Terminal authentication method and device
By installing client programs on the terminal and configuring the authentication policies of the management platform, flexible control over cloud desktop resources is achieved, solving the problems of cloud desktop resource theft and privacy data leakage, and improving security and user experience.
Patent Information
- Application Number
- CN202511165603.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2025-11-14
AI Technical Summary
In existing technologies, users face risks of identity theft and leakage of personal privacy data when logging into cloud desktop resources via terminals, resulting in low security.
By installing client programs on the terminal, configuring authentication policies on the management platform, verifying terminal information and authentication information, establishing a communication connection between the terminal and the cloud desktop, and flexibly controlling terminal access using policies configured by the administrator, including configuration items such as IP range, MAC whitelist, and geographical location range.
It improves the security of accessing cloud desktop resources, reduces the risk of privacy and data breaches, and enhances the user experience.
Smart Images

Figure CN120956491A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of cloud desktops, and more particularly to a terminal authentication method and apparatus. Background Technology
[0002] Currently, when users log in to cloud desktop resources through a terminal using some method, including but not limited to username / password, Ukey, SMS verification code, QR code, etc.
[0003] However, logging in through the above methods carries the risk of unauthorized access to cloud desktop resources, leakage of personal privacy and user data, and lacks security, leaving users' privacy and personal data unprotected. Summary of the Invention
[0004] This disclosure provides a terminal authentication method and apparatus that can improve the security of cloud desktop resource access and enhance user experience. The technical solution is as follows: the terminal's client program sends terminal information to a management platform; the management platform verifies the terminal information using its authentication policy, which includes at least one configuration item; when all configuration items of the authentication policy are successfully verified, the terminal's authentication information is verified; when the terminal's authentication information is successfully verified, a communication connection is established between the terminal and the cloud desktop.
[0005] Based on the above solution, the client program can flexibly control the terminal's access to cloud desktop resources without the user's awareness, through the authentication policy configured by the administrator on the management platform. This improves security, protects user privacy and personal data, reduces the risk of leakage, and enhances the user experience.
[0006] In some embodiments, after sending terminal information to the management platform via the terminal's client program, the method further includes setting an authentication policy through the management platform.
[0007] In some embodiments, the method further includes setting priority for configuration items included in the authentication policy.
[0008] In some embodiments, the terminal information is verified through the authentication policy of the management platform, including: verifying the terminal information according to priority through the authentication policy of the management platform.
[0009] In some embodiments, the method further includes: dynamically adjusting the authentication strategy according to the actual situation.
[0010] In some embodiments, after verifying the terminal information through the authentication policy of the management platform, the method further includes:
[0011] The terminal can request to log in to the cloud desktop using any of the following methods: username and password, USB Key (Ukey), SMS verification code, or QR code.
[0012] In some embodiments, before sending terminal information to the management platform via the terminal's client program, the method further includes: installing a client program on the terminal, the client being used to establish a management channel with the management platform and running automatically when the terminal is powered on.
[0013] In some embodiments, the configuration item is any one of the following: the terminal's Internet protocol (IP) range, usage time period, Media access control (MAC) whitelist, geographic location range, Universally Unique Identifier (UUID), or Serial Number (SN) whitelist.
[0014] In some embodiments, the terminal information includes the terminal's IP address information, MAC address information, location information, UUID information, and SN information.
[0015] In some embodiments, the terminal's authentication information includes one of the following: the terminal's username and password, Ukey information, SMS verification code information, and QR code information.
[0016] According to a second aspect of the present disclosure, a terminal authentication device is provided, including a memory and a processor. The memory stores a program. When the program is executed in the processor, the processor performs the methods of the first aspect and any embodiment of the first aspect.
[0017] Based on the aforementioned equipment, the client program can flexibly control the terminal's access to cloud desktop resources without the user's knowledge, through the authentication policy configured by the administrator on the management platform. This improves security, protects user privacy and personal data, reduces the risk of leakage, and enhances the user experience.
[0018] According to a third aspect of the present disclosure, a terminal authentication device is provided, comprising: a sending module for sending terminal information to a management platform via a client program of the terminal; a first verification module for verifying the terminal information according to an authentication policy of the management platform, the authentication policy including at least one configuration item; a second verification module for verifying the terminal's authentication information when all configuration items of the authentication policy are successfully verified; and a communication module for establishing a communication connection between the terminal and a cloud desktop when the terminal's authentication information is successfully verified.
[0019] In some embodiments, the apparatus further includes a setting module for setting an authentication policy through a management platform.
