Cloud desktop login method, system, electronic device, and storage medium

By introducing security modules on the cloud server and storing ciphertexts on the user terminal, the security problems caused by centralized storage of cloud desktop login passwords are solved, and the security and reliability of cloud desktop login are realized.

WO2025120431A1PCT designated stage expired Publication Date: 2025-06-12CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2024/061548
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-05
Filing Date
2024-11-19
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

In the existing cloud desktop login system, the login password is stored in a centralized database on the cloud, which is easily stolen by malicious programs or leaked by developers, resulting in user data leakage or tampering.

Method used

A security module is introduced on the cloud server, which decrypts the security module corresponding to the cloud desktop identity, obtains the cloud desktop login password, and stores it in the ciphertext of the user terminal. When logging in, the user terminal sends the ciphertext to the cloud server for decryption and login.

Benefits of technology

By introducing security modules, a one-machine-one-secret login method is realized, which reduces the risk of cloud desktop being used by others and ensures the security and reliability of cloud desktop login.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2024061548_12062025_PF_FP_ABST
    Figure IB2024061548_12062025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a cloud desktop login method, a system, an electronic device, and a storage medium. The method comprises: receiving a cloud desktop connection request sent by a user terminal, the cloud desktop connection request carrying a ciphertext of a cloud desktop login password and a cloud desktop identifier; decrypting the ciphertext by means of a security module corresponding to the cloud desktop identifier, to obtain the cloud desktop login password; and using the cloud desktop login password to log in to a cloud desktop system corresponding to the cloud desktop identifier, and sending interface data of the cloud desktop system to the user terminal. A security module is introduced to a cloud desktop on a cloud server, and the security module manages the login to the corresponding cloud desktop, avoiding a leakage problem caused by storing a cloud desktop login password in a cloud database. In addition, the indicator of the security module of the cloud desktop is a cryptographic computing capability, not direct storage of a login password. In this way, the security module achieves one password for one device, reducing the risk of the cloud desktop being used by others, ensuring the security and reliability of the login to the cloud desktop.
Need to check novelty before this filing date? Find Prior Art

