A multi-purpose network password service system
By designing a multi-purpose network cryptographic service system in a domestic desktop cloud environment and adopting a cryptographic service middle platform and national cryptographic algorithms, the cryptographic testing needs of the domestic desktop cloud are solved, the seamless integration and unified interface of security equipment are achieved, and the stability and security of the system are improved.
Patent Information
- Application Number
- CN202510290866.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-03-12
AI Technical Summary
In the existing technology, desktop clouds based on domestic environments lack related products for confidentiality testing, resulting in insufficient operational stability and security, and unable to meet information security requirements.
A multi-purpose network password service system is designed, which adopts a password service middle platform with domestic algorithms. Through the combination of Untrust domain, DMZ domain, desktop management domain, desktop domain and IT infrastructure domain, it realizes seamless docking and unified security interface of security devices of different brands, and uses the password service middle platform to provide safe and reliable password services.
It achieves seamless integration of security devices from different brands, reduces cost investment, improves system security and management efficiency, meets password testing needs, and helps customers' cloud desktops pass password assessments.
Smart Images

Figure CN120150939B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network cryptography, in particular to a multi-purpose network cryptography service system. Background Art
[0002] Today, there's a clear trend toward localized IT infrastructure, which has directly driven the widespread adoption of desktop cloud applications based on this infrastructure. With China placing high priority on information security, the combination of localized hardware and software provides a more reliable operating environment for desktop cloud, meeting the business needs of various industries across China while also enhancing national information security.
[0003] However, there are currently no products for performing security testing on desktop clouds based on domestic environments, which has become a shortcoming in current development. Security testing is a priority for users due to the importance of information security. Only by rigorously performing security testing on domestic desktop clouds can we ensure their stability, security, and reliability during operation, thereby fully leveraging the advantages of domestic infrastructure and desktop cloud applications. Summary of the Invention
[0004] In order to solve the above technical problems, the present invention provides a multi-purpose network cryptographic service system. By adopting a cryptographic service middle platform with a domestic algorithm, it provides secure and reliable cryptographic services for the desktop management domain, is compatible with multiple security devices, and provides a unified security interface for Huawei Cloud Desktop, helping customers' cloud desktops pass password assessments to solve the problems in the existing technology.
[0005] The technical solutions of the present invention are as follows:
[0006] A multi-purpose network password service system includes: Untrust domain, DMZ domain, desktop management domain, desktop domain and IT infrastructure domain. The connection between the domains includes Web authentication service flow and virtual machine access service flow;
[0007] The Untrust zone is used to connect to the external network and provide users with access to internal resources, including TC terminals, Ukey-driven cloud clients, and HDP Viewers.
[0008] The DMZ domain serves as a buffer between the external network and the internal network, including a virtual load balancer vLB based on the TCP 433 network transmission protocol and a virtual access gateway vAG based on the TCP 8443 and UDP 8443 network transmission protocols;
[0009] The desktop management domain is used to manage and control the access and use of user desktops, including the login server WebInterface, desktop controller HDC, database GaussDB, desktop management platform ITA and the password service middle platform based on the password machine and authentication gateway, referred to as the password middle platform;
[0010] The desktop domain includes multiple user desktops, which are used to provide users with user desktops that support password assessment;
[0011] The IT infrastructure domain is used to provide basic network services and resource management for the entire system, including user active directory AD, domain name system DNS and dynamic host configuration protocol DHCP;
[0012] In the multi-purpose network cryptographic service system, the connection relationship between each domain and each component is as follows:
[0013] The Untrust zone passes web authentication service flows and virtual machine access service flows through the virtual private network SSLVPN and WAF. The web authentication service flows are then connected to the virtual load balancer vLB in the DMZ zone, and the virtual machine access service flows are connected to the virtual access gateway vAG in the DMZ zone.
[0014] The vLB connects to the login server in the desktop management domain through a Web authentication service flow, passing through the firewall, and then to the desktop controller. The desktop controller connects to the password service center through a Web authentication service flow, and the password service center connects to the user active directory AD in the IT infrastructure domain through a Web authentication service flow.
