Remote access processing method and device

By receiving access requests on the server side, creating and encrypting access tokens, the function of remote logging into the server or container is solved, and the problem of being unable to log in directly into the container in the prior art is solved, enhancing the user experience and reducing resource usage.

CN120110698APending Publication Date: 2025-06-06CHINA PETROLEUM & CHEMICAL CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311662757.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-06
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

In the prior art, it is impossible to log in directly into the container, the user experience is poor, and the server deployment method occupies a large amount of resources and makes the operation cumbersome.

Method used

By receiving user access requests on the server side, creating access tokens, encrypting them, and sending encryption tokens to the container or host to request connections, the function of remote login to the server or container is realized.

Benefits of technology

It solves the problem of not being able to log in directly into the container, enhances the user experience, reduces resource usage and operational complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110698A_ABST
    Figure CN120110698A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a remote access processing method and device, and the method comprises the steps: receiving an access request of a user, and the access request comprises an access type and access information; creating an access token according to the access type and the access information; performing encryption processing on the access token to obtain an encrypted token; sending the encryption token to a corresponding container or host to request connection; and receiving reply information of the container or the host to confirm that the connection is successful. According to the method, the function of remotely logging in the server or the container is realized, the problem that the container cannot be directly logged in in the prior art is solved, and the user experience is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a remote access processing method and device. Background Art

[0002] The existing access deployment method is server deployment. First, a server with remote control service installed must be provided. After the remote control is installed on the server, the address of the remote control service is exposed. When a user needs to log in to a server, he needs to enter the address of the remote control service in the browser, and enter the IP, account, and password of the server that needs to be remotely logged in on this page before logging in to the server. In addition, if you want to log in to a container service, you need to log in remotely through the above server, and then execute container-related commands, so as to achieve the purpose of manually entering the container service for related operations. This method requires the deployment of the environment in the early stage, which is cumbersome in practice. In addition, since this method uses server deployment, it takes up a lot of resources. Summary of the invention

[0003] The purpose of the embodiments of the present invention is to provide a remote access processing method and device, which realizes the function of remotely logging into a server or a container, solves the problem in the prior art that it is impossible to directly log into the container, and enhances the user experience.

[0004] In order to achieve the above object, an embodiment of the present invention provides a remote access processing method for a server, the method comprising:

[0005] receiving an access request from a user, wherein the access request includes an access type and access information;

[0006] Creating an access token based on the access type and access information;

[0007] Encrypting the access token to obtain an encrypted token;

[0008] Sending the encrypted token to the corresponding container or host to request a connection;

[0009] Receive a reply from the container or host to confirm that the connection was successful.

[0010] Optionally, the access type is host access or container access, the access information is host information or container information, and creating an access token according to the access type and the access information includes:

[0011] When the access object is a host, the access information is host information, and a host access token is created according to the host information;

[0012] When the access object is a container, the access information is container information, and a container access token is created according to the container information.

[0013] Optionally, the host information includes host address, host login account, host login password, and request time;

[0014] The container information includes the host address where the container is located, the host login account, the host login password, and the request time.

[0015] Optionally, the method further includes:

[0016] After establishing a connection with the container or host, send test requests regularly. If no test reply information is received from the container or host within a certain period of time, the connection is disconnected.

[0017] In another aspect, the present invention provides a remote access processing method for a host or a container, the method comprising:

[0018] Receiving an encrypted token, wherein the encrypted token is obtained by creating an access token according to the access type and access information and performing encryption processing;

[0019] Parsing the encrypted token to obtain parsing information;

[0020] Execute the parsed information;

[0021] Send a reply message to the server to confirm successful execution.

[0022] Optionally, the method further includes:

[0023] The validity of the encrypted token is verified, and if the encrypted token is within the validity period, it is decrypted to obtain decrypted information.

[0024] Optionally, the method further includes:

[0025] Receive test requests;

[0026] Send a test reply message to the server to confirm a normal connection.

[0027] On the other hand, the present invention provides a remote access processing device for use on a server side, the device comprising:

[0028] A first receiving module, configured to receive an access request from a user, wherein the access request includes an access type and access information;

[0029] A first processing module, configured to create an access token according to the access type and the access information;

[0030] A second processing module, configured to encrypt the access token to obtain an encrypted token;

[0031] A third processing module, configured to send the encrypted token to a corresponding container or host to request a connection;

[0032] The second receiving module is used to receive reply information from the container or the host to confirm that the connection is successful.

[0033] Optionally, the access type is host access or container access, the access information is host information or container information, and creating an access token according to the access type and the access information includes:

[0034] When the access object is a host, the access information is host information, and a host access token is created according to the host information;

[0035] When the access object is a container, the access information is container information, and a container access token is created according to the container information.

