Cloud desktop login method and system, electronic equipment and storage medium
By introducing security modules and user terminals to store ciphertexts on the cloud server, the security problems caused by centralized storage of cloud desktop login passwords are solved, and the security and reliability of cloud desktop login are realized.
Patent Information
- Application Number
- CN202311661461.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-05
- Publication Date
- 2025-06-06
AI Technical Summary
In the existing cloud desktop login system, the login password is stored in a cloud database, which is easily stolen by malicious programs or leaked by developers, resulting in user data leakage or tampering.
A security module is introduced on the cloud server to manage the login of the corresponding cloud desktop, decrypt the ciphertext carried through password learning and obtain the login password. At the same time, the user terminal stores the ciphertext and sends the cloud desktop identity and ciphertext to the cloud server for decryption and login when logging in.
Through the management of security modules of one machine and one secret, the risk of cloud desktop being used by others is reduced, and the security and reliability of cloud desktop login is guaranteed.
Smart Images

Figure CN120110697A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a cloud desktop login method, system, electronic device and storage medium. Background Art
[0002] Cloud desktop is a computer desktop running in the cloud, and user terminals access the cloud desktop remotely through the network. Cloud desktop is increasingly used in corporate office environments, bringing convenience and efficiency to enterprises in operation and maintenance. At the same time, enterprises have higher and higher requirements for the security of cloud desktop.
[0003] Currently, access to cloud desktops often involves user login and verification. The login password of the cloud desktop is the user's credential for using the cloud desktop. The login password is stored in a database in the cloud, and the database manages the login passwords of all cloud desktops in the cloud. Once stolen by malicious programs or maliciously leaked by developers, the cloud desktop will be used by others, causing problems of user data leakage or tampering. Even if the login password is encrypted, once the key is leaked, the cloud desktop will be used by others. Summary of the invention
[0004] The purpose of this application is to propose a cloud desktop login method, system, electronic device and storage medium to address the deficiencies of the above-mentioned prior art, and this purpose is achieved through the following technical solutions.
[0005] The first aspect of the present application proposes a cloud desktop login method, which is applied to a cloud server, and the method includes:
[0006] Receiving a cloud desktop connection request sent by a user terminal, wherein the cloud desktop connection request carries a ciphertext of a cloud desktop login password and a cloud desktop identifier;
[0007] Decrypting the ciphertext through a security module corresponding to the cloud desktop identifier to obtain a cloud desktop login password;
[0008] The cloud desktop system corresponding to the cloud desktop identifier is logged in using the cloud desktop login password, and the interface data of the cloud desktop system is sent to the user terminal.
[0009] The cloud desktop login method described in the first aspect above has at least the following beneficial effects or advantages:
[0010] By introducing a security module on the cloud desktop of the cloud server, the login of the corresponding cloud desktop is managed in the security module to avoid the leakage problem caused by storing the login password of the cloud desktop in the cloud database management. In addition, the indicator of the security module introduced for the cloud desktop is the cryptographic operation capability, not the direct storage of the login password of the cloud desktop. That is, when the cloud server receives a cloud desktop connection request, the security module corresponding to the cloud desktop requested to connect uses its own cryptographic operation capability to decrypt the ciphertext carried in the request to obtain the login password used to log in to the cloud desktop. The security module introduced in this way is equivalent to one machine and one password, which can reduce the risk of the cloud desktop being used by others and ensure the security and reliability of the cloud desktop login.
[0011] A second aspect of the present application provides a cloud desktop login method, which is applied to a user terminal, and the method includes:
[0012] When the received local password is successfully verified, the cloud desktop identifier of the cloud desktop to be connected is obtained;
[0013] Sending a cloud desktop connection request carrying the cloud desktop identifier and the locally stored ciphertext to the cloud server; the ciphertext is obtained by encrypting the cloud desktop login password by the cloud server using the security module corresponding to the cloud desktop;
[0014] Display the interface data of the cloud desktop system returned by the cloud server.
