problem, or some configurations on the target host that affect the execution of the script.

[0093] S124. Reuse the connection or close the remote connection session according to the test execution result.

[0094] In this embodiment, it is decided whether to keep or close the remote connection session according to the execution result of the connection test script. If the test result shows that everything is normal and subsequent operations are expected to be executed, the current connection session can be retained for reuse. However, if the test fails or there is no subsequent operation plan, the connection session should be closed in time to release the occupied resources.

[0095] By reusing the existing connection session, the time cost of re - establishing the connection before each operation is reduced, and the overall efficiency of automated operations is improved. In the case of using domain users, creating locks can avoid security risks caused by concurrent execution of multiple tasks and enhance the security of the system. Reasonably managing the life cycle of the connection session can effectively utilize network resources and computing resources and avoid unnecessary waste. By executing the connection test script, potential problems can be detected at an early stage, avoiding unforeseen errors during the formal execution of tasks, thus reducing the failure rate. Whether using ordinary users or domain users for authentication, this mechanism can flexibly handle different usage scenarios and improve the adaptability of the system.

[0096] In summary, initializing and testing the remote connection through the above steps can not only improve the efficiency and security of automated operations, but also ensure the effective utilization of resources, which is a recommended practice.

[0097] S130. Select an execution method for the script according to the storage location and type of the script.

[0098] In this embodiment, during the process of remotely executing a script, selecting an appropriate execution method is crucial for ensuring the successful execution of the script.

[0099] In one embodiment, please refer to Figure 4 , the above step S130 may include steps S131 to S133.

[0100] S131. Obtain the storage location of the script and the type of the script. The storage location of the script includes the target host or the remote execution system, and the type of the script includes PowerShell or non-PowerShell.

[0101] In this embodiment, before starting to execute the script, it is first necessary to clarify the storage location of the script (i.e., on which machine the script is stored) and the type of the script (whether it is a PowerShell script or a non-PowerShell script). The storage location of the script determines the subsequent execution method, while the type of the script affects the specific execution command. The storage location of the script can be the target host (i.e., the machine on which the script needs to be finally executed) or the remote execution system (i.e., the machine that initiates the remote execution request). The types of scripts are mainly divided into two categories: PowerShell scripts and non-PowerShell scripts.

[0102] S132. If the PowerShell script is stored in the remote system, use the base64 encoding execution method; if the PowerShell script is stored in the target system, call the PowerShell command execution method, and use the Invoke-Expression method for non-PowerShell scripts.

[0103] In this embodiment, when the script is stored in the remote execution system, the script can be executed in the form of Base64 encoding. Specifically, first convert the script content into a Base64 encoded string, and then execute it through the powershell -encodedcommand {Base64 encoded script} command. The advantage of this method is that it can hide the script content and add an extra layer of security protection. However, this method has a limit on the length of the script content, and the length of the encoded script cannot exceed 8,164 characters. For scripts longer than this length, another method needs to be adopted: first create a temporary file in the remote execution system, write the script content into this file; then use the WinRM protocol to upload the temporary file to the specified location on the target host; finally, execute the script content through the powershell -NoProfile -ExecutionPolicy Bypass {path of the temporary file} command on the target host. Remember to delete the temporary file after execution to clean up resources.

[0104] If the script already exists on the target host, it can be directly executed through the powershell -NoProfile -ExecutionPolicy Bypass {path of the script file} command. This method is simple and direct without an additional data transfer process.

[0105] For non-PowerShell scripts (such as Windows batch files or EXE programs), the Invoke-Expression "& SCRIPT MYARGS" command can be used to execute them. Among them, the SCRIPT variable represents the absolute path of the script, and the MYARGS variable represents the parameters passed to the script. To simplify the operation, the above command can be encapsulated into a PowerShell script to determine whether it is a PowerShell script according to whether the configured script path name ends with.ps1, and then call the corresponding execution method.

[0106] S133. For programs with a GUI interface, create a scheduled task to solve the problem that the program exits after the remote connection is disconnected, and use the scheduled task to trigger the script execution.