Description

[0001]A Cloud Desktop Login Method, System, Electronic Device, and Storage Medium. The present disclosure relates to the field of computer technology, and more specifically, to a cloud desktop login method, system, electronic device, and storage medium. Background: A cloud desktop is a computer desktop running in the cloud, accessed remotely by user terminals via a network. Cloud desktops are increasingly widely used in enterprise office environments, bringing convenience and efficiency to operations and maintenance. At the same time, enterprises are placing increasing demands on the security of cloud desktops. Currently, accessing cloud desktops often involves user login and verification. The login password for a cloud desktop is the user's credential for using the cloud desktop. The login password is stored in a cloud database, which manages the login passwords for all cloud desktops. Once stolen by malicious programs or maliciously leaked by developers, the cloud desktop can be used by others, leading to the leakage or tampering of user data. Even if the login password is encrypted, the leakage of the key can also result in the cloud desktop being used by others. SUMMARY OF THE INVENTION The present disclosure addresses the shortcomings of the aforementioned prior art by providing a cloud desktop login method, system, electronic device, and storage medium. This objective is achieved through the following technical solutions. A first aspect of the present disclosure provides a cloud desktop login method, applied to a cloud server. The method comprises: receiving a cloud desktop connection request from a user terminal, the cloud desktop connection request carrying a ciphertext of a cloud desktop login password and a cloud desktop identifier; decrypting the ciphertext using a security module corresponding to the cloud desktop identifier to obtain the cloud desktop login password; using the cloud desktop login password to log in to the cloud desktop system corresponding to the cloud desktop identifier, and sending interface data of the cloud desktop system to the user terminal. The cloud desktop login method described in the first aspect has at least the following beneficial effects or advantages: By introducing a security module into the cloud desktop on the cloud server, logins to the corresponding cloud desktop are managed in the security module, thereby avoiding the leakage problem caused by storing all cloud desktop login passwords in a cloud database. Furthermore, the security module introduced for the cloud desktop is based on cryptographic computing power, rather than directly storing the cloud desktop login password. That is, upon receiving a cloud desktop connection request, the cloud server uses the cryptographic computing power of the security module corresponding to the cloud desktop requesting connection to decrypt the ciphertext carried in the request to obtain the login password used to log in to the cloud desktop. The security module introduced in this way is equivalent to one machine and one password, which can reduce the risk of the cloud desktop being used by others and ensure the security and reliability of cloud desktop login.A second aspect of the present disclosure provides a cloud desktop login method, applied to a user terminal, comprising: upon successful verification of a received local password, obtaining a cloud desktop identifier for the cloud desktop to be connected; sending a cloud desktop connection request carrying the cloud desktop identifier and a locally stored ciphertext to a cloud server; wherein the ciphertext is obtained by encrypting the cloud desktop login password by the cloud server using a security module corresponding to the cloud desktop; and displaying interface data of the cloud desktop system returned by the cloud server. The cloud desktop login method described in the second aspect has at least the following beneficial effects or advantages: the ciphertext of the cloud desktop login password is stored on the terminal side, obtained by encrypting the cloud desktop login password by the cloud server using a security module corresponding to the cloud desktop. Therefore, when the user terminal logs in to the cloud desktop, the local password entered by the user is successfully verified to complete the local login. The obtained cloud desktop identifier and the locally stored ciphertext are then sent to the cloud server in the cloud desktop connection request, allowing the cloud server to perform the cloud desktop login operation and display the cloud desktop system interface transmitted back by the cloud server. Because the terminal maintains the encrypted version of the cloud desktop login password, even if it is leaked, others cannot easily log in and use the cloud desktop. This requires further cracking of the encrypted version, which requires decryption using a one-machine-one-secret security module implemented on the cloud server. This makes it difficult for someone who steals the encrypted version to obtain the password. Therefore, the present disclosure can ensure the security and reliability of cloud desktop login. A third aspect of the present disclosure provides a cloud desktop login system, comprising: a user terminal for executing the method described in the second aspect; and a cloud server for executing the method described in the first aspect. A fourth aspect of the present disclosure provides an electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, the processor executing the program to implement the method described in the first or second aspect. A fifth aspect of the present disclosure provides a computer-readable storage medium storing a computer program, the program executed by the processor to implement the method described in the first or second aspect. The above description is merely an overview of the technical solutions of the present disclosure. To provide a clearer understanding of the technical solutions of the present disclosure, implementation should be carried out in accordance with the description. To further enhance the understanding of the above and other