[0015] The cloud desktop login method according to the second aspect above has at least the following beneficial effects or advantages:
[0016] The ciphertext of the cloud desktop login password is stored on the terminal side. The ciphertext is obtained by encrypting the cloud desktop login password using the security module corresponding to the cloud desktop. Therefore, when the user terminal logs in to the cloud desktop, it first verifies the local password entered by the user and completes the local login, and then carries the obtained cloud desktop identifier and the locally stored ciphertext in the cloud desktop connection request and sends it to the cloud server side, so that the cloud server side can perform the cloud desktop login operation and display the interface of the cloud desktop system transmitted back by the cloud server side. Since the terminal side maintains the ciphertext of the cloud desktop login password, even if it is leaked, others cannot easily log in to use the cloud desktop, because the ciphertext needs to be further cracked, and the ciphertext needs to be decrypted using the one-machine-one-secret security module introduced on the cloud server side, which is difficult for people who steal the ciphertext to obtain. Therefore, this application can ensure the security and reliability of cloud desktop login.
[0017] The third aspect of the present application proposes a cloud desktop login system, the system comprising:
[0018] A user terminal, used to execute the method according to the second aspect above;
[0019] The cloud service end is used to execute the method described in the first aspect above.
[0020] The fourth aspect of the present application proposes an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method described in the first aspect or the second aspect above.
[0021] A fifth aspect of the present application proposes a computer-readable storage medium having a computer program stored thereon, wherein the program is executed by a processor to implement the method described in the first aspect or the second aspect above.
[0022] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0024] Figure 1 A schematic diagram of a cloud desktop login process in the prior art;
[0025] Figure 2 The present invention is a flow chart of an embodiment of a cloud desktop login method according to an exemplary embodiment;
[0026] Figure 3 The present invention is a flowchart of another cloud desktop login method according to an exemplary embodiment;
[0027] Figure 4 This is a multi-terminal interaction schematic diagram of a cloud desktop login according to an exemplary embodiment;
[0028] Figure 5 is a schematic diagram of a hardware structure of an electronic device according to an exemplary embodiment;
[0029] Figure 6 The figure is a schematic diagram of the structure of a storage medium according to an exemplary embodiment. DETAILED DESCRIPTION
[0030] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of systems and methods consistent with some aspects of the present application as detailed in the appended claims.
[0031] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms of "a", "said" and "the" used in this application and the appended claims are also intended to include plural forms unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.
[0032] It should be understood that although the terms first, second, third, etc. may be used in the present application to describe various information, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0033] Figure 1 This is the cloud desktop login process adopted in the prior art, and the login password of the cloud desktop is centrally managed in the database of the cloud management service.
[0034] The user initiates a login on the terminal side. First, the terminal account used for local login obtains the connection credentials issued by the management service on the cloud server. Then the terminal initiates a cloud desktop connection to the cloud desktop service on the cloud server based on the obtained connection credentials. After the cloud desktop service verifies the connection credentials through the management service, it obtains the login password for the cloud desktop. Finally, the cloud desktop service uses the login password to perform the login operation and transmits the interface data of the successfully logged-in cloud desktop system to the terminal in real time.
[0035] The above cloud desktop login solutions are all based on software logic, and the login passwords of all cloud desktops are managed in the database of the control service, which is easy to be stolen by malicious programs or maliciously leaked by developers. Even if the login password is encrypted and stored, once the key is leaked, it will also lead to the leakage of the cloud desktop login password. Therefore, the existing cloud desktop login solution cannot guarantee safe and reliable login.
[0036] In order to solve the above technical problems, the present application proposes a cloud desktop login method, in which the cloud server and the user terminal cooperate to realize the safe and reliable login of the cloud desktop.
[0037] On the cloud server side, a security module is introduced into the cloud desktop of the cloud server, and the login of the corresponding cloud desktop is managed in the security module to avoid the leakage problem caused by storing the login password of the cloud desktop in the cloud database for centralized management. In addition, the indicator of the security module introduced for the cloud desktop is the cryptographic computing capability, rather than directly storing the login password of the cloud desktop. That is, when the cloud server receives a cloud desktop connection request, it uses its own cryptographic computing capability to decrypt the ciphertext carried in the request through the security module corresponding to the cloud desktop requested to connect, and obtains the login password of the cloud desktop. In this way, the introduced security module is equivalent to one machine and one password, which can reduce the risk of the cloud desktop being used by others and ensure the security and reliability of the cloud desktop login.