[0015] vAG is connected to the desktop controller through the virtual machine access service flow. At the same time, vAG is connected to the user desktop in the desktop domain through the virtual machine access service flow through the firewall. The user desktop is then connected to the user active directory AD in the IT infrastructure domain through the virtual machine access service flow through the firewall.
[0016] Preferably, in the Untrust domain: the TC terminal is a terminal device that processes the virtual desktop protocol and is used to realize remote access of users. The Ukey-based cloud client Cloud Client is used to ensure that users access Huawei cloud services under the Ukey-based security authentication; the HDP Viewer high-definition transmission protocol is used to realize image and data transmission, providing a channel for users to interact with internal systems in an external environment.
[0017] Preferably, in the DMZ domain: the virtual load balancer vLB authenticates incoming network traffic based on the TCP 433 protocol; the virtual access gateway vAG performs protocol inspection and screening on traffic entering the internal network based on the TCP 8443 and UDP 8443 protocols.
[0018] Preferably, the login server Web Interface in the desktop management domain is used to provide a user login interface, and cooperates with the password service middle platform to verify the logged-in user. The desktop controller HDC and the desktop management platform ITA are used to control and manage the desktop. The database GaussDB is bidirectionally connected to the desktop controller, the password service middle platform and the desktop management platform data, and is used to store relevant data, including user data, system data and desktop data. The password service middle platform is based on a domestic algorithm cryptographic machine and a verification gateway, and provides secure and reliable password services for the desktop management domain through a bidirectional connection of the Web authentication business flow.
[0019] Preferably, the authentication gateway in the cryptographic service based on the cryptographic machine and the verification gateway is used to implement signature verification;
[0020] The signature verification can manage multiple applications. Each application entity contains a signature certificate, an encryption certificate and a corresponding key. Application certificate management can perform operations including application certificate creation, import, viewing, certificate activation / deactivation and deletion.
[0021] Preferably, in the cryptographic service center based on the cryptographic machine and the verification gateway, the cryptographic machine performs encryption calculation based on the national secret algorithm;
[0022] The national secret algorithms include but are not limited to SM2, SM3, SM4 and Zu Chongzhi algorithm.
[0023] Preferably, the desktop management domain can establish data connection with an external computer. In the data connection architecture between the desktop management domain and the external computer, the external computer must first access the bastion host, and then pass through the virtual private network SSLVPN and the Web application firewall WAF to finally achieve connection with the desktop management domain.
[0024] Preferably, the user active directory AD in the IT infrastructure domain is used to centrally manage the identity information of users and devices; the domain name system DNS is used to ensure that devices in the network can correctly find the corresponding IP address through the domain name; and the dynamic host configuration protocol DHCP is used to automatically allocate network configuration information to devices.
[0025] Preferably, the connection mode in the system includes a Web authentication business flow and a virtual machine access business flow;
[0026] The Web authentication service flow is used to implement the user's login authentication process to ensure that the user legally enters the system; the virtual machine access service flow is used to protect the user's access to the virtual machine.
[0027] Compared with the prior art, the present invention has the following beneficial effects:
[0028] 1. The present invention requires the virtual private network SSLVPN and WAF in the Untrust domain, which can standardize the network traffic and adapt to the differences in network traffic monitoring and access control among security devices of different brands. It makes it compatible with multiple security devices such as Venustech, Sangfor, NetGuard Nebula, and TopSec, achieving seamless connection between security devices of different brands, solving the integration problems caused by differences in security device brands, reducing cost investment, and building a more solid security line of defense.
[0029] 2. The present invention uses the password service middle platform in the desktop management domain, the login server, and the desktop controller to uniformly process data and requests from different sources. Regardless of the brand of the underlying security device, the password service middle platform can convert it into a format and protocol that meets the overall requirements of the system, providing a unified security interface for Huawei Cloud Desktop, simplifying system deployment and management processes, improving work efficiency, solving the challenges of system integration and management, and bringing users a convenient, stable and secure experience.
