Safe remote control method and system

By introducing dynamic hybrid programming technology and hybrid encryption methods into traditional remote control software, the security risks existing in Internet server communications are solved, the security and efficiency of remote control are achieved, and information security and remote office environment are improved.

CN119945664APending Publication Date: 2025-05-06PETROCHINA CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311465204.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-06
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Traditional remote control software poses security risks in Internet server communications, especially for organizations with extremely high information security requirements, the existing technology is difficult to effectively solve this problem.

Method used

The controller dynamically mixes the key layout of the input device according to the key layout of the input device, generates the mixed key, and mixes and encrypts the initial operation instructions of the target user with the mixed key, and transmits them to the controlled machine for analysis and execution, ensuring the security of the operation instructions during transmission.

Benefits of technology

It realizes the security and efficiency of remote control. Through unique mixed keys and input rules, the operation instructions are prevented from being cracked or stolen during transmission, improve information security, and strengthen the security of the remote office environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945664A_ABST
    Figure CN119945664A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of information and communication, and particularly relates to a safe remote control method and system. The method comprises the following steps: a control machine carries out dynamic shuffling according to key layout of input equipment to obtain a shuffling key; obtaining an initial operation instruction input by a target user, and performing hybrid encryption on the initial operation instruction and the hybrid key to obtain an encryption result; the encryption result is transmitted to the controlled machine for analysis operation, and a target operation instruction is obtained; and the controlled machine executes work according to the content of the target operation instruction. By dynamically producing the ASCII code of the keyboard, the encryption and decryption processes are realized by combining a keyboard hybrid programming technology and enterprise authentication, different types of desktop operating systems are adapted, and the safety and high efficiency of remote control are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information and communication technology, and in particular relates to a safe remote control method and system. Background Art

[0002] In today's digital age, enterprise remote work and enterprise IT service desks' rapid remote support for users have become a necessity, especially in the face of emergencies, travel, non-working hours or disaster recovery. A safe and efficient means of remote work is particularly important.

[0003] Traditional remote control software usually relies on Internet servers for communication. If keyboard commands are intercepted and tampered with, it may cause huge security risks, especially for organizations such as governments and central enterprises that have extremely high requirements for information security. In response to these challenges, a new generation of remote office technology has emerged. Summary of the invention

[0004] In view of the above problems, the present invention provides a secure remote control method, the method comprising:

[0005] The control machine performs dynamic mixing according to the key layout of the input device to obtain the mixed key;

[0006] Obtaining the initial operation instruction input by the target user, performing mixed encryption on the initial operation instruction and the mixed key to obtain an encryption result;

[0007] The encrypted result is transmitted to the controlled machine for parsing operation to obtain the target operation instruction;

[0008] The controlled machine performs work according to the content of the target operation instruction.

[0009] Preferably, before the control machine performs dynamic mixing according to the key layout of the input device, the process includes: initializing the keyboard coding of the control machine.

[0010] Preferably, before the control machine performs dynamic mixing according to the key layout of the input device, the control machine includes:

[0011] Establish module connection between the control machine and the controlled machine.

[0012] Preferably, establishing a module connection between the control machine and the controlled machine includes:

[0013] The control machine sends a control request to the remote control module;

[0014] Determining whether there is a remote control protocol corresponding to the control request;

[0015] The remote control module sends a control request to the controlled machine;

[0016] The controlled machine receives the control request and realizes the module connection between the control machine and the controlled machine.

[0017] Preferably, before obtaining the initial operation instruction input by the target user, it is also necessary to perform user authentication on the target user to determine the session ID of the target user.

[0018] Preferably, the initial operation instruction and the mixed key are mixed and encrypted to obtain an encryption result, including:

[0019] The target user's session ID, initial operation instruction and mixed key are mixed and encrypted to obtain an encryption result.

[0020] The present invention also provides a secure remote control system, the system comprising:

[0021] The key generation module is used to dynamically mix the keys according to the key layout of the input device to obtain the mixed key;

[0022] The instruction encryption module is used to perform mixed encryption on the initial operation instruction and the mixed key to obtain an encryption result;

[0023] The instruction parsing module is used to transmit the encryption result to the controlled machine for parsing operation to obtain the target operation instruction;

[0024] The instruction execution module is used to execute work according to the content of the target operation instruction.