[0038] On the user terminal side, the ciphertext of the cloud desktop login password is stored. The ciphertext is obtained by encrypting the cloud desktop login password using the security module corresponding to the cloud desktop on the cloud server side. Therefore, when the user terminal logs in to the cloud desktop, it first verifies the local password entered by the user and completes the local login after success. Then, the obtained cloud desktop identifier and the locally stored ciphertext are sent to the cloud server side in the cloud desktop connection request to connect to the cloud desktop and display the interface of the cloud desktop system transmitted back by the cloud server side. Since the terminal side maintains the ciphertext of the cloud desktop login password, even if it is leaked, others cannot easily obtain and use the cloud desktop, because the ciphertext needs to be further cracked, and the ciphertext needs to be decrypted using the one-machine-one-secret security module introduced on the cloud server side, which is difficult for people who steal the ciphertext to obtain, so the security and reliability of the cloud desktop login can be guaranteed.
[0039] It should be noted here that the security module involved in this application can be a virtualized software module, such as vTPM (virtual Trusted Platform Module), or a hardware module, such as TPM (Trusted Platform Module). This application does not limit the specific form of the security module, as long as it can provide the required security technology for cryptographic operations.
[0040] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The several specific embodiments listed can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0041] Embodiment 1:
[0042] Figure 2This is a flowchart of a cloud desktop login method according to an exemplary embodiment. This embodiment takes the cloud server as the execution subject and mainly describes the operation process on the cloud server side. The cloud server provides cloud desktop service and management service. These two services can be deployed on the same machine or on different machines. Figure 2 As shown, the cloud desktop login method includes the following steps:
[0043] Step 201: Receive a cloud desktop connection request sent by a user terminal, where the cloud desktop connection request carries a ciphertext of a cloud desktop login password and a cloud desktop identifier.
[0044] In this step, since the cloud desktop service on the cloud server includes the cloud desktop system activated by the user, the cloud desktop service processes the cloud desktop connection request from the user terminal. The ciphertext is used to obtain the cloud desktop login password, which is a string of strings without any regularity. The cloud desktop identifier is used to uniquely identify a cloud desktop system in the cloud desktop service. It can be represented by the access address and port information of the cloud desktop system, or by a separately defined identification information.
[0045] Furthermore, the cloud desktop connection request sent by the user terminal may also include, in addition to the ciphertext of the cloud desktop login password and the cloud desktop identifier, the user terminal account information and connection credential information. The connection credential information is obtained by the user terminal from the management and control service when the user terminal logs in to the cloud desktop. The cloud desktop service can use the user terminal account information and connection credential information for verification. Successful verification indicates that the cloud desktop connection request is a normal connection request.
[0046] Step 202: Decrypt the ciphertext through the security module corresponding to the cloud desktop identifier to obtain the cloud desktop login password.
[0047] Before executing step 202, the cloud server needs to initialize the cloud desktop and establish the content to be used for logging into the cloud desktop (including the security module, the cloud desktop identification, and the login password) in advance according to the request.
[0048] In one feasible implementation, a cloud desktop initialization request is received from a user terminal, a cloud desktop system and a security module are allocated to the user terminal based on the cloud desktop initialization request, a login password and a cloud desktop identifier are generated for the cloud desktop system, the cloud desktop identifier is then stored, and the generated login password is encrypted by the security module to obtain a ciphertext, which is then sent to the user terminal.
[0049] In this implementation, the cloud desktop system is an operating system similar to the Windows system and the Linux system, and is generally composed of a CPU and memory. Therefore, the cloud desktop initialization request can carry the CPU indicators and memory indicators required by the user terminal, so that the cloud server allocates the cloud desktop system to the user terminal according to the required CPU indicators and memory indicators, and establishes a security module with cryptographic algorithm operation capabilities for the cloud desktop system. A key is solidified in the security module, which cannot be obtained by the outside world and is dedicated to encryption and decryption in the security module. At the same time, the cryptographic algorithm used in the security module is used for encryption and decryption operations, that is, it is used to encrypt the login password and output the ciphertext of the login password when used for the first time, and is used to decrypt the ciphertext and output the login password when used later.
