Access permission control method and device of virtual machine, electronic equipment and storage medium
The virtual machine access control method employs a data transfer disk and software layer disk to manage application types and network communications, addressing data leakage and unauthorized access risks by ensuring secure and efficient data transmission and access control.
Patent Information
- Application Number
- CN202410051771.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-12
- Publication Date
- 2025-07-15
AI Technical Summary
On the cloud desktop of virtual machines, there is a risk of data leakage and tampering, and the threat of illegal access and network attacks, especially in the need to store source code and other business data, data leakage is easily caused when accessed through the external network.
By loading data into the virtual machine and transferring disks and software layered disks, data isolation and secure transmission are achieved, access permissions are determined based on the target application type recorded by the software layered disk, and process communication and data access are controlled using network filtering drivers and application layer agents.
It realizes the isolation of the use of local applications and Internet applications on the same virtual machine cloud desktop, avoids data leakage and tampering, prevents illegal access and network attacks, and improves network security and isolation.
Smart Images

Figure CN120315802A_ABST
Abstract
Description
Technical Field
[0001] This application relates to computer technology, specifically to virtual machine technology, and particularly to a method, device, electronic device, and storage medium for controlling access rights to virtual machines. Background Art
[0002] Currently, on the cloud desktop of a virtual machine, for example, a R & D desktop, there is a need to store business data such as source code and also a need to access the external network. In this way, it is very easy to leak internal network data to the external network through the external network, posing risks of data leakage and tampering, as well as threats of illegal access and network attacks.
[0003] Therefore, there is a need to provide a solution for controlling access rights to virtual machines that can both access the external network and prevent local data from being transmitted externally through the network. Summary of the Invention
[0004] This application provides a method, device, electronic device, and storage medium for controlling access rights to virtual machines to solve the problems in the existing access right control solution for virtual machines, such as risks of data leakage and tampering, and threats of illegal access and network attacks.
[0005] On the one hand, this application provides a method for controlling access rights to virtual machines. The method includes:
[0006] After logging in to the cloud desktop of the virtual machine on the terminal device, load the data transfer disk and software layered disk of the virtual machine. Among them, the software layered disk is used to record the target application programs that can only access the target server on the specified network. Data is isolated between the software layered disk and the local disk of the terminal device. The data transfer disk is used to perform data transmission with the local disk and the software layered disk respectively;
[0007] In response to recognizing a startup operation on the target application program, determine the access rights of the target application program according to the type of the target application program recorded by the software layered disk.
[0008] By loading the data transfer disk and software layered disk, data isolation and secure transmission of the virtual machine are achieved, avoiding the risks of data leakage and tampering; by determining the access rights of the target application program according to the type of the target application program recorded by the software layered disk, access control and network isolation of the virtual machine are achieved, preventing threats of illegal access and network attacks.
[0009] In one embodiment, the following method is used to determine the type of the target application program:
[0010] The process of obtaining the terminal events of the terminal device and the process identifier of the process, where the terminal events include at least one of the following: external connection event, received connection event, message sending event, and message receiving event;
[0011] According to the process identifier of the process, identify the type of the target application program to which the process belongs.
[0012] By obtaining the process of the terminal events of the terminal device and the process identifier, the dynamic identification of the type of the target application program is realized, which improves the flexibility and accuracy of access control; identifying the type of the target application program to which the process belongs according to the process identifier realizes the classified management of the target application program, which is convenient for setting different access permissions according to different application program types.
[0013] In one embodiment, determining the access permission of the target application program according to the type of the target application program includes:
[0014] Obtain the IP address of the target server accessed by the process, where the IP address includes: internal network IP address and external network IP address;
[0015] According to the type of the target application program to which the process belongs and the target server accessed by the process, determine whether to allow communication between the process and the target server.
[0016] By obtaining the IP address of the target server accessed by the process, the identification of the network location of the target server is realized, which improves the accuracy and security of access control; determining whether to allow communication between the process and the target server according to the type of the target application program to which the process belongs and the target server accessed by the process realizes the control of the network access of the target application program and prevents the possibility of network pollution or information leakage.
[0017] In one embodiment, determining whether to allow communication between the process and the target server according to the IP address and the target application program to which the process belongs includes:
[0018] If the target application program to which the process belongs is an Internet application program and the IP address of the target server accessed by the process is an external network IP address, then determine to allow communication between the process and the target server;
[0019] If the target application program to which the process belongs is an Internet application program and the IP address of the target server accessed by the process is an internal network IP address, then determine to intercept the communication between the process and the target server;
[0020] If the target application to which the process belongs is a local application and the IP address of the target server accessed by the process is an internal network IP address, it is determined to allow communication between the process and the target server;
[0021] If the target application to which the process belongs is a local application and the IP address of the target server accessed by the process is an external network IP address, it is determined to intercept communication between the process and the target server.
[0022] By determining whether to allow communication between a process and a target server according to the IP address and the target application to which the process belongs, fine-grained control over the network access of the target application is achieved, improving network security and efficiency; different communication policies are set according to different application types and network locations, achieving network isolation of the target application and preventing the possibility of network pollution or information leakage.
[0023] In one embodiment, obtaining the process of the terminal event of the terminal device and the process identifier of the process includes:
[0024] Using the network filtering driver module set in the terminal device to obtain the process of the terminal event of the terminal device and the process identifier of the process.
[0025] By using the network filtering driver module set in the terminal device, efficient acquisition of the process of the terminal event and the process identifier is achieved, improving the speed and accuracy of target application type identification.
[0026] In one embodiment, the method further includes:
[0027] Using the network filtering driver module set in the terminal device to separately authorize the process of individual terminal events.
[0028] By using the network filtering driver module set in the terminal device, separate authorization of the process of individual terminal events is achieved, improving the flexibility and adaptability of access control.
[0029] In one embodiment, the specified network includes: an external network, and determining the access permission of the target application according to the type of the target application includes:
[0030] If it is determined that the type of the target application is an Internet application that is only allowed to access servers on the external network, it is determined to only allow the Internet application to access the software layered disk and intercept the Internet application from accessing the local disk.
[0031] By specifying an external network as the access scope for target applications, network isolation of Internet-accessible applications is achieved, preventing Internet-accessible applications from communicating with servers on the internal network, thereby protecting the security and stability of the internal network. Only allowing Internet-accessible applications to access the software-layered disk and intercepting Internet-accessible applications from accessing the local disk realizes data isolation of Internet-accessible applications, preventing the exchange of data between Internet-accessible applications and the local disk, thereby protecting the security and integrity of the data on the local disk.
[0032] In one embodiment, before loading the data transfer disk and the software-layered disk of the virtual machine in response to logging in to the cloud desktop of the virtual machine of the terminal device, the method further includes:
[0033] In response to an image editing operation on the local disk, record Internet-accessible applications in the local disk that are only allowed to access servers on the external network in the virtual machine to obtain the software-layered disk.
[0034] By recording Internet-accessible applications that are only allowed to access servers on the external network in the virtual machine in response to an image editing operation on the local disk, dynamic generation of the software-layered disk is achieved, improving the flexibility and adaptability of the software-layered disk; generating the software-layered disk before loading the data transfer disk and the software-layered disk of the virtual machine realizes preprocessing of the software-layered disk, improving the security and efficiency of the software-layered disk.
[0035] In one embodiment, the method further includes at least one of the following:
[0036] Use the application layer proxy program in the terminal device to control the local application to unidirectionally read partial data from the Internet-accessible application, where the partial data includes: clipboard and screenshots;
[0037] Use the application layer proxy program in the terminal device to intercept the process communication between the local application and the Internet-accessible application;
[0038] Use the application layer proxy program in the terminal device to encrypt the transmission data between the local disk and the data transfer disk, and between the software-layered disk and the data transfer disk;
[0039] Use the application layer proxy program in the terminal device to upload the encrypted transmission data to the approval system to obtain the approval system instruction to decrypt the encrypted transmission data.
[0040] By using the application layer proxy program in the terminal device, the control of data and communication between local applications and Internet applications is realized, improving the security and efficiency of data and the network; by using the application layer proxy program, the encryption and approval of transmitted data are realized, improving the confidentiality and legality of data.
[0041] In one embodiment, the method further includes at least one of the following:
[0042] In response to the access operation of the Internet application to the operating system file, use the application layering module in the terminal device to perform file filtering drive on the virtual machine, and allow the Internet application to access the operating system file on the local disk;
[0043] In response to the installation operation of the Internet application, use the application layering module to redirect the Internet application to the software layering disk, and use the application layering module to perform registry filtering drive on the virtual machine, and record the registry change information during the installation process to the software layering disk.
