Cloud desktop access method, target zero-trust gateway and cloud desktop access system
By establishing multiple communication connections with zero trust gateways and application gateways on client devices, the cloud desktop application access problem caused by hierarchical management platform failure is solved, achieving higher reliability and simplified configuration process.
Patent Information
- Application Number
- CN202510369732.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-06-10
AI Technical Summary
In the prior art, when the hierarchical management platform is prone to failure, it will cause the user to be unable to access multiple cloud desktop applications.
Access to multiple cloud desktop applications is achieved by establishing multiple first communication connections and zero trust gateways on the client device and establishing a second communication connection with multiple application gateways.
Reduces deployment resources, simplifies the difficulty of software configuration, reduces system maintenance, and effectively avoids the inaccessibility of multiple cloud desktop applications due to a component failure.
Smart Images

Figure CN120128409A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and particularly relates to a cloud desktop access method, a target zero-trust gateway, and a cloud desktop access system. Background Art
[0002] A cloud desktop (Cloud Desktop), also known as a virtual desktop infrastructure (VDI, Virtual Desktop Infrastructure), is a cloud computing technology that enables users to access a virtualized desktop environment through a network. All desktop environments and data are centralized on cloud servers, facilitating management and maintenance. Users can access their desktops anytime and anywhere through various devices (such as computers, tablets, and smartphones).
[0003] Currently, there are multiple cloud desktops in some enterprises, and it is somewhat difficult for users to manage and access them. However, by docking the cloud desktop solution through zero-trust technology, the security and management efficiency can be effectively enhanced. After deploying the zero-trust access mechanism, strict authentication is required every time the cloud desktop is accessed to ensure that the user is authorized and prevent unauthorized access.
[0004] For the data transmission of accessing multiple cloud desktops based on the existing zero-trust mechanism, it is managed by a hierarchical management platform. When the hierarchical management platform is prone to failures, it will lead to the problem that users cannot access multiple cloud desktops. Summary of the Invention
[0005] In view of this, this application proposes a cloud desktop access method, a target zero-trust gateway, and a cloud desktop access system to solve the problem in the related technology that when the hierarchical management platform is prone to failures, it will lead to the problem that users cannot access multiple cloud desktops.
[0006] The first aspect of the embodiments of this application proposes a cloud desktop access method, and the method is applied to a client device; the method includes:
[0007] In response to receiving an access instruction to access multiple cloud desktop applications, send the identity information of the client device to the cloud desktop controller;
[0008] After receiving multiple zero-trust gateway addresses from the cloud desktop controller, respectively establish multiple first communication connections between the client device and multiple zero-trust gateways;
[0009] Send an access request containing the corresponding cloud desktop port information to the corresponding zero-trust gateway through any one of the first communication connections, so that the zero-trust gateway establishes a second communication connection with the application gateway corresponding to the cloud desktop port information;
[0010] Access the multiple cloud desktop applications through the multiple first communication connections and the multiple second communication connections corresponding to the multiple first communication connections.
[0011] In the embodiments of the present application, by establishing multiple first communication connections between the client device and multiple zero-trust gateways, and establishing multiple second communication connections between the multiple zero-trust gateways and multiple application gateways, the purpose of accessing multiple cloud desktop applications through the multiple first communication connections and the multiple second communication connections corresponding to the multiple first communication connections is achieved. It can reduce the deployment resources (i.e., the hierarchical management platform), simplify the software configuration difficulty, thereby reducing the system maintenance difficulty, and can effectively avoid the situation where multiple cloud desktop applications cannot be accessed due to the failure of a certain component.
[0012] In the embodiments of the present application, the client device includes an access client and an authentication client; in response to receiving an access instruction to access multiple cloud desktop applications, sending the identity information of the client device to the cloud desktop controller includes:
[0013] The access client, in response to receiving an access instruction to access multiple cloud desktop applications, transmits the identity information of the access client to the authentication client bound to the access client;
[0014] The authentication client sends the identity information of the access client to the cloud desktop controller and receives multiple zero-trust gateway addresses from the cloud desktop controller.
[0015] In the embodiments of the present application, after sending the identity information of the client device to the cloud desktop controller, the method further includes: receiving user authentication information from the cloud desktop controller;
[0016] Establishing multiple first communication connections between the client device and multiple zero-trust gateways respectively, including:
[0017] According to the multiple zero-trust gateway addresses, sending communication connection requests containing the user authentication information to the multiple zero-trust gateways respectively, so that each zero-trust gateway authenticates the user authentication information;
[0018] Receiving connection responses sent by each zero-trust gateway to establish a first communication connection between each zero-trust gateway and the client device, and obtaining multiple first communication connections between the client device and the multiple zero-trust gateways.