[0107] In this embodiment, for programs with a graphical user interface (GUI), the program may automatically exit after the remote connection is disconnected. To solve this problem, a scheduled task can be created on the target host, and this task will be triggered under specific conditions and execute the corresponding script. For example, the schtasks / create / tn start_telnet / tr c:\scripts\start_telnet.bat / sc once / st 00:00:00 / sd 2020 / 01 / 01 command can be used to create a scheduled task named start_telnet, and this task will execute the start_telnet.bat batch file located in the c:\scripts\ directory at the specified date and time. For convenient remote invocation, a PowerShell script named start_telnet.ps1 can also be created, and its content is only Start-ScheduledTask -TaskName "start_telnet", which is used to start the scheduled task. In this way, the program can continue to run even after the remote connection is disconnected.

[0108] Select the most suitable execution method according to the storage location and type of the script, so that the system can flexibly adapt to different usage scenarios. Executing the PowerShell script using Base64 encoding can hide the script content and enhance the security of the system. By encapsulating the execution logic into a script, the operation process is simplified, which is convenient for later maintenance and upgrade. By creating a scheduled task, the problem that the GUI program exits after the remote connection is disconnected is effectively solved, ensuring the continuous operation of the program. Reasonably managing and optimizing resource usage, such as timely deleting temporary files that are no longer needed, helps to improve the overall performance of the system.

[0109] S140. Execute the script according to the execution method and process the result of the script execution.

[0110] In this embodiment, the script is executed according to the execution method, and the result of the script execution is processed in a synchronous or asynchronous manner; the synchronous method is to return the result after waiting for the execution to complete, and the asynchronous method is to dynamically obtain the output result in real time.

[0111] During the remote script execution process, correctly processing the result of the script execution is crucial for evaluating the effect of the script execution and timely discovering potential problems. After determining the storage location and type of the script and selecting an appropriate execution method, the next step is to execute the script and process its result. According to the synchronous or asynchronous characteristics of the script execution, the result processing method will also be different.

[0112] In the synchronous call mode, the system will directly wait for the script to finish execution, collect the script's return status code, standard output (stdout), and error output (stderr), and return these results to the caller of the script remote execution system. It is simple to implement and has clear logic, suitable for scenarios where the script execution time is short. When the script execution time is long, the caller needs to wait for a long time to receive a response, resulting in a poor user experience; in addition, the parallel execution efficiency of the synchronous method is low because a task queue can only process one script execution request at a time.

[0113] At this time, an asynchronous call and real-time dynamic acquisition of the script output are required. Specifically, start the script execution without blocking the caller, allowing the caller to continue to execute other tasks. Establish a WebSocket connection to enable real-time communication and allow the server side to push the dynamic output results of the script execution to the client. Regularly check the standard output and error output of the script. Once new output content is detected, immediately send it to the caller of the script remote execution system in line format through the WebSocket connection. When the script execution is completed, stop the output check loop and send the final status code and any remaining output content to the caller to complete the entire asynchronous execution process.

[0114] The caller can immediately see the execution progress and output of the script, improving the user experience. Since the asynchronous execution does not block the caller, multiple script execution requests can be processed simultaneously, improving the system's concurrent processing ability. Once an exception occurs during script execution, the caller can immediately receive the error message, which helps to quickly locate the problem. However, the implementation is relatively complex and requires additional infrastructure support (such as a WebSocket service).

[0115] Whether directly obtaining the execution result through the synchronous method or real-time monitoring of the script execution status through the asynchronous method, both can meet the needs of different users and improve the user experience. The asynchronous processing mechanism enables the system to better handle complex execution environments, support a higher concurrency, and also leaves room for future function expansion. By real-time monitoring of the script execution status, problems can be discovered and solved in the first time, reducing the troubleshooting time. The asynchronous execution method avoids occupying system resources for a long time, improving resource utilization, especially when dealing with a large number of script execution requests.

[0116] In summary, choosing the appropriate synchronous or asynchronous result processing method according to the script execution method can not only meet the diverse application scenario requirements but also significantly improve the system's performance and reliability.