[0050] The login password is the login credential of the cloud desktop system, which is dynamically generated by the cloud server based on some information of the assigned cloud desktop system. The cloud desktop identifier is used to identify a unique cloud desktop and can be stored in the management and control service of the cloud server so that the user terminal can obtain the information of the cloud desktop to be connected from the management and control service. As mentioned above, the cloud desktop identifier can be represented by the access address and port information of the cloud desktop system, or by a separately defined identification information.
[0051] In this embodiment, considering that each cloud desktop needs to have a corresponding security module, a virtualized software module can be used on the cloud server to implement the capabilities of the security module and reduce hardware costs.
[0052] It can be seen that on the cloud service side, each cloud desktop corresponds to a security module to manage the login password. However, the security module does not directly store the login password. Instead, it uses cryptographic algorithms to perform operations from the login password to the ciphertext, and from the ciphertext to the login password. Moreover, one cloud desktop is managed by one security module, which can reduce the risk of leakage and has relatively high security.
[0053] It should be noted that an anti-brute force cracking mechanism can be preset in the security module of the cloud server, that is, if the security module detects that a preset number of login passwords have been received within a preset time range, a locking operation will be performed to further improve the security of cloud desktop login.
[0054] That is to say, if the ciphertext of the login password is intercepted, others use special cracking equipment to generate a large number of login passwords based on this ciphertext, and then encrypt these login passwords in turn through the security module and output the ciphertext, and compare the ciphertext output by the security module with the intercepted ciphertext. If the comparison is consistent, it means that the brute force cracking is successful. Therefore, after detecting that the security module has received multiple attempts to encrypt the login password, the security module is locked to prevent brute force cracking during the login process.
[0055] Based on the above implementation, for the decryption process of the ciphertext in the cloud desktop connection request, a security module corresponding to the cloud desktop identifier is obtained, and the security module uses a locally preset key and cryptographic algorithm to decrypt the ciphertext to obtain the cloud desktop login password.
[0056] Step 203: Use the cloud desktop login password to log in to the cloud desktop system corresponding to the cloud desktop identifier, and send the interface data of the cloud desktop system to the user terminal.
[0057] In this step, the cloud server calls the cloud desktop service and passes in the login password and cloud desktop ID to log in to the cloud desktop system, and sends the interface data of the cloud desktop system to the user terminal in real time, so that the user can use the cloud desktop system remotely on the terminal side.
[0058] At this point, the above Figure 2 The cloud desktop login process shown in the figure introduces a security module on the cloud desktop of the cloud server, manages the login of the corresponding cloud desktop in the security module, and avoids the problem of leakage caused by storing the login password of the cloud desktop in the cloud database management. And the indicator of the security module introduced for the cloud desktop is the cryptographic operation capability, not the direct storage of the login password of the cloud desktop. That is, when the cloud server receives the cloud desktop connection request, it uses its own cryptographic operation capability to decrypt the ciphertext carried in the request through the security module corresponding to the cloud desktop requested to connect, and obtains the login password used to log in to the cloud desktop. The security module introduced in this way is equivalent to one machine and one password, which can reduce the risk of the cloud desktop being used by others and ensure the security and reliability of the cloud desktop login.
[0059] Embodiment 2:
[0060] Figure 3 FIG. 1 is a flowchart of another cloud desktop login method according to an exemplary embodiment. This embodiment takes a user terminal as the execution subject and mainly describes the operation process of the user terminal. The user terminal can be any device that can connect to the Internet, such as a computer or a tablet. Figure 3 As shown, the cloud desktop login method includes the following steps:
[0061] Step 301: When the received local password is successfully verified, obtain the cloud desktop identifier of the cloud desktop to be connected.
[0062] In this step, the local password is the credential for the user terminal to log in to the local cloud desktop client. Therefore, only after the local password verification is successful and the local cloud desktop client is logged in, can the remote cloud desktop be connected.
[0063] As mentioned above, the cloud desktop identifier is managed on the cloud server's management service. Based on this, the user terminal can send a desktop connection credential request to the cloud server, so that the cloud server's management service returns the user terminal's cloud desktop identifier according to the desktop connection credential request.
[0064] Before executing step 301, the user terminal needs to pre-establish the login credentials of the local cloud desktop client and complete the cloud desktop initialization work.