[0019] In the embodiments of the present application, sending an access request containing corresponding cloud desktop port information to the corresponding zero-trust gateway through any one of the first communication connections, so that the zero-trust gateway establishes a second communication connection with the application gateway corresponding to the cloud desktop port information, includes:
[0020] For any first communication connection, an access request including corresponding cloud desktop port information is sent to the corresponding zero-trust gateway through the first communication connection, so that the corresponding zero-trust gateway filters out a target application gateway that matches the corresponding cloud desktop port information from multiple application gateways, and establishes a second communication connection between the target zero-trust gateway and the target application gateway.
[0021] An embodiment of the second aspect of the present application provides a target zero-trust gateway, and the target zero-trust gateway is any one of multiple zero-trust gateways;
[0022] The target zero-trust gateway receives a communication connection request including user authentication information from a client device, and authenticates the user authentication information;
[0023] After the authentication is passed, a connection reply is sent to the client device, so that a first communication connection is established between the client device and the target zero-trust gateway;
[0024] Receive an access request including corresponding cloud desktop port information from the client device, and filter out a target application gateway that matches the corresponding cloud desktop port information from multiple application gateways;
[0025] Establish a second communication connection between the target zero-trust gateway and the target application gateway;
[0026] Access the corresponding cloud desktop application through the first communication connection and the second communication connection.
[0027] An embodiment of the third aspect of the present application provides a cloud desktop access system, and the system includes: an authentication client, an access client, a cloud desktop controller, multiple zero-trust gateways, and multiple application gateways; the multiple application gateways correspond to multiple cloud desktop applications;
[0028] The authentication client is configured to, in response to receiving an access instruction to access multiple cloud desktop applications, send identity information to the cloud desktop controller;
[0029] The cloud desktop controller is configured to authenticate the identity information to obtain user authentication information, and match multiple zero-trust gateway addresses and multiple cloud desktop port information corresponding to the identity information, and send the user authentication information, the multiple zero-trust gateway addresses, and the multiple cloud desktop port information to the authentication client;
[0030] The authentication client is further configured to forward the user authentication information, the multiple zero-trust gateway addresses, and the multiple cloud desktop port information to the access client;
[0031] The access client is used to receive the user authentication information, the multiple zero-trust gateway addresses, and the multiple cloud desktop port information; send communication connection requests containing the user authentication information to the multiple zero-trust gateways respectively; send access requests containing the corresponding cloud desktop port information to the multiple zero-trust gateways respectively.
[0032] Any zero-trust gateway is used to authenticate the user authentication information; after successful authentication, send a connection reply to the access client to establish a first communication connection between the access client and the zero-trust gateway; screen out the target application gateway that matches the corresponding cloud desktop port information from the multiple application gateways, and establish a second communication connection between the zero-trust gateway and the target application gateway.
[0033] Any application gateway is used to allow the access client to access the corresponding cloud desktop application through the corresponding first communication connection and the corresponding second communication connection.
[0034] In the embodiment of the present application, the cloud desktop controller is further used to create multiple cloud desktop applications, and authorize one or more cloud desktop applications for the authenticated client after identity authentication.
[0035] An embodiment of the fourth aspect of the present application provides a cloud desktop access device, and the device includes:
[0036] An identity information sending module, configured to send the identity information of the client device to the cloud desktop controller in response to receiving an access instruction to access multiple cloud desktop applications.
[0037] A first communication connection establishment module, configured to establish multiple first communication connections between the client device and multiple zero-trust gateways respectively after receiving multiple zero-trust gateway addresses from the cloud desktop controller.
[0038] A second communication connection establishment module, configured to send an access request containing the corresponding cloud desktop port information to the corresponding zero-trust gateway through any one of the first communication connections, so that the zero-trust gateway establishes a second communication connection with the application gateway corresponding to the cloud desktop port information.
[0039] A cloud desktop application access module, configured to access the multiple cloud desktop applications through the multiple first communication connections and the multiple second communication connections corresponding to the multiple first communication connections.
[0040] An embodiment of the fifth aspect of the present application provides a computer device, which includes a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the cloud desktop access method described in the first aspect above.
[0041] An embodiment of the sixth aspect of the present application provides a computer-readable storage medium, on which computer instructions are stored, and the computer instructions are used to cause a computer to execute the cloud desktop access method described in the first aspect above.
[0042] Additional aspects and advantages of the present application will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to limit the present application. Moreover, throughout the drawings, the same reference numerals are used to represent the same components.