[0044] By using the application layering module in the terminal device, the hierarchical management of files and registries of Internet applications is realized, improving the security and efficiency of files and registries; by using the application layering module, the access control of the operating system files of Internet applications is realized, improving the protection and compatibility of operating system files.
[0045] In one embodiment, the specified network further includes: an internal network. Determining the access permission of the target application according to the type of the target application recorded on the software layering disk includes:
[0046] If it is determined that the type of the target application is a local application that is only allowed to access the server of the internal network, it is determined that only the local application is allowed to access the local disk, and the access of the local application to the software layering disk and the data transfer disk is intercepted.
[0047] By specifying the internal network as the access range of the target application, the network isolation of the local application is realized, preventing the local application from communicating with the servers of the external network, thereby protecting the security and stability of the external network; only allowing the local application to access the local disk, and intercepting the access of the local application to the software layering disk and the data transfer disk, realizing the data isolation of the local application, preventing the local application from exchanging data with the software layering disk and the data transfer disk, thereby protecting the security and integrity of the data on the software layering disk and the data transfer disk.
[0048] In one embodiment, after logging in to the cloud desktop of the virtual machine of the terminal device and before loading the data transfer disk and software layered disk of the virtual machine, the method further includes:
[0049] In response to the mirror editing operation on the local disk, record the local applications of the servers that can only access the internal network in the local disk in the virtual machine to obtain the software layered disk.
[0050] By recording the local applications of the servers that can only access the internal network in the virtual machine in response to the mirror editing operation on the local disk, the dynamic generation of the software layered disk is realized, improving the flexibility and adaptability of the software layered disk; before loading the data transfer disk and software layered disk of the virtual machine, the generation of the software layered disk is carried out, realizing the preprocessing of the software layered disk, and improving the security and efficiency of the software layered disk.
[0051] On the other hand, the present application provides an access permission control device for a virtual machine, and the device includes:
[0052] A loading module, configured to load the data transfer disk and software layered disk of the virtual machine after logging in to the cloud desktop of the virtual machine of the terminal device, wherein the software layered disk is used to record the target applications of the servers that can only access the specified network, and data isolation is performed between the software layered disk and the local disk of the terminal device, and the data transfer disk is used to perform data transmission with the local disk and the software layered disk respectively;
[0053] An access control module, configured to determine the access permission of the target application according to the type of the target application recorded in the software layered disk in response to identifying the start operation of the target application.
[0054] In one embodiment, the following modules are used to determine the type of the target application:
[0055] A process identifier acquisition module, configured to acquire the process of the terminal event of the terminal device and the process identifier of the process, wherein the terminal event includes at least one of the following: an external connection event, a received connection event, a message sending event, and a message receiving event;
[0056] An identification module, configured to identify the type of the target application to which the process belongs according to the process identifier of the process.
[0057] In one embodiment, the access control module includes:
[0058] An obtaining unit, configured to obtain an IP address of a target server accessed by the process, where the IP address includes: an internal network IP address and an external network IP address;
[0059] A first access control unit, configured to determine whether to allow communication between the process and the target server according to a type of a target application to which the process belongs and the target server accessed by the process.
[0060] In one embodiment, the access control unit includes:
[0061] A first determination subunit, configured to determine to allow communication between the process and the target server if the target application to which the process belongs is an Internet access application and the IP address of the target server accessed by the process is an external network IP address;
[0062] A second determination subunit, configured to determine to intercept communication between the process and the target server if the target application to which the process belongs is an Internet access application and the IP address of the target server accessed by the process is an internal network IP address;
[0063] A third determination subunit, configured to determine to allow communication between the process and the target server if the target application to which the process belongs is a local application and the IP address of the target server accessed by the process is an internal network IP address;
[0064] A fourth determination subunit, configured to determine to intercept communication between the process and the target server if the target application to which the process belongs is a local application and the IP address of the target server accessed by the process is an external network IP address.
[0065] In one embodiment, the process identification obtaining module includes:
[0066] An obtaining unit, configured to use a network filtering driver module set in the terminal device to obtain a process of a terminal event of the terminal device and a process identification of the process.
[0067] In one embodiment, the device further includes:
[0068] An authorization module, configured to use a network filtering driver module set in the terminal device to perform separate authorization on processes of individual terminal events.
[0069] In one embodiment, the specified network includes: an external network, and the access control module includes:
[0070] A second access control unit, configured to determine that only the Internet access application is allowed to access the software layered disk and intercept the Internet access application from accessing the local disk if it is determined that the type of the target application is an Internet access application that only accesses a server on an external network.
[0071] In one embodiment, the apparatus further includes:
[0072] A first recording module, configured to record, in the virtual machine, an Internet access application in the local disk that only accesses a server on an external network in response to a mirror editing operation on the local disk, to obtain the software layered disk.
[0073] In one embodiment, the apparatus further includes at least one of the following:
[0074] A control unit, configured to use an application layer proxy program in the terminal device to control a local application to unidirectionally read partial data from the Internet access application, where the partial data includes: clipboard and screenshots;
[0075] An interception unit, configured to use an application layer proxy program in the terminal device to intercept process communication between the local application and the Internet access application;
[0076] An encryption unit, configured to use an application layer proxy program in the terminal device to encrypt transmission data between the local disk and the data transfer disk, and between the software layered disk and the data transfer disk;
[0077] A decryption unit, configured to use an application layer proxy program in the terminal device to upload encrypted transmission data to an approval system to obtain the approval system instruction to decrypt the encrypted transmission data.
[0078] In one embodiment, the apparatus further includes at least one of the following:
[0079] An access unit, configured to, in response to an access operation of an Internet access application to an operating system file, use an application layering module in the terminal device to perform file filtering driver on the virtual machine, and allow the Internet access application to access the operating system file on the local disk;
[0080] An installation unit, configured to, in response to an installation operation of the Internet access application, use the application layering module to redirect the Internet access application to the software layered disk, and use the application layering module to perform registry filtering driver on the virtual machine, and record registry change information during the installation process to the software layered disk.
[0081] In one embodiment, the specified network further includes: an internal network, and the access control module includes:
[0082] A third access control unit, configured to determine that only the local application is allowed to access the local disk and intercept the local application from accessing the software layered disk and the data transfer disk if it is determined that the type of the target application is a local application that can only access servers on the internal network.
[0083] In one embodiment, the device further includes:
[0084] A second recording module, configured to record, in the virtual machine, a local application in the local disk that can only access servers on the internal network in response to a mirror editing operation on the local disk, to obtain the software layered disk.
[0085] On the other hand, the present application provides an electronic device, including: a processor, and a memory connected to the processor; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the method as described in any one of the above.
[0086] On the other hand, the present application provides a computer-readable storage medium, in which computer execution instructions are stored, and the computer execution instructions are used to implement the method as described in any one of the above when executed by a processor.
[0087] On the other hand, the present application provides a computer program product, including a computer program, and the computer program implements the method as described in any one of the above when executed by a processor.
[0088] The access permission control method, device, electronic device and storage medium of the virtual machine provided by the present application, the method loads a data transfer disk and a software layered disk of the virtual machine in response to logging in to the cloud desktop of the virtual machine of the terminal device, wherein the software layered disk is used to record a target application of a target server that can only access a specified network, data is isolated between the software layered disk and the local disk of the terminal device, and the data transfer disk is used to perform data transmission with the local disk and the software layered disk respectively; in response to recognizing a start operation on the target application, determine the access permission of the target application according to the type of the target application recorded by the software layered disk.
[0089] In the embodiments of the present application, taking the above-mentioned target application programs including local application programs and Internet application programs as an example, by setting up a data transfer disk and a software layered disk on a virtual machine, and loading the data transfer disk and the software layered disk in response to logging in to the cloud desktop of the virtual machine on the terminal device, data isolation and secure transmission of the virtual machine are achieved, and the risks of data leakage and tampering are avoided. By determining the access permissions of the target application program according to the type of the target application program recorded by the software layered disk, it is possible to isolate the use of local application programs and Internet application programs on the cloud desktop of the same virtual machine without affecting the security and isolation of the internal and external networks, thereby realizing access control and network isolation of the virtual machine and preventing the threats of illegal access and network attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0090] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0091] Figure 1 is a flowchart of a method for controlling access permissions of a virtual machine provided by an embodiment of the present application;
[0092] Figure 2 is a schematic diagram of an optional architecture of a virtual machine provided by an embodiment of the present application;
[0093] Figure 3 is a flowchart of a method for controlling access permissions of a virtual machine provided by an embodiment of the present application;
[0094] Figure 4 is a flowchart of an optional method for controlling access permissions of a virtual machine provided by an embodiment of the present application;
[0095] Figure 5 is a flowchart of an optional method for controlling access permissions of a virtual machine provided by an embodiment of the present application;
[0096] Figure 6 is a block diagram of a device for controlling access permissions of a virtual machine provided by an embodiment of the present application;
[0097] Figure 7 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application.