[0036] Optionally, the host information includes host address, host login account, host login password, and request time;

[0037] The container information includes the host address where the container is located, the host login account, the host login password, and the request time.

[0038] In another aspect, the present invention provides a remotely accessible processing device for a host or a container, the device comprising:

[0039] A third receiving module is used to receive an encrypted token, where the encrypted token is obtained by creating an access token according to the access type and access information and performing encryption processing;

[0040] A parsing module, used for parsing the encrypted token to obtain parsing information, and executing the parsing information;

[0041] The first sending module is used to send a reply message to the server to confirm the successful execution.

[0042] Optionally, the device further comprises:

[0043] The verification module is used to verify the validity of the encrypted token. If the encrypted token is within the validity period, it is decrypted to obtain decrypted information.

[0044] Optionally, the device further comprises:

[0045] A fourth receiving module, used for receiving a test request;

[0046] The second sending module is used to send a test reply message to the server to confirm a normal connection.

[0047] A remote access processing method of the present invention is used on the server side, and the method includes: receiving a user's access request, the access request including an access type and access information; creating an access token according to the access type and access information; encrypting the access token to obtain an encrypted token; sending the encrypted token to a corresponding container or host to request a connection; receiving a reply message from the container or host to confirm that the connection is successful. The present invention implements the function of remotely logging into a server or container through the deployment of a remote login service, solves the problem that the prior art can only log in to a remote host through a page and cannot directly log in to the container, and enhances the user experience.

[0048] Other features and advantages of the embodiments of the present invention will be described in detail in the subsequent detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following specific implementations, they are used to explain the embodiments of the present invention, but do not constitute a limitation on the embodiments of the present invention. In the accompanying drawings:

[0050] Figure 1 It is a flow chart of a processing method for remote access of a server side of the present invention;

[0051] Figure 2 It is a flowchart of a processing method for remote access of a host or a container of the present invention;

[0052] Figure 3 is a flow chart of an embodiment of a remote access processing method of the present invention;

[0053] Figure 4 It is a schematic diagram of an embodiment of a remote access processing method of the present invention. DETAILED DESCRIPTION

[0054] The specific implementation of the embodiment of the present invention is described in detail below in conjunction with the accompanying drawings. It should be understood that the specific implementation described here is only used to illustrate and explain the embodiment of the present invention, and is not used to limit the embodiment of the present invention.

[0055] Figure 1 It is a flowchart of a processing method for remote access to a server of the present invention, such as Figure 1 As shown, a remote access processing method of the present invention is used on a server side, and the method includes:

[0056] Step S101 is to receive an access request from a user, wherein the access request includes an access type and access information. The access type is host access or container access, and the access information is host information or container information. The present invention deploys remote services through a Docker container and sends a container or host remote login request through remote control.

[0057] Step S102 is to create an access token according to the access type and access information. Specifically, the access type is host access or container access, the access information is host information or container information, and the access token is created according to the access type and access information, including: when the access object is a host, the access information is host information, and a host access token is created according to the host information; when the access object is a container, the access information is container information, and a container access token is created according to the container information.

[0058] The host information includes the host address, host login account, host login password, and request time; the container information includes the host address where the container is located, the host login account, the host login password, and request time.

[0059] This method uses docker container technology to independently build the image of the remote service and independently write the startup file to implement docker container deployment, and modify the deployment access of the remote service to container deployment. It can ignore complex environment preparation, integrate remote access request types, merge remote access servers and remote access containers, and implement a set of services compatible with two access types. The service can be deployed and started in seconds, and has the ability to self-check and self-start after service exceptions.

[0060] Step S103 is to encrypt the access token to obtain an encrypted token. The token is an encrypted string generated by the server, which is used as an instruction for the client to make a request. Encrypting it is to encrypt it twice to increase reliability. When the access object is a host, the access information is the host information, and a host access token is created based on the host information. The host access token is encrypted to obtain a host encrypted token; when the access object is a container, the access information is the container information, and a container access token is created based on the container information. The container access token is encrypted to obtain a container encrypted token.

[0061] This method adds validity verification and secondary encryption and decryption actions during login, ensuring the security and effectiveness of the access link.

[0062] Step S104 is to send the encryption token to the corresponding container or host to request a connection. Specifically, when the access object is a host, the host encryption token is sent to the corresponding host to request a connection; when the access object is a container, the container encryption token is sent to the corresponding container to request a connection.