[0030] 3. The present invention uses the national secret algorithm to perform encryption calculations based on the cryptographic machine through the cryptographic service middle platform, providing a solid guarantee for data security. At the same time, it works in conjunction with the authentication gateway to realize signature verification services, strengthen identity authentication and data integrity verification, and provide customers with high security protection through virtual private networks, firewalls, etc. in terms of system connection, meeting the requirements of password testing, helping customers' cloud desktops pass password assessments, and solving the problem of customer cloud desktop password assessments. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 It is a connection diagram of the present invention;
[0032] Figure 2 This is a flowchart of secure desktop access on the FusionAccess desktop cloud user side according to an embodiment of the present invention;
[0033] Figure 3 This is a flowchart of the Portal access to the FusionAccess desktop cloud management side in an embodiment of the present invention;
[0034] Figure 4 This is a flowchart of FusionAccess desktop cloud data storage according to an embodiment of the present invention;
[0035] Figure 5 This is a flowchart of FusionAccess desktop cloud data query according to an embodiment of the present invention. DETAILED DESCRIPTION
[0036] The following embodiments of the present invention are described in further detail with reference to the accompanying drawings and examples. The following examples are used to illustrate the present invention but are not intended to limit the scope of the present invention.
[0037] like Figure 1 As shown, the present invention provides a multi-purpose network password service system, including: Untrust domain, DMZ domain, desktop management domain, desktop domain and IT infrastructure domain;
[0038] The Untrust zone is used to connect to the external network and provide users with access to internal resources, including TC terminals, Ukey-driven cloud clients, and HDP Viewers.
[0039] The DMZ serves as a buffer between the external network and the internal network. It includes a virtual load balancer (vLB) based on the TCP 433 network transmission protocol and a virtual access gateway (vAG) based on the TCP 8443 and UDP 8443 network transmission protocols.
[0040] The desktop management domain is used to manage and control user desktop access and usage, including the login server WebInterface, desktop controller HDC, database GaussDB, desktop management platform ITA, and the password service middle platform based on the password machine and authentication gateway, referred to as the password middle platform.
[0041] The desktop domain includes multiple user desktops, which are used to provide users with an actual working environment;
[0042] The IT infrastructure domain provides basic network services and resource management for the entire system, including Active Directory (AD), Domain Name System (DNS), and Dynamic Host Configuration Protocol (DHCP).
[0043] In the multi-purpose network cryptographic service system, the connection relationship between each domain and each component is as follows:
[0044] The Untrust zone passes the web authentication service flow and the virtual machine access service flow through the virtual private network SSLVPN and WAF. Finally, the web authentication service flow is connected to the virtual load balancer vLB in the DMZ zone, and the virtual machine access service flow is connected to the virtual access gateway vAG in the DMZ zone.
[0045] The vLB connects to the login server in the desktop management domain through a Web authentication service flow, passing through the firewall, and then to the desktop controller. The desktop controller connects to the password service center through a Web authentication service flow, and the password service center connects to the user active directory AD in the IT infrastructure domain through a Web authentication service flow.
[0046] vAG is connected to the desktop controller through the virtual machine access service flow. At the same time, vAG is connected to the user desktop in the desktop domain through the virtual machine access service flow through the firewall. The user desktop is then connected to the IT infrastructure domain user active directory AD through the virtual machine access service flow through the firewall.
[0047] Example 1: Figures 1-5 As shown in this example, the procuratorial work network of a certain municipal People's Procuratorate uses entirely domestic infrastructure, with Huawei Cloud Desktop as the terminal. However, no product currently available on the market meets the requirements for cryptographic testing. Therefore, a multi-purpose network cryptographic service system is required that can connect with Gel Identity Authentication, Hitech Key, and Venustech Cryptographic Machines, and provide a unified security interface for Huawei Cloud Desktop. Furthermore, the system must be quickly implemented without replacing underlying security equipment and pass cryptographic testing.