[0020] In some embodiments, the setting module is further configured to: set the priority of configuration items included in the authentication policy.
[0021] In some embodiments, the first verification module is specifically used to: verify the terminal information according to the management platform's authentication policy based on priority.
[0022] In some embodiments, the device further includes an adjustment module for dynamically adjusting the authentication strategy according to actual conditions.
[0023] In some embodiments, the device further includes a login module, used by the terminal to request login to the cloud desktop via any one of a username and password, a USB Key (Ukey), an SMS verification code, or a QR code.
[0024] In some embodiments, the device further includes an installation module for installing a client program on the terminal, the client being used to establish a management channel with the management platform and running automatically when the terminal is powered on.
[0025] In some embodiments, the configuration item is any one of the terminal's Internet Protocol (IP) range, usage time period, MAC whitelist, geographic location range, UUID, or SN whitelist.
[0026] In some embodiments, the terminal information includes the terminal's IP address information, MAC address information, location information, UUID information, and SN information.
[0027] In some embodiments, the terminal's authentication information includes one of the following: the terminal's username and password, Ukey information, SMS verification code information, and QR code information.
[0028] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided, characterized in that the computer program storage medium has program instructions that, when executed by a processor, cause the processor to perform the method of the first aspect and any embodiment of the first aspect.
[0029] According to a fifth aspect of the present disclosure, a chip system is provided, characterized in that the chip system includes at least one processor, which, when program instructions are executed in the at least one processor, causes the at least one processor to perform the method of the first aspect and any embodiment of the first aspect.
[0030] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0031] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.
[0032] Figure 1 This is a schematic diagram of a terminal authentication method 100 provided in an embodiment of this disclosure;
[0033] Figure 2 This is a flowchart of a terminal authentication method 100 provided in an embodiment of this disclosure;
[0034] Figure 3 This is a structural diagram of a terminal authentication device 300 provided in an embodiment of this disclosure;
[0035] Figure 4 This is a structural diagram of a terminal authentication device 400 provided in an embodiment of this disclosure;
[0036] Figure 5 This is another structural diagram of a terminal authentication device 400 provided in an embodiment of this disclosure;
[0037] Figure 6 This is another structural diagram of a terminal authentication device 400 provided in an embodiment of this disclosure;
[0038] Figure 7 This is another structural diagram of a terminal authentication device 400 provided in an embodiment of this disclosure;
[0039] Figure 8 This is another structural diagram of a terminal authentication device 400 provided in an embodiment of this disclosure. Detailed Implementation
[0040] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.
[0041] Currently, when users log in to cloud desktop resources through a terminal using some method, including but not limited to username / password, Ukey, SMS verification code, QR code, etc.
[0042] However, logging in through the above methods carries the risk of unauthorized access to cloud desktop resources, leakage of personal privacy and user data, and lacks security, leaving users' privacy and personal data unprotected.
[0043] In view of this, this disclosure provides a terminal authentication method that can improve the above-mentioned problems and enhance the user experience.
[0044] This disclosure provides a terminal authentication method 100, such as... Figure 1 As shown, the terminal authentication method 100 includes the following steps:
[0045] S110 sends terminal information to the management platform through the terminal's client program.
[0046] The terminal information includes the terminal's IP address, MAC address, location, UUID, and SN.
[0047] For example, a client program on the terminal can report some terminal information to the management platform, including but not limited to the terminal's IP address, MAC address, location, host (UUID) information, and unique identifier (SN) information. Upon receiving this information, the management platform will record it.
[0048] Optionally, prior to S110, the method may further include:
[0049] Install a client program on the terminal. The client is used to establish a management channel with the management platform and runs automatically when the terminal is powered on.
[0050] For example, a management client program can be installed on the terminal. During the installation process, information about the management platform, including but not limited to the IP address and port number, can be configured. After the client program is installed, it will run automatically when the terminal is powered on, and it is used to establish a management channel with the management platform.
[0051] Optionally, after S110, the method may further include:
[0052] Configure authentication policies through the management platform.
[0053] The authentication policy includes at least one configuration item, which can be any one of the following: IP range of the terminal, usage time period, MAC whitelist, geographical location range, UUID, or SN whitelist.
[0054] For example, an administrator can set authentication policies through the management platform. An authentication policy may include at least one configuration item, and each configuration item may be one of the following: IP range of the terminal, time period of use, MAC whitelist, geographical location range, UUID, SN whitelist, etc.