[0025] Preferably, the system further comprises:

[0026] The initialization module is used to initialize the keyboard code of the control machine.

[0027] Preferably, the system further comprises:

[0028] The connection module is used to establish a module connection between the control machine and the controlled machine.

[0029] Preferably, the connection module is used to establish a module connection between the control machine and the controlled machine, including:

[0030] The connection module is used for the control machine to send a control request to the remote control module;

[0031] Determining whether there is a remote control protocol corresponding to the control application;

[0032] The remote control module sends a control request to the controlled machine;

[0033] The controlled machine receives the control request and realizes the module connection between the control machine and the controlled machine.

[0034] Preferably, the system further comprises:

[0035] The authentication module is used to authenticate the target user and determine the session ID of the target user.

[0036] Preferably, the instruction encryption module is used to perform mixed encryption on the initial operation instruction and the mixed key to obtain an encryption result, including:

[0037] The instruction encryption module is used to perform mixed encryption on the target user's session ID, initial operation instruction and mixed key to obtain an encryption result.

[0038] The present invention has the following beneficial effects:

[0039] (1) The present invention dynamically generates keyboard ASCII codes, uses keyboard mixing technology combined with enterprise authentication to implement encryption and decryption processes, adapts to different types of desktop operating systems, and achieves safe and efficient remote control;

[0040] (2) In the present invention, the hashing key and input rule are independently set by each user, so the hashing key and input rule of each user are unique. This means that even if two users use the same hashing key, different input sequences will be generated due to their different input rules, which prevents the operation instructions from being cracked or misused during transmission, thereby improving information security.

[0041] (3) The present invention can realize safe and fast connection of desktop remote control, enhance the security of the remote office environment, ensure the confidentiality of sensitive information, and improve the efficiency of remote office.

[0042] Other features and advantages of the present invention will be described in the following description, and partly become obvious from the description, or be understood by implementing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0044] Figure 1 A diagram showing a secure remote control method according to an embodiment of the present invention is shown;

[0045] Figure 2 A diagram of a secure remote control system according to an embodiment of the present invention is shown;

[0046] Figure 3A diagram of a secure remote control device according to an embodiment of the present invention is shown;

[0047] Figure 4 A workflow diagram of a secure remote control method in an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0048] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as being limited to the examples set forth herein; on the contrary, these embodiments are provided so that the present disclosure will be more comprehensive and complete, and the concepts of the example embodiments are fully conveyed to those skilled in the art. The described features, structures, or characteristics may be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present disclosure. However, those skilled in the art will appreciate that the technical solutions of the present disclosure may be practiced while omitting one or more of the specific details, or other methods, components, devices, steps, etc. may be adopted. In other cases, known technical solutions are not shown or described in detail to avoid obscuring various aspects of the present disclosure.

[0049] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and thus their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware units or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.

[0050] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the steps. For example, some steps may be decomposed, while some steps may be combined or partially combined, so the actual execution order may change according to the actual situation.

[0051] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchanged where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein, for example.

[0052] In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or sub-modules is not necessarily limited to those steps or sub-modules explicitly listed, but may include other steps or sub-modules not explicitly listed or inherent to these processes, methods, products, or apparatuses.

[0053] This invention seamlessly integrates the enterprise's internal authentication with the remote office platform, deploys the enterprise's own services in the DMZ area, ensures security through single sign-on, and adopts innovative communication channels and two-way encrypted collaboration methods to improve efficiency. This is the technical background behind a safe and efficient enterprise remote online office method. The birth of this technology is to solve the security and efficiency problems existing in traditional remote office software and provide enterprises with a safer and more efficient remote office method.

[0054] like Figure 1 As shown, the present invention proposes a secure remote control method, the method comprising the following steps:

[0055] S1 performs user authentication on the target user and determines the session ID of the target user;

[0056] S2 establishes module connection between the control machine and the controlled machine;

[0057] S3 performs keyboard code initialization on the control machine;

[0058] The S4 controller performs dynamic mixing according to the key layout of the input device to obtain the mixed key;

[0059] S5 obtains the initial operation instruction input by the target user, performs mixed encryption on the initial operation instruction and the mixed key, and obtains an encryption result;

[0060] S6 transmits the encrypted result to the controlled machine for parsing operation to obtain the target operation instruction;

[0061] The S7 controlled machine executes work according to the content of the target operation instruction.