[0117] The method of this embodiment is targeted at the field of IT system automated operation and maintenance, aiming to solve the challenges faced by IT administrators in efficiently and uniformly managing and automating multiple Windows servers, especially the deficiencies in the current method of remotely executing scripts in Windows systems. Specifically, the traditional method of remotely executing scripts usually relies on an agent program installed on the target machine. Although the method of this embodiment achieves remote control, it also brings potential security risks, such as security hazards caused by vulnerabilities or improper configurations of the agent program itself. The present invention adopts an agentless approach to eliminate this risk, thereby improving the overall security of the system.

[0118] The agentless approach does not require installing and running additional agent programs on each target machine, which effectively reduces the consumption of resources such as CPU and memory. Especially in an environment with limited resources or strict performance requirements, the advantages of this method are particularly obvious.

[0119] The traditional agent-based method requires complex installation, configuration, and upgrade operations on each target machine, increasing the management difficulty of the system. The method of this embodiment avoids these cumbersome operations through the agentless approach, greatly simplifying the system deployment and subsequent maintenance work, enabling IT administrators to focus more on the management and optimization of core business.

[0120] Before remotely executing a script, the method of this embodiment first performs initialization and connection tests to pre-check problems that may cause the script execution to fail or the output to be unexpected. By reusing the remote execution connection, not only the execution efficiency is improved, but also the impact on the target host is reduced.

[0121] According to the storage location and type of different scripts, the method of this embodiment can automatically select the most suitable script execution method. This flexible execution strategy is applicable to a variety of complex application scenarios, ensuring the success rate and efficiency of script execution.

[0122] In some cases, the disconnection of the remote connection may cause programs with a graphical user interface (GUI) to unexpectedly exit. The method of this embodiment uses specific technical means to ensure that these programs can continue to run even after the remote connection is disconnected, thereby improving the stability and reliability of the system.

[0123] The method of this embodiment supports asynchronous call mode, allowing the script to execute in the background, and at the same time providing instant feedback by dynamically obtaining the script output in real time. This mode not only improves the user experience, but also enhances the system's concurrent processing ability and troubleshooting efficiency.

[0124] The method of this embodiment comprehensively improves the efficiency and reliability of IT system automated operation and maintenance by enhancing security, reducing resource consumption, simplifying deployment and maintenance, optimizing remote execution initialization and connection testing, automatically selecting the script execution method, solving the problem of GUI program exit after remote connection disconnection, and supporting asynchronous calls and real-time dynamic acquisition of script output. This not only addresses the deficiencies in existing methods but also provides IT administrators with a more efficient and convenient management tool.

[0125] The above-mentioned agentless remote script execution method for Windows systems configures the remote execution environment of the Windows system, sets up identity authentication, and selects an appropriate script execution method, including configuring the WinRM service. Initialize the remote connection and perform connection testing. After ensuring a stable connection, select the execution method according to the script type and storage location. Finally, run the script according to the execution method and process its execution results to ensure efficient and stable automated operation and maintenance, providing a more stable, secure, and flexible remote execution ability without additional installation and configuration, and further improving the efficiency of automated operation and maintenance.

[0126] Figure 5 It is a schematic block diagram of an agentless remote script execution device 300 for Windows systems provided by an embodiment of the present invention. As Figure 5 shown, corresponding to the above-mentioned agentless remote script execution method for Windows systems, the present invention also provides an agentless remote script execution device 300 for Windows systems. The agentless remote script execution device 300 for Windows systems includes units for executing the above-mentioned agentless remote script execution method for Windows systems, and this device can be configured in terminals such as desktop computers, tablet computers, laptops, etc. Specifically, please refer to Figure 5 and the agentless remote script execution device 300 for Windows systems includes a configuration unit 301, an initialization unit 302, a selection unit 303, and an execution processing unit 304.

[0127] The configuration unit 301 is used to configure the Windows system remote execution environment, including setting identity authentication, selecting the script execution method, and configuring the WinRM service when selecting the script execution method; the initialization unit 302 is used to initialize the remote connection and perform connection testing; the selection unit 303 is used to select the execution method of the script according to the storage location and type of the script; the execution processing unit 304 is used to execute the script according to the execution method and process the results of the script execution.

