NoVNC security control method and system based on dynamic token and network isolation
By generating dynamic tokens and implementing network isolation, the vulnerability of noVNC to attacks is solved. This achieves cross-version compatibility without modifying the source code, strong authentication with dynamic tokens, and kernel-mode network isolation, thereby improving the security and stability of enterprise-level cloud environments.
Patent Information
- Application Number
- CN202511382883.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-25
- Publication Date
- 2025-11-18
AI Technical Summary
The existing noVNC security mechanism is vulnerable to brute-force attacks. Once the token is leaked, it remains valid indefinitely, exposing the service to risks. It cannot cope with dynamic attacks, limiting its application in enterprise-level high-security environments.
By generating dynamic tokens based on client IP address, timestamp, and random factor, binding user session IDs and sharing their lifecycle, and combining Netfilter's PREROUTING and INPUT chain rules for network isolation, dynamic whitelist management and real-time policy circuit breaking are achieved, preventing token leakage and port exposure.
It achieves cross-version compatibility with zero source code modification, strong dynamic token authentication, kernel-mode network isolation, and millisecond-level response time, enhancing the security and stability of enterprise-level cloud environments.
Smart Images

Figure CN120979677A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and more particularly to a noVNC security control method and system based on dynamic tokens and network isolation. BACKGROUND
[0002] In the field of remote desktop control, noVNC, as a VNC client solution based on HTML5 WebSockets, is widely used in cloud desktop, remote operation and maintenance and other scenarios due to its cross-platform and plugin-free characteristics. However, its native security mechanism has significant defects: it relies on the password authentication of the VNC protocol, which is limited in length and low in encryption strength, and is vulnerable to brute force attacks. Existing technical solutions attempt to enhance security, but all have deficiencies. For example, the unified console access solution generates a long-term valid HTTP access URL through the cloud management platform, but the token is not bound to the user session or source IP, and can be reused indefinitely after being leaked, and the noVNC service is directly exposed to the public network, which is easy to be scanned by attackers. The token control solution generates a token on the server side, but also does not implement time effectiveness and IP binding, resulting in permanent validity of the token after it is leaked, and the service exposure risk is not solved. The two-factor authentication solution requires modifying the noVNC front-end source code to add one-time password verification, which not only introduces cross-version compatibility issues (such as the need to re-adapt the authentication module when upgrading), but also separates the proxy layer from the kernel network policy, making it impossible to respond to security incidents in conjunction. These defects collectively result in a disconnection between the authentication layer and the network layer protection, making it impossible to respond to dynamic attacks (such as token leakage or port scanning), and limiting the application of noVNC in enterprise-level high-security environments. SUMMARY
[0003] To solve the above technical problems, the present application proposes a noVNC security control method and system based on dynamic tokens and network isolation.
[0004] The technical solution of the present application is as follows: The present application proposes a noVNC security control method based on dynamic tokens and network isolation, comprising: Step S1, in response to a user remote connection request, performing a hash operation on the client IP address, timestamp and random factor to generate a dynamic token; binding the dynamic token with the user session ID, both sharing the same life cycle; Step S2, adding the client IP address bound with the dynamic token to the ipset dynamic whitelist set; configuring a DNAT rule in the PREROUTING chain of Netfilter to redirect the traffic accessing the noVNC port on the public network to a private network IP; setting a filtering rule in the INPUT chain to allow only the traffic with a source IP belonging to the ipset whitelist to access the noVNC service; Step S3, listen to the user session termination event, remove the binding relationship between the dynamic token and the user session; and remove the client IP corresponding to the dynamic token from the ipset whitelist, and delete the related DNAT rule in the PREROUTING chain.
[0005] Preferably, the dynamic token and the user session ID binding relationship is stored in the Redis cache database; the cache key is the session ID, and the value is a JSON object containing the token hash value, the client IP and the expiration time, the JSON object containing the dynamic token, the client IP and the expiration time.
[0006] Preferably, in the noVNC service TCP handshake stage, it is verified in real time whether the request source IP exists in the ipset whitelist; if not, the SYN packet is discarded and a security alarm log is generated.
[0007] Preferably, the DNAT rule of the PREROUTING chain contains a load balancing strategy; the public network flow is distributed to a plurality of private network IP addresses.
[0008] Preferably, the listening to the user session termination event is achieved by the Java Listener listener to listen to the session state change in real time; and the deleting the related DNAT rule in the PREROUTING chain is achieved by calling the command to delete the DNAT and the ipset rule.
[0009] Preferably, the method is realized by an external service, and the external service interacts with the noVNC service through a REST API.