[0098] Through the above-mentioned accompanying drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These accompanying drawings and the textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0099] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0100] First, the terms involved in the present application will be explained:
[0101] 1. File and Registry Filter Driver
[0102] Using the interfaces provided by the Windows operating system, the filter driver can capture the write operations of programs in Windows on files and the registry. By modifying the parameters of the write operations, the write operations can be redirected to another location. In this way, when an administrator edits a virtual machine image, the write operations of the software installation package can be redirected to a disk partition (referred to as the application layering disk). When Windows reads these files and the registry, the two filter drivers modify the parameters of the read operations to point to the path of the disk partition, enabling Windows to access the files and the registry normally.
[0103] When the file filter driver captures the read and write operations of a program on a file, it can also determine whether to intercept the read and write operations by identifying the path information of the target file in the read and write parameters, so that a certain program can only access files in a certain area.
[0104] 2. Application Layering
[0105] From the above introduction of the file and registry filter driver, by redirecting the write operations of the installation package, one or more installed software can be written entirely to the application layering disk. If this partition is loaded into a certain Windows operating system, it will be found that the installed software saved in the partition appears in this operating system. In this way, the application software and the operating system can be separated and combined as if the application software exists separately in a layer, so it is called application layering.
[0106] For Windows, the software in the application layering is the same as the locally installed software. For example, they are both located in the C:\Program Files(x86) directory (because the files in the application layering are redirected back to the C:\Program Files(x86) directory). However, for the file filter driver, it is clear which software is actually installed in the C:\Program Files(x86) directory and which software is physically stored in the application layering disk.
[0107] 3. Network Filter Driver
[0108] The network filter driver can perform network filtering at multiple layers. When intercepting network communication, it can obtain the current application path and process ID to achieve process-based network filtering.
[0109] 4. Internal and External Network IP Addresses
[0110] In the TCP / IP protocol, three IP address ranges are specifically reserved as private addresses (internal network IPs), and their address ranges are as follows:
[0111] 10.0.0.0 / 8: 10.0.0.0 to 10.255.255.255
[0112] 172.16.0.0 / 12: 172.16.0.0 to 172.31.255.255
[0113] 192.168.0.0 / 16: 192.168.0.0 to 192.168.255.255
[0114] By determining whether a server's IP address falls within these three IP ranges, it can be known whether it is an internal or external network IP. In practice, some customers may use an external network segment IP as an internal network IP address. Therefore, an interface can be provided to allow administrators to add the range of internal network IPs.
[0115] 5. Cloud Desktop
[0116] Through virtualization technology, virtual machines are run on the server, and the terminal is only responsible for displaying the virtual desktop image and receiving keyboard and mouse messages. This virtual desktop is called a cloud desktop. The cloud desktop and its data are separated from the physical terminal, which can ensure that the data is always stored on the server and achieve data non-landing. Through peripheral redirection, the control of peripheral access can be achieved. Therefore, the cloud desktop environment itself is data secure.
[0117] Currently, on the cloud desktop of the virtual machine, for example, the R & D desktop, there is a need to store business data such as source code and also a need to access the external network. Therefore, it is very easy to leak data through the network. A working environment that can access the external network but does not transmit data through the network needs to be provided.
[0118] To address the above problems, there is currently a personal computer PC + cloud desktop solution. Each employee has a PC and a cloud desktop. The PC can only access the internal network for development; the cloud desktop uses a software whitelist solution to prevent the installation of development tools on the cloud desktop, so it is only used to access the external network purely.
[0119] The above solution can well isolate the working area and the Internet access area, preventing business data from being transmitted externally through the network. However, the cost is that an employee needs to be equipped with two desktops, doubling the deployment cost.
[0120] In response to the above problems, there are currently implementation solutions using sandbox technology. One is to install business data and application programs in a sandbox desktop as a secure area; the area outside the sandbox is used as an insecure area for Internet access. Business data generated within the secure area cannot be copied to the insecure area to protect business data. The other is to install business data and application programs in one sandbox desktop and install the remaining Internet application programs in another sandbox desktop. Their access to different networks is controlled through sandbox policies, and programs in the second sandbox cannot access the business data in the first sandbox. When programs in the first sandbox write data to the second sandbox, it will be encrypted.
[0121] However, the above solutions have the following problems:
[0122] 1. Since the business software and business data that need to be kept confidential are placed in the sandbox for protection (perhaps a concept left over from the personal computer PC era, where data security in the PC environment is not guaranteed. For example, users can obtain data by unplugging the hard drive), the advantage of data not landing in the cloud desktop solution is not fully utilized, resulting in the need for the sandbox to be adapted and compatible with a wide variety of business software. And the compatibility of the sandbox has an upper limit. For example, it does not support business software with drivers. In addition, for some development software that needs to connect to physical peripherals for debugging, there may also be compatibility problems. Moreover, the operating experience of running software in the sandbox is not exactly the same as that of native programs.
[0123] 2. Administrators cannot uniformly manage the business software in the sandbox. If a new business software needs to be added, it needs to be deployed one by one on each user's desktop.
[0124] 3. Users can download insecure software through the Internet software in the sandbox and run it in the sandbox, or they can write and run insecure software outside the sandbox through development tools. When illegal software can be run both inside and outside the sandbox, it is very easy to break through the data isolation of the sandbox. For example, data can be transmitted through means such as the registry, broadcast messages, and Windows kernel shared memory and sent to the external network.
[0125] To solve the problems of high cost, poor compatibility, difficult management, and security vulnerabilities in the data leakage prevention solution, in the cloud desktop of a virtual machine in the embodiments of the present application, by means of application layering, Internet access applications and local application software (local business software) are distinguished, and then the file areas they can access are restricted through a file filtering driver, and the IP addresses of the remote servers they can access are restricted through a process-based network filtering driver, and the process communication between these two types of application programs is restricted, realizing data leakage prevention with dual use of one machine.
[0126] In the solution of the present application, when the user operates a virtual machine, one desktop is adopted, and the interference with business software is small and their compatibility is not affected; software batch update can be realized by using application layering; it can be ensured that only the programs recorded in the application layering disk can access the Internet, without leaving security vulnerabilities.
[0127] The access permission control method for a virtual machine provided by the present application aims to solve the above technical problems in the prior art. The technical solution of the present application and how the technical solution of the present application solves the above technical problems will be described in detail below with specific embodiments. These specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below with reference to the drawings.
[0128] Figure 1 is a schematic flowchart of an access permission control method for a virtual machine provided by an embodiment of the present application, as Figure 1 shown, the method includes:
[0129] S101, after logging in to the cloud desktop of the virtual machine on the terminal device, load the data transfer disk and software layering disk of the virtual machine, where the software layering disk is used to record the target application programs that can only access the target servers in the specified network, data isolation is performed between the software layering disk and the local disk of the terminal device, and the data transfer disk is used to perform data transfer with the local disk and the software layering disk respectively;
[0130] S102, in response to recognizing a startup operation on the target application program, determine the access permission of the target application program according to the type of the target application program recorded in the software layering disk.
[0131] Optionally, the embodiments of the present application provide a flexible internal and external network access method, which can not only meet the user's Internet access needs on the virtual machine, but also avoid data leakage and attacks between the internal and external networks.
[0132] Optionally, the above specified network includes: an internal network and an external network. The external network refers to the public Internet, and the internal network refers to the private local area network.
[0133] Optionally, the target application refers to an application running in a virtual machine, such as an Internet application or a local application. An Internet application refers to an application that can only access servers on an external network, such as a browser or a mail client. A local application refers to an application that can only access servers on an internal network, such as office software or a database management system.
[0134] Optionally, the above data isolation means that data cannot be directly read or written between the software layered disk and the local disk of the terminal device.
[0135] Optionally, a virtual machine refers to a simulated computer system running in a terminal device. A software layered disk is a special virtual disk used to record Internet applications that can only access servers on an external network. A data transfer disk is a temporary storage space used to transfer data between the virtual machine and the terminal device. Loading means mounting the data transfer disk and the software layered disk of the virtual machine into the virtual machine so that they can be accessed by the virtual machine.
[0136] In an embodiment of the present application, after logging in to the cloud desktop of the virtual machine of the terminal device, two disks are loaded on the virtual machine, one is a data transfer disk and the other is a software layered disk.
[0137] In one example, the data transfer disk is a temporary storage space used to transfer data between the local disk and the software layered disk without affecting the content of the local disk or the software layered disk. For example, if a user wants to send a file on the local disk to an application on the software layered disk, the file can be first copied to the data transfer disk and then copied from the data transfer disk to the software layered disk.