[0062] Specifically, S2 establishes a module connection between the control machine and the controlled machine, including:

[0063] The control machine sends a control request to the remote control module;

[0064] Determining whether there is a remote control protocol corresponding to the control request;

[0065] The remote control module sends a control request to the controlled machine;

[0066] The controlled machine receives the control request and realizes the module connection between the control machine and the controlled machine.

[0067] Specifically, S5 performs mixed encryption on the initial operation instruction and the mixed key to obtain an encryption result, including:

[0068] The target user's session ID, initial operation instruction and mixed key are mixed and encrypted to obtain an encryption result.

[0069] like Figure 2 As shown, the present invention also proposes a secure remote control system, the system comprising:

[0070] Authentication module 1, used to perform user authentication on the target user and determine the session ID of the target user;

[0071] A connection module 2, used to establish a module connection between the control machine and the controlled machine;

[0072] Initialization module 3, used to initialize the keyboard code of the control machine;

[0073] The key generation module 4 is used to dynamically mix the keys according to the key layout of the input device to obtain a mixed key;

[0074] The instruction encryption module 5 is used to perform mixed encryption on the initial operation instruction and the mixed key to obtain an encryption result;

[0075] The instruction parsing module 6 is used to transmit the encryption result to the controlled machine for parsing operation to obtain the target operation instruction;

[0076] The instruction execution module 7 is used to execute work according to the content of the target operation instruction.

[0077] In some embodiments, such as Figure 3 As shown, the present invention also discloses a secure remote control device, comprising:

[0078] The global control module is used to control the modules of the system and the communication between the modules;

[0079] The remote control module receives the operation instructions parsed by the data decryption module and calls the protocol library API method according to different remote control protocols to operate the target device;

[0080] The command mixing module dynamically generates keyboard rules and generates a mixed key. When the user operates the controlled machine, the control machine client encrypts the mixed key command input by the user, the mixed key and the session ID obtained by the user in the authentication center. After the controlled machine receives the operation data packet, it verifies the legitimacy of the operation data packet to the user authentication module according to the user information, and then parses the operation command according to the mixed key.

[0081] Image processing module, encrypting and decrypting the operation image;

[0082] User authentication module verifies the legitimacy of user operations and generates a user session ID;

[0083] Protocol library, used to adapt remote control protocols of various operating systems, such as RDP, X11, etc.

[0084] Visual simulator, dynamically displays the remote operation images transmitted by the image analysis module;

[0085] The audit and monitoring module conducts real-time audit and recording of operation data, detects potential abnormal behaviors in time and blocks them, and tracks down illegal operations afterwards;

[0086] Among them, the global control module is connected with the remote control module, the image processing module and the user authentication module respectively, the image processing module is connected with the visual simulator, and the remote control module is connected with the instruction mixing module, the protocol library and the audit and monitoring module respectively.

[0087] based on Figure 3 The present invention also discloses a secure remote control method, such as Figure 4 As shown, the following steps are included:

[0088] Step 1: The user is authenticated through the user authentication module;

[0089] Step 2: The control machine client sends a control request to the remote control module, and the global control module determines whether the protocol library has a corresponding remote control protocol. If so, execute step 3;

[0090] Step 3: The remote control module sends a control request to the client of the controlled machine. The client of the controlled machine receives the request and executes step 4. If not, executes step 2.

[0091] Step 4: The global control module notifies the remote control module to establish a connection, and the remote control module sends a handshake message to the control machine client and completes the connection;

[0092] Step 5: The control machine client performs remote operation initialization, and the command mixing module performs dynamic mixing according to the key layout of the input device and generates a mixing key, waiting for the user to input the operation command;

[0093] Step 6: After the user inputs the command, the command mixing module encrypts the input mixed key command, the mixing key and the session ID obtained by the user in the authentication center and transmits them to the remote control module;

[0094] Step 7: After the remote control module verifies the legitimacy of the data, it passes the command to the command mixing module of the controlled machine to perform mixed key parsing operation instructions. At the same time, the global control module copies the instruction to the audit and monitoring module;

[0095] Step 8: The controlled machine executes the operation instruction, and the image processing module encrypts the operation image and returns it to the remote control module. At the same time, the global control module copies the image to the audit and monitoring module;

[0096] Step 9: The image processing module of the control machine client decrypts the received operation image and calls the visual simulator to generate an operation interface.