[0065] In one feasible implementation, the local password entered by the user for the first time to log in to the cloud desktop client is received, and a hash value is calculated based on the local password through a preset security module, the hash value is stored in a hash list, and then a cloud desktop initialization request is sent to the cloud server, and the ciphertext returned by the cloud server for logging in to the cloud desktop is received and stored.
[0066] In this embodiment, the local password used to log in to the cloud desktop client can be in the form of a user name and password, or it can be user biometric information, such as fingerprint information, face information, etc. The local password is a login credential that the user needs to remember and is managed by the security module introduced on the user terminal. In order to ensure security, the security module uses a hash algorithm to calculate the hash value of the local password and stores it in a locally maintained hash list to facilitate verification and matching with the password entered by the user. In addition to recording the hash value of the local password set by the user in advance for logging in to the cloud desktop client, the hash list in the security module also contains other hash values on the user terminal that need to be guaranteed to be used safely, such as hash values used for disk reading and writing. In addition, when calculating the hash value, the security module can also calculate the hash value in combination with the terminal information of the user terminal in addition to referring to the local password to improve the login security of the user terminal.
[0067] When the user terminal initializes the cloud desktop, it can carry the required CPU indicators and memory indicators in the cloud desktop initialization request, so that the cloud server can allocate an appropriate cloud desktop system.
[0068] The ciphertext is obtained by encrypting the cloud desktop login password using the security module corresponding to the cloud desktop. For the user terminal, it is the credential for connecting to the cloud desktop. Therefore, it needs to be stored locally on the terminal and used when connecting to the cloud desktop.
[0069] In this embodiment, considering that the local password on the terminal side only needs to use one security module, a hardware module can be used on the user terminal to implement the capabilities of the security module. With the development of user terminal technology, a TPM security chip is usually installed on the terminal hardware to protect the data on the terminal, so that the TPM security chip on the user terminal can be used to manage the local password.
[0070] Based on the above implementation, for the local password verification process, when the local password input by the user for logging into the cloud desktop client is received, the received local password is verified by a preset security module.
[0071] The verification process of the security module is as follows:
[0072] First, the hash value of the local password is determined, and then the hash value is matched against the stored hash list.
[0073] Then, if the hash value is matched, it is determined that the local password verification is successful, and if the hash value is not matched, it is determined that the local password verification fails.
[0074] It should be noted that the security module on the user terminal can also preset an anti-brute force cracking mechanism, that is, when the security module detects that a local password has been received a preset number of times within a preset time range, a locking operation is performed to further improve the security of cloud desktop login.
[0075] Step 302: Send a cloud desktop connection request carrying the cloud desktop identifier and the locally stored ciphertext to the cloud server.
[0076] In this step, after obtaining the cloud desktop identifier to be connected, the user terminal can generate a cloud desktop connection request based on the cloud desktop identifier and the locally stored ciphertext and send it to the cloud server to enable the cloud server to log in to the cloud desktop.
[0077] Step 303: Display the interface data of the cloud desktop system returned by the cloud server.
[0078] In this step, the user terminal displays the interface data of the cloud desktop system sent back by the cloud server in real time, allowing the user to operate the remote cloud desktop system.
[0079] Based on the above-mentioned second embodiment, the ciphertext of the cloud desktop login password is stored on the terminal side. The ciphertext is obtained by encrypting the cloud desktop login password using the security module corresponding to the cloud desktop on the cloud server side. Therefore, when the user terminal logs in to the cloud desktop, it first verifies the local password entered by the user and completes the local login after success, and then carries the obtained cloud desktop identifier and the locally stored ciphertext in the cloud desktop connection request and sends it to the cloud server side, so that the cloud server side performs the cloud desktop login operation and displays the interface of the cloud desktop system transmitted back by the cloud server side. Since the terminal side maintains the ciphertext of the cloud desktop login password, even if it is leaked, others cannot easily log in and use the cloud desktop, because the ciphertext needs to be further cracked, and the ciphertext needs to be decrypted using the one-machine-one-secret security module introduced on the cloud server side, which is difficult for people who steal the ciphertext to obtain. Therefore, this application can ensure the security and reliability of cloud desktop login.
[0080] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0081] Corresponding to the above-mentioned cloud desktop login method embodiment, the present application also provides a cloud desktop login system embodiment, in which the system includes a user terminal and a cloud server, and the user terminal is used to execute the above-mentioned Figure 3 The process of the embodiment shown in the figure, the cloud service end is used to execute the above Figure 2 The process of the embodiment shown.