[0138] In one example, the software layered disk is a special virtual disk used to record target applications that can only access servers on a specified network, such as Internet applications or local applications. These applications can run in the virtual machine but cannot access the local disk or other networks, thus protecting the security of data and networks.
[0139] For example, in an example of the present application, the software layered disk (e.g., drive M:) is obtained by recording the local disk and is an image of the local disk (e.g., local drive C:). However, the software layered disk and the local disk are data-isolated, that is, they cannot directly access and modify each other's data and can only exchange data through the data transfer disk (e.g., drive S:).
[0140] In one example, taking the above target program as an Internet application program, on the cloud desktop of the virtual machine, users can use the application programs on the software layered disk to access the external network. For example, Internet application programs such as browsers, email clients, and instant messaging tools can communicate with servers on the external network. For example, they can access web pages, send emails, chat, etc. However, Internet application programs cannot access the local disks of the internal network, thus not breaking the isolation and security between the internal and external networks and not affecting the compatibility of various business software.
[0141] In an alternative embodiment, the administrator can maintain Internet application programs at any time. By determining whether an Internet application program is in the program list recorded by the administrator, without the need for the administrator to manually configure (manual configuration is laborious, error-prone, and has a very high usage threshold) the whitelist of programs that can access the external network, it can be easily ensured that only the programs recorded by the administrator can access the Internet. The administrator's operation is simple and the usage threshold is low. Moreover, the system has good security and can ensure that the programs accessing the Internet are all recorded by the administrator.
[0142] In another example, still taking the above target program as an Internet application program, without setting the local desktop of the terminal device, on the cloud desktop of the virtual machine, local application programs access the local disks of the above terminal device. For example, they access office software, graphic editors, database management tools, etc. on the local disks in the internal network. These application programs can also communicate with servers in the internal network. For example, they can open documents, modify pictures, query data, etc. However, local application programs are not allowed to access the software layered disk and the data transfer disk, that is, they cannot access the external network because this may lead to data leakage and attacks on the external network.
[0143] There is also an alternative embodiment where the access permission is determined according to the type of the target application program and the IP address of the target server being accessed. For example, if the target application program is an Internet application program, then it is only allowed to access external network IP addresses. If it is a local application program, then it is only allowed to access internal network IP addresses. In this way, it can prevent the target application program from accessing inappropriate networks or servers, thus avoiding the possibility of network pollution or information leakage.
[0144] Moreover, in the embodiments of the present application, there is no layer of isolation between the local application program and the operating system. Therefore, it does not affect the compatibility and running performance of the local application program, and users can also install and uninstall the local application program at any time.
[0145] Through the embodiments of the present application, taking the above target application programs including local application programs and Internet application programs as an example, by setting up a data transfer disk and a software layering disk on a virtual machine, and loading the data transfer disk and the software layering disk in response to logging in to the cloud desktop of the virtual machine on the terminal device, data isolation and secure transmission of the virtual machine are achieved, and the risks of data leakage and tampering are avoided. By determining the access permissions of the target application program according to the type of the target application program recorded by the software layering disk, it is possible to isolate the use of local application programs and Internet application programs on the cloud desktop of the same virtual machine without affecting the security and isolation of the internal and external networks, thereby achieving access control and network isolation of the virtual machine and preventing the threats of illegal access and network attacks.
[0146] The access permission control method of the virtual machine can be applicable to Figure 2 An optional schematic diagram of the architecture of a virtual machine shown in the figure. In an optional example, for a Windows dual-use cloud desktop, components such as an application layering module, a network filtering driver module, and an application layer proxy program can be used to control and intercept data exchange and network communication between local application programs and Internet application programs to ensure the isolation and security of the internal and external networks. As Figure 2 shown in the figure, the virtual machine includes:
[0147] An application layering module for implementing file filtering drivers and registry filtering drivers; specifically, it is also responsible for implementing the application layering function (recording and loading the software layering disk M:\); responsible for generating the data transfer disk S:\; taking the target program as an Internet application program as an example, the application layering module is also used to intercept the access of the Internet application program to local business files, and intercept the write operations of local application programs to the data transfer disk S:\ and the software layering disk M:\; intercept the operation of non-administered recorded programs on the software layering disk.
[0148] The network filtering driver module, specifically the process-based network filtering driver module, is used to intercept the processes for TCP external connection events, the processes for Transmission Control Protocol (TCP) receiving connection events, and the processes for User Datagram Protocol (UDP) packet sending events and packet receiving events. Then, it obtains the process identifier of the process (for example, the process id), determines whether the process belongs to a local application or an Internet access application of the software layered disk, and then intercepts the communication between the local application and the external network server, as well as the communication between the Internet access application and the internal network server, based on whether the IP address of the remote server accessed by the process is an internal network server or an external network server. Optionally, the above process-based network filtering driver can also use the TrandportDriver Interface (TDI) to implement the filtering driver.
[0149] In the embodiments of this application, the network filtering driver module also supports exception authorization for individual processes. For example, it allows local applications (such as distributed version control systems (such as the software program GIT), drawing software CAD, browsers, code-writing programs vscode, etc.) to access external network plugin servers, and so on.
[0150] The application layer proxy program can also be used to be responsible for implementing one-way reading of the clipboard, screenshots, etc. of the local application by the Internet access application; intercepting the process communication between the Internet access application and the local application; being responsible for implementing file encryption / decryption mutual transfer between the local disk and the data transfer disk, and between the software layered disk and the data transfer disk; and also being used to initiate a decryption application, upload encrypted data such as encrypted files to the approval system, and receive the approval system instruction to decrypt the above encrypted data.
[0151] In addition, in one example, for some cloud desktops that process data such as security and government affairs, in order to protect the internal network server from being attacked by unknown download software, it is required that only specific applications can access the internal network server. The embodiments of this application can modify the policy so that only the Internet access applications recorded by the administrator have the permission to access the internal network IP, and other Internet access applications can only access the external network, thus realizing that one cloud desktop can access the external network and run internal network applications, and ensuring the security of the internal network server. In this case, since there is no need to protect local data files, it is not limited to be in the cloud desktop either.
[0152] In one embodiment, the following method is used to determine the type of the above target application:
[0153] S201, obtain the process of the terminal event of the above terminal device and the process identifier of the above process, where the above terminal event includes at least one of the following: external connection event, receive connection event, message sending event, and message receiving event;
[0154] S202, identify the type of the target application program to which the above process belongs according to the process identifier of the above process.
[0155] Optionally, the above terminal event refers to the communication activity between the terminal device and an external network or server, such as an external connection event, a receive connection event, a message sending event, and a message receiving event. It can be understood that each terminal event is initiated or responded to by a process, and a process refers to a program or task running on the terminal device. Each process has a process identifier, which is used to uniquely distinguish different processes.
[0156] Optionally, in the example of this application, the process identifier is a tag used to identify a process, usually including information such as the name, path, and version of the process.
[0157] By obtaining the process and process identifier of the terminal event of the terminal device, the communication behavior of the terminal device can be monitored and analyzed in real time, so as to determine the type of the target application program to which the process belongs, such as: an Internet application program or a local application program. Further, by identifying the type of the target application program to which the process belongs according to the process identifier, the target application programs can be classified into different categories, such as Internet application programs or local application programs. In this way, different access permissions can be set according to different application program types, for example, only Internet application programs are allowed to access the external network, and only local application programs are allowed to access the internal network. Furthermore, the classified management of the target application programs can be realized, which is convenient for controlling and protecting the security of data and the network.
[0158] By obtaining the process and process identifier of the terminal event of the terminal device, the dynamic identification of the type of the target application program is realized, which improves the flexibility and accuracy of access control. By identifying the type of the target application program to which the process belongs according to the process identifier, the classified management of the target application programs is realized, which is convenient for setting different access permissions according to different application program types.
[0159] In one embodiment, Figure 3 is a schematic flowchart of an optional access permission control method for a virtual machine provided by an embodiment of this application, as Figure 3 shown, to determine the access permission of the above target application program according to the type of the above target application program, including:
[0160] S301, obtain the IP address of the target server accessed by the above process, where the above IP address includes: internal network IP address and external network IP address;
[0161] S302. Determine whether to allow communication between the process and the target server according to the type of the target application to which the process belongs and the target server accessed by the process.
[0162] In an alternative embodiment, the above method steps further refine how to control and intercept network communication between local applications and Internet access applications to ensure the isolation and security of the internal and external networks.
[0163] Optionally, the IP address of the target server refers to the Internet Protocol address, which is a digital label used to identify network devices. IP addresses are divided into internal network IP addresses and external network IP addresses. An internal network IP address refers to an IP address used within a local area network, and an external network IP address refers to an IP address used on a public network.