[0044] In the drawings:
[0045] Figure 1 A flowchart showing a cloud desktop access method provided by an embodiment of the present application is shown;
[0046] Figure 2 A system structure diagram of a cloud desktop access system provided by an embodiment of the present application is shown;
[0047] Figure 3 A flowchart showing a method for optimizing the use scenario of a zero-trust solution docking multiple sets of cloud desktops provided by an embodiment of the present application is shown;
[0048] Figure 4 A structure diagram of a cloud desktop access device provided by an embodiment of the present application is shown;
[0049] Figure 5 A structure diagram of a computer device provided by an embodiment of the present application is shown;
[0050] Figure 6 A schematic diagram of a storage medium provided by an embodiment of the present application is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0051] Hereinafter, the exemplary embodiments of the present application will be described in more detail with reference to the drawings. Although the exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present application can be more thoroughly understood and the scope of the present application can be fully conveyed to those skilled in the art.
[0052] It should be noted that, unless otherwise specified, the technical terms or scientific terms used in this application should have the ordinary meanings understood by those skilled in the art to which this application belongs.
[0053] According to an embodiment of the present application, an embodiment of a cloud desktop access method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0054] Embodiment 1:
[0055] In this embodiment, a cloud desktop access method is provided, which can be used for a client device. Figure 1 is a flowchart of the cloud desktop access method according to an embodiment of the present application, as Figure 1 shown, the process includes the following steps:
[0056] Step S101, in response to receiving an access instruction to access multiple cloud desktop applications, send the identity information of the client device to the cloud desktop controller.
[0057] Specifically, after receiving the identity information of the client device, the cloud desktop controller will first screen out multiple cloud desktop applications whose identity information is authorized to be accessed from all cloud desktop applications, and then screen out multiple zero-trust gateway addresses corresponding one-to-one to the multiple cloud desktop applications from all zero-trust gateway addresses; send the multiple zero-trust gateway addresses to the client device, so that the client device can establish multiple first communication connections with multiple zero-trust gateways through the multiple zero-trust gateway addresses.
[0058] More specifically, for example Figure 2 shown, the client device includes an access client and an authentication client. Among them, the authentication client is used to interact with the cloud desktop controller to authenticate the identity of the user logging in to the client, and the access client is used to access the cloud desktop application.
[0059] In some specific embodiments, the above step S101 includes steps S1011 - step S1022:
[0060] Step S1011, in response to receiving an access instruction to access multiple cloud desktop applications, the access client transmits the identity information of the access client to the authentication client bound to the access client.
[0061] Wherein, the binding of the access client and the authentication client means that the identity information of the logged-in users of the two clients is the same.
[0062] In the embodiments of the present application, before each call to the access client to access the cloud desktop application, it is necessary to call the authentication client to authenticate the logged-in user, and the identity information includes but is not limited to the username, password, and random number; wherein, the random number is generated according to the identity authentication request, that is, the random numbers generated for each authentication request are different.
[0063] Step S1012, the authentication client sends the identity information of the access client to the cloud desktop controller and receives multiple zero-trust gateway addresses from the cloud desktop controller.
[0064] In the embodiments of the present application, after receiving the identity information, the cloud desktop controller authenticates the identity information to obtain user authentication information (including but not limited to user token), and adds the IP address of the access client to the whitelist; and matches multiple zero-trust gateway addresses and multiple cloud desktop port information corresponding to the identity information; sends the user authentication information, multiple zero-trust gateway addresses, and multiple cloud desktop port information to the authentication client. Among them, multiple zero-trust gateway addresses correspond to multiple zero-trust gateways (SDP gateways) one by one.
[0065] In some specific embodiments, after receiving the identity information, the cloud desktop controller may generate an application list according to the identity information, and the application list contains multiple cloud desktop applications that can be accessed. At the same time, the cloud desktop controller will send the cloud desktop applications that the user can access and their access permissions to the corresponding zero-trust gateway.
[0066] Step S102, after receiving multiple zero-trust gateway addresses from the cloud desktop controller, establish multiple first communication connections between the client device and multiple zero-trust gateways respectively.
[0067] In some specific embodiments, the above step S102 includes steps S1021 - S1022:
[0068] Step S1021, according to the multiple zero-trust gateway addresses, send communication connection requests containing the user authentication information to the multiple zero-trust gateways respectively, so that each zero-trust gateway authenticates the user authentication information.
[0069] In the embodiments of the present application, the access client sends a communication connection request to the corresponding zero-trust gateway through each zero-trust gateway address (the message of the connection request includes an extended field, and the user authentication information is carried in the extended field), and the corresponding zero-trust gateway authenticates the user authentication information. If the authentication is passed, a connection reply is returned to the access client.