[0063] Step S105 is to receive a reply message from the container or host to confirm that the connection is successful. After the container or host receives the container encryption token or the host encryption token, a connection with the user is established, and a reply message is sent to the server to inform that the connection is successful. The method also includes: after establishing a connection with the container or the host, a test request is sent regularly, and if no test reply message from the container or the host is received within a certain period of time, the connection is disconnected.

[0064] The present invention implements the function of remotely logging into a server or a container by deploying a remote login service, thereby solving the problem in the prior art that the remote host can only be logged into via a page and the container cannot be directly logged into, thereby enhancing the user experience.

[0065] Figure 2 is a flow chart of a processing method for remote access of a host or container of the present invention, such as Figure 2 As shown, the present invention provides a remote access processing method for a host or a container, the method comprising:

[0066] Step S201 is to receive an encrypted token, and the encrypted token is obtained by the server creating an access token according to the access type and access information and performing encryption processing. Step S202 is to parse the encrypted token to obtain parsing information. Step S203 is to execute the parsing information. Step S204 is to send a reply message to the server to confirm successful execution. The method also includes: verifying the timeliness of the encrypted token, and if the encrypted token is within the validity period, decrypting it to obtain decrypted information. The method also includes: receiving a test request; sending a test reply message to the server to confirm a normal connection.

[0067] Figure 3 is a flow chart of an embodiment of a remote access processing method of the present invention, such as Figure 3 As shown, first the user initiates a remote access request and sends a container or host remote login request through remote control (the request interface carries host information and container information). Determine the type of remote access requested. If it is a container remote login request, create a container access token, otherwise create a host access token. After the token is generated, the host information and container information are encrypted again, and the relevant information is passed to the remote login service for remote login parsing.

[0068] The remote login service verifies the validity of the request token. If it is within the validity period, it will decrypt the request host and container information. After the remote login service decrypts the request information, it will establish a connection for remote login of the container or host based on the information and return the URL for remote login. After the remote login service returns the URL, the receiving service will re-encrypt the URL and return it to the user interface. After the user interface receives the final request return, it will open a new page containing the console of the container or host, and the user can perform related operations in the console. If there is no operation in the container or host console within ten minutes, the connection will be disconnected. If the user needs to reconnect, the remote login request must be re-initiated.

[0069] Among them, the request token carries relevant information about the request time, request host, and request container, and is encrypted to prevent information leakage. After the recipient receives the token and parses the token content to be valid, a connection channel with the request address will be established. Otherwise, the connection channel will be refused to be created.

[0070] Figure 4 is a schematic diagram of an embodiment of a remote access processing method of the present invention, such as Figure 4 As shown in the figure, the user selects the virtual server or container to be remotely logged in from the console; the console encrypts the request twice, generates a token, and sends an encryption request to the remote control service; the remote control service receives the request, verifies the token, decrypts the information, and then establishes a connection to the remote virtual server or container; after the connection is established, the information is returned to the remote control service, and the remote control service encrypts the connection information twice and returns it to the console. The console parses the connection information and creates a remote operation window that the user can use.

[0071] This method deploys remote login services based on Docker containers and implements the function of remotely logging into a server or container. It is used to solve the problem that the existing technology can only log in to the remote host through a page and cannot directly log in to the container, and when logging in to the remote host, it is necessary to configure parameters such as the host IP, host username, and host password. The remote access process is cumbersome and requires certain container knowledge. Enhance user experience. Since the relevant information of the remote login service itself is not directly exposed, the security risk of the remote login service itself is reduced.

[0072] On the other hand, the present invention provides a remote access processing device for use on a server side, the device comprising: a first receiving module for receiving an access request from a user, the access request comprising an access type and access information; a first processing module for creating an access token based on the access type and access information; a second processing module for encrypting the access token to obtain an encrypted token; a third processing module for sending the encrypted token to a corresponding container or host to request a connection; and a second receiving module for receiving a reply message from the container or host to confirm that the connection is successful.

[0073] The access type is host access or container access, the access information is host information or container information, and the creating an access token according to the access type and the access information includes: when the access object is a host, the access information is host information, and a host access token is created according to the host information; when the access object is a container, the access information is container information, and a container access token is created according to the container information. The host information includes a host address, a host login account, a host login password, and a request time; the container information includes a host address where the container is located, a host login account, a host login password, and a request time.

[0074] On the other hand, the present invention provides a remote access processing device for a host or a container, the device comprising: a third receiving module for receiving an encrypted token, the encrypted token is obtained by the server creating an access token according to the access type and access information and performing encryption processing; a parsing module for parsing the encrypted token to obtain parsing information and executing the parsing information; a first sending module for sending a reply message to the server to confirm successful execution. The device also comprises: a verification module for verifying the timeliness of the encrypted token, and if the encrypted token is within the validity period, decrypting it to obtain decrypted information. The device also comprises: a fourth receiving module for receiving a test request; a second sending module for sending a test reply message to the server to confirm a normal connection.