[0082] Based on the above Figures 2 to 3 Based on the illustrated embodiment, the cloud desktop login process is described in detail in a multi-terminal interactive manner.
[0083] Figure 4 This is a multi-terminal interaction diagram of a cloud desktop login according to an exemplary embodiment. On the user terminal side, it involves the cloud desktop client and security module, and on the cloud service side, it involves the management service, cloud desktop service, and cloud desktop security module. The complete cloud desktop login implementation involves two stages: cloud desktop initialization stage and cloud desktop login stage.
[0084] In the cloud desktop initialization stage: the user enters the initial local password on the login interface of the cloud desktop client. The local password is the local login credential set by the user. The cloud desktop client sends the local password to the security module of the user terminal; the security module of the user terminal calculates the hash value of the local password and stores it locally for subsequent verification and matching, and returns a successful setting notification to the cloud desktop client; after receiving the successful setting notification, the cloud desktop client sends a cloud desktop initialization request to the cloud desktop service through the management and control service; the cloud desktop service allocates a cloud desktop system and a security module based on the cloud desktop initialization request, generates a login password and a cloud desktop identifier for the cloud desktop system, and sends the cloud desktop identifier to the management and control service storage, and the cloud desktop service sends the login password to the assigned security module; the security module uses a preset key and cryptographic algorithm to encrypt the login password to obtain a ciphertext, and returns the ciphertext to the cloud desktop client on the user terminal through the management and control service.
[0085] In the cloud desktop login stage: when the user needs to access the cloud desktop remotely, open the cloud desktop client on the user terminal and enter the local password set in the initialization stage. The cloud desktop client sends the received local password to the security module on the user terminal for verification; the security module on the user terminal calculates the hash value of the local password and matches the hash value in the local hash list. When the hash value is matched, a verification success notification is returned to the cloud desktop client; the cloud desktop client completes the local login and sends a desktop connection credential request to the management service on the cloud server; the management service obtains the user terminal based on the desktop connection credential request The cloud desktop identifier is obtained and returned to the cloud desktop client; the cloud desktop client generates a cloud desktop connection request based on the cloud desktop identifier and the locally stored ciphertext and sends it to the cloud desktop service on the cloud server; the cloud desktop service sends the ciphertext to the security module corresponding to the cloud desktop identifier; the security module corresponding to the cloud desktop identifier decrypts the ciphertext using the locally preset key and cryptographic algorithm, obtains the cloud desktop login password and outputs it, the cloud desktop service uses the cloud desktop login password to log in to the cloud desktop system corresponding to the cloud desktop identifier, and sends the interface data of the cloud desktop system to the user terminal to complete the cloud desktop login.
[0086] The embodiment of the present application also provides an electronic device corresponding to the cloud desktop login method provided in the aforementioned embodiment to execute the aforementioned cloud desktop login method.
[0087] Figure 5 6 is a hardware structure diagram of an electronic device according to an exemplary embodiment, and the electronic device includes: a communication interface 601, a processor 602, a memory 603 and a bus 604; wherein the communication interface 601, the processor 602 and the memory 603 complete mutual communication through the bus 604. The processor 602 can execute the cloud desktop login method described above by reading and executing the machine executable instructions corresponding to the control logic of the cloud desktop login method in the memory 603. The specific content of the method is referred to the above embodiment, and will not be repeated here.
[0088] The memory 603 mentioned in this application can be any electronic, magnetic, optical or other physical storage system, and can contain storage information, such as executable instructions, data, etc. Specifically, the memory 603 can be RAM (Random Access Memory), flash memory, storage drive (such as hard disk drive), any type of storage disk (such as optical disk, DVD, etc.), or similar storage medium, or a combination thereof. The communication connection between the system network element and at least one other network element is realized through at least one communication interface 601 (which can be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. can be used.
[0089] The bus 604 may be an ISA bus, a PCI bus or an EISA bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. The memory 603 is used to store programs, and the processor 602 executes the programs after receiving execution instructions.