objectives, features, and advantages of the present disclosure, specific embodiments of the present disclosure are described below. BRIEF DESCRIPTION OF THE DRAWINGS The accompanying drawings described herein are provided to further enhance understanding of the present disclosure and constitute a part of the present disclosure. The illustrative embodiments of the present disclosure and their descriptions are provided for illustrative purposes only and are not intended to unduly limit the present disclosure.In the accompanying drawings: Figure 1 is a schematic diagram of a cloud desktop login process in the prior art; Figure 2 is a flowchart of an embodiment of a cloud desktop login method according to an exemplary embodiment; Figure 3 is a flowchart of an embodiment of another cloud desktop login method according to an exemplary embodiment; Figure 4 is a schematic diagram of multi-terminal interaction for cloud desktop login according to an exemplary embodiment; Figure 5 is a schematic diagram of the hardware structure of an electronic device according to an exemplary embodiment; and Figure 6 is a schematic diagram of the structure of a storage medium according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, like numerals in different drawings represent the same or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Rather, they are merely examples of systems and methods consistent with certain aspects of the present disclosure, as detailed in the appended claims. The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. As used in this disclosure and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more associated listed items. It should be understood that while the present disclosure may employ terms such as "first," "second," and "third" to describe various information, such information should not be limited to these terms. These terms are merely used to distinguish information of the same type from one another. For example, without departing from the scope of the present disclosure, the first information could also be referred to as the second information, and similarly, the second information could also be referred to as the first information. Depending on the context, the term "if," as used herein, could be interpreted as meaning "at the time," "at that time," or "in response to a determination." Figure 1 illustrates a cloud desktop login process used in the prior art. The cloud desktop login password is centrally managed in the database of a cloud management service. A user initiates login on the terminal side. First, the terminal uses the terminal account used for local login to obtain connection credentials issued by the cloud server's management service. The terminal then initiates a cloud desktop connection to the cloud desktop service on the cloud server based on the obtained connection credentials. After verifying the connection credentials with the management service, the cloud desktop service obtains the cloud desktop login password. Finally, the cloud desktop service executes the login operation using the login password and transmits the successful login to the terminal in real time.The aforementioned cloud desktop login solutions are all implemented based on software logic, and the management service database manages the login passwords for all cloud desktops. This makes them vulnerable to theft by malicious programs or malicious leaks by developers. Furthermore, even if the login passwords are encrypted and stored, a leak of the key can also lead to the leakage of the cloud desktop login passwords. Therefore, existing cloud desktop login solutions cannot guarantee secure and reliable logins. To address the above technical issues, the present disclosure proposes a cloud desktop login method that collaborates with a cloud server and a user terminal to achieve secure and reliable cloud desktop logins. On the cloud server side, a security module is introduced to the cloud desktop on the cloud server to manage logins for the corresponding cloud desktop, thus avoiding the leakage issues associated with storing the cloud desktop login passwords in a centralized cloud database. Furthermore, the security module introduced for the cloud desktop is evaluated based on cryptographic computing power, rather than directly storing the cloud desktop login passwords. That is, when the cloud server receives a cloud desktop connection request, it uses the cryptographic computing power of the security module corresponding to the requested cloud desktop to decrypt the ciphertext contained in the request to obtain the cloud desktop login password. In this way, the introduced security module is equivalent to a one-machine-one-secret system, reducing the risk of cloud desktop access by others and ensuring the security and reliability of cloud desktop login. On the user terminal side, the ciphertext of the cloud desktop login password is stored. This ciphertext is obtained by encrypting the cloud desktop login password on the cloud server using the security module corresponding to the cloud desktop. Therefore, when logging into the cloud desktop, the user terminal first verifies the local password entered by the user and completes the local login. The user terminal then sends the obtained cloud desktop identifier and the locally stored ciphertext in a cloud desktop connection request to the cloud server, establishing the cloud desktop connection and displaying the cloud desktop system interface transmitted back by the cloud server. Since the terminal maintains the ciphertext of the cloud desktop login password, even if it is leaked, others cannot easily access the cloud desktop. This requires further cracking of the ciphertext, which is then decrypted using the one-machine-one-secret security module implemented on the cloud server. This makes it difficult for someone who steals the ciphertext to obtain, thus ensuring the security and reliability of cloud desktop login. It should be noted that the security module referred to in this disclosure can be a virtualized software module, such as a vTPM (virtual Trusted Platform Module), or a hardware