[0055] For example, in this step, the administrator can pre-configure authentication policies. When setting the authentication policy, one or more configuration items can be selected from multiple options as needed to generate the authentication policy. For instance, the authentication policy can be configured to include two configuration items: geographic location range and UUID. This authentication policy will then use joint verification based on geographic location range and UUID. Further, after selecting the corresponding configuration item, the legality criteria range for that item needs to be set. For geographic location range, this refers to the geographic coordinate range of a legal geographic location area. Location information within this range is considered legal; otherwise, it is considered illegal. For UUID, a list of legal UUIDs can be pre-configured. UUIDs on this list are considered legal; otherwise, they are considered illegal. The setting methods for other configuration items are similar. For example, when a time period is selected as a configuration item, usage time within a preset time range is considered legal; otherwise, it is considered illegal. When a MAC whitelist is selected as a configuration item, MAC addresses on the whitelist are considered legal; otherwise, they are considered illegal. The setting methods for the remaining configuration items follow the same logic.
[0056] Furthermore, the method may also include:
[0057] Prioritize the configuration items included in the authentication strategy.
[0058] For example, in actual operation, the priority of multiple configuration items can also be set.
[0059] S120 verifies terminal information through the authentication policy of the management platform.
[0060] For example, the terminal's information can be verified through the authentication policy of the management platform.
[0061] It should be understood that in this step, when the preset authentication policy includes multiple configuration items, the authentication policy will only be considered to have passed the verification if each configuration item is verified as valid; if at least one configuration item is not satisfied, the authentication policy verification will fail.
[0062] Furthermore, after prioritizing the configuration items included in the authentication policy, the terminal information is verified through the management platform's authentication policy, which may specifically include:
[0063] The terminal information is verified according to the authentication policy of the management platform based on priority.
[0064] For example, after setting priorities, multiple configuration items can be verified sequentially according to their priority.
[0065] For example, when the authentication policy configuration includes a geographic location range and a UUID, the geographic location range can be set to have a higher priority than the UUID. When executing the authentication policy, the geographic location range will be verified first. If this verification fails, the current authentication process will be exited and the authentication policy verification will be deemed to have failed. If this verification succeeds, the UUID will be verified. If the verification succeeds, the current authentication policy verification is considered successful; otherwise, the verification fails.
[0066] Optionally, after S120, the method may further include:
[0067] The terminal can request to log in to the cloud desktop using any of the following methods: username and password, Ukey, SMS verification code, or QR code.
[0068] For example, users can log in to cloud desktop resources through a terminal using some method, including but not limited to username / password, Ukey, SMS verification code, QR code, etc.
[0069] It should be understood that after a user logs into the cloud desktop resource via a terminal, the management platform will first check whether an authentication policy is configured. If an authentication policy is configured, the above-mentioned policy verification will be performed; if no authentication policy is configured, the terminal's authentication information will be verified directly.
[0070] For example, if an authentication policy is configured, the configuration items, the range of valid conditions for the configuration items, and the priority of the configuration items are read, and the authentication policy verification process is executed based on the above information; if no authentication policy is configured, the terminal authentication information is verified directly, and if the verification is successful, a connection is established between the cloud desktop and the user terminal; if the terminal authentication information verification fails, the authentication fails, and the user's connection request is rejected.
[0071] S130: When all configuration items of the authentication policy are successfully verified, verify the terminal's authentication information.
[0072] The terminal's authentication information includes one of the following: the terminal's username and password, Ukey, SMS verification code, or QR code.
[0073] For example, if all configuration items included in the authentication policy pass the verification, the terminal's authentication information will be further verified; if any configuration item included in the authentication policy fails the verification, the authentication process will end.
[0074] S140: When the terminal's authentication information is successfully verified, a communication connection is established between the terminal and the cloud desktop.
[0075] For example, if the authentication policy verification passes, and the terminal's authentication information is successfully verified, then the authentication verification passes and a communication connection is established between the cloud desktop and the user terminal; if the terminal's authentication information verification fails, then the authentication verification fails and the user's connection request is rejected.
[0076] Optionally, the method may further include:
[0077] The authentication strategy should be dynamically adjusted according to the actual situation.
[0078] For example, administrators can dynamically adjust the authentication policy according to actual needs. After the authentication policy is dynamically adjusted, the system will execute the authentication process based on the new authentication policy.
[0079] As an example, Figure 2 This is a flowchart of a terminal authentication method 100 provided in this embodiment.