[0075] A remote access processing method of the present invention is used on the server side, and the method includes: receiving a user's access request, the access request including an access type and access information; creating an access token according to the access type and access information; encrypting the access token to obtain an encrypted token; sending the encrypted token to a corresponding container or host to request a connection; receiving a reply message from the container or host to confirm that the connection is successful. The present invention implements the function of remotely logging into a server or container through the deployment of a remote login service, solves the problem that the prior art can only log in to a remote host through a page and cannot directly log in to the container, and enhances the user experience.

[0076] The embodiment of the present invention further provides a storage medium on which a program is stored. When the program is executed by a processor, the remote access processing method is implemented.

[0077] An embodiment of the present invention further provides a processor, which is used to run a program, wherein the remote access processing method is executed when the program is running.

[0078] An embodiment of the present invention further provides a device, which includes a processor, a memory, and a program stored in the memory and executable on the processor. The above steps are implemented when the processor executes the program.

[0079] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a program initialized with the above method steps.

[0080] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0081] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0082] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0083] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0084] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0085] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0086] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0087] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0088] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A remote access processing method, used on the server side, It is characterized in that The method includes: receiving an access request from a user, wherein the access request includes an access type and access information; Creating an access token based on the access type and access information; Encrypting the access token to obtain an encrypted token; Sending the encrypted token to the corresponding container or host to request a connection; Receive a reply from the container or host to confirm that the connection was successful.

2. The method according to claim 1, It is characterized in that The access type is host access or container access, the access information is host information or container information, and creating an access token according to the access type and the access information includes: When the access object is a host, the access information is host information, and a host access token is created according to the host information; When the access object is a container, the access information is container information, and a container access token is created according to the container information.

3. The method according to claim 2, It is characterized in that The host information includes host address, host login account, host login password, and request time; The container information includes the host address where the container is located, the host login account, the host login password, and the request time.

4. The method according to claim 1, It is characterized in that The method further includes: After establishing a connection with the container or host, send test requests regularly. If no test reply information is received from the container or host within a certain period of time, the connection is disconnected.

5. A remote access processing method for a host or a container, It is characterized in that The method includes: Receiving an encrypted token, wherein the encrypted token is obtained by creating an access token according to the access type and access information and performing encryption processing; Parsing the encrypted token to obtain parsing information; Execute the parsed information; Send a reply message to the server to confirm successful execution.

6. The method according to claim 5, It is characterized in that The method further includes: The validity of the encrypted token is verified, and if the encrypted token is within the validity period, it is decrypted to obtain decrypted information.

7. The method according to claim 5, It is characterized in that The method further includes: Receive test requests; Send a test reply message to the server to confirm a normal connection.

8. A remote access processing device, used on a server side, It is characterized in that The device includes: A first receiving module, configured to receive an access request from a user, wherein the access request includes an access type and access information; A first processing module, configured to create an access token according to the access type and the access information; A second processing module, configured to encrypt the access token to obtain an encrypted token; A third processing module, configured to send the encrypted token to a corresponding container or host to request a connection; The second receiving module is used to receive reply information from the container or the host to confirm that the connection is successful.

9. The device according to claim 8, It is characterized in that The access type is host access or container access, the access information is host information or container information, and creating an access token according to the access type and the access information includes: When the access object is a host, the access information is host information, and a host access token is created according to the host information; When the access object is a container, the access information is container information, and a container access token is created according to the container information.

10. The device according to claim 9, It is characterized in that The host information includes host address, host login account, host login password, and request time; The container information includes the host address where the container is located, the host login account, the host login password, and the request time.

11. A remotely accessible processing device for a host or a container, It is characterized in that The device includes: A third receiving module is used to receive an encrypted token, where the encrypted token is obtained by creating an access token according to the access type and access information and performing encryption processing; A parsing module, used for parsing the encrypted token to obtain parsing information, and executing the parsing information; The first sending module is used to send a reply message to the server to confirm the successful execution.

12. The device according to claim 11, It is characterized in that The device also includes: The verification module is used to verify the validity of the encrypted token. If the encrypted token is within the validity period, it is decrypted to obtain decrypted information.

13. The device according to claim 11, It is characterized in that The device also includes: A fourth receiving module, used for receiving a test request; The second sending module is used to send a test reply message to the server to confirm a normal connection.