[0164] In the example of this application, the above communication refers to the data exchange between the process and the target server, which is usually implemented through network protocols and ports. By determining whether to allow communication between the process and the target server according to the type of the target application to which the process belongs and the target server accessed by the process, the control of the network access of the target application can be achieved. For example, if the target application to which the process belongs is an Internet access application, then only communication with an external network server is allowed. If it is a local application, then only communication with an internal network server is allowed. In this way, it is possible to prevent the target application from accessing inappropriate networks or servers, thereby preventing the possibility of network pollution or information leakage.
[0165] By obtaining the IP address of the target server accessed by the process, it can be determined whether the target server is located in the internal network or the external network, and thus different access permissions can be set according to different network locations, improving the accuracy and security of access control. By determining whether to allow communication between the process and the target server according to the type of the target application to which the process belongs and the target server accessed by the process, the control of the network access of the target application is achieved, preventing the possibility of network pollution or information leakage.
[0166] In one embodiment, Figure 4 is a schematic flowchart of an alternative method for controlling access permissions of a virtual machine provided by an embodiment of this application. As Figure 4 shown, determining whether to allow communication between the process and the target server according to the above IP address and the target application to which the process belongs includes:
[0167] S401. If the target application to which the process belongs is an Internet access application and the IP address of the target server accessed by the process is an external network IP address, determine to allow communication between the process and the target server;
[0168] S402, if the target application to which the above process belongs is an Internet application and the IP address of the target server accessed by the above process is an internal network IP address, then determine to intercept the communication between the above process and the above target server;
[0169] S403, if the target application to which the above process belongs is a local application and the IP address of the target server accessed by the above process is an internal network IP address, then determine to allow the communication between the above process and the above target server;
[0170] S404, if the target application to which the above process belongs is a local application and the IP address of the target server accessed by the above process is an external network IP address, then determine to intercept the communication between the above process and the above target server.
[0171] Optionally, the above IP address and the target application to which the process belongs are two important factors that affect whether the communication between the process and the target server is legal and necessary. By determining whether to allow the communication between the process and the target server based on these two factors, fine control of the network access of the target application can be achieved, thereby improving network security and efficiency.
[0172] For example, if the target application to which the process belongs is an Internet application, then it should only communicate with external network servers. If it communicates with internal network servers, it may cause pollution or leakage of the internal network. If the target application to which the process belongs is a local application, then it should only communicate with internal network servers. If it communicates with external network servers, it may cause external attacks or congestion. By determining whether to allow the communication between the process and the target server based on the IP address and the target application to which the process belongs, these situations can be effectively prevented, thereby improving network security and efficiency.
[0173] Furthermore, by setting different communication policies according to different application types and network locations, network isolation of the target application can be achieved, thereby preventing the possibility of network pollution or information leakage. For example, if the target application to which the process belongs is an Internet application, then the communication policy is to only allow communication with external network IP addresses and intercept communication with internal network IP addresses. In this way, it can be ensured that the Internet application can only access the external network and will not affect the security and stability of the internal network. If the target application to which the process belongs is a local application, then the communication policy is to only allow communication with internal network IP addresses and intercept communication with external network IP addresses. In this way, it can be ensured that the local application can only access the internal network and will not be exposed to the risks and interferences of the external network. By setting different communication policies according to different application types and network locations, network isolation of the target application can be achieved, thereby preventing the possibility of network pollution or information leakage.
[0174] By determining whether to allow communication between a process and a target server according to the IP address and the target application to which the process belongs, fine-grained control over the network access of the target application is achieved, improving network security and efficiency. By setting different communication policies according to different application types and network locations, network isolation of the target application is achieved, preventing the possibility of network pollution or information leakage.
[0175] In one embodiment, obtaining the process of the terminal event of the above terminal device and the process identifier of the above process includes:
[0176] Using the network filtering driver module set in the above terminal device, obtain the process of the terminal event of the above terminal device and the process identifier of the above process.
[0177] Optionally, the above embodiment specifically illustrates the technical means for obtaining the process of the terminal event of the terminal device and the process identifier of the above process, mainly including the following content:
[0178] Using the network filtering driver module set in the terminal device, obtain the process of the terminal event of the terminal device and the process identifier of the above process, that is, filter, intercept, and analyze the network traffic on the terminal device through the above network filtering driver module, and extract information about the process where the terminal event occurs from it, such as process name, process ID, process path, etc.; and, the network filtering driver module is also used to separately authorize individual processes in local applications and / or Internet applications, and thus permission management of the processes on the terminal device can be realized. For example, users can allow or prohibit certain processes from accessing the internal and external networks, or set access rules and conditions for certain processes to achieve more detailed network control.
[0179] The network filtering driver module is a driver program installed in the terminal device for filtering and intercepting the network communication of the terminal device. By using the network filtering driver module, when a terminal event occurs, the process and process identifier of the terminal event can be immediately obtained without waiting or querying other systems or modules. In this way, efficient acquisition of the process and process identifier of the terminal event can be realized, thereby improving the speed and accuracy of target application type recognition.
[0180] In addition, by using the network filtering driver module, the process of the terminal event can be intercepted and analyzed before the terminal event occurs without relying on or interfering with other systems or modules. In this way, underlying interception and analysis of the process of the terminal event can be realized, thereby improving the security and reliability of target application type recognition.
[0181] In one embodiment, the above method further includes:
[0182] Use the network filtering driver module set in the above terminal device to separately authorize the processes of individual above terminal events.
[0183] For example, if the target application to which a certain process belongs is an Internet application, but it needs to access some resources of the internal network server, then the process can be separately authorized to allow it to communicate with the internal network server without affecting the communication policies of other Internet applications.
[0184] By using the network filtering driver module, the processes of individual terminal events can be separately authorized, that is, according to specific situations or requirements, the communication between certain processes and the target server can be allowed or intercepted without affecting the communication of other processes. In this way, separate authorization of the processes of individual terminal events can be achieved, thereby improving the flexibility and adaptability of access control.
[0185] In addition, the network filtering driver module can also be used to perform special processing on the processes of individual terminal events, that is, according to specific rules or conditions, encrypt, record, audit or perform other operations on the communication between certain processes and the target server without affecting the communication of other processes. In this way, special processing of the processes of individual terminal events can be achieved, thereby improving the security and efficiency of access control. For example, if the target application to which a certain process belongs is a local application, but it needs to access some sensitive information of the external network server, then the process can be specially processed, and the communication between it and the external network server can be encrypted and recorded to prevent information leakage or tampering without affecting the communication efficiency of other local applications.
[0186] In one embodiment, the above specified network includes: an external network, and determining the access rights of the above target application according to the type of the above target application includes:
[0187] If it is determined that the type of the above target application is an Internet application that is only allowed to access servers on the external network, then it is determined that only the above Internet application is allowed to access the above software layered disk, and the above Internet application is intercepted from accessing the above local disk.
[0188] Optionally, the above external network refers to the public Internet, and the internal network refers to the private local area network. The target application refers to an application running in a virtual machine, such as an Internet application or a local application. An Internet application refers to an application that is only allowed to access servers on the external network, such as a browser or a mail client. A local application refers to an application that is only allowed to access servers on the internal network, such as office software or a database management system.
[0189] By specifying the external network as the access scope for the target application, network isolation for the Internet-accessible application can be achieved, that is, only allowing the Internet-accessible application to communicate with the servers on the external network, while not allowing the Internet-accessible application to communicate with the servers on the internal network. In this way, the security and stability of the internal network can be protected, preventing the Internet-accessible application from causing pollution or leakage of the internal network.
[0190] Furthermore, by only allowing the Internet-accessible application to access the software-layered disk and intercepting the Internet-accessible application's access to the local disk, data isolation for the Internet-accessible application can be achieved, that is, only allowing the Internet-accessible application to exchange data with the software-layered disk, while not allowing the Internet-accessible application to exchange data with the local disk. In this way, the security and integrity of the data on the local disk can be protected, preventing the Internet-accessible application from causing damage or leakage of the local disk.
[0191] In one embodiment, after logging in to the cloud desktop of the virtual machine of the terminal device and before loading the data transfer disk and software-layered disk of the virtual machine, the above method further includes:
[0192] In response to the mirror editing operation on the local disk, record the Internet-accessible applications in the local disk that are only allowed to access the servers on the external network in the virtual machine to obtain the software-layered disk.
[0193] Optionally, the local disk refers to the physical disk of the terminal device, and the mirror editing operation refers to an operation of modifying or adding content to the local disk, such as installing or uninstalling an application.
[0194] For example, Internet software that the user wants to use can be installed and configured on the local disk, such as: browsers, email clients, instant messaging tools, etc., and then the local disk is mirror-edited in the virtual machine to generate a software-layered disk, which contains the Internet software that the user wants to use, as well as the corresponding settings and data.