[0010] Preferably, the method further comprises an illegal IP monitoring mechanism, when detecting illegal IP access, a session termination event is triggered automatically; and the token unbinding, IP removal and rule deletion operations are executed in linkage.
[0011] In another aspect, the application also provides a noVNC security control system based on dynamic token and network isolation, comprising: A dynamic token engine, comprising: A hash calculator: performing SHA3 to generate a dynamic token; A session binder: writing the session ID and token mapping relationship into a Redis database; A double-chain isolation module, comprising: A DNAT redirection unit: deployed in the PREROUTING chain of Netfilter, performing address conversion from public network to private network; A dynamic filtering unit: deployed in the INPUT chain, and achieving dynamic update of the source IP whitelist through an ipset; A policy synchronization engine, comprising: Event listener: Capture session termination event through Java Listener; Rule fuse: Invoke command to delete DNAT and ipset rules; Non-invasive interface: Interact with noVNC service through REST API without modifying its source code.
[0012] In still another aspect, the present application also provides an electronic device having a computer program stored thereon, which, when executed by a processor, implements a noVNC security control method based on dynamic token and network isolation as described in any embodiment of the present application.
[0013] In still another aspect, the present application also provides a computer readable medium for storing one or more programs, which, when executed by one or more processors, cause the one or more processors to implement a noVNC security control method based on dynamic token and network isolation as described in any embodiment of the present application.
[0014] The present application has the following beneficial effects: Zero modification of source code and cross-version compatibility: Using external services to interact with noVNC through REST API without modifying noVNC source code, avoiding adaptation problems during version upgrade, and supporting seamless integration of historical versions.
[0015] Dynamic token strong authentication: Based on client IP address, timestamp, and random factor to generate SHA3-256 hash dynamic token, bind user session ID and share life cycle. This mechanism solves the problem of static token reuse across devices, effectively resists replay attacks, and automatically expires and cleans up with Redis cache, ensuring that the token is invalidated immediately after being leaked.
[0016] Kernel network isolation and dynamic control: In the Linux Netfilter framework, public network traffic is redirected to a private network IP through the PREROUTING chain DNAT rule, the server port is hidden, and the INPUT chain is combined with the ipset dynamic whitelist. This dual-chain architecture achieves zero exposure of public networks, and the attack surface converges to the private boundary.
[0017] Millisecond-level policy fuse: Use Java Listener to listen to session termination events in real time, triggering a three-level cleanup: token unbinding, ipset whitelist removal, and DNAT rule deletion, with a response time of less than 200ms, ensuring that authority recovery and attack defense are synchronized.
[0018] Enhanced scalability and stability: DNAT rules support load balancing to distribute traffic to multiple private nodes; illegal IP monitoring mechanism automatically links session termination, further strengthening the security loop.
[0019] In summary, the application constructs a "authentication-isolation-fuse" trinity protection system, which significantly improves security (such as token irreversibility, network zero exposure) while maintaining high compatibility and low latency, and is suitable for enterprise-level cloud environments. BRIEF DESCRIPTION OF DRAWINGS
[0020] Figure 1 A flowchart of the method of the application. DETAILED DESCRIPTION
[0021] The technical solutions in the embodiments of the application will be described clearly and completely below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, rather than all the embodiments of the application. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the application.
[0022] It should be understood that the step numbers used herein are only for the convenience of description and do not limit the execution sequence of the steps.
[0023] It should be understood that the terms used in the specification of the application are only for the purpose of describing specific embodiments and are not intended to limit the application. As used in the specification and the appended claims of the application, the singular forms "a", "an" and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0024] The terms "comprise" and "include" indicate the presence of the described features, integers, steps, operations, elements, and / or components, but do not exclude one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0025] The term "and / or" refers to any combination of one or more of the associated listed items and all possible combinations thereof, and includes these combinations.
[0026] Embodiment one: To make the purpose, technical solutions and advantages of the application clearer, the following will combine specific embodiments of the application and refer to the accompanying drawings Figure 1 The technical solutions of the application are clearly and completely described.