[0090] Processor 602 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in processor 602 or an instruction in software form. The above-mentioned processor 602 can be a general-purpose processor, including a network processor (Network Processor, referred to as NP), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a readily available programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The disclosed methods, steps and logic block diagrams in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as a hardware decoding processor to execute, or the hardware and software modules in the decoding processor are combined to execute.
[0091] The electronic device provided in the embodiment of the present application and the cloud desktop login method provided in the embodiment of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented therein.
[0092] The present application also provides a computer-readable storage medium corresponding to the cloud desktop login method provided in the above embodiment. Figure 6 As shown, the computer-readable storage medium shown is a CD 30 on which a computer program (ie, a program product) is stored. When the computer program is run by a processor, the cloud desktop login method provided in any of the aforementioned embodiments will be executed.
[0093] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical or magnetic storage media, which are not listed here one by one.
[0094] The computer-readable storage medium provided in the above-mentioned embodiments of the present application and the cloud desktop login method provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the application programs stored therein.
[0095] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0096] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0097] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
Claims
1. A cloud desktop login method, It is characterized in that Applied to a cloud server, the method includes: Receiving a cloud desktop connection request sent by a user terminal, wherein the cloud desktop connection request carries a ciphertext of a cloud desktop login password and a cloud desktop identifier; Decrypting the ciphertext through a security module corresponding to the cloud desktop identifier to obtain a cloud desktop login password; The cloud desktop system corresponding to the cloud desktop identifier is logged in using the cloud desktop login password, and the interface data of the cloud desktop system is sent to the user terminal.
2. The method according to claim 1, It is characterized in that Before decrypting the ciphertext by a security module corresponding to the cloud desktop identifier, the method further includes: Receiving a cloud desktop initialization request from a user terminal; Allocate a cloud desktop system and a security module to the user terminal based on the cloud desktop initialization request, generate a login password and a cloud desktop identifier for the cloud desktop system, and store the cloud desktop identifier; The login password is encrypted by the security module to obtain a ciphertext, which is then sent to the user terminal.
3. The method according to any one of claims 1 to 2, It is characterized in that The method further comprises: The security module detects that a login password has been received a preset number of times within a preset time range, and executes a locking operation.
4. A cloud desktop login method, It is characterized in that Applied to a user terminal, the method comprises: When the received local password is successfully verified, the cloud desktop identifier of the cloud desktop to be connected is obtained; Sending a cloud desktop connection request carrying the cloud desktop identifier and the locally stored ciphertext to the cloud server; the ciphertext is obtained by encrypting the cloud desktop login password by the cloud server using the security module corresponding to the cloud desktop; Display the interface data of the cloud desktop system returned by the cloud server.
5. The method according to claim 4, It is characterized in that The local password verification process includes: Receive the local password entered by the user for logging into the cloud desktop client; The local password is verified by a preset security module.
6. The method according to claim 5, It is characterized in that The verifying the local password by a preset security module includes: Determine a hash value of the local password, and match the hash value with a stored hash list, the hash list containing hash values of local passwords preset by a user; In case the hash value is matched, determining that the local password verification is successful; If the hash value is not matched, it is determined that the local password verification fails.
7. The method according to claim 4, It is characterized in that The step of obtaining the cloud desktop identifier of the cloud desktop to be connected includes: Send the desktop connection credential request to the cloud service end; Receive the cloud desktop identifier returned by the cloud server.
8. The method according to claim 4, It is characterized in that Before verifying the local password, the method further includes: Receive the local password entered by the user for logging into the cloud desktop client for the first time; Calculate a hash value according to the local password by a preset security module, and store the hash value in a hash list; Send a cloud desktop initialization request to the cloud server, receive a ciphertext returned by the cloud server for logging into the cloud desktop, and store the ciphertext.
9. The method according to any one of claims 5, 6 and 8, It is characterized in that The method further comprises: The security module detects that a local password is received a preset number of times within a preset time range, and executes a locking operation.
10. A cloud desktop login system, It is characterized in that The system comprises: A user terminal, configured to execute the method according to any one of claims 4 to 9; A cloud service end, used to execute the method described in any one of claims 1-3.
11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, It is characterized in that The processor executes the program to implement the method according to any one of claims 1 to 9.
12. A computer-readable storage medium having a computer program stored thereon, It is characterized in that The program is executed by a processor to implement the method according to any one of claims 1 to 9.