[0080] In summary, this embodiment of the disclosure involves installing a management client on a terminal. During the installation process, information about the management platform is configured, including but not limited to the IP address and port number. After the client program is installed, it automatically runs when the terminal is powered on, establishing a management channel with the management platform. The client program reports some terminal information to the management platform, including but not limited to the terminal's IP address, MAC address, geographic location information, UUID, and SN. The management platform records the information reported by the terminal. Users log in to cloud desktop resources through the terminal using some method, including but not limited to username / password, Ukey, SMS verification code, and QR code. The management platform first checks the system according to the policies configured by the administrator (using a single policy or a combination of policies depending on the actual situation). These policies include, but are not limited to, IP range, usage time period, MAC whitelist, geographic location range, UUID, and SN whitelist. In addition, the priority of each configuration item in the policy can be set. If the policy check is successful, the authentication information (username / password, Ukey, SMS verification code, QR code, etc.) is verified; otherwise, login fails and the user is prompted.
[0081] Furthermore, the client program can flexibly control the terminal's access to cloud desktop resources without the user's awareness, through the authentication policy configured by the administrator on the management platform. This improves security, protects user privacy and personal data, reduces the risk of leakage, and enhances the user experience.
[0082] Based on the above Figure 1 The terminal authentication method described in the corresponding embodiments is described below as a device embodiment of this disclosure, which can be used to execute the method embodiment of this disclosure.
[0083] This disclosure provides a terminal authentication device 300, such as... Figure 3As shown. The terminal authentication device 300 includes: a memory 301 and a processor 302.
[0084] Memory 301 is used to store programs.
[0085] When the program is executed in processor 302, processor 302 is used to execute the terminal authentication method described above.
[0086] The processor 302 is used to: send terminal information to the management platform through the terminal's client program; verify the terminal information through the management platform's authentication policy, which includes at least one configuration item; verify the terminal's authentication information when all configuration items of the authentication policy are successfully verified; and establish a communication connection between the terminal and the cloud desktop when the terminal's authentication information is successfully verified.
[0087] Optionally, after the terminal's information is sent to the management platform via the client program of the terminal, the processor 302 is also used to: set an authentication policy through the management platform.
[0088] Optionally, the processor 302 is also used to: prioritize the configuration items included in the authentication policy.
[0089] Optionally, the processor 302 is specifically used to: verify the terminal information according to the authentication policy of the management platform based on priority.
[0090] Optionally, the processor 302 is also used to: dynamically adjust the authentication strategy according to the actual situation.
[0091] Optionally, after verifying the terminal information through the authentication policy of the management platform, the processor 302 is also used to request login to the cloud desktop via any of the following methods: username and password, USB Key (Ukey), SMS verification code, or QR code.
[0092] Optionally, before sending terminal information to the management platform via the terminal's client program, the processor 302 is further configured to: install a client program on the terminal, the client being used to establish a management channel with the management platform and running automatically when the terminal is powered on.
[0093] Optionally, the configuration item can be any one of the following: Internet protocol (IP) range, usage time period, Media access control (MAC) whitelist, geographic location range, Universally Unique Identifier (UUID), or Serial Number (SN) whitelist.
[0094] Optionally, the terminal information includes the terminal's IP address information, MAC address information, location information, UUID information, and SN information.
[0095] Optionally, the terminal's authentication information includes one of the following: the terminal's username and password, Ukey information, SMS verification code information, and QR code information.
[0096] The terminal authentication device provided in this embodiment allows the client program to flexibly control the terminal's access to cloud desktop resources without the user's awareness, through the authentication policy configured by the administrator on the management platform. This improves security, protects user privacy and personal data, reduces the risk of leakage, and enhances the user experience.
[0097] Based on the above Figure 1 The terminal authentication method described in the corresponding embodiments is described below as a device embodiment of this disclosure, which can be used to execute the method embodiment of this disclosure.
[0098] Based on the above Figure 1 In addition to the terminal authentication method described in the corresponding embodiments, this disclosure also provides a terminal authentication device 400, such as... Figure 4 As shown.
[0099] The terminal authentication device 400 includes:
[0100] The sending module 410 is used to send terminal information to the management platform through the terminal's client program;
[0101] The first verification module 420 is used to verify the terminal information through the authentication policy of the management platform. The authentication policy includes at least one configuration item.
[0102] The second verification module 430 is used to verify the terminal's authentication information when all configuration items of the authentication policy are successfully verified.
[0103] The communication module 440 is used to establish a communication connection between the terminal and the cloud desktop when the terminal's authentication information is successfully verified.
[0104] Optionally, such as Figure 5 As shown, the device 400 also includes:
[0105] Module 450 is used to set authentication policies through the management platform.