[0027] To solve the problems in the prior art, the embodiment provides a noVNC security control method based on dynamic tokens and network isolation, comprising the following steps: Step S1, in response to a user remote connection request, performing a hash operation on the client IP address, timestamp and random factor to generate a dynamic token; binding the dynamic token with the user session ID, both sharing the life cycle; Step S101, when the user initiates a remote connection request through the browser (such as clicking the cloud platform console button); capture the request and extract three core parameters: client public IP address (such as 203.0.113.5), current accurate timestamp (accurate to millisecond level), and 16-bit high-strength random string generated by the system; Step S102, the above three parameters are spliced into an input string in a fixed order; a one-way hash operation is performed on the string using the SHA3-256 encryption algorithm to generate a 64-bit irreversible dynamic token; Step S103, establish a binding relationship between the dynamic token and the user session ID, and store the binding relationship in the Redis cache database, the data structure includes: dynamic token complete hash value, client IP address and expiration time (this embodiment is set to automatically expire after 30 minutes); Step S104, set the Redis key value automatic expiration mechanism to ensure that the token life cycle is completely synchronized with the user session.
[0028] Step S2, add the client IP address bound to the dynamic token to the ipset dynamic white list collection; configure DNAT rules in the PREROUTING chain of Netfilter to redirect public network access noVNC port traffic to private network IP; set filtering rules in the INPUT chain to allow only traffic with source IP belonging to the ipset white list to access the noVNC service; Step S201, DNAT public traffic redirection includes: Add rules to the PREROUTING chain of the Linux kernel Netfilter framework: Listen to TCP access requests on the public network card port; Expand to meet the load balancing conditions: Configure multiple DNAT rules to implement traffic distribution; Redirect the target address of the data packet to the private network IP according to the preset weight to poll forward the public network traffic to multiple private network node conditions; Step S202, dynamic white list filtering, create an ipset dynamic white list collection and set an automatic cleaning mechanism of 1800 seconds; add the client IP bound to the current token to the collection; and configure filtering rules in the INPUT chain of Netfilter, specifically: Only allow traffic with source IP existing in the dynamic white list collection to access the port; Directly discard access requests from non-white list IP.
[0029] The above steps can completely hide the noVNC service port on the public network (only private network is visible), and attackers cannot discover the service port through public network scanning.
[0030] Step S3, listen to the user session termination event, remove the dynamic token and the binding relationship of the user session; and remove the client IP corresponding to the dynamic token from the ipset whitelist, and call the iptables command to delete the related DNAT rule in the PREROUTING chain.
[0031] Step S301, listen to the user session state file change through the Java Listener listener; the monitoring events include: user active logout, session timeout, and system forced termination.
[0032] Step S302, when detecting the session termination event, sequentially execute: Token binding release: delete the key value record corresponding to the session ID in Redis; Clear network permissions: remove the bound client IP from the ipset whitelist set; Delete DNAT rule: locate and delete the corresponding DNAT entry in the PREROUTING chain through the pre-stored rule identifier.
[0033] As a preferred embodiment of the embodiment, the method steps S1-S3 are implemented through an external service, and the external service interacts with the noVNC service through a REST API.
[0034] As a preferred embodiment of the embodiment, the method further includes an illegal IP monitoring mechanism, when detecting illegal IP access, automatically triggering a session termination event; and performing token unbinding, IP removal, and rule deletion operations in linkage. Specifically: Real-time analysis of access traffic characteristics, when detecting illegal IP (such as high-frequency brute force cracking): Automatically trigger a false session termination event; Synchronously perform the three steps of token release, IP removal, and rule deletion; The mechanism can make the whole process from attack to policy taking effect take less than 200 milliseconds.
[0035] Embodiment two: The embodiment provides a noVNC security control system based on dynamic tokens and network isolation, comprising: A dynamic token engine, comprising: A hash calculator: performing SHA3 to generate a dynamic token; A session binder: writing a session ID and token mapping relationship into a Redis database; A double-chain isolation module, comprising: A DNAT redirection unit: deployed in the PREROUTING chain of Netfilter, performing address conversion from a public network to a private network; Dynamic filtering unit: deployed in the INPUT chain, and the dynamic update of the source IP whitelist is realized through an ipset; The policy synchronization engine comprises: Event listener: a session termination event is captured through a Java Listener; Rule fuse: a command is called to delete DNAT and ipset rules; wherein the DNAT rule is deleted through an iptables command, and the ipset rule is deleted through an ipset command; Non-invasive interface: the noVNC service is interacted with through a REST API without modifying the source code.
[0036] Embodiment three: The embodiment provides an electronic device, which has a computer program stored thereon, and the computer program is executed by a processor to implement a noVNC security control method based on dynamic tokens and network isolation according to any one of the embodiments of the application.
[0037] Embodiment four: The embodiment provides a computer readable medium for storing one or more programs, and when the one or more programs are executed by one or more processors, the one or more processors implement a noVNC security control method based on dynamic tokens and network isolation according to any one of the embodiments of the application.