[0195] In addition, for another example, a data transfer disk can be created in advance on the terminal device for transferring data between the local disk and the software-layered disk. This data transfer disk can be a fixed disk partition or a removable disk device, such as a USB flash drive, a portable hard drive, etc.
[0196] Through the above method steps, it is possible to generate a data transfer disk on the virtual machine by mirror editing the local disk, preparing for the login operation of the virtual machine. Specifically, through the mirror editing of the local disk, the customization and personalization of the software-layered disk are achieved, improving the adaptability and compatibility of the Internet software; by pre-generating the data transfer disk, data exchange between the local disk and the software-layered disk can be performed subsequently.
[0197] For example, if a user wants to save a file on a software layered disk to a local disk, the file can be first copied to a data transfer disk and then copied from the data transfer disk to the local disk.
[0198] Optionally, in the embodiments of the present application, the data transfer operation can be manual, that is, the user can select the file to be transferred and the target location by himself, or it can be automatic, that is, the user only needs to set some rules or conditions to let the system automatically execute the data transfer operation, such as: scheduled transfer, on-demand transfer, transfer by type, etc.
[0199] Through the embodiments of the present application, it is possible to perform data exchange between the local disk and the software layered disk on the virtual machine through the data transfer disk, realizing data synchronization and backup between the local disk and the software layered disk, and improving the availability and reliability of the data; through the control of the data transfer operation, it is possible to screen and filter the transfer data between the local disk and the software layered disk, improving the effectiveness and legality of the data.
[0200] By responding to the mirror editing operation on the local disk and recording the Internet application programs of the server that only accesses the external network in the virtual machine, it is possible to realize the dynamic generation of the software layered disk, that is, according to the changes of the local disk, automatically update the content of the software layered disk, so as to ensure the synchronization between the software layered disk and the local disk. In this way, the flexibility and adaptability of the software layered disk can be improved, enabling it to adapt to different user needs and scenarios.
[0201] By generating the software layered disk before loading the data transfer disk and the software layered disk of the virtual machine, it is possible to perform preprocessing on the software layered disk, that is, before the virtual machine starts, complete the update and inspection of the content of the software layered disk, thus avoiding frequent read and write operations on the software layered disk during the operation of the virtual machine, and improving the security and efficiency of the software layered disk.
[0202] Optionally, in the embodiments of the present application, an application layering module set in the terminal device is used to record the local disk in the virtual machine to obtain the software layered disk. It can be understood that in the embodiments of the present application, an application layering module is specifically used to layer the local disk, separate the Internet software and related data and settings that the user wants to use, and form a separate disk layer, which is the software layered disk. It can be separated from other layers of the local disk or merged with other disk layers.
[0203] Moreover, in the embodiments of the present application, the application layering module is further configured to support the virtual machine to perform file filtering drivers and registry filtering drivers, and generate a data transfer disk. That is, this software tool can be used to perform some settings and optimizations on the virtual machine. For example, the virtual machine can only access files and registries on the software layering disk under certain conditions, and cannot access files and registries on the local disk. In addition, a data transfer disk can be created in the virtual machine to transfer data between the software layering disk and the local disk.
[0204] In one embodiment, Figure 5 is a schematic flowchart of an optional method for controlling access rights of a virtual machine provided by the embodiments of the present application. As Figure 5 shown, based on the method steps provided in the above various embodiments, other technical means included in this method are supplemented. The above method further includes at least one of the following:
[0205] S501: Using the application layer proxy program in the above terminal device, control the local application program to unidirectionally read part of the data from the Internet access application program, where the above part of the data includes: clipboard and screenshots;
[0206] S502: Using the application layer proxy program in the above terminal device, intercept the process communication between the above local application program and the above Internet access application program;
[0207] S503: Using the application layer proxy program in the above terminal device, encrypt the transmission data between the above local disk and the above data transfer disk, and between the above software layering disk and the above data transfer disk;
[0208] S504: Using the application layer proxy program in the above terminal device, upload the encrypted transmission data to the approval system to obtain the approval system instruction to decrypt the encrypted transmission data.
[0209] For example, the user can copy some text or pictures from the Internet access application program and then paste them on the local application program, but cannot operate in the reverse. For example, it is not allowed to copy data from the local application program and then paste it on the Internet access application program, because this will cause data leakage and attacks.
[0210] For example, it is prohibited for the local application program and the Internet access application program to call or pass parameters to each other, because this will damage the isolation and security between the internal and external networks.
[0211] For example, when the user copies data from the local disk to the data transfer disk, the data can be encrypted, and then when copying from the data transfer disk to the software layering disk, the data can be decrypted, which can ensure the security and integrity of the data during the transmission process.
[0212] For example, when a user wants to copy data from a local disk to a software - layered disk, the encrypted data can be first uploaded to an approval system (operated by an administrator or automatically based on rules), and then wait for the instructions from the approval system. If the approval system approves the user's request, the user can copy the data from the data transfer disk to the software - layered disk. If the approval system rejects the user's request, the data cannot be copied from the data transfer disk to the software - layered disk. This can ensure the legality and compliance of the data.
[0213] Through the above - mentioned embodiments of the present application, by adopting the application - layer proxy program, it is possible to realize the control and interception of data exchange and communication between the local application program and the Internet - access application program, realize the data reading and isolation between the local application program and the Internet - access application program, and improve the availability and security of the data; by encrypting the transmitted data, it is possible to realize the security and integrity of data transmission between the local disk and the software - layered disk, and improve the confidentiality and integrity of the data; by approving the encrypted data and decrypting the instructions, it is possible to realize the legality and compliance of data transmission between the local disk and the software - layered disk, and improve the legality and compliance of the data.
[0214] By adopting the application - layer proxy program in the terminal device, the control of data and communication between the local application program and the Internet - access application program is realized, and the security and efficiency of data and network are improved. The application - layer proxy program is a program running in the terminal device, used to intercept and forward data and communication between the local application program and the Internet - access application program. The local application program refers to an application program that can only access the server of the internal network, and the Internet - access application program refers to an application program that can only access the server of the external network. By adopting the application - layer proxy program, the control of data and communication between the local application program and the Internet - access application program can be realized. For example, control the local application program to unidirectionally read part of the data from the Internet - access application program, and intercept the process communication between the local application program and the Internet - access application program. In this way, the security and efficiency of data and network can be improved, preventing data leakage or tampering, as well as network pollution or attack.
[0215] By adopting an application-layer proxy program, the encryption and approval of transmitted data are realized, improving the confidentiality and legality of the data. The transmitted data refers to the data transmitted between the virtual machine and the terminal device, including the data between the local disk and the data transfer disk, and the data between the software-layered disk and the data transfer disk. The local disk refers to the physical disk of the terminal device, the data transfer disk is a temporary storage space, and the software-layered disk is a special virtual disk. By adopting the application-layer proxy program, the encryption and approval of the transmitted data can be realized. For example, the transmitted data between the local disk and the data transfer disk, and between the software-layered disk and the data transfer disk is encrypted, and the encrypted transmitted data is uploaded to the approval system to obtain the approval system instruction to decrypt the encrypted transmitted data. In this way, the confidentiality and legality of the data can be improved, preventing the leakage or tampering of the data, as well as the illegal use or dissemination of the data.
[0216] In one embodiment, the above method further includes at least one of the following:
[0217] In response to the access operation of the Internet application program to the operating system file, the application layering module in the above terminal device is used to perform file filtering drive on the above virtual machine, allowing the above Internet application program to access the operating system file on the above local disk;
[0218] In response to the installation operation of the above Internet application program, the above application layering module redirects the above Internet application program to the above software-layered disk, and the above application layering module is used to perform registry filtering drive on the above virtual machine, and record the registry change information during the installation process to the above software-layered disk.
[0219] Optionally, the application layering module is a program running in the terminal device, used for hierarchical management of the files and registries of the Internet application program. Files and registries refer to the data stored in the operating system, including system configurations, application program settings, user information, etc.
[0220] Optionally, the operating system file refers to the core files in the operating system, including system programs, driver programs, library files, etc. The operating system files are usually stored on the local disk, and the local disk refers to the physical disk of the terminal device.
[0221] In the above method embodiments, by responding to the access operation of the above Internet application program to the operating system files, using the above application layering module to perform file filtering drive on the above virtual machine, and allowing the above Internet application program to access the operating system files on the above local disk, file filtering on the virtual machine can be achieved, enabling the Internet application program to access the operating system files on the local disk. For example, users can allow the Internet application program to access system configuration files, system log files, system font files, etc. on the local disk. This can ensure the normal operation and display of the Internet application program, and improve the availability and compatibility of the files.