[0048] System Construction: The Untrust domain is equipped with Huawei Cloud Desktop's TC terminal, through which users can remotely access the procuratorial work network. A Ukey-driven cloud client, Cloud Client, is also configured to ensure that users access cloud services under Ukey-based security authentication, meeting high security requirements. Furthermore, an HDP Viewer is configured to allow users to view specific high-definition procuratorial work-related content, providing a channel for users to interact with internal systems in an external environment.
[0049] The DMZ domain deploys a virtual load balancer vLB based on the TCP 433 network transmission protocol. This protocol strictly authenticates incoming network traffic and prevents illegal traffic from entering the internal network. At the same time, a virtual access gateway vAG based on the TCP 8443 and UDP 8443 network transmission protocols is configured. These two protocols are used to ensure secure access control, perform protocol inspection and screening on traffic entering the internal network, and further enhance network security.
[0050] The desktop management domain establishes a login server Web Interface, providing users with a simple and clear login interface. The desktop controller HDC is deployed to provide centralized and efficient desktop control. The desktop management platform ITA is established to implement comprehensive desktop management capabilities and ensure the stable operation of Huawei Cloud Desktop. The GaussDB database is used to store relevant data, and bidirectional data connections are established with the desktop controller, the password service middleware, and the desktop management platform to ensure data storage security and efficient management.
[0051] A cryptographic service platform based on a cryptographic machine and an authentication gateway was built. The cryptographic machine performs encryption calculations based on the national secret algorithm SM2, providing high-strength encryption for the system. The authentication gateway implements signature verification services to ensure data integrity and authenticity. The cryptographic service platform and the authentication gateway are bidirectionally connected via a web authentication service flow, further enhancing system security.
[0052] The desktop domain is configured with multiple Huawei cloud desktops to provide users with a comfortable actual working environment.
[0053] The IT infrastructure domain established Active Directory (AD) to centrally manage user and device identity information, ensuring the security and reliability of user identities on the procuratorial work network. Domain Name System (DNS) was deployed to ensure that devices on the network could correctly locate their corresponding IP addresses using domain names, improving network access efficiency. Dynamic Host Configuration Protocol (DHCP) was established to automatically assign network configuration information to devices, simplifying network management.
[0054] By requiring the virtual private network SSLVPN and WAF to pass through the Untrust domain, this part can standardize network traffic and adapt to the differences in network traffic monitoring and access control among security devices of different brands. It makes it compatible with multiple security devices such as Venustech, Sangfor, NetGuard Nebula, and TopSec, achieving seamless connection between security devices of different brands, solving the integration difficulties caused by differences in security device brands, reducing cost investment, and building a more solid security line of defense.
[0055] Through the password service middle platform in the desktop management domain, the login server, and the desktop controller, data and requests from different sources are uniformly processed. Regardless of the brand of the underlying security device, the password service middle platform can convert it into a format and protocol that meets the overall system requirements, providing a unified security interface for Huawei Cloud Desktop, simplifying the system deployment and management process, improving work efficiency, solving the challenges of system integration and management, and bringing users a convenient, stable and secure experience.
[0056] After the system is built, the usage process is as follows:
[0057] For remote access, users initiate remote access requests to the Ukey-driven cloud client CloudClient through the TC terminal in the Untrust zone. When using Cloud Client, users need to insert Ukey for security authentication. The system filters and performs security checks on user requests through the virtual private network SSLVPN and WAF.
[0058] Login authentication: The user's request reaches the Web Interface, the login server of the desktop management domain. The user enters information such as user name and password on the login interface. The login server sends the user information to the password service center, which calls the Gel identity authentication system for identity authentication.
[0059] Desktop access: After passing authentication, users access Huawei Cloud Desktop in the desktop domain through the desktop controller HDC. During the access process, the virtual access gateway vAG and virtual load balancer vLB will manage and control network traffic to ensure network stability and security.