[0128] In one embodiment, the configuration unit 301 includes an authentication setting subunit and a method selection subunit.

[0129] An authentication setting sub-unit is used to set the identity authentication of the executing user, where the identity authentication of the executing user includes a common user or a domain user; a method selection sub-unit is used to select a script execution method, where the script execution method includes a non-encrypted service or an SSL encryption service, and the WinRM service is configured when selecting the script execution method. Specifically, log in to the Windows server with administrative privileges and start PowerShell; execute the winrm quickconfig -quiet command to quickly configure the WinRM service; enable basic authentication; when non-encrypted communication needs to be allowed, run the PowerShell command for configuring the Windows Remote Management service; set the maximum number of Shells that can be opened simultaneously by each user; set the maximum memory usage of each Shell; configure the WinRM listening port; when an SSL encryption service is needed, write and execute a.ps1 script, and this script should contain all the configuration steps and run this script with administrative privileges.

[0130] In one embodiment, the initialization unit 302 includes:

[0131] A lock creation determination sub-unit is used to determine whether a lock needs to be created according to the identity authentication, and create a lock when needed, where the lock is used to limit concurrent execution; a session judgment sub-unit is used to confirm whether there is an established remote connection session in the system currently; a startup test sub-unit is used to start a Shell on the remote host and run a connection test script to obtain a test execution result; a processing sub-unit is used to reuse the connection or close the remote connection session according to the test execution result.

[0132] In one embodiment, the selection unit 303 includes:

[0133] An acquisition sub-unit is used to acquire the storage location of the script and the type of the script, where the storage location of the script includes a target host or a remote execution system, and the type of the script includes PowerShell or non-PowerShell;

[0134] A call sub-unit is used to, if the PowerShell script is stored in the remote system, use the base64 encoding execution method; if the PowerShell script is stored in the target system, call the PowerShell command execution method, and use the Invoke-Expression method for non-PowerShell scripts.

[0135] An interface processing sub-unit is used to, for a program with a GUI interface, solve the problem that the program exits after the remote connection is disconnected by creating a scheduled task, and use the scheduled task to trigger the script execution.

[0136] In one embodiment, the execution processing unit 304 is configured to execute the script according to the execution method, and process the result of the script execution in a synchronous or asynchronous manner; the synchronous manner is to return the result after waiting for the execution to complete, and the asynchronous manner is to dynamically obtain the output result in real time.

[0137] It should be noted that those skilled in the art can clearly understand the specific implementation processes of the above-mentioned windows system proxy-free remote script execution device 300 and each unit, and can refer to the corresponding descriptions in the foregoing method embodiments. For the sake of convenience and brevity of description, they will not be elaborated here.

[0138] The above-mentioned windows system proxy-free remote script execution device 300 can be implemented in the form of a computer program, and this computer program can run on a computer device as shown in Figure 6 shown.

[0139] Please refer to Figure 6 , Figure 6 which is a schematic block diagram of a computer device provided by an embodiment of the present application. The computer device 500 may be a terminal. Among them, the terminal may be an electronic device with a communication function such as a smart phone, a tablet computer, a notebook computer, a desktop computer, a personal digital assistant, and a wearable device.

[0140] Refer to Figure 6 , the computer device 500 includes a processor 502, a memory, and a network interface 505 connected through a system bus 501. Among them, the memory may include a non-volatile storage medium 503 and an internal memory 504.

[0141] The non-volatile storage medium 503 can store an operating system 5031 and a computer program 5032. The computer program 5032 includes program instructions, and when these program instructions are executed, the processor 502 can be made to execute a windows system proxy-free remote script execution method.

[0142] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.

[0143] The internal memory 504 provides an environment for the operation of the computer program 5032 in the non-volatile storage medium 503. When the computer program 5032 is executed by the processor 502, the processor 502 can be made to execute a windows system proxy-free remote script execution method.