module, such as a TPM (Trusted Platform Module). This disclosure does not limit the specific form of the security module, as long as it can provide the required cryptographic security technology. The following describes in detail the technical solution of this disclosure and how it solves the aforementioned technical problems using specific embodiments.The specific embodiments listed above can be combined with each other, and identical or similar concepts or processes may not be described in detail in certain embodiments. The embodiments of the present disclosure will be described in detail below in conjunction with the accompanying drawings. Example 1: Figure 2 is a flow chart illustrating an embodiment of a cloud desktop login method according to an exemplary embodiment. This embodiment uses a cloud server as the execution entity and primarily describes the operational process on the cloud server side. The cloud server provides a cloud desktop service and a management and control service, which can be deployed on the same machine or on different machines. As shown in Figure 2, the cloud desktop login method includes the following steps: Step 201: Receive a cloud desktop connection request from a user terminal. The cloud desktop connection request carries a ciphertext of a cloud desktop login password and a cloud desktop identifier. In this step, since the cloud desktop service on the cloud server includes a cloud desktop system activated by the user, the cloud desktop service processes the cloud desktop connection request from the user terminal. The ciphertext is used to obtain the cloud desktop login password and is a sequence of characters with no regularity. The cloud desktop identifier uniquely identifies a cloud desktop system within the cloud desktop service. It can be represented by the cloud desktop system's access address and port information, or by separately defined identification information. Furthermore, the cloud desktop connection request sent by the user terminal may include, in addition to the encrypted cloud desktop login password and the cloud desktop identifier, the user terminal account information and connection credential information. This connection credential information is obtained from the management and control service when the user terminal logs in to the cloud desktop. The cloud desktop service can use this information to verify the connection request. Successful verification indicates that the cloud desktop connection request is a legitimate one. Step 202: The encrypted text is decrypted using the security module corresponding to the cloud desktop identifier to obtain the cloud desktop login password. Before executing step 202, the cloud server must initialize the cloud desktop and establish the required login content (including the security module, cloud desktop identifier, and login password) based on the request. In one feasible implementation, a cloud desktop initialization request is received from a user terminal, a cloud desktop system and a security module are allocated to the user terminal based on the cloud desktop initialization request, a login password and a cloud desktop identifier are generated for the cloud desktop system, the cloud desktop identifier is stored, and the generated login password is encrypted by the security module to obtain a ciphertext, which is then sent to the user terminal.In this embodiment, the cloud desktop system is an operating system similar to Windows and Linux, typically consisting of a CPU and memory. Therefore, the cloud desktop initialization request can carry the CPU and memory specifications required by the user terminal. The cloud server then assigns the cloud desktop system to the user terminal based on the required CPU and memory specifications. A security module with cryptographic algorithm computing capabilities is also established for the cloud desktop system. A key is embedded in the security module, which is inaccessible to the outside world and is used exclusively by the security module for encryption and decryption. The cryptographic algorithm used in the security module performs encryption and decryption operations. Specifically, upon initial use, it encrypts the login password and outputs the ciphertext of the login password. Upon subsequent use, it decrypts the ciphertext and outputs the login password. The login password is the login credential for the cloud desktop system and is dynamically generated by the cloud server based on information about the assigned cloud desktop system. The cloud desktop identifier uniquely identifies the cloud desktop and can be stored in the cloud server's management and control service, allowing user terminals to obtain information about the cloud desktop they wish to connect to from the management and control service. As previously mentioned, the cloud desktop identifier can be represented by the cloud desktop system's access address and port information, or by separately defined identification information. In this embodiment, given that each cloud desktop requires a corresponding security module, a virtualized software module can be used on the cloud server to implement the security module's capabilities, reducing hardware costs. Thus, on the cloud server, each cloud desktop has a corresponding security module to manage login passwords. However, this security module does not directly store login passwords. Instead, it uses cryptographic algorithms to convert login passwords to ciphertext and vice versa. Furthermore, each cloud desktop is managed by a single security module, thus reducing the risk of data leakage and providing higher security. It should be noted that an anti-brute force cracking mechanism can be pre-configured in the cloud server's security module. Specifically, if the security module detects a preset number of login password attempts within a preset timeframe, it will lock the login password, further enhancing cloud desktop login security. That is to say, if the ciphertext of the login password is intercepted, someone uses a dedicated cracking device to generate a large number of login passwords based on this