[0038] In the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. The "and / or" describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which means that A exists alone, A and B exist together, and B exists alone. Wherein A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it. "At least one of the following" and the like means any combination of these items, including any combination of single or multiple items. For example, at least one of a, b and c can mean: a, b, c, a and b, a and c, b and c, or a and b and c, wherein a, b, and c can be single or multiple.
[0039] Those of ordinary skill in the art can realize that the units and algorithm steps described in the embodiments disclosed herein can be realized by electronic hardware, computer software and a combination of electronic hardware and computer software. Whether the functions are realized in hardware or software mode depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0040] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the system, device and unit described above can refer to the corresponding processes in the foregoing method embodiments, and will not be described here.
[0041] In several embodiments provided in the present application, any function realized in the form of a software function unit and sold or used as an independent product can be stored in a computer-readable storage medium. Based on such understanding, the technical solutions of the present application essentially or the parts of the technical solutions that make contributions to the prior art or the parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (Read-Only Memory; hereinafter referred to as: ROM), a random access memory (Random Access Memory; hereinafter referred to as: RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0042] The above is only an embodiment of the present application, and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation, or direct or indirect application in other related technical fields based on the content of the specification and drawings of the present application, are also included in the patent protection scope of the present application.
Claims
1. A noVNC security control method based on dynamic token and network isolation, characterized in that, The method comprises the following steps: Step S1, in response to a user remote desktop connection request, performing a hash operation on a client IP address, a timestamp and a random factor to generate a dynamic token; The dynamic token is bound to a user session ID, and both share a life cycle; Step S2, adding the client IP address bound to the dynamic token to an ipset dynamic white list set; configuring a DNAT rule in a PREROUTING chain of Netfilter to redirect traffic accessing a noVNC port in a public network to a private network IP; and setting a filtering rule in an INPUT chain to allow only traffic with a source IP belonging to the ipset white list to access the noVNC service; Step S3, listening to a user session termination event, and unbinding the dynamic token from the user session; And removing the client IP corresponding to the dynamic token from the ipset white list, and deleting the related DNAT rule in the PREROUTING chain.
2. The noVNC security control method based on dynamic token and network isolation according to claim 1, characterized in that: The binding relationship between the dynamic token and the user session ID is stored in a Redis cache database; the cache key is the session ID, and the value is a JSON object containing the token hash value, the client IP and the expiration time; the JSON object contains the dynamic token, the client IP and the expiration time.
3. The noVNC security control method based on dynamic token and network isolation according to claim 1, characterized in that: In the TCP handshake phase of the noVNC service, it is verified in real time whether the request source IP exists in the ipset white list; if not, the SYN packet is discarded and a security alarm log is generated.
4. The noVNC security control method based on dynamic token and network isolation according to claim 1, characterized in that: The DNAT rule of the PREROUTING chain contains a load balancing strategy; public network traffic is distributed to multiple private network IP addresses.
5. The noVNC security control method based on dynamic token and network isolation according to claim 1, characterized in that: The listening to the user session termination event is achieved by a Java Listener listener listening to the session state change in real time; and the deleting the related DNAT rule in the PREROUTING chain is achieved by calling a command to delete the DNAT and ipset rules.
6. The noVNC security control method based on dynamic token and network isolation according to claim 1, characterized in that: The method is implemented by an external service which interacts with the noVNC service through a REST API.
7. The noVNC security control method based on dynamic token and network isolation according to claim 1, characterized in that: The method further comprises an illegal IP monitoring mechanism, which automatically triggers a session termination event when detecting illegal IP access; and performs token unbinding, IP removal and rule deletion operations in linkage.
8. A noVNC security control system based on dynamic token and network isolation, for implementing the method of any one of claims 1-7, characterized in that, It comprises: A dynamic token engine, comprising: A hash calculator: performing SHA3 to generate a dynamic token; A session binder: writing a session ID and token mapping relationship into a Redis database; A double-chain isolation module, comprising: A DNAT redirection unit: deployed in the PREROUTING chain of Netfilter, performing address conversion from a public network to a private network; A dynamic filtering unit: deployed in the INPUT chain, and achieving dynamic update of a source IP white list through an ipset; A policy synchronization engine, comprising: An event listener: capturing a session termination event through a Java Listener listener; A rule fuse: calling a command to delete the DNAT and ipset rules; A non-invasive interface: interacting with the noVNC service through a REST API without modifying the source code thereof.
9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor implements the noVNC security control method based on dynamic tokens and network isolation as claimed in claims 1-7 when executing the program.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program implements the noVNC security control method based on dynamic tokens and network isolation as claimed in claims 1-7 when executed by the processor.