[0070] Step S1022: Receive the connection responses sent by each zero-trust gateway to establish a first communication connection between each zero-trust gateway and the client device, and obtain multiple first communication connections between the client device and the multiple zero-trust gateways.
[0071] In the embodiments of the present application, after the access client receives the connection response sent by the corresponding zero-trust gateway, it will establish a first communication connection between the access client and the corresponding zero-trust gateway according to the connection response, so as to obtain multiple first communication connections between the access client and multiple zero-trust gateways.
[0072] Step S103: Send an access request containing the corresponding cloud desktop port information to the corresponding zero-trust gateway through any one of the first communication connections, so that the zero-trust gateway establishes a second communication connection with the application gateway corresponding to the cloud desktop port information.
[0073] Specifically, multiple application gateways correspond to multiple cloud desktop applications one by one. Each application gateway is used to manage and control the communication connection between the client device and the corresponding cloud desktop application. The client device can access the corresponding cloud desktop application through the application gateway.
[0074] In the embodiments of the present application, multiple first communication connections, multiple zero-trust gateways, and multiple cloud desktop applications correspond to each other one by one. After the client device establishes communication connections with multiple zero-trust gateways through multiple first communication connections, the client will send the cloud desktop port information corresponding to each zero-trust gateway to each zero-trust gateway, so that the zero-trust gateway screens out the application gateway corresponding to the cloud desktop port information from all application gateways and establishes a second communication connection between the zero-trust gateway and the application gateway, so that the client device can access multiple cloud desktop applications through multiple first communication connections and multiple second communication connections.
[0075] In some specific embodiments, the above step S103 includes step 1031:
[0076] Step 1031: For any one of the first communication connections, send an access request containing the corresponding cloud desktop port information to the corresponding zero-trust gateway through the first communication connection, so that the corresponding zero-trust gateway screens out the target application gateway that matches the corresponding cloud desktop port information from multiple application gateways, and establishes a second communication connection between the target zero-trust gateway and the target application gateway.
[0077] Specifically, when the access client sends an access request to the corresponding zero-trust gateway through any one of the first communication connections, the corresponding zero-trust gateway will match the target application gateway corresponding to it according to the cloud desktop port information in the access request, so as to establish a second communication connection between the corresponding zero-trust gateway and the target application gateway. An example is given to illustrate this:
[0078] Assume that an access client A establishes multiple first communication connections C1, C2, ..., Cn with multiple zero-trust gateways B1, B2, ..., Bn. Among them, C1 represents the first communication connection between A and B1, C2 represents the first communication connection between A and B2, and Cn represents the first communication connection between A and Bn. There are multiple application gateways D1, D2, ..., Dn, and each application gateway is connected to a corresponding cloud desktop application (E1, E2, ..., En), that is: D1 - E1, D2 - E2, ..., Dn - En;
[0079] When A sends an access request containing cloud desktop port information e1 to B1 through C1, B1 will screen out the target application gateway D1 corresponding to e1 from multiple application gateways D1, D2, ..., Dn, so as to establish a second communication connection F1 between B1 and D1. Thus, the access client A can access the cloud desktop application E1 through the first communication connection C1 (A → B1) and the second communication connection F1 (B1 → D1), for example Figure 2 in "access client → zero-trust gateway → application gateway → cloud desktop application".
[0080] Step S104, access the multiple cloud desktop applications through the multiple first communication connections and the multiple second communication connections corresponding to the multiple first communication connections.
[0081] Specifically, the embodiment of the present application can realize the access to multiple cloud desktop applications by establishing multiple first communication connections and multiple second communication connections corresponding to the multiple first communication connections.
[0082] The embodiment of the present application can simplify the difficulty of software configuration, reduce the system dimension, and avoid the situation that multiple cloud desktop applications cannot be accessed through zero trust when the hierarchical management platform fails by reducing the deployed resources (hierarchical management platform). And by directly forwarding the access request to the cloud platform containing multiple cloud desktop applications through the application gateway (i.e., VDI gateway), its performance is greatly improved.
[0083] Embodiment 2:
[0084] Corresponding to the implementation manner of the above cloud desktop access method, a target zero-trust gateway is further provided in this embodiment. The target zero-trust gateway is any one of the multiple zero-trust gateways in Embodiment 1 above;
[0085] The target zero-trust gateway receives a communication connection request containing user authentication information from a client device and authenticates the user authentication information;
[0086] After successful authentication, send a connection response to the client device to establish a first communication connection between the client device and the target zero-trust gateway;
[0087] Receive an access request from the client device that contains the corresponding cloud desktop port information, and screen out a target application gateway that matches the corresponding cloud desktop port information from multiple application gateways;
[0088] Establish a second communication connection between the target zero-trust gateway and the target application gateway;
[0089] Access the corresponding cloud desktop application through the first communication connection and the second communication connection.