[0222] In response to the installation operation of the above Internet application program, using the above application layering module to redirect the above Internet application program to the above software layering disk, and using the above application layering module to perform registry filtering drive on the above virtual machine, recording the registry change information during the installation process to the above software layering disk. In this way, when installing an application program on the virtual machine, it can be installed on the software layering disk instead of the local disk. For example, users can install a new browser on the virtual machine, and then this browser will be redirected to the software layering disk without affecting other application programs on the local disk. At the same time, users can also use this software tool to filter the registry on the virtual machine, so that the registry change information during the installation process is also recorded on the software layering disk instead of the registry on the local disk. This can ensure the independence and isolation of the Internet application program, and thus achieve the layering and isolation of the installation and registry changes of the Internet application program, improving the security and efficiency of the application program.
[0223] In the embodiments of this application, application layering (file filtering drive and registry filtering drive based on the file system micro-filter driver Minifilter) technology can be specifically adopted to identify Internet software and local business software, thereby controlling the file areas that these software can access respectively; combined with network filtering drive technology based on processes, controlling the internal and external network IP areas that these software can access respectively; and finally controlling the process communication (such as the clipboard, etc.) between these local application software and Internet application programs. It can be achieved that within a cloud desktop virtual machine, some software can access the local disk but cannot access the external network, and some disks can access the external network, but the local files read are all encrypted. In this way, within a virtual machine, the effects of running local application programs (such as vscode) and external communication software (such as Internet application programs like instant messaging software) at the same time, and not leaking local business data can be satisfied.
[0224] By adopting an application layering module, hierarchical management of the files and registry of Internet access applications can be achieved, thereby avoiding chaos or conflicts in the files and registry and improving the read / write speed of the files and registry. By adopting the application layering module, access control over the operating system files of Internet access applications can also be achieved, which can improve the protection and compatibility of the operating system files, prevent Internet access applications from modifying or deleting the operating system files, and ensure the normal operation of Internet access applications.
[0225] In one embodiment, the specified network further includes: an internal network. Determining the access permission of the target application according to the type of the target application recorded by the software layering disk includes:
[0226] If it is determined that the type of the target application is a local application that is only allowed to access the server of the internal network, it is determined that only the local application is allowed to access the local disk, and the access of the local application to the software layering disk and the data transfer disk is intercepted.
[0227] Optionally, the internal network refers to a private local area network, and the external network refers to a public Internet. The target application refers to an application running in a virtual machine, such as a local application or an Internet access application. A local application refers to an application that is only allowed to access the server of the internal network, such as office software or a database management system. An Internet access application refers to an application that is only allowed to access the server of the external network, such as a browser or a mail client.
[0228] Through the above method steps, by adopting the method of specifying the internal network as the access range of the target application, network isolation of the local application is achieved, that is, only the local application is allowed to communicate with the server of the internal network, and the local application is not allowed to communicate with the server of the external network. In this way, the security and stability of the external network can be protected, and the pollution or leakage of the external network caused by the local application can be prevented.
[0229] Furthermore, only allowing the local application to access the local disk and intercepting the access of the local application to the software layering disk and the data transfer disk realizes data isolation of the local application, prevents the local application from exchanging data with the software layering disk and the data transfer disk, and thus protects the security and integrity of the data on the software layering disk and the data transfer disk.
[0230] In one embodiment, before loading the data transfer disk and the software layering disk of the virtual machine after logging in to the cloud desktop of the virtual machine of the terminal device, the method further includes:
[0231] In response to an image editing operation on the above local disk, record the local applications of the servers that can only access the internal network in the above local disk in the above virtual machine to obtain the above software layered disk.
[0232] Through the above example, in response to an image editing operation on the local disk, recording the local applications of the servers that can only access the internal network in the virtual machine realizes the dynamic generation of the software layered disk, improving the flexibility and adaptability of the software layered disk; before loading the data transfer disk and the software layered disk of the virtual machine, generating the software layered disk realizes the preprocessing of the software layered disk, improving the security and efficiency of the software layered disk.
[0233] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or reject.
[0234] According to one or more embodiments of the present application, an embodiment of an access permission control device for a virtual machine is provided. Figure 6 The following is a structural block diagram of an access permission control device for a virtual machine provided by an embodiment of the present application, as Figure 6 shown, the above device includes:
[0235] A loading module 601, configured to load the data transfer disk and the software layered disk of the above virtual machine in response to logging in to the cloud desktop of the virtual machine on the terminal device, wherein the above software layered disk is used to record the target applications of the servers that can only access the specified network, data isolation is performed between the above software layered disk and the local disk of the above terminal device, and the above data transfer disk is used to perform data transmission with the above local disk and the above software layered disk respectively;
[0236] An access control module 602, configured to determine the access permission of the above target application according to the type of the above target application recorded by the above software layered disk in response to identifying a startup operation on the above target application.
[0237] In one embodiment, the following module is used to determine the type of the above target application:
[0238] A process identifier acquisition module, configured to acquire the process of the terminal event of the above terminal device and the process identifier of the above process, wherein the above terminal event includes at least one of the following: external connection event, received connection event, message sending event, and message receiving event;
[0239] An identification module, configured to identify the type of the target application to which the above process belongs according to the process identifier of the above process.
[0240] In one embodiment, the above access control module includes:
[0241] An obtaining unit, configured to obtain the IP address of the target server accessed by the above process, where the above IP address includes: an internal network IP address and an external network IP address;
[0242] A first access control unit, configured to determine whether to allow communication between the above process and the target server according to the type of the target application to which the above process belongs and the target server accessed by the above process.
[0243] In one embodiment, the above access control unit includes:
[0244] A first determination subunit, configured to determine to allow communication between the above process and the above target server if the target application to which the above process belongs is an Internet application and the IP address of the target server accessed by the above process is an external network IP address;
[0245] A second determination subunit, configured to determine to intercept communication between the above process and the above target server if the target application to which the above process belongs is an Internet application and the IP address of the target server accessed by the above process is an internal network IP address;
[0246] A third determination subunit, configured to determine to allow communication between the above process and the above target server if the target application to which the above process belongs is a local application and the IP address of the target server accessed by the above process is an internal network IP address;
[0247] A fourth determination subunit, configured to determine to intercept communication between the above process and the above target server if the target application to which the above process belongs is a local application and the IP address of the target server accessed by the above process is an external network IP address.
[0248] In one embodiment, the above process identifier obtaining module includes:
[0249] An obtaining unit, configured to use the network filtering driver module set in the above terminal device to obtain the process of the terminal event of the above terminal device and the process identifier of the above process.
[0250] In one embodiment, the above device further includes:
[0251] An authorization module, configured to use the network filtering driver module set in the above terminal device to perform separate authorization on the processes of individual above terminal events.
[0252] In one embodiment, the specified network includes: an external network, and the access control module includes:
[0253] A second access control unit, configured to, if it is determined that the type of the target application is an Internet access application that is only allowed to access a server on the external network, determine that only the Internet access application is allowed to access the software layered disk, and intercept the Internet access application from accessing the local disk.
[0254] In one embodiment, the apparatus further includes:
[0255] A first recording module, configured to, in response to a mirror editing operation on the local disk, record, in the virtual machine, an Internet access application in the local disk that is only allowed to access a server on the external network, to obtain the software layered disk.
[0256] In one embodiment, the apparatus further includes at least one of the following:
[0257] A control unit, configured to use an application layer proxy program in the terminal device to control a local application to unidirectionally read partial data from the Internet access application, where the partial data includes: clipboard and screenshot;
[0258] An interception unit, configured to use an application layer proxy program in the terminal device to intercept process communication between the local application and the Internet access application;
[0259] An encryption unit, configured to use an application layer proxy program in the terminal device to encrypt transmission data between the local disk and the data transfer disk, and between the software layered disk and the data transfer disk;
[0260] A decryption unit, configured to use an application layer proxy program in the terminal device to upload encrypted transmission data to an approval system, so as to obtain an instruction from the approval system to decrypt the encrypted transmission data.
[0261] In one embodiment, the apparatus further includes at least one of the following:
[0262] An access unit, configured to, in response to an access operation of an Internet access application to an operating system file, use an application layering module in the terminal device to perform file filtering drive on the virtual machine, and allow the Internet access application to access the operating system file on the local disk;
[0263] An installation unit, configured to, in response to the installation operation of the above-mentioned Internet access application, redirect the above-mentioned Internet access application to the above-mentioned software layered disk by using the above-mentioned application layering module, and perform registry filtering drive on the above-mentioned virtual machine by using the above-mentioned application layering module, and record the registry change information during the installation process to the above-mentioned software layered disk.
[0264] In one embodiment, the above-mentioned specified network further includes: an internal network, and the above-mentioned access control module includes:
[0265] A third access control unit, configured to, if it is determined that the type of the above-mentioned target application is a local application that is only allowed to access the server of the internal network, determine that only the above-mentioned local application is allowed to access the above-mentioned local disk, and intercept the above-mentioned local application from accessing the above-mentioned software layered disk and the above-mentioned data transfer disk.