ciphertext, and then encrypts these login passwords in sequence through the security module and outputs the ciphertext. The ciphertext output by the security module is compared with the intercepted ciphertext. If the comparison is consistent, it means that the brute force cracking is successful. Therefore, by detecting that the security module has received multiple login password encryption attempts, the security module is locked to protect the login process from brute force cracking.Based on the above implementation, the decryption process of the ciphertext in the cloud desktop connection request is performed by obtaining a security module corresponding to the cloud desktop identifier. This security module then decrypts the ciphertext using a locally preset key and cryptographic algorithm, thereby obtaining the cloud desktop login password. Step 203: The cloud desktop login password is used to log in to the cloud desktop system corresponding to the cloud desktop identifier, and the interface data of the cloud desktop system is sent to the user terminal. In this step, the cloud server calls the cloud desktop service and passes in the login password and cloud desktop identifier to log in to the cloud desktop system. Simultaneously, the cloud desktop system interface data is sent to the user terminal in real time, allowing the user to remotely access the cloud desktop system from the terminal. This completes the cloud desktop login process shown in Figure 2. By introducing a security module into the cloud desktop on the cloud server and managing the corresponding cloud desktop login in the security module, the cloud desktop login password is prevented from being stored in the cloud database and leaked. Furthermore, the security module introduced for cloud desktops is based on cryptographic computing power, rather than directly storing the cloud desktop login password. That is, when the cloud server receives a cloud desktop connection request, it uses its own cryptographic computing power to decrypt the ciphertext carried in the request through the security module corresponding to the cloud desktop being connected, obtaining the login password used to log in to the cloud desktop. This introduced security module is equivalent to a one-machine, one-key system, which reduces the risk of the cloud desktop being used by others and ensures the security and reliability of cloud desktop login. Example 2: Figure 3 is a flow chart illustrating another cloud desktop login method according to an exemplary embodiment. This embodiment uses a user terminal as the execution subject and primarily describes the operational process of the user terminal. The user terminal can be any internet-connected device, such as a computer or tablet. As shown in Figure 3, the cloud desktop login method includes the following steps: Step 301: If the received local password is successfully verified, obtain the cloud desktop identifier of the cloud desktop to be connected. In this step, the local password is the user terminal's login credential for the local cloud desktop client. Therefore, only after the local password verification is successful and the local cloud desktop client login is completed can a remote cloud desktop connection be established. As previously mentioned, cloud desktop identifiers are managed by the cloud server's management and control service. Based on this, the user terminal can send a desktop connection credential request to the cloud server, which in turn returns the user terminal's cloud desktop identifier based on the desktop connection credential request. Before executing step 301, the user terminal must have previously established login credentials for the local cloud desktop client and completed cloud desktop initialization.In one feasible implementation, a local password entered by a user for logging into a cloud desktop client for the first time is received. A preset security module calculates a hash value based on the local password and stores the hash value in a hash table. A cloud desktop initialization request is then sent to the cloud server, and the ciphertext returned by the cloud server for logging into the cloud desktop is received and stored. In this implementation, the local password used to log into the cloud desktop client can be in the form of a username and password, or biometric information such as fingerprint or facial information. This local password is a login credential that the user needs to remember and is managed by the security module installed on the user terminal. To ensure security, the security module uses a hash algorithm to calculate the hash value of the local password and stores it in a locally maintained hash table for verification and matching with the password entered by the user. In addition to recording the hash value of the local password pre-set by the user for logging into the cloud desktop client, the hash table in the security module also contains other hash values ​​on the user terminal that require secure use, such as hash values ​​used for disk reading and writing. Furthermore, when calculating hash values, the security module can not only reference the local password but also the user terminal's terminal information to enhance login security. When initializing a cloud desktop, the user terminal can include the required CPU and memory metrics in the cloud desktop initialization request, facilitating the cloud server's allocation of an appropriate cloud desktop system. The ciphertext is obtained by encrypting the cloud desktop login password using the security module corresponding to the cloud desktop. For the user terminal, this serves as the connection credential for the cloud desktop and therefore needs to be stored locally on the terminal for use when connecting to the cloud desktop. In this embodiment, considering that the local password on the terminal side can be handled by a single security module, the user terminal can utilize a hardware-based module to implement the security module's capabilities. With the advancement of user terminal technology, terminal hardware often includes a TPM security chip to