[0144] The network interface 505 is used for network communication with other devices. Those skilled in the art can understand that Figure 6The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device 500 to which the solution of this application is applied. Specifically, the computer device 500 may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.

[0145] Among them, the processor 502 is used to run the computer program 5032 stored in the memory to implement the following steps:

[0146] Configure the Windows system remote execution environment, including setting identity authentication, selecting a script execution method, and configuring the WinRM service when selecting a script execution method; initialize the remote connection and perform a connection test; select an execution method for the script according to the storage location and type of the script; execute the script according to the execution method, and process the result of the script execution.

[0147] In one embodiment, when the processor 502 implements the steps of configuring the Windows system remote execution environment, including setting identity authentication, selecting a script execution method, and configuring the WinRM service, the following steps are specifically implemented:

[0148] Set the identity authentication of the executing user, where the identity authentication of the executing user includes a normal user or a domain user; select a script execution method, where the script execution method includes a non-encrypted service or an SSL encryption service, and configure the WinRM service when selecting a script execution method.

[0149] In one embodiment, when the processor 502 implements the step of configuring the WinRM service when selecting a script execution method, the following steps are specifically implemented:

[0150] Log in to the Windows server with administrator privileges and start PowerShell; execute the winrm quickconfig -quiet command to quickly configure the WinRM service; enable basic authentication; when non-encrypted communication is required, run the PowerShell command for configuring the Windows Remote Management service; set the maximum number of Shells that can be opened simultaneously by each user; set the maximum memory usage of each Shell; configure the WinRM listening port; when an SSL encryption service is required, write and execute a.ps1 script, and this script should contain all the configuration steps and run this script with administrator privileges.

[0151] In one embodiment, when the processor 502 implements the step of initializing the remote connection and performing a connection test, the following steps are specifically implemented:

[0152] Determine whether a lock needs to be created based on the identity authentication, and create a lock when needed, where the lock is used to limit concurrent execution; confirm whether there is an established remote connection session in the system currently; start a Shell on the remote host and run a connection test script to obtain a test execution result; reuse the connection or close the remote connection session according to the test execution result.

[0153] In one embodiment, when the processor 502 implements the step of selecting the execution method of the script according to the storage location and type of the script, the following steps are specifically implemented:

[0154] Obtain the storage location of the script and the type of the script. The storage location of the script includes the target host or the remote execution system, and the type of the script includes PowerShell or non-PowerShell; if the PowerShell script is stored in the remote system, use the base64 encoding execution method; if the PowerShell script is stored in the target system, call the PowerShell command execution method, and use the Invoke-Expression method for non-PowerShell scripts.

[0155] In one embodiment, after the processor 502 implements the step of using the base64 encoding execution method if the PowerShell script is stored in the remote system, calling the PowerShell command execution method if the PowerShell script is stored in the target system, and using the Invoke-Expression method for non-PowerShell scripts, the following steps are also implemented:

[0156] For programs with a GUI interface, solve the problem of the program exiting after the remote connection is disconnected by creating a scheduled task, and use the scheduled task to trigger the execution of the script.

[0157] In one embodiment, when the processor 502 implements the step of executing the script according to the execution method and processing the result of the script execution, the following steps are specifically implemented:

[0158] Execute the script according to the execution method, and process the result of the script execution in a synchronous or asynchronous manner; the synchronous method is to return the result after waiting for the execution to complete, and the asynchronous method is to obtain the output result dynamically in real time.

[0159] It should be understood that in the embodiments of the present application, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0160] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program includes program instructions, and the computer program can be stored in a storage medium, and the storage medium is a computer-readable storage medium. The program instructions are executed by at least one processor in the computer system to implement the process steps of the embodiments of the above methods.

[0161] Therefore, the present invention also provides a storage medium. The storage medium may be a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, the processor is caused to execute the following steps:

[0162] Configure the Windows system remote execution environment, including setting identity authentication, selecting a script execution method, and configuring the WinRM service when selecting the script execution method; initialize the remote connection and perform a connection test; select an execution method for the script according to the storage location and type of the script; execute the script according to the execution method, and process the results of the script execution.