[0266] In one embodiment, the above-mentioned device further includes:
[0267] A second recording module, configured to, in response to an image editing operation on the above-mentioned local disk, record the local application in the above-mentioned local disk that is only allowed to access the server of the internal network in the above-mentioned virtual machine to obtain the above-mentioned software layered disk.
[0268] In an exemplary embodiment, an embodiment of the present application further provides an electronic device, including: a processor, and a memory connected to the above-mentioned processor;
[0269] The above-mentioned memory stores computer execution instructions;
[0270] The above-mentioned processor executes the computer execution instructions stored in the above-mentioned memory to implement the method as described in any one of the above.
[0271] In an exemplary embodiment, an embodiment of the present application further provides a computer-readable storage medium, in which computer execution instructions are stored, and when the computer execution instructions are executed by a processor, they are used to implement the method as described in any one of the above.
[0272] In an exemplary embodiment, an embodiment of the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method as described in any one of the above.
[0273] To implement the above embodiments, an embodiment of the present application further provides an electronic device. Refer to Figure 7, which shows a schematic structural diagram of an electronic device 700 suitable for implementing the embodiments of the present application. The electronic device 700 can be a terminal device or a server. Among them, the terminal device can include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, messaging devices, game consoles, medical devices, fitness devices, personal digital assistants (PDAs), tablet computers (PADs), portable media players (PMPs), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The electronic device shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.
[0274] As Figure 7 shown, the electronic device 700 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the electronic device 700 are also stored. The processing device 701, the ROM 702, and the RAM 703 are connected to each other through a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0275] Generally, the following devices may be connected to the I / O interface 705: an input device 706 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 707 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 708 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 709. The communication device 709 can allow the electronic device 700 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 7 the electronic device 700 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.
[0276] In particular, according to an embodiment of the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device 709, or installed from a storage device 708, or installed from a ROM 702. When the computer program is executed by a processing device 701, the above-mentioned functions defined in the method of the embodiment of the present application are executed.
[0277] It should be noted that the above-mentioned computer-readable medium in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program codes. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program codes contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0278] The above-mentioned computer-readable medium can be included in the above-mentioned electronic device; or it can exist separately and not be assembled into the electronic device.
[0279] The above-mentioned computer-readable medium carries one or more programs, and when the above-mentioned one or more programs are executed by the electronic device, the electronic device is caused to execute the methods shown in the above embodiments.
[0280] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a Local Area Network (LAN) or a Wide Area Network (WAN), or it can be connected to an external computer (for example, by connecting through the Internet using an Internet service provider).
[0281] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0282] The units involved in the embodiments described in this application can be implemented in software or in hardware. Among them, the name of the unit does not constitute a limitation on the unit itself in some cases. For example, the first acquisition unit can also be described as "the unit for acquiring at least two Internet protocol addresses".
[0283] The functions described above herein can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGA), Application Specific Integrated Circuits (ASIC), Application Specific Standard Products (ASSP), Systems on Chip (SOC), Complex Programmable Logic Devices (CPLD), and so on.
[0284] In the context of the present application, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0285] Other embodiments of the present application will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. The present application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include known common knowledge or conventional technical means in the technical field not disclosed herein. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present application are pointed out by the following claims.
[0286] It should be understood that the present application is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present application is only limited by the appended claims.
Claims
1. A method for controlling access rights of a virtual machine, characterized in that The method includes: After logging in to the cloud desktop of the virtual machine of the terminal device, loading the data transfer disk and the software layering disk of the virtual machine, where the software layering disk is used to record the target application of the target server that can only access the specified network, data isolation is performed between the software layering disk and the local disk of the terminal device, and the data transfer disk is used to perform data transfer with the local disk and the software layering disk respectively; In response to recognizing a startup operation for the target application, determine the access permission of the target application according to the type of the target application recorded by the software layering disk.
2. The method according to claim 1, wherein The following method is used to determine the type of the target application: Obtain the process of the terminal event of the terminal device and the process identifier of the process, where the terminal event includes at least one of the following: external connection event, received connection event, message sending event, and message receiving event; According to the process identifier of the process, identify the type of the target application to which the process belongs.
3. The method according to claim 2, characterized in that, Determining the access permission of the target application according to the type of the target application includes: Obtain the IP address of the target server accessed by the process, where the IP address includes: internal network IP address and external network IP address; According to the type of the target application to which the process belongs and the target server accessed by the process, determine whether to allow communication between the process and the target server.
4. The method according to claim 3, wherein Determining whether to allow communication between the process and the target server according to the IP address and the target application to which the process belongs includes: If the target application to which the process belongs is an Internet application and the IP address of the target server accessed by the process is an external network IP address, then determine to allow communication between the process and the target server; If the target application to which the process belongs is an Internet application and the IP address of the target server accessed by the process is an internal network IP address, then determine to intercept communication between the process and the target server; If the target application to which the process belongs is a local application and the IP address of the target server accessed by the process is an internal network IP address, then determine to allow communication between the process and the target server; If the target application to which the process belongs is a local application and the IP address of the target server accessed by the process is an external network IP address, then determine to intercept communication between the process and the target server.
5. The method according to claim 2, wherein Obtaining the process of the terminal event of the terminal device and the process identifier of the process includes: Using the network filtering driver module set in the terminal device, obtain the process of the terminal event of the terminal device and the process identifier of the process.
6. The method according to claim 2, wherein The method further includes: Using the network filtering driver module set in the terminal device, perform separate authorization on the processes of individual terminal events.
7. The method according to claim 1, wherein The specified network includes: an external network, and determining the access permission of the target application according to the type of the target application includes: If it is determined that the type of the target application is an Internet access application that can only access servers on the external network, it is determined that only the Internet access application is allowed to access the software layered disk, and the Internet access application's access to the local disk is intercepted.
8. The method according to claim 1, characterized in that, Before loading the data transfer disk and software layered disk of the virtual machine in response to logging in to the cloud desktop of the virtual machine of the terminal device, the method further includes: In response to a mirror editing operation on the local disk, record the Internet access applications in the local disk that can only access servers on the external network in the virtual machine to obtain the software layered disk.
9. The method according to any one of claims 1 to 8, characterized in that The method further includes at least one of the following: Use the application layer proxy program in the terminal device to control the local application to unidirectionally read part of the data from the Internet access application, where the part of the data includes: clipboard and screenshots; Use the application layer proxy program in the terminal device to intercept the process communication between the local application and the Internet access application; Use the application layer proxy program in the terminal device to encrypt the transmission data between the local disk and the data transfer disk, and between the software layered disk and the data transfer disk; Use the application layer proxy program in the terminal device to upload the encrypted transmission data to the approval system to obtain the approval system instruction to decrypt the encrypted transmission data.
10. The method according to any one of claims 1 to 8, characterized in that, The method further includes at least one of the following: In response to an access operation of the Internet access application to the operating system file, use the application layer module in the terminal device to perform file filtering drive on the virtual machine to allow the Internet access application to access the operating system file on the local disk; In response to the installation operation of the Internet access application, use the application layer module to redirect the Internet access application to the software layered disk, and use the application layer module to perform registry filtering drive on the virtual machine to record the registry change information during the installation process to the software layered disk.
11. The method according to claim 1, wherein The specified network further includes: an internal network. Determining the access permission of the target application according to the type of the target application recorded in the software layered disk includes: If it is determined that the type of the target application is a local application that can only access servers on the internal network, it is determined that only the local application is allowed to access the local disk, and the local application's access to the software layered disk and the data transfer disk is intercepted.
12. The method according to claim 1 or 11, characterized in that, Before loading the data transfer disk and software layered disk of the virtual machine in response to logging in to the cloud desktop of the virtual machine of the terminal device, the method further includes: In response to a mirror editing operation on the local disk, record the local applications in the local disk that can only access servers on the internal network in the virtual machine to obtain the software layered disk.
13. An access right control device for a virtual machine, characterized in that, The device includes: A loading module, configured to load a data transfer disk and a software layered disk of the virtual machine in response to the cloud desktop of the virtual machine logging in to the terminal device, wherein the software layered disk is used to record a target application that can only access a server in a specified network, data between the software layered disk and a local disk of the terminal device is isolated, and the data transfer disk is used to perform data transfer with the local disk and the software layered disk respectively; An access control module, configured to determine the access permission of the target application according to the type of the target application recorded by the software layered disk in response to identifying a start operation on the target application.
14. An electronic device, characterized in that, Comprising: A processor, and a memory connected to the processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory to implement the method according to any one of claims 1 to 12.
15. A computer program product, characterized in that, Comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 12.