[0060] Data interaction: When users interact with data on Huawei Cloud Desktop, such as uploading, downloading files, or processing data, the cryptographic service center will call the Hitech key to encrypt the data as needed to ensure data security; at the same time, during the data transmission process, the signature verification is performed through the Venusstar cryptographic machine to ensure the integrity and authenticity of the data.
[0061] External computer connection: When an external computer needs to connect to the procuratorial work network, it first connects to the bastion host, and after security checks of the virtual private network SSLVPN and WAF, it finally connects to the desktop management domain. During the connection process, it also needs to pass the identity authentication and security check of the password service middle platform to ensure the access security of the external computer.
[0062] The system is based entirely on domestically produced infrastructure, meeting the strict security testing requirements of the procuratorial work network. By employing nationally recognized cryptographic algorithms, integrating security devices, and implementing unified security interfaces, the system ensures security and compliance. Furthermore, the system can be rapidly implemented without replacing underlying security equipment, reducing implementation costs and time. Furthermore, by integrating and optimizing existing security equipment, the overall security and performance of the system are enhanced.
[0063] The various components of the multi-purpose network cryptographic service system work together to effectively manage and control network traffic. The use of virtual load balancers, virtual access gateways, firewalls, and other devices ensures system stability and reliability, preventing system failures caused by network attacks or traffic overloads.
[0064] Example 2: Figures 1-5 As shown, in this embodiment, after the system of Example 1 is built and running, the system performs the following operations: FusionAccess desktop cloud user-side desktop security access, FusionAccess desktop cloud management-side portal access, FusionAccess desktop cloud data storage and query:
[0065] The user-side desktop secure access process for FusionAccess Desktop Cloud is as follows:
[0066] Users perform security authentication, including using certificates and performing Ukey authentication;
[0067] Users access desktop management through SSL VPN;
[0068] The user performs signature verification on the password service center through the desktop WI management plane service;
[0069] The password service center returns the verification result to the desktop WI management plane service;
[0070] Verification fails, the client fails to launch, verification succeeds, the user launches the client and logs in to the desktop.
[0071] Through multiple security authentication methods, reliable protection is provided for users to access the desktop cloud. Certificate and Ukey authentication ensure the authenticity of user identity. SSL VPN access improves network transmission security. Signature verification to the password service middle platform further enhances the authenticity verification of user identity. Compared with existing technologies, this process pays more attention to the security of user access. The combination of multiple authentication methods can effectively prevent unauthorized access and malicious attacks.
[0072] The portal access process on the FusionAccess desktop cloud management side is as follows:
[0073] Users use the secret key UKey and Gel certificate to perform Ukey authentication and log in to the password service center through SSL VPN;
[0074] The user logs in to the bastion host;
[0075] The user accesses the FA management portal.
[0076] Strict authentication and access control processes ensure the legality of management users and provide multi-layer security protection for management operations. Compared with existing technologies, this increases the security of management operations, prevents malicious access to the management portal by unauthorized users, and improves the stability of system management.
[0077] The FusionAccess desktop cloud data storage process is as follows:
[0078] The cryptographic service center based on the cryptographic machine encrypts / signs important data;
[0079] The cryptographic service center based on the cryptographic machine returns the encryption / signature results to the source of important data;
[0080] The important data source stores the encrypted / signed important data in the DB database;
[0081] The cryptographic service center encrypts and signs important data to ensure the security and integrity of data storage. Compared with traditional storage methods, it provides stronger security protection and effectively prevents data leakage and tampering.
[0082] The FusionAccess desktop cloud data query process is as follows:
[0083] Query important data from the DB database;
[0084] The cryptographic service center based on the cryptographic machine calls the service to decrypt and verify the integrity of the data;
[0085] The password service center returns the verification result;
[0086] If the check passes, the query is successful; if the check fails, an alarm is triggered.
[0087] The cryptographic service center decrypts and performs integrity verification on the query data to ensure that the data is authentic and complete. If the verification fails, an alarm will be triggered to detect anomalies in a timely manner. Compared with existing technologies, this improves the reliability of query data and ensures the security and stability of system data. The alarm mechanism can promptly remind administrators to deal with abnormal situations.