[0097] Example: Remote Operation and Maintenance

[0098] After the user's remote control connection request is passed, the command mixing module will initialize the keyboard encoding. After receiving the user's keyboard input, the command mixing module completes the mixed encoding and sends the encoded operation command to the remote control module. For example, in this embodiment, the keys entered by the user on the keyboard are "delete table user". At this time, the command mixing module will generate the edogd gqgodjwdf key command according to the dynamically generated keyboard rules, and then mix the three with the mixed key generated according to the user device and the session ID generated by the user in the user authentication module. This remote operation command is encrypted and transmitted to the local area network remote control module, and then decrypted by the controlled client command mixing module, and the remote operation command is executed.

[0099] Those skilled in the art should understand that although the present invention has been described in detail with reference to the aforementioned embodiments, it is still possible to modify the technical solutions described in the aforementioned embodiments, or to make equivalent replacements for some of the technical features therein; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A secure remote control method, characterized in that: The method comprises: The control machine performs dynamic mixing according to the key layout of the input device to obtain the mixed key; Obtaining the initial operation instruction input by the target user, performing mixed encryption on the initial operation instruction and the mixed key to obtain an encryption result; The encrypted result is transmitted to the controlled machine for parsing operation to obtain the target operation instruction; The controlled machine performs work according to the content of the target operation instruction.

2. The secure remote control method according to claim 1, characterized in that: Before the control machine performs dynamic mixing according to the key layout of the input device, it includes: initializing the keyboard coding of the control machine.

3. The secure remote control method according to claim 1, characterized in that: Before the control machine performs dynamic mixing according to the key layout of the input device, it includes: Establish module connection between the control machine and the controlled machine.

4. The secure remote control method according to claim 3, characterized in that: Establish module connection between the control machine and the controlled machine, including: The control machine sends a control request to the remote control module; Determining whether there is a remote control protocol corresponding to the control request; The remote control module sends a control request to the controlled machine; The controlled machine receives the control request and realizes the module connection between the control machine and the controlled machine.

5. The secure remote control method according to claim 1, characterized in that: Before obtaining the initial operation instruction input by the target user, it is necessary to authenticate the target user and determine the session ID of the target user.

6. The secure remote control method according to claim 5, characterized in that: The initial operation instruction and the mixed key are mixed and encrypted to obtain an encryption result, including: The target user's session ID, initial operation instruction and mixed key are mixed and encrypted to obtain an encryption result.

7. A secure remote control system, characterized in that: The system comprises: The key generation module is used to dynamically mix the keys according to the key layout of the input device to obtain the mixed key; The instruction encryption module is used to perform mixed encryption on the initial operation instruction and the mixed key to obtain an encryption result; The instruction parsing module is used to transmit the encryption result to the controlled machine for parsing operation to obtain the target operation instruction; The instruction execution module is used to execute work according to the content of the target operation instruction.

8. The secure remote control system according to claim 7, characterized in that: The system further comprises: The initialization module is used to initialize the keyboard code of the control machine.

9. The secure remote control system according to claim 7, characterized in that: The system further comprises: The connection module is used to establish a module connection between the control machine and the controlled machine.

10. The secure remote control system according to claim 9, characterized in that: The connection module is used to establish a module connection between the control machine and the controlled machine, including: The connection module is used for the control machine to send a control request to the remote control module; Determining whether there is a remote control protocol corresponding to the control application; The remote control module sends a control request to the controlled machine; The controlled machine receives the control request and realizes the module connection between the control machine and the controlled machine.

11. The secure remote control system according to claim 7, characterized in that: The system further comprises: The authentication module is used to authenticate the target user and determine the session ID of the target user.

12. The secure remote control system according to claim 11, characterized in that: The instruction encryption module is used to perform mixed encryption on the initial operation instruction and the mixed key to obtain an encryption result, including: The instruction encryption module is used to encrypt the target user's session ID, initial operation instruction and mixed key to obtain an encryption result.