[0163] In an embodiment, when the processor executes the computer program to implement the steps of configuring the Windows system remote execution environment, including setting identity authentication, selecting a script execution method, and configuring the WinRM service, the following steps are specifically implemented:

[0164] Set the identity authentication of the executing user, where the identity authentication of the executing user includes a regular user or a domain user; select a script execution method, where the script execution method includes a non-encrypted service or an SSL encrypted service, and configure the WinRM service when selecting the script execution method.

[0165] In one embodiment, when the processor executes the computer program to implement the step of configuring the WinRM service when selecting the script execution method, the following specific steps are implemented:

[0166] Log in to the Windows server with administrative privileges and start PowerShell; execute the winrm quickconfig -quiet command to quickly configure the WinRM service; enable basic authentication; when non-encrypted communication needs to be allowed, run the PowerShell command to configure the Windows Remote Management service; set the maximum number of Shells that can be opened simultaneously by each user; set the maximum memory usage of each Shell; configure the WinRM listening port; when SSL encryption service is required, write and execute a.ps1 script, and this script should contain all the configuration steps and run this script with administrative privileges.

[0167] In one embodiment, when the processor executes the computer program to implement the step of initializing the remote connection and performing a connection test, the following specific steps are implemented:

[0168] Determine whether a lock needs to be created according to the identity authentication, and create a lock when needed, where the lock is used to limit concurrent execution; confirm whether there is an established remote connection session in the system currently; start a Shell on the remote host and run the connection test script to obtain the test execution result; reuse the connection or close the remote connection session according to the test execution result.

[0169] In one embodiment, when the processor executes the computer program to implement the step of selecting the execution method of the script according to the storage location and type of the script, the following specific steps are implemented:

[0170] Obtain the storage location of the script and the type of the script, where the storage location of the script includes the target host or the remote execution system, and the type of the script includes PowerShell or non-PowerShell; if the PowerShell script is stored in the remote system, use the base64 encoding execution method; if the PowerShell script is stored in the target system, call the PowerShell command execution method, and use the Invoke-Expression method for non-PowerShell scripts.

[0171] In one embodiment, after the processor executes the computer program to implement the method of executing the PowerShell script stored remotely using base64 encoding; if the PowerShell script is stored in the target system, calling the PowerShell command execution method, and using the Invoke-Expression method for non-PowerShell scripts, the following steps are further implemented:

[0172] For programs with a GUI interface, the problem of the program exiting after the remote connection is disconnected is solved by creating a scheduled task, and the scheduled task is used to trigger the execution of the script.

[0173] In one embodiment, when the processor executes the computer program to implement the step of executing the script according to the execution method and processing the result of the script execution, the following steps are specifically implemented:

[0174] Execute the script according to the execution method, and process the result of the script execution in a synchronous or asynchronous manner; the synchronous manner is to return the result after waiting for the execution to complete, and the asynchronous manner is to dynamically obtain the output result in real time.

[0175] The storage medium can be various computer-readable storage media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disc that can store program codes.

[0176] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0177] In several embodiments provided by the present invention, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of each unit is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed.

[0178] The steps in the method of the embodiments of the present invention can be adjusted in order, combined, and deleted according to actual needs. The units in the device of the embodiments of the present invention can be combined, divided, and deleted according to actual needs. In addition, in each embodiment of the present invention, the functional units can be integrated in one processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0179] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a terminal, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention.