protect data on the terminal. Therefore, the TPM security chip on the user terminal can be used to manage local passwords. Based on the above implementation, regarding the local password verification process, upon receiving the local password entered by the user to log in to the cloud desktop client, the received local password is verified by the pre-set security module. The security module's verification process is as follows: First, the local password's hash value is determined. The hash value is then matched against a stored hash list. If a hash value matches, the local password verification is considered successful. If a hash value does not match, the local password verification is considered failed.It should be noted that the security module on the user terminal can also be configured with a pre-set anti-brute force cracking mechanism. Specifically, if the security module detects that a local password has been received a preset number of times within a preset time range, a lock operation is executed, further enhancing the security of cloud desktop login. Step 302: Send a cloud desktop connection request carrying the cloud desktop identifier and locally stored ciphertext to the cloud server. In this step, after obtaining the cloud desktop identifier to connect to, the user terminal generates a cloud desktop connection request based on the cloud desktop identifier and locally stored ciphertext and sends it to the cloud server, enabling the cloud server to perform cloud desktop login. Step 303: Display the cloud desktop system interface data returned by the cloud server. In this step, the user terminal displays the cloud desktop system interface data returned by the cloud server in real time, allowing the user to operate the remote cloud desktop system. Based on the above-described second embodiment, the terminal stores the ciphertext of the cloud desktop login password. This ciphertext is obtained by encrypting the cloud desktop login password using the cloud server's security module corresponding to the cloud desktop. Therefore, when a user terminal logs in to the cloud desktop, it first verifies the local password entered by the user and completes the local login. The terminal then sends the obtained cloud desktop identifier and the locally stored ciphertext along with the cloud desktop connection request to the cloud server, allowing the cloud server to perform the cloud desktop login operation and display the cloud desktop system interface transmitted back by the cloud server. Since the terminal maintains the ciphertext of the cloud desktop login password, even if it is leaked, others cannot easily log in and use the cloud desktop. This requires further decryption of the ciphertext, which requires decryption using the cloud server's one-machine-one-key security module. This makes it difficult for someone who steals the ciphertext to obtain the password. Therefore, the present disclosure can ensure the security and reliability of cloud desktop login. It should be noted that all user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, storage, and display, etc.) referred to in this disclosure are authorized by the user or fully authorized by all parties. The collection, use, and processing of such data must comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding access points are provided for users to choose to authorize or deny such access. Corresponding to the aforementioned cloud desktop login method embodiment, this disclosure also provides an embodiment of a cloud desktop login system, which includes a user terminal and a cloud server. The user terminal is used to execute the process of the embodiment shown in Figure 3, and the cloud server is used to execute the process of the embodiment shown in Figure 2. Based on the embodiments shown in Figures 2 and 3, the cloud desktop login process is described in detail below using a multi-terminal interactive approach.Figure 4 shows a multi-terminal interaction diagram for cloud desktop login, according to an exemplary embodiment. On the user terminal side, this involves the cloud desktop client and security module. On the cloud server side, this involves the management and control service, the cloud desktop service, and the cloud desktop security module. A complete cloud desktop login implementation involves two phases: cloud desktop initialization and cloud desktop login. During the cloud desktop initialization phase: the user enters the initial local password on the login interface of the cloud desktop client. The local password is the local login credential set by the user. The cloud desktop client sends the local password to the security module of the user terminal; the security module of the user terminal calculates the hash value of the local password and stores it locally for subsequent verification and matching, and returns a successful setting notification to the cloud desktop client; after receiving the successful setting notification, the cloud desktop client sends a cloud desktop initialization request to the cloud desktop service through the management and control service; the cloud desktop service allocates a cloud desktop system and security module based on the cloud desktop initialization request, generates a login password and cloud desktop identifier for the cloud desktop system, and sends the cloud desktop identifier to the management and control service for storage. At the same time, the cloud desktop service sends the login password to the assigned security module; the security module uses a preset key and cryptographic algorithm to encrypt the login password to obtain a ciphertext, and returns the ciphertext to the cloud desktop client on the user terminal through the management and control service. During the cloud desktop login phase: When the user needs to access the cloud desktop remotely, he opens the cloud desktop client on the user terminal and enters the local password set in the initialization phase. The cloud desktop client sends the received local password to the security module on the user terminal for verification; the security module on the user terminal