[0088] Example 3: In this example, the cryptographic service middleware of this system serves as the HUAWEI Cloud Desktop cryptographic service middleware, managing security hardware such as cryptographic machines and providing cryptographic functions for HUAWEI Cloud Desktop. It is mainly divided into cryptographic machine-related services and signature verification-related services. The operations of the cryptographic service middleware are as follows:
[0089] 1. Cryptographic machine related services:
[0090] 1. Open the browser, enter the password service center IP address, enter the account password and click Login;
[0091] 2. After logging in, enter the main management interface; the main management interface can provide information about the version of the password device, CPU usage, memory usage, number of concurrent password services, device status, key storage status, etc.
[0092] 3. SM2 key management, manage SM2 key pairs, including generating, importing, deleting and setting access control codes:
[0093] 3.1. Generate key: Click Create, enter the index, select the purpose, and click 'OK';
[0094] 3.2. Generate a certificate request: Enter the index, select "Generate" or "Encrypt" for the purpose, and enter the certificate subject. Click "OK." The CN in the certificate subject is required and can contain letters, numbers, Chinese characters, @, underscores, and hyphens, separated by ",";
[0095] 4. Symmetric key management: manage symmetric keys, including generating and deleting symmetric keys.
[0096] 2. Signature Verification Services:
[0097] 1. Application certificate management: The signature verification service can manage multiple applications. Each application entity contains a signature certificate, an encryption certificate, and the corresponding key. Application certificate management allows operations such as creating, importing, viewing, enabling / disabling, and deleting application certificates.
[0098] 1.1. Generate an application certificate. Click "Create" in the application certificate management interface.
[0099] Enter the certificate label, select "Generate" for the new method, select the key type and key length, and enter the certificate subject. Click "OK"; the certificate label can be 1-127 characters long and can contain letters, numbers, @, $, underscores, and hyphens; the CN in the certificate subject is required and can contain letters, numbers, Chinese characters, @, underscores, and hyphens, separated by ",";
[0100] After successful creation, the newly added application certificate information will be displayed in the certificate list;
[0101] Export the certificate request file and click the Download button. The certificate request will be downloaded to the management terminal. The certificate request is in CSR format and is used to apply for a certificate from the CA.
[0102] After obtaining the certificate file issued by the CA, import it into the device. Before importing, confirm that the issuer CA certificate has been imported and click the "Import" button in the operation column of the certificate list.
[0103] Upload the signature certificate and encryption certificate on the pop-up page, and then click "OK". After the import is complete, the certificate list will display the imported certificate information; the certificate status will change from "Applying" to "In Use". If the issuer CA certificate of the application certificate is not imported,
[0104] Importing the application certificate will fail and prompt that the CA certificate does not exist. In this case, you need to import the corresponding issuer CA certificate in advance.
[0105] 1.2. Create an application certificate by importing a PFX file;
[0106] Click the "Create" button on the application certificate management page to pop up the new application certificate page;
[0107] On the pop-up page, select "Import", upload the PFX file and enter the certificate information, then click "OK";
[0108] After the import is complete, the certificate list displays the imported certificate information. The certificate status displays as "In Use." If the issuer CA certificate for the application certificate has not been imported, importing the application certificate will fail and the user will be prompted that the CA certificate does not exist. In this case, you must import the corresponding issuer CA certificate in advance.
[0109] 1.3. Find the application certificate;
[0110] On the App Certificate Management page, enter the tag keyword and certificate type, click "Search", and the certificates that meet the conditions will be displayed in the list. If the conditions are empty, all certificates will be displayed.
[0111] 1.4. View application certificate details;
[0112] Click the "View" button in the operation column of the certificate list to display the certificate details on the pop-up page, including certificate content such as certificate label, certificate type, key index, and certificate serial number.
[0113] 2. User certificate management;
[0114] User certificate management allows operations such as importing, searching, viewing, and deleting user certificates.