[0090] In the embodiment of the present application, when the target zero-trust gateway receives a communication connection request sent by the client device, the target zero-trust gateway authenticates the user authentication information in the communication connection request. If the authentication is successful, a connection response signal is sent back to the client device, and the client device will establish a first communication connection with the target zero-trust gateway after receiving the connection response signal. When the target zero-trust gateway receives an access request from the client device, it will screen out a target application gateway that matches the corresponding cloud desktop port information from multiple application gateways according to the cloud desktop application information in the access request, thereby establishing a second communication connection between the target zero-trust gateway and the target application gateway, and further achieving the purpose of the client device accessing the corresponding cloud desktop application through the first communication connection and the second communication connection.
[0091] Embodiment 3:
[0092] Corresponding to the implementation manner of the above cloud desktop access method, the embodiment of the present application further provides a cloud desktop access system, for example Figure 2 As shown: The cloud desktop access system includes an authentication client, an access client, a cloud desktop controller, multiple zero-trust gateways, and multiple application gateways; the multiple application gateways correspond to multiple cloud desktop applications;
[0093] The authentication client is used to send identity information to the cloud desktop controller in response to receiving an access instruction to access multiple cloud desktop applications;
[0094] The cloud desktop controller is used to authenticate the identity information to obtain user authentication information, and match multiple zero-trust gateway addresses and multiple cloud desktop port information corresponding to the identity information, and send the user authentication information, the multiple zero-trust gateway addresses, and the multiple cloud desktop port information to the authentication client;
[0095] The authentication client is further configured to forward the user authentication information, the multiple zero-trust gateway addresses, and the multiple cloud desktop port information to the access client;
[0096] The access client is configured to receive the user authentication information, the multiple zero-trust gateway addresses, and the multiple cloud desktop port information; send communication connection requests containing the user authentication information to the multiple zero-trust gateways respectively; send access requests containing the corresponding cloud desktop port information to the multiple zero-trust gateways respectively;
[0097] Any zero-trust gateway is configured to authenticate the user authentication information; after successful authentication, send a connection response to the access client to establish a first communication connection between the access client and the zero-trust gateway; screen out a target application gateway that matches the corresponding cloud desktop port information from the multiple application gateways, and establish a second communication connection between the zero-trust gateway and the target application gateway;
[0098] Any application gateway is configured to allow the access client to access the corresponding cloud desktop application through the corresponding first communication connection and the corresponding second communication connection.
[0099] In some specific embodiments, the cloud desktop controller is further configured to create multiple cloud desktop applications, and authorize one or more cloud desktop applications to the authenticated authentication client.
[0100] In the embodiments of the present application, the specific embodiments of each step can refer to the relevant descriptions in Embodiment 1 above, and will not be repeated here.
[0101] Embodiment 4:
[0102] Currently, when docking multiple sets of cloud desktop application scenarios, a hierarchical management platform is used as a middleware to forward traffic, but this method has the following technical problems: 1. The addition of the hierarchical management platform will increase the configuration difficulty of the entire solution. 2. If the hierarchical platform fails, it will lead to the unavailability of the overall function. 3. The hierarchical management platform may become a performance bottleneck. 4. The overall solution is slightly complex and the access process is cumbersome.
[0103] The following takes the authentication client implemented as iNode, the access client implemented as workspace client, the zero-trust gateway implemented as SDP gateway, and the application gateway implemented as VDI gateway as an example to illustrate a method for optimizing the use scenario of a zero-trust solution for docking multiple sets of cloud desktops provided by the embodiments of the present application:
[0104] For example Figure 3 As shown, the specific process includes:
[0105] 1) The iNode carries the aid, random number, and password to perform SPA authentication with the controller, and adds the terminal IP to the whitelist.
[0106] 2) After the user's SPA authentication is successful, the user logs in. After successful authentication, there are the following two operations:
[0107] The controller sends the username, the virtual address assigned by the controller to the iNode client, aid, key, token, and authorized cloud desktop application permission information to the SDP gateway.
[0108] The controller returns the user token, multiple SDP gateway IPs, the authentication ports of multiple SDP gateways, the tcp proxy ports (i.e., application ports) of multiple SDP gateways, the SDP terminal aid and key (only returned for the first login), and the list of accessible applications to the terminal.