calculates the hash value of the local password and matches the hash value in the local hash list. When the hash value is matched, a verification success notification is returned to the cloud desktop client; the cloud desktop client completes the local login and sends a desktop connection credential request to the management and control service on the cloud server; the management and control service obtains the cloud desktop identifier of the user terminal based on the desktop connection credential request, and returns the obtained cloud desktop identifier to the cloud desktop client; the cloud desktop client generates a cloud desktop connection request based on the cloud desktop identifier and the locally stored ciphertext and sends it to the cloud desktop service on the cloud server; the cloud desktop service sends the ciphertext to the security module corresponding to the cloud desktop identifier; the security module corresponding to the cloud desktop identifier uses the locally preset key and cryptographic algorithm to decrypt the ciphertext, obtains the cloud desktop login password and outputs it. The cloud desktop service uses the cloud desktop login password to log in to the cloud desktop system corresponding to the cloud desktop identifier and sends the interface data of the cloud desktop system to the user terminal, completing the cloud desktop login. The disclosed embodiments also provide an electronic device corresponding to the cloud desktop login method provided in the aforementioned embodiments, for executing the aforementioned cloud desktop login method.Figure 5 is a hardware structure diagram of an electronic device according to an exemplary embodiment. The electronic device includes a communication interface 601, a processor 602, a memory 603, and a bus 604. The communication interface 601, processor 602, and memory 603 communicate with each other via bus 604. Processor 602 executes the cloud desktop login method described above by reading and executing machine-executable instructions corresponding to the control logic of the cloud desktop login method in memory 603. The details of this method are described in the above embodiments and are not repeated here. The memory 603 referred to in this disclosure can be any electronic, magnetic, optical, or other physical storage system and can contain stored information such as executable instructions, data, and so on. Specifically, memory 603 can be RAM (Random Access Memory), flash memory, a storage drive (such as a hard drive), any type of storage disk (such as an optical disk, DVD, etc.), or similar storage media, or a combination thereof. The system network element and at least one other network element are connected via at least one communication interface 601 (which may be wired or wireless). The Internet, wide area network, local area network, metropolitan area network, etc. may be used. Bus 604 may be an ISA bus, a PCI bus, or an EISA bus. Such buses may be classified as address buses, data buses, control buses, etc. Memory 603 is used to store programs, and processor 602 executes the programs upon receiving execution instructions. Processor 602 may be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above method may be completed by hardware integrated logic circuits or software instructions within processor 602. Processor 602 may be a general-purpose processor, including a network processor (NP), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf field programmable gate array (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. These processors may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present disclosure. The general processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the embodiments of the present disclosure may be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor.The electronic device provided in the embodiments of the present disclosure and the cloud desktop login method provided in the embodiments of the present disclosure are based on the same inventive concept and have the same beneficial effects as the methods employed, executed, or implemented therein. The embodiments of the present disclosure also provide a computer-readable storage medium corresponding to the cloud desktop login method provided in the aforementioned embodiments. Referring to FIG6 , the computer-readable storage medium shown is an optical disc 30 storing a computer program (i.e., a program product). When executed by a processor, the computer program executes the cloud desktop login method provided in any of the aforementioned embodiments. It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other optical or magnetic storage media, and these are not described in detail here. The computer-readable storage medium provided in the aforementioned embodiments of the present disclosure and the cloud desktop login method provided in the embodiments of the present disclosure are based on the same inventive concept and have the same beneficial effects as the methods employed, executed, or implemented by the application programs stored therein. Those skilled in the art will readily envision other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only; the true scope and spirit of the present disclosure are indicated by the following claims. It should also be noted that the terms "comprise," "comprising," or any other variations thereof are intended to encompass a non-exclusive inclusion, such that a process, method, product, or apparatus comprising a list of elements may include not only those elements but also other elements not expressly listed, or elements inherent to such process, method, product, or apparatus. Without further limitation, the phrase "comprising a..." does not preclude the presence of additional identical elements in the process, method, product, or apparatus comprising the recited elements. The above description is merely a preferred embodiment of the present disclosure and is not intended to limit the present disclosure. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present disclosure shall be included in the scope of protection of the present disclosure.