[0106] Optionally, the setting module 450 is also used to: prioritize the configuration items included in the authentication strategy.
[0107] Optionally, the first verification module 420 is specifically used to verify the terminal information according to the management platform's authentication strategy based on priority.
[0108] Optionally, such as Figure 6 As shown, the device 400 also includes:
[0109] The adjustment module 460 is used to dynamically adjust the authentication strategy according to the actual situation.
[0110] Optionally, such as Figure 7 As shown, the device 400 also includes:
[0111] The login module 470 is used to request login to the cloud desktop via any of the following methods: username and password, Ukey, SMS verification code, or QR code.
[0112] Optionally, such as Figure 8 As shown, the device 400 also includes:
[0113] Install module 480 is used to install client programs on the terminal. The client is used to establish a management channel with the management platform and runs automatically when the terminal is powered on.
[0114] Optionally, the configuration item can be any one of the following: Internet Protocol (IP) range of the terminal, usage time period, MAC whitelist, geographical location range, UUID, or SN whitelist.
[0115] Optionally, the terminal information includes the terminal's IP address information, MAC address information, location information, UUID information, and SN information.
[0116] Optionally, the terminal's authentication information includes one of the following: the terminal's username and password, Ukey information, SMS verification code information, and QR code information.
[0117] Based on the above Figure 1 In addition to the terminal authentication method described in the corresponding embodiments, this disclosure also provides a computer-readable storage medium. For example, a non-transitory computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a CD-ROM, magnetic tape, a floppy disk, or an optical data storage device. This storage medium stores computer instructions for executing the above-described... Figure 1 The terminal authentication method described in the corresponding embodiments will not be repeated here.
[0118] Based on the above Figure 1 In addition to the terminal authentication method described in the corresponding embodiments, this disclosure also provides a chip system including at least one processor. When program instructions are executed in the at least one processor, the at least one processor performs the aforementioned terminal authentication method. Figure 1 The terminal authentication method described in the corresponding embodiments will not be repeated here.
[0119] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.
[0120] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.
Claims
1. A terminal authentication method, characterized in that, The method includes: The terminal's client program sends terminal information to the management platform; The terminal information is verified through the authentication policy of the management platform, and the authentication policy includes at least one configuration item. When all configuration items of the authentication policy are successfully verified, the authentication information of the terminal is verified. When the authentication information of the terminal is successfully verified, a communication connection is established between the terminal and the cloud desktop.
2. The method according to claim 1, characterized in that, After the client program on the terminal sends the terminal information to the management platform, the method further includes: The authentication policy is set through the management platform.
3. The method according to claim 2, characterized in that, The method further includes: Priority settings are configured for the configuration items included in the authentication strategy.
4. The method according to claim 3, characterized in that, The verification of the terminal's information through the authentication policy of the management platform includes: The terminal information is verified according to the priority and the authentication policy of the management platform.
5. The method according to claim 1, characterized in that, The method further includes: The authentication strategy will be dynamically adjusted according to the actual situation.
6. The method according to claim 1, characterized in that, After verifying the terminal's information through the authentication policy of the management platform, the method further includes: The terminal requests to log in to the cloud desktop using any of the following methods: username and password, Ukey, SMS verification code, or QR code.
7. The method according to claim 1, characterized in that, Before the client program on the terminal sends the terminal information to the management platform, the method further includes: The client program is installed on the terminal. The client is used to establish a management channel with the management platform and runs automatically when the terminal is powered on.
8. The method according to claim 1, characterized in that, The configuration item is any one of the following: the terminal's Internet Protocol (IP) range, usage time period, Media Access Control (MAC) whitelist, geographical location range, Universal Unique Identifier (UUID), and Serial Number (SN) whitelist.
9. The method according to claim 1, characterized in that, The terminal information includes the terminal's IP address, MAC address, location, UUID, and SN.
10. The method according to claim 1, characterized in that, The authentication information of the terminal includes one of the following: the terminal's username and password, Ukey information, SMS verification code information, and QR code information.
11. A terminal authentication device, characterized in that, Including memory and processor; The memory is used to store programs; When the program is executed in the processor, the processor is used to perform the method of any one of claims 1-10.
12. A computer-readable storage medium, characterized in that, The computer-readable storage medium has program instructions that, when executed by a processor, cause the processor to perform the method of any one of claims 1-10.
Citation Information
Cited By
Terminal domain adding method and system based on non-Kerberos protocol
CN121690834A