[0115] 2.1. Import user certificate;
[0116] On the User Certificate Management page, click the "Create" button;
[0117] On the pop-up page, enter the user certificate label and upload the user signature certificate and encryption certificate, then click "OK". Please enter 1-127 characters for the certificate label, which can contain letters, numbers, @, $, underscores, and hyphens;
[0118] After the import is complete, the certificate list displays the imported certificate information.
[0119] 2.2. Check the user certificate;
[0120] Click the "View" button in the action column of the certificate list to display the certificate details on a pop-up page. This includes certificate label, certificate type, certificate serial number, certificate subject, and other certificate content.
[0121] 3. Trust domain management;
[0122] Signature verification management allows the configuration of multiple trust domains. Each trust domain contains a CA certificate or certificate chain and a set of verification policies, which are used to provide signature verification and certificate verification services.
[0123] To add a trust domain, click the "Create" button on the trust domain management page;
[0124] Pop-up page on the CA certificate and input certificate label, "certificate authentication mode" drop-down box has the following options: no authentication. This way does not verify the validity of the certificate when signing, CA certificate authentication, in the signing of the signature certificate using root certificate to verify the validity of the signature certificate, you can choose whether to allow expired certificate to pass the verification.
[0125] CRL authentication, CRL authentication mode can choose to upload CRL file manually, CRL download and download from certificate CRL publishing point;
[0126] The manually uploaded CRL file can be successfully created after being verified by the configured CA certificate, and the CRL file smaller than 100M is uploaded;
[0127] CRL authentication using CRL timing download mode, will first download CRL file when configuring, and automatically update CRL at each update time, and use the CRL publishing point of the certificate to download, this option will obtain CRL file when verifying signature and verifying certificate each time;
[0128] OCSP authentication, input OCSP service address, if the OCSP server needs identity authentication, OCSP client authentication certificate needs to be uploaded and the correct certificate password needs to be input, and the certificate state is obtained online by accessing the OCSP server each time when verifying signature and verifying certificate;
[0129] After inputting the trust domain configuration item, click "OK" to complete the trust domain creation.
[0130] Through the password service platform based on the password machine using national secret algorithm for encryption calculation, a solid guarantee is provided for the security of data, at the same time, the authentication gateway is cooperated to realize the signature verification service, the identity authentication and data integrity verification are strengthened, and in the system connection aspect, a virtual private network, a firewall and the like are used to provide high security guarantee for customers, help customers to pass the password evaluation of cloud desktop, and solve the problem of password evaluation of cloud desktop of customers.
[0131] The embodiments of the present application are given for example and description, although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary, and cannot be understood as limiting the present application, and those skilled in the art can change, modify, replace and modify the above embodiments within the scope of the present application.
Claims
1. A multi-purpose network cryptographic service system, characterized in that: include: Untrust, DMZ, desktop management, desktop, and IT infrastructure domains. Connections between these domains include web authentication and virtual machine access flows. The Untrust zone is used to connect to the external network and provide users with access to internal resources, including TC terminals, Ukey-driven cloud clients, and HDP Viewers. The DMZ domain serves as a buffer between the external network and the internal network, including a virtual load balancer vLB based on the TCP 433 network transmission protocol and a virtual access gateway vAG based on the TCP 8443 and UDP 8443 network transmission protocols; The desktop management domain is used to manage and control the access and use of user desktops, including the login server WebInterface, desktop controller HDC, database GaussDB, desktop management platform ITA and the password service middle platform based on the password machine and authentication gateway, referred to as the password middle platform; The desktop domain includes multiple user desktops, which are used to provide users with user desktops that support password assessment; The IT infrastructure domain is used to provide basic network services and resource management for the entire system, including user active directory AD, domain name system DNS and dynamic host configuration protocol DHCP; In the multi-purpose network cryptographic service system, the connection relationship between each domain and each component is as follows: The Untrust zone passes web authentication service flows and virtual machine access service flows through the virtual private network SSLVPN and WAF. The web authentication service flows are then connected to the virtual load balancer vLB in the DMZ zone, and the virtual machine access service flows are connected to the virtual access gateway vAG in the DMZ zone. The vLB connects to the login server in the desktop management domain through a Web authentication service flow, passing through the firewall, and then to the desktop controller. The desktop controller connects to the password service center through a Web authentication service flow, and the password service center connects to the user active directory AD in the IT infrastructure domain through a Web authentication service flow. vAG is connected to the desktop controller through the virtual machine access service flow. At the same time, vAG is connected to the user desktop in the desktop domain through the virtual machine access service flow through the firewall. The user desktop is then connected to the user active directory AD in the IT infrastructure domain through the virtual machine access service flow through the firewall.