Claims

Claims 1. A cloud desktop login method, applied to a cloud server, comprising: Receiving a cloud desktop connection request sent by a user terminal, wherein the cloud desktop connection request carries a ciphertext of a cloud desktop login password and a cloud desktop identifier; The ciphertext is decrypted by a security module corresponding to the cloud desktop identifier to obtain a cloud desktop login password; the cloud desktop system corresponding to the cloud desktop identifier is logged in using the cloud desktop login password, and the interface data of the cloud desktop system is sent to the user terminal.

2. The method according to claim 1, wherein: Before decrypting the ciphertext through the security module corresponding to the cloud desktop identifier, the method also includes: receiving a cloud desktop initialization request from a user terminal; allocating a cloud desktop system and a security module to the user terminal based on the cloud desktop initialization request, generating a login password and a cloud desktop identifier for the cloud desktop system, and storing the cloud desktop identifier; encrypting the login password through the security module to obtain a ciphertext, and sending the ciphertext to the user terminal.

3. The method according to any one of claims 1 to 2, wherein: The method further includes: detecting, by the security module, that a login password is received a preset number of times within a preset time range, and executing a locking operation.

4. A cloud desktop login method, wherein: Applied to a user terminal, the method includes: obtaining a cloud desktop identifier to be connected to the cloud desktop when the received local password verification succeeds; sending a cloud desktop connection request carrying the cloud desktop identifier and a locally stored ciphertext to a cloud server; the ciphertext is obtained by encrypting the cloud desktop login password by the cloud server using a security module corresponding to the cloud desktop; and displaying interface data of the cloud desktop system returned by the cloud server.

5. The method according to claim 4, wherein: The local password verification process includes: receiving a local password input by a user for logging into a cloud desktop client; and verifying the local password through a preset security module.

6. The method according to claim 5, wherein: The verifying the local password by using a preset security module includes: determining a hash value of the local password, matching the hash value with a stored hash list, the hash list containing hash values ​​of local passwords preset by a user; if the hash value is matched, determining that the local password verification is successful; if the hash value is not matched, determining that the local password verification fails.

7. The method according to claim 4, wherein: The cloud desktop label to be connected to the cloud desktop is obtained Identification, including: sending a desktop connection credential request to a cloud server; and receiving a cloud desktop identifier returned by the cloud server.

8. The method according to claim 4, wherein: Before verifying the local password, the method also includes: receiving the local password entered by the user for the first time to log in to the cloud desktop client; calculating a hash value based on the local password through a preset security module, and storing the hash value in a hash list; sending a cloud desktop initialization request to the cloud server, receiving a ciphertext returned by the cloud server for logging in to the cloud desktop, and storing the ciphertext.

9. The method according to any one of claims 5, 6 and 8, wherein: The method further includes: detecting, by the security module, that a local password is received a preset number of times within a preset time range, and executing a locking operation.

10. A cloud desktop login system, the system comprising: User terminal, used to execute the method according to any one of claims 4 to 9; A cloud service end, used to execute the method described in any one of claims 1-3.

11. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method according to any one of claims 1 to 9.

12. A computer-readable storage medium having a computer program stored thereon, wherein the program is executed by a processor to implement the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Identity authentication method and system for cloud computing desktop terminal

    CN102857522A

  • A Trusted Security Enhancement Method in a Desktop Virtualization Environment

    CN103747036B

  • A virtual desktop security authentication system and method for multiple security levels.

    CN103780393B

  • Virtualization technology-based cloud computing security terminal

    CN104125251A

  • Remote distribution method and system for terminal master keys

    CN108513704B