[0109] 3) The iNode launches the workspace client and passes the username, password, user token, the IPs and tcp proxy ports of multiple SDP gateways.
[0110] 4) The iNode terminal sends a SPA authentication request to multiple SDP gateways, carrying the authentication port and tcp proxy port. After successful authentication, the SDP gateway adds the IP and port to the whitelist.
[0111] 5) The iNode terminal initiates an ssl connection request to multiple SDP gateways with the user token and obtains the token from the previous gateway for authentication. After successful authentication, the SSL connection is successfully established, and the SDP gateway returns information such as the virtual network card IP and the route to the application.
[0112] 6) The iNode adds an IP address to the virtual network card, and the terminal adds the routing information of the accessible tunnel resources to the SDP terminal, and designates the next hop of the tunnel resources accessible by this user as the address of the virtual network card (excluding cloud desktop applications).
[0113] 7) The workspace client inserts the user token information into the ClientHello message and initiates an ssl connection to multiple sets of SDP gateways.
[0114] 8) Multiple sets of SDP gateways verify the user token and perform permission checks on the accessed applications.
[0115] 9) After successful authentication by the SDP gateway, it initiates an ssl connection to multiple VDI gateways respectively.
[0116] 10) The VDI gateway forwards the traffic to the cloud desktop management platform and successfully accesses multiple sets of cloud desktops.
[0117] 11) The controller executes user logout and sends a user logout message to the gateway.
[0118] 12) The gateway deletes the online user information, disconnects the TCP proxy connection, disconnects the sslvpn tunnel, and notifies the iNode user to log out.
[0119] The embodiment of the present application is directed to the multi-cloud desktop scenario, without hierarchical management, and can directly change on the single-set cloud desktop environment process, saving deployment resources and reducing the system maintenance volume. It can reduce deployment resources, simplify the software configuration difficulty, reduce the system dimension, and also avoid the situation where multiple cloud desktop applications cannot access through zero trust when the hierarchical management platform fails. And by directly forwarding the access request to the cloud platform containing multiple cloud desktop applications through the application gateway (i.e., the VDI gateway), its performance is greatly improved.
[0120] Embodiment 5:
[0121] Corresponding to the implementation manner of the above cloud desktop access method, the embodiment of the present application further provides a cloud desktop access device for executing the cloud desktop access method described in the above embodiment. As Figure 4 shown, the cloud desktop access device includes:
[0122] An identity information sending module, configured to send the identity information of the client device to the cloud desktop controller in response to receiving an access instruction for accessing multiple cloud desktop applications;
[0123] A first communication connection establishment module, configured to respectively establish a plurality of first communication connections between the client device and a plurality of zero trust gateways after receiving a plurality of zero trust gateway addresses from the cloud desktop controller;
[0124] A second communication connection establishment module, configured to send an access request including corresponding cloud desktop port information to the corresponding zero trust gateway through any one of the first communication connections, so that the zero trust gateway establishes a second communication connection with the application gateway corresponding to the cloud desktop port information;
[0125] A cloud desktop application access module, configured to access the multiple cloud desktop applications through the plurality of first communication connections and the plurality of second communication connections corresponding to the plurality of first communication connections.
[0126] Optionally, the identity information sending module is further configured to, in response to receiving an access instruction for accessing multiple cloud desktop applications, transmit the identity information of the access client to the authentication client bound to the access client; the authentication client sends the identity information of the access client to the cloud desktop controller and receives a plurality of zero trust gateway addresses from the cloud desktop controller.
[0127] Optionally, the device further includes an authentication information receiving module, configured to receive user authentication information from the cloud desktop controller after sending the identity information of the client device to the cloud desktop controller;
[0128] Optionally, the first communication connection establishment module is further configured to send communication connection requests including the user authentication information to the multiple zero-trust gateways respectively according to the multiple zero-trust gateway addresses, so that each zero-trust gateway authenticates the user authentication information; receive connection responses sent by each zero-trust gateway to establish a first communication connection between each zero-trust gateway and the client device, and obtain multiple first communication connections between the client device and the multiple zero-trust gateways.
[0129] Optionally, the second communication connection establishment module is further configured to, for any one of the first communication connections, send an access request including the corresponding cloud desktop port information to the corresponding zero-trust gateway through the first communication connection, so that the corresponding zero-trust gateway filters out a target application gateway that matches the corresponding cloud desktop port information from multiple application gateways, and establish a second communication connection between the target zero-trust gateway and the target application gateway.