2. A multi-purpose network cryptographic service system as claimed in claim 1, characterized in that: In the Untrust zone, the TC terminal is a terminal device that processes the virtual desktop protocol and is used to enable remote user access. The Ukey-based cloud client is used to ensure that users access Huawei cloud services under Ukey-based security authentication. The HDP Viewer high-definition transmission protocol is used to implement image and data transmission, providing a channel for users to interact with internal systems in an external environment.
3. A multi-purpose network cryptographic service system as claimed in claim 1, characterized in that: In the DMZ domain: the virtual load balancer vLB authenticates the incoming network traffic based on the TCP 433 protocol; the virtual access gateway vAG performs protocol inspection and screening on the traffic entering the internal network based on the TCP 8443 and UDP 8443 protocols.
4. A multi-purpose network cryptographic service system as claimed in claim 1, characterized in that: The login server Web Interface in the desktop management domain is used to provide an interface for user login, and collaborates with the password service middle platform to verify the logged-in user. The desktop controller HDC and the desktop management platform ITA are used to control and manage the desktop. The database GaussDB is bidirectionally connected to the desktop controller, the password service middle platform and the desktop management platform data, and is used to store relevant data, including user data, system data and desktop data. The password service middle platform is based on domestic algorithm cryptographic machines and authentication gateways, and provides secure and reliable password services for the desktop management domain through bidirectional connections of Web authentication business flows.
5. A multi-purpose network cryptographic service system as claimed in claim 4, characterized in that: In the cryptographic service center based on the cryptographic machine and the authentication gateway, the authentication gateway is used to implement signature verification; The signature verification can manage multiple applications. Each application entity contains a signature certificate, an encryption certificate and a corresponding key. Application certificate management can perform operations including application certificate creation, import, viewing, certificate activation / deactivation and deletion.
6. A multi-purpose network cryptographic service system as claimed in claim 4, characterized in that: In the cryptographic service center based on the cryptographic machine and the authentication gateway, the cryptographic machine performs encryption calculations based on the national secret algorithm; The national secret algorithms include but are not limited to SM2, SM3, SM4 and Zu Chongzhi algorithm.
7. A multi-purpose network cryptographic service system as claimed in claim 4, characterized in that: The desktop management domain can establish data connection with external computers. In the data connection architecture between the desktop management domain and external computers, the external computer must first connect to the bastion host, and then pass through the virtual private network SSLVPN and the Web application firewall WAF to finally achieve connection with the desktop management domain.
8. A multi-purpose network cryptographic service system as claimed in claim 1, characterized in that: The user active directory AD in the IT infrastructure domain is used to centrally manage the identity information of users and devices; The Domain Name System (DNS) is used to ensure that devices on the network can correctly find the corresponding IP address through the domain name; the Dynamic Host Configuration Protocol (DHCP) is used to automatically assign network configuration information to devices.
9. A multi-purpose network cryptographic service system as claimed in claim 1, characterized in that: The connection mode in the system includes a Web authentication business flow and a virtual machine access business flow; The Web authentication service flow is used to implement the user's login authentication process to ensure that the user legally enters the system; the virtual machine access service flow is used to protect the user's access to the virtual machine.
Citation Information
Patent Citations
System and method for checking cloud terminal or cloud desktop
CN115729678A
System and method for cloud desktop management using a secure cloud proxy
US20250030687A1