[0180] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A method for executing remote scripts without an agent in Windows system, characterized in that: include: Configure the Windows system remote execution environment, including setting identity authentication, selecting the script execution method, and configuring the WinRM service when selecting the script execution method; Initialize remote connection and perform connection test; Selecting a script execution method according to the script storage location and script type; Execute the script according to the execution method, and process the result of the script execution; The configuration of the Windows system remote execution environment includes setting identity authentication, selecting the script execution mode, and configuring the WinRM service, including: Setting the identity authentication of the executing user, wherein the identity authentication of the executing user includes a common user or a domain user; Select a script execution mode, wherein the script execution mode includes a non-encrypted service or an SSL encrypted service, and configure a WinRM service when selecting the script execution mode; The configuration of the WinRM service when selecting the script execution mode includes: Log in to the Windows server with administrator privileges and start PowerShell; Run the winrmquickconfig -quiet command to quickly configure the WinRM service; Enable Basic Authentication; When you need to allow unencrypted communication, run the PowerShell command to configure the Windows Remote Management service; Set the maximum number of shells that each user can open simultaneously; Set the maximum memory usage for each shell; Configure WinRM listening port; When SSL encryption service is required, write and execute a .ps1 script, which should contain all the configuration steps and run the script with administrator privileges; The method of executing the script is selected according to the storage location and the script type of the script, including: Obtaining a storage location of the script and a type of the script, wherein the storage location of the script includes a target host or a remote execution system, and the type of the script includes PowerShell or non-PowerShell; If the PowerShell script is stored in the remote system, use the base64 encoding execution method; if the PowerShell script is stored in the target system, call the PowerShell command execution method, and use the Invoke-Expression method for non-PowerShell scripts.

2. The Windows system agentless remote script execution method according to claim 1, characterized in that: Initializing the remote connection and performing the connection test include: Determine whether a lock needs to be created according to the identity authentication, and create a lock when necessary, wherein the lock is used to limit concurrent execution; Check whether the system currently has an established remote connection session; Start a shell on the remote host and run the connection test script to get the test execution results; Reuse the connection or close the remote connection session according to the test execution result.

3. The Windows system agentless remote script execution method according to claim 1, characterized in that: If the PowerShell script is stored in the remote system, the base64 encoding execution method is used; if the PowerShell script is stored in the target system, the PowerShell command execution method is called, and the non-PowerShell script uses the Invoke-Expression method, and also includes: For programs with GUI interfaces, create a scheduled task to solve the problem of program exit after the remote connection is disconnected, and use the scheduled task to trigger script execution.

4. The Windows system agentless remote script execution method according to claim 1, characterized in that: The step of executing the script according to the execution method and processing the result of the script execution includes: The script is executed according to the execution method, and the result of the script execution is processed in a synchronous or asynchronous manner; the synchronous manner is to wait for the result to be returned after the execution is completed, and the asynchronous manner is to dynamically obtain the output result in real time.

5. A Windows system agentless remote script execution device, characterized in that: include: Configuration unit, used to configure the Windows system remote execution environment, including setting identity authentication, selecting the script execution mode, and configuring the WinRM service when the script execution mode is selected; Initialization unit, used to initialize remote connection and perform connection test; A selection unit, used to select an execution method of the script according to the storage location and script type of the script; An execution processing unit, used to execute the script according to the execution method and process the result of the script execution; The configuration unit includes an authentication setting subunit and a mode selection subunit; The authentication setting subunit is used to set the identity authentication of the executing user, wherein the identity authentication of the executing user includes ordinary users or domain users; the mode selection subunit is used to select the script execution mode, wherein the script execution mode includes non-encrypted service or SSL encrypted service, and the WinRM service is configured when the script execution mode is selected; specifically, use administrator privileges to log in to the Windows server and start PowerShell; execute the winrmquickconfig -quiet command to quickly configure the WinRM service; enable basic authentication; when it is necessary to allow non-encrypted communication, run the PowerShell command to configure the Windows remote management service; set the maximum number of shells that each user can open at the same time; set the maximum memory usage of each shell; configure the WinRM listening port; when SSL encrypted service is required, write and execute a .ps1 script, the script should contain all the configuration steps, and run this script with administrator privileges; Wherein, the selection unit comprises: An acquisition subunit is used to acquire a storage location of a script and a type of the script, wherein the storage location of the script includes a target host or a remote execution system, and the type of the script includes PowerShell or non-PowerShell; The calling subunit is used to execute the PowerShell script using base64 encoding if the PowerShell script is stored in the remote system; if the PowerShell script is stored in the target system, the PowerShell command execution method is called, and the Invoke-Expression method is used for non-PowerShell scripts.

6. A computer device, characterized in that: The computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the method according to any one of claims 1 to 4 when executing the computer program.

7. A storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.