[0130] The cloud desktop access device provided in the above embodiments of the present application and the cloud desktop access method provided in the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the application programs stored therein.
[0131] The embodiments of the present application further provide a computer device, which can be used as a client device or a zero-trust gateway. When the computer device is used as a client device (including an authentication client and an access client), it can execute some or all of the steps executed by the authentication client and the access client, or the iNode client and the workspace client in the above cloud desktop access method. When the computer device is used as a zero-trust gateway, it can execute some or all of the steps executed by the zero-trust network management or the SDP gateway in the above cloud desktop access method.
[0132] Please refer to Figure 5 which shows a schematic diagram of a computer device provided in some embodiments of the present application. As Figure 5 shown, the computer device 5 includes: a processor 500, a memory 501, a bus 502, and a communication interface 503. The processor 500, the communication interface 503, and the memory 501 are connected through the bus 502; a computer program that can run on the processor 500 is stored in the memory 501, and when the processor 500 runs the computer program, it executes the cloud desktop access method provided in the foregoing embodiments of the present application.
[0133] Among them, the memory 501 may include high-speed random access memory (RAM), and may also include non-volatile memory, such as at least one disk memory. The communication connection between the system network element and at least one other network element is realized through at least one communication interface 503 (which can be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. can be used.
[0134] The bus 502 can be an ISA bus, a PCI bus, an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. Among them, the memory 501 is used to store a program, and after receiving an execution instruction, the processor 500 executes the program. The cloud desktop access method disclosed in the foregoing embodiments can be applied to the processor 500 or implemented by the processor 500.
[0135] The processor 500 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 500 or by instructions in software form. The above-mentioned processor 500 may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 501, and the processor 500 reads the information in the memory 501 and combines its hardware to complete the steps of the above method.
[0136] The computer device provided by the embodiments of the present application and the cloud desktop access method provided by the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run, or implemented by them.
[0137] The embodiments of the present application also provide a computer-readable storage medium corresponding to the cloud desktop access method provided by the foregoing embodiments. Please refer to Figure 6, which shows that the computer-readable storage medium is an optical disc 30, on which a computer program (i.e., program product) is stored. When the computer program is run by a processor, it will execute the cloud desktop access method provided by any of the foregoing embodiments.
[0138] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other optical and magnetic storage media, which will not be elaborated here one by one.
[0139] The computer-readable storage medium provided by the above embodiments of the present application and the cloud desktop access method provided by the embodiments of the present application are based on the same inventive concept and have the same beneficial effects as the methods adopted, run, or implemented by the application programs stored therein.
[0140] It should be noted that:
[0141] In the specification provided here, a large number of specific details are described. However, it can be understood that the embodiments of the present application can be practiced without these specific details. In some instances, well-known structures and technologies are not shown in detail so as not to obscure the understanding of this specification.
[0142] Similarly, it should be understood that, in order to streamline the present application and help understand one or more of the various inventive aspects, in the above description of the exemplary embodiments of the present application, the various features of the present application are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting the following schematic: that the claimed present application requires more features than those expressly recited in each claim. Rather, as reflected in the following claims, the inventive aspect lies in less than all the features of the single embodiment disclosed above. Therefore, the claims following the detailed description are hereby expressly incorporated into the detailed description, where each claim itself serves as a separate embodiment of the present application.
[0143] In addition, those skilled in the art can understand that although some of the embodiments described herein include certain features included in other embodiments but not other features, the combination of the features of different embodiments means that it is within the scope of the present application and forms different embodiments. For example, in the following claims, any of the claimed embodiments can be used in any combination.
[0144] As described above, it is only the preferred specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A cloud desktop access method, characterized in that: The method is applied to a client device; the method comprises: In response to receiving an access instruction to access a plurality of cloud desktop applications, sending the identity information of the client device to a cloud desktop controller; After receiving multiple zero-trust gateway addresses from the cloud desktop controller, establish multiple first communication connections between the client device and the multiple zero-trust gateways respectively; Sending an access request including corresponding cloud desktop port information to the corresponding zero-trust gateway through any first communication connection, so that the zero-trust gateway establishes a second communication connection with the application gateway corresponding to the cloud desktop port information; The plurality of cloud desktop applications are accessed through the plurality of first communication connections and a plurality of second communication connections corresponding to the plurality of first communication connections.
2. The method according to claim 1, characterized in that The client device includes an access client and an authentication client; In response to receiving an access instruction to access a plurality of cloud desktop applications, sending the identity information of the client device to the cloud desktop controller includes: The access client transmits the identity information of the access client to the authentication client bound to the access client in response to receiving the access instruction to access the plurality of cloud desktop applications; The authentication client sends the identity information of the access client to the cloud desktop controller, and receives multiple zero-trust gateway addresses from the cloud desktop controller.
3. The method according to claim 1, characterized in that After sending the identity information of the client device to the cloud desktop controller, the method further includes: receiving user authentication information from the cloud desktop controller; Establishing a plurality of first communication connections between the client device and a plurality of zero-trust gateways respectively includes: According to the multiple zero-trust gateway addresses, respectively send communication connection requests containing the user authentication information to the multiple zero-trust gateways, so that each zero-trust gateway authenticates the user authentication information; A connection response sent by each zero-trust gateway is received to establish a first communication connection between each zero-trust gateway and the client device, thereby obtaining multiple first communication connections between the client device and the multiple zero-trust gateways.
4. The method according to claim 1 or 2, characterized in that: Sending an access request including corresponding cloud desktop port information to a corresponding zero-trust gateway through any first communication connection, so that the zero-trust gateway establishes a second communication connection with an application gateway corresponding to the cloud desktop port information, including: For any first communication connection, an access request containing corresponding cloud desktop port information is sent to the corresponding zero trust gateway through the first communication connection, so that the corresponding zero trust gateway filters out a target application gateway that matches the corresponding cloud desktop port information from multiple application gateways, and establishes a second communication connection between the target zero trust gateway and the target application gateway.
5. A target zero-trust gateway, characterized in that: The target zero-trust gateway is any one of multiple zero-trust gateways; The target zero-trust gateway receives a communication connection request including user authentication information from a client device, and authenticates the user authentication information; After the authentication is passed, a connection response is sent to the client device to establish a first communication connection between the client device and the target zero-trust gateway; Receiving an access request including corresponding cloud desktop port information from the client device, and screening out a target application gateway matching the corresponding cloud desktop port information from a plurality of application gateways; Establishing a second communication connection between the target zero trust gateway and the target application gateway; The corresponding cloud desktop application is accessed through the first communication connection and the second communication connection.
6. A cloud desktop access system, the system comprising: Authentication client, access client, cloud desktop controller, multiple zero-trust gateways, and multiple application gateways; The multiple application gateways correspond to multiple cloud desktop applications; an authentication client, configured to send identity information to the cloud desktop controller in response to receiving an access instruction to access a plurality of cloud desktop applications; The cloud desktop controller is used to authenticate the identity information to obtain user authentication information, match multiple zero-trust gateway addresses and multiple cloud desktop port information corresponding to the identity information, and send the user authentication information, the multiple zero-trust gateway addresses and the multiple cloud desktop port information to the authentication client; The authentication client is further used to forward the user authentication information, the multiple zero-trust gateway addresses and the multiple cloud desktop port information to the access client; The access client is used to receive the user authentication information, the multiple zero-trust gateway addresses and the multiple cloud desktop port information; Sending communication connection requests containing user authentication information to the multiple zero-trust gateways respectively; Sending access requests including corresponding cloud desktop port information to the multiple zero-trust gateways respectively; Any zero-trust gateway, used to authenticate the user authentication information; After the authentication is passed, a connection response is sent to the access client to establish a first communication connection between the access client and the zero-trust gateway; Filter out a target application gateway that matches the corresponding cloud desktop port information from the multiple application gateways, and establish a second communication connection between the zero trust gateway and the target application gateway; Any application gateway is used to allow the access client to access the corresponding cloud desktop application through the corresponding first communication connection and the corresponding second communication connection.
7. The system according to claim 6, characterized in that The cloud desktop controller is also used to create multiple cloud desktop applications and authorize one or more cloud desktop applications for the authenticated client after identity authentication.
8. A cloud desktop access device, characterized in that: The device comprises: an identity information sending module, configured to send the identity information of the client device to the cloud desktop controller in response to receiving an access instruction to access a plurality of cloud desktop applications; A first communication connection establishing module, configured to respectively establish a plurality of first communication connections between the client device and a plurality of zero-trust gateways after receiving a plurality of zero-trust gateway addresses from the cloud desktop controller; A second communication connection establishing module, configured to send an access request including corresponding cloud desktop port information to a corresponding zero-trust gateway through any first communication connection, so that the zero-trust gateway establishes a second communication connection with an application gateway corresponding to the cloud desktop port information; The cloud desktop application access module is used to access the multiple cloud desktop applications through the multiple first communication connections and the multiple second communication connections corresponding to the multiple first communication connections.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the cloud desktop access method according to any one of claims 1 to 7 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the cloud desktop access method